Wireless Trust Metric for Malicious Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current LTE wireless communication networks assume a trustworthy network side, but femtocells, which can be operated by individuals, are vulnerable to malicious actors who can modify them for traffic interception or denial of service attacks, or extract cryptographic keys to impersonate legitimate infrastructure.
Innovation Solution
Determining a trust metric for each access point to assess its trustworthiness, allowing user equipment (UE) to avoid communicating with untrustworthy access points by categorizing them into trust categories and modifying measurement reports to prioritize handovers to more trustworthy access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If femtocells are deployed to improve indoor signal quality and coverage, then service reliability and user experience are improved, but the risk of malicious infrastructure attacks increases
Solution Approach 1:
The system performs preliminary trust assessments of access points before allowing connections. Trust metrics are calculated in advance based on multiple factors including signal characteristics, location information, and historical data, enabling UEs to proactively avoid malicious femtocells before establishing communication
Solution Approach 2:
A trust metric calculation mechanism acts as an intermediary between the UE and access points. This intermediary evaluates the trustworthiness of access points using multiple parameters and provides a trust score that mediates the connection decision, preventing direct exposure to malicious infrastructure
2Reliability
If trust metric calculation and verification mechanisms are implemented to protect against malicious access points, then security against malicious infrastructure is improved, but device complexity and processing overhead increase
Solution Approach 1:
The trust assessment system is segmented into multiple independent components: signal strength analysis, location verification, historical behavior tracking, and trust metric calculation. Each component operates independently and contributes to the overall trust score, making the system manageable and scalable
Solution Approach 2:
The system uses parameter changes in the trust metric calculation based on different scenarios. The weight of different trust factors can be dynamically adjusted based on network conditions, UE capabilities, and security requirements, allowing the system to adapt complexity to actual needs
3Measurement precision
If UEs continuously monitor and assess trust metrics for all accessible access points, then detection precision of malicious infrastructure is improved, but energy consumption and processing time increase
Solution Approach 1:
The system performs partial trust assessments by focusing on the most critical trust factors first. If initial quick checks indicate high trustworthiness, detailed assessment is skipped. This partial action approach maintains detection precision for malicious APs while reducing energy consumption for legitimate ones
Solution Approach 2:
The trust assessment process can be skipped or rushed through for access points that pass initial screening criteria. Once a UE establishes trust in an access point through initial assessment, subsequent assessments are minimized or skipped, allowing rapid movement through trusted networks while maintaining security
Data Source
Figure 1
Figure 2
Figure 3
AI summary
System, apparatus, and methods are provided for protecting against malicious infrastructure in a wireless communication network. A system determines a trust metric for an access point and decides to avoid communication with the access point based on the trust metric for the access point. The trust metric may, for example, be a numeric value such as a probability of trustworthiness or a categorization of trustworthiness. The system may determine the trust metric by receiving a list of access points and their corresponding trust metrics and matching a potential access point to its listed trust metric. The system may try to avoid using an untrustworthy access point's services unless it deems the services important enough to risk the communication.