Fake base station detection

US11503472B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11503472-B2
Application numberUS-201716614787-A
CountryUS
Kind codeB2
Filing dateMay 31, 2017
Priority dateMay 31, 2017
Publication dateNov 15, 2022
Grant dateNov 15, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A mobile device collects received information and processes it. In some instances, the mobile device detects, based on the collected information, that a base station is likely not legitimate, i.e., it is likely a fake base station, and the mobile device bars communication with the base station for a time. In some embodiments, the mobile device determines, based on the received information, that the base station is a genuine base station. When the mobile device determines that the base station is a genuine base station or the mobile device does not determine that it is likely the base station is a fake base station, the mobile device allows or continues communication with the base station.

First claim

Opening claim text (preview).

What is claimed is: 1. A mobile device comprising: wireless circuitry; and at least one processor communicatively coupled to the wireless circuitry and to a memory storing instructions that, when executed on the at least one processor, cause the mobile device to: allow communication with a base station after determining one or more conclusive indications that the base station is genuine; and bar communication with the base station for a time period after i) determining no conclusive indications that the base station is genuine, and ii) determining occurrence of at least one condition indicating the base station is likely fake, wherein the at least one condition includes receiving from the base station at least two consecutive paging channel messages, each paging channel message including identical address values. 2. The mobile device of claim 1 , wherein a conclusive indication comprises: i) observation of a base station message associated with authentication capability or associated with packet data capability, ii) observation of system information indicating the base station has packet data capability, or iii) observation of a command shifting the mobile device to a second base station without interrupting a call. 3. The mobile device of claim 1 , wherein a conclusive indication includes observation of one or more of: 1) a 3GPP Long Term Evolution (LTE) message accepting an update of a logical group of base stations that the mobile device belongs to in a serving network, 2) an LTE message with an integrity-check field that the mobile device is able to verify with an integrity key, or 3) an LTE message via a short message service (SMS) service center (SMS-SC) coincident with reception of an LTE message routed through a gateway general packet radio service (GPRS) support node (GGSN). 4. The mobile device of claim 1 , wherein a conclusive indication includes observation of one or more of: 1) a Global System for Mobile Communications (GSM) message indicating that packet service parameters are available in a system information (SI) transmission, or 2) a GSM message providing a second temporary identifier to replace a first temporary identifier in order to protect against the mobile device being identified and located by a malicious party. 5. The mobile device of claim 1 , wherein execution of the instructions further cause the mobile device to: determine a first score based on one or more traits of a fake base station, wherein the one or more traits of the fake base station include: i) a cell selection minimum received signal level that is more than 10 dB less than a previously measured cell selection signal level of a genuine base station, ii) system information indicating that packet data service is not supported, or iii) reception of a message rejecting a rudimentary request from the mobile device such as a location area update; and compare the first score with a first threshold to determine whether the base station is likely fake. 6. The mobile device of claim 5 , wherein execution of the instructions further cause the mobile device to: compare a second score with a second threshold when the comparison using the first score does not indicate the base station is likely fake; and bar communication with the base station for the time period when the comparison using the second score indicates the base station is likely fake. 7. The mobile device of claim 6 , wherein: the second score is based on one or more traits of a fake base station, and the one or more traits of the fake base station include: i) observation that the base station supports only one radio frequency carrier, or ii) reception of a date-stamped message with a date not matching a current date. 8. The mobile device of claim 5 , wherein execution of the instructions further cause the mobile device to: receive system information to produce received system information; apply a first set of conditions to the received system information to produce a first set of satisfied conditions; and determine the first score as a first number of elements in the first set of satisfied conditions. 9. The mobile device of claim 8 , wherein the first set of conditions includes observation of 3GPP Long Term Evolution (LTE) system information indicating a cell selection minimum received signal level that is more than 10 dB less than a previously measured cell selection signal level of a genuine base station. 10. A method comprising: by a mobile device: determining a first signature component associated with a first base station; determining a first score associated with the first base station; determining a second signature component associated with a second base station; determining a second score associated with the second base station; receiving a user message from the second base station; when the first signature component indicates the first base station is trustworthy and the second signature component indicates that the second base station is trustworthy, providing the user message to a user of the mobile device; when a combination based at least in part on the first score and the second score indicates that the first base station or the second base station is untrustworthy, discarding the user message; and when the combination does not indicate that the first base station or the second base station is untrustworthy, providing the user message to the user of the mobile device. 11. The method of claim 10 , wherein the first signature component comprises: i) observation of a base station message associated with authentication capability or associated with packet data capability, ii) observation of system information indicating the first base station has packet data capability, or iii) observation of a command shifting the mobile device to the second base station without interrupting a call. 12. The method of claim 10 , wherein the first score and the second score are based on one or more traits of a fake base station. 13. The method of claim 12 , wherein the one or more traits of a fake base station include: i) a cell selection minimum received signal level that is more than 10 dB less than a previously measured cell selection signal level of a genuine base station, ii) observation of a redundant address on a paging channel, iii) system information indicating that packet data service is not supported, iv) reception of a message rejecting an attempt by the mobile device to update a logical group of cells that the mobile device is associated with, v) observation that only one radio frequency carrier is supported, or vi) reception of a date-stamped message with a date not matching a current date. 14. A mobile device comprising: wireless circuitry; and at least one processor communicatively coupled to the wireless circuitry and to a memory storing instructions that, when executed on the at least one processor, cause the mobile device to: listen to a first base station to acquire first information; test the first information to obtain a first score; when the first score indicates that the first base station is not trustworthy: place an identifier of the first base station on an untrusted list, and discontinue listening to the first base station; when the first score does not indicate that the first base station is not trustworthy: receive a first message from the first base station, wherein the first message includes an identifier of a first frequency channel, and listen to a second base station at the first frequency channel to acquire second information, wherein the first score indicates that the first

Assignees

Inventors

Classifications

  • Time-dependent · CPC title

  • Source integrity · CPC title

  • H04W12/66Primary

    Trust-dependent, e.g. using trust scores or trust relationships · CPC title

  • H04W12/122Primary

    Counter-measures against attacks; Protection against rogue devices · CPC title

  • Detection or prevention of fraud · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11503472B2 cover?
A mobile device collects received information and processes it. In some instances, the mobile device detects, based on the collected information, that a base station is likely not legitimate, i.e., it is likely a fake base station, and the mobile device bars communication with the base station for a time. In some embodiments, the mobile device determines, based on the received information, that…
Who is the assignee on this patent?
Apple Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/66. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 15 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).