IP Library Granted Patent US 11,638,152
Granted Patent B2
US 11,638,152 · App. 16/699,075 · Granted Apr 25, 2023

Identifying an illegitimate base station based on improper response

Inventors: Xuepan Guan (San Diego, CA); Subrato Kumar De (San Diego, CA); Nitin Pant (San Diego, CA); Mattias Kaulard Huber (Solana Beach, CA); Krishna Ram Budhathoki (San Diego, CA); Ankur Bhattacharjee (San Diego, CA)
Assignee: QUALCOMM Incorporated
H04W12/122H04W8/26H04W12/06H04W12/30H04W60/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,638,152
App. No.
16/699,075
Granted
Apr 25, 2023
Kind
B2
Abstract

Various embodiments include methods, components and wireless devices configured to identify illegitimate base station. The processor of the wireless device may determine that a device in communication with the wireless device is a suspect base station. The processor may send a fabricated message to the device, and may receive one or more response messages from the device. The processor may determine whether one or more of the response messages received from the device is an appropriate response or an inappropriate response to the fabricated message. In response to determining that a response message is an inappropriate response, the processor may determine that the device is an illegitimate base station. In response to determining that the device is an illegitimate base station, the wireless device may perform a protective action.

Claims (120)

1. A method of identifying an illegitimate base station performed by a processor of a wireless device, comprising:

sending a fabricated message containing content that is falsified, garbled or otherwise improper to a device in communication with the wireless device in response to determining that the device is a suspect base station;

receiving a response message from the device;

determining whether the response message is an appropriate response or an inappropriate response to the fabricated message, wherein a determination that the response message is an appropriate response is based on a determination that the device has identified the fabricated message as containing content that is falsified, garbled or otherwise improper, and a determination that the response message is an inappropriate response is based on a determination that the device has not identified the fabricated message as containing content that is falsified, garbled or otherwise improper;

determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message; and

performing a protective action in response to determining that the device is an illegitimate base station.

2. The method of claim 1 , wherein the fabricated message comprises an area update message that includes a fabricated Temporary Mobile Subscriber Identity (TMSI).

3. The method of claim 2 , wherein the fabricated TMSI is a fabricated TMSI without integrity protection, and wherein:

an appropriate response comprises an identity request message; and

an inappropriate response comprises a message that does not include an identity request message.

4. The method of claim 1 , further comprising:

determining whether an International Mobile Subscriber Identity (IMSI) was sent to the device in response to receiving a message from the device; and

performing one or more authentication operations in response to determining that an IMSI was sent to the device,

wherein determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining that the device is an illegitimate base station in response to determining that an IMSI was not sent to the device.

5. The method of claim 4 , wherein when the message received from the device is an identity request message performing one or more authentication operations comprises:

receiving an authentication request message from the device;

determining whether the authentication request message can be verified;

determining that the device is a legitimate base station in response to determining that the authentication request message can be verified; and

determining that the device is an illegitimate base station in response to determining that the authentication request message cannot be verified.

6. The method of claim 1 , wherein:

sending the fabricated message comprises sending a service request message that includes at least one of a fabricated response (RES) value, a fabricated cipher key sequence number (CKSN), or a key set identifier (ID);

the appropriate response comprises a service reject message; and

the inappropriate response comprises a service accept message.

7. The method of claim 6 , further comprising:

determining whether an International Mobile Subscriber Identity (IMSI) was sent to the device; and

attempting to re-register with the device in response to determining that an IMSI was sent to the device,

wherein determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining that the device is an illegitimate base station in response to determining that an IMSI was not sent to the device.

8. The method of claim 7 , wherein:

sending the fabricated message to the device comprises sending an authentication response including the fabricated message;

attempting to re-register with the device comprises:

sending an attach request message to the device; and

receiving an authentication request from the device; and

determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining that the device is an illegitimate base station in response to determining that the response message includes an attach accept message,

the method further comprising determining that the device is a legitimate base station in response to determining that the response message includes an authentication reject message.

9. The method of claim 1 , further comprising:

receiving an emergency message from the device; and

sending a message invoking a service to the device;

wherein determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining whether the device is an illegitimate base station based on a response to the message invoking the service that is received from the device.

10. The method of claim 9 , further comprising:

determining that the device is a legitimate base station in response to determining that the response to the message invoking the service includes a positive response.

11. The method of claim 10 , further comprising:

performing a soft reset operation in response to determining that the device is a legitimate base station.

12. The method of claim 10 , further comprising:

simulating removal and re-insertion of a universal integrated circuit card (UICC) containing a universal SIM (USIM) card in response to determining that the device is a legitimate base station.

13. The method of claim 1 , wherein:

sending a fabricated message to the device comprises sending one or more fabricated messages to the device;

receiving a response message from the device comprises receiving more than one response from the device; and

determining whether the response message is an inappropriate response to the fabricated message comprises determining whether any one or more of the received response messages is an inappropriate response.

14. A wireless device, comprising:

a wireless transceiver; and

a processor coupled to the wireless transceiver and configured with processor-executable instructions to perform operations comprising:

sending a fabricated message containing content that is falsified, garbled or otherwise improper to a device in communication with the wireless device in response to determining that the device is a suspect base station;

receiving a response message from the device;

determining whether the response message is an appropriate response or an inappropriate response to the fabricated message, wherein a determination that the response message is an appropriate response is based on a determination that the device has identified the fabricated message as containing content that is falsified, garbled or otherwise improper, and a determination that the response message is an inappropriate response is based on a determination that the device has not identified the fabricated message as containing content that is falsified, garbled or otherwise improper;

determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message; and

performing a protective action in response to determining that the device is an illegitimate base station.

15. The wireless device of claim 14 , wherein the processor is configured with processor-executable instructions to perform operations such that sending the fabricated message to the device comprises sending an area update message that includes a fabricated Temporary Mobile Subscriber Identity (TMSI).

16. The wireless device of claim 15 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

fabricating the TMSI without integrity protection;

determining that the response message is an appropriate response in response to determining that the response message comprises an identity request message; and

determining that the response message is an inappropriate response in response to determining that the response message comprises an identity request message.

17. The wireless device of claim 14 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

determining whether an International Mobile Subscriber Identity (IMSI) was sent to the device in response to receiving a message from the device; and

performing one or more authentication operations in response to determining that an IMSI was sent to the device,

wherein the processor is configured with processor-executable instructions to perform operations such that determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining that the device is an illegitimate base station in response to determining that an IMSI was not sent to the device.

18. The wireless device of claim 17 , wherein the processor is configured with processor-executable instructions to perform one or more authentication operations in response receiving an identity request message from the device comprising:

receiving an authentication request message from the device;

determining whether the authentication request message can be verified;

determining that the device is a legitimate base station in response to determining that the authentication request message can be verified; and

determining that the device is an illegitimate base station in response to determining that the authentication request message cannot be verified.

19. The wireless device of claim 14 , wherein the processor is configured with processor-executable instructions to perform operations such that:

sending the fabricated message comprises sending a service request message that includes at least one of a fabricated response (RES) value, a fabricated cipher key sequence number (CKSN), or a key set ID;

the appropriate response comprises a service reject message; and

the inappropriate response comprises a service accept message.

20. The wireless device of claim 19 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

determining whether an International Mobile Subscriber Identity (IMSI) was sent to the device;

attempting to re-register with the device in response to determining that an IMSI was sent to the device; and

determining that the device is an illegitimate base station in response to determining that an IMSI was not sent to the device.

21. The wireless device of claim 20 , wherein the processor is configured with processor-executable instructions to perform operations such that:

sending the fabricated message to the device comprises sending an authentication response including the fabricated message;

attempting to re-register with the device comprises:

sending an attach request message to the device; and

receiving an authentication request from the device; and

determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining that the device is an illegitimate base station in response to determining that the response message includes an attach accept message,

wherein the processor is configured with processor-executable instructions to perform operations further comprising determining that the device is a legitimate base station in response to determining that the response message includes an authentication reject message.

22. The wireless device of claim 14 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

receiving an emergency message from the device; and

sending a message invoking a service to the device,

wherein the processor is configured with processor-executable instructions to perform operations such that determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining whether the device is an illegitimate base station based on a response to the message invoking the service that is received from the device.

23. The wireless device of claim 22 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

determining that the device is a legitimate base station in response to determining that the response to the message invoking the service includes a positive response.

24. The wireless device of claim 23 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

performing a soft reset operation in response to determining that the device is a legitimate base station.

25. The wireless device of claim 23 , wherein the processor is configured with processor-executable instructions to perform operations further comprising:

simulating removal and re-insertion of a universal integrated circuit card (UICC) containing a universal SIM (USIM) card in response to determining that the device is a legitimate base station.

26. The wireless device of claim 14 , wherein the processor is configured with processor-executable instructions to perform operations such that:

sending a fabricated message to the device comprises sending one or more fabricated messages to the device;

receiving a response message from the device comprises receiving more than one response from the device; and

determining whether the response message is an inappropriate response to the fabricated message comprises determining whether any one or more of the received response messages in an inappropriate response.

27. A wireless device, comprising:

means for sending a fabricated message containing content that is falsified, garbled or otherwise improper to the device a device in communication with the wireless device in response to determining that the device is a suspect base station;

means for receiving response messages from the device;

means for determining whether a response message received from the device is an appropriate response or an inappropriate response to the fabricated message, wherein a determination that the response message is an appropriate response is based on a determination that the device has identified the fabricated message as containing content that is falsified, garbled or otherwise improper, and a determination that the response message is an inappropriate response is based on a determination that the device has not identified the fabricated message as containing content that is falsified, garbled or otherwise improper;

means for determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message; and

means for performing a protective action in response to determining that the device is an illegitimate base station.

28. A non-transitory processor-readable storage medium having stored thereon processor-executable software instructions configured to cause a processor of a wireless device to perform operations for identifying an illegitimate base station, comprising:

sending a fabricated message containing content that is falsified, garbled or otherwise improper to a device in communication with the wireless device in response to determining that the device is a suspect base station;

receiving a response message from the device;

determining whether the response message is an appropriate response or an inappropriate response to the fabricated message, wherein a determination that the response message is an appropriate response is based on a determination that the device has identified the fabricated message as containing content that is falsified, garbled or otherwise improper, and a determination that the response message is an inappropriate response is based on a determination that the device has not identified the fabricated message as containing content that is falsified, garbled or otherwise improper;

determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message; and

performing a protective action in response to determining that the device is an illegitimate base station.

29. The non-transitory processor-readable storage medium of claim 28 , wherein the stored processor-executable software instructions are configured to cause the processor of the wireless device to perform operations further comprising:

determining whether an International Mobile Subscriber Identity (IMSI) was sent to the device in response to receiving a message from the device; and

performing one or more authentication operations in response to determining that an IMSI was sent to the device,

wherein the stored processor-executable software instructions are configured to cause the processor of the wireless device to perform operations such that determining that the device is an illegitimate base station in response to determining that the response message is an inappropriate response to the fabricated message comprises determining that the device is an illegitimate base station in response to determining that an IMSI was not sent to the device.

30. The non-transitory processor-readable storage medium of claim 29 , wherein the stored processor-executable software instructions are configured to cause the processor of the wireless device to perform one or more authentication operations when the message received from the device is an identity request message comprising:

receiving an authentication request message from the device;

determining whether the authentication request message can be verified;

determining that the device is a legitimate base station in response to determining that the authentication request message can be verified; and

determining that the device is an illegitimate base station in response to determining that the authentication request message cannot be verified.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE LAST INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 51567 FRAME: 395. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 4, 2020
From: GUAN, XUEPAN; DE, SUBRATO KUMAR; PANT, NITIN; HUBER, MATTIAS KAULARD; BUDHATHOKI, KRISHNA RAM; BHATTACHARJEE, ANKUR
To: QUALCOMM INCORPORATED
Reel/Frame 051800/0173 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2020
From: GUAN, XUEPAN; DE, SUBRATO KUMAR; PANT, NITIN; HUBER, MATTIAS KAULARD; BUDHATHOKI, KRISHNA RAM; BHATTACHARJE, ANKUR
To: QUALCOMM INCORPORATED
Reel/Frame 051567/0395 →
Continuity (1)
Related Publication 20210168615A1 · Jun 3, 2021