Dynamic service handling using a honeypot
US-9838427-B2 · Dec 5, 2017 · US
US2020236554A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2020236554-A1 |
| Application number | US-202016743927-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 15, 2020 |
| Priority date | Jan 18, 2019 |
| Publication date | Jul 23, 2020 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods, systems, and devices for wireless communications are described. In some systems, devices may use information protection to detect fake base stations. A base station verified by a network may transmit first information to a user equipment (UE) in an unprotected message. If a fake base station intercepts and modifies the message before relaying the message to the UE, the UE may receive different information than the transmitted first information. The UE may then transmit an indication of the received information to the verified base station in a protected message. In some cases, based on the indication, the verified base station may re-transmit the first information to the UE in a message protected against modification by the fake base station. If the UE determines that the initially received information is different from the information received in the protected retransmission, the UE identifies message modification by the fake base station.
Opening claim text (preview).
What is claimed is: 1 . A method for wireless communications at a user equipment (UE), comprising: receiving, from a base station, a first set of information associated with communicating with a network, wherein the first set of information lacks protection via ciphering, integrity protection, or a combination thereof; transmitting, to the base station, an indication of the first set of information, wherein the indication is protected via ciphering, integrity protection, or a combination thereof; determining authenticity of the first set of information based at least in part on whether a second set of information associated with communicating with the network is received from the base station that is different from the first set of information; and communicating with the network based at least in part on the determining. 2 . The method of claim 1 , further comprising: receiving, from the base station, the second set of information, wherein the second set of information is protected via ciphering, integrity protection, or a combination thereof and comparing the second set of information with the first set of information, wherein the determining is based at least in part on the comparing. 3 . The method of claim 2 , wherein the second set of information is received in a radio resource control re-configuration message. 4 . The method of claim 1 , wherein: the first set of information comprises a first master information block, a first set of system information blocks, or a combination thereof and the second set of information comprises a second master information block, a second set of system information blocks, or a combination thereof. 5 . The method of claim 1 , wherein the indication comprises a hash value based at least in part on the first set of information and a system frame number value associated with the first set of information, the method further comprising: receiving, from the base station, the second set of information if the second set of information is different from the first set of information. 6 . The method of claim 1 , wherein the indication comprises a request for the second set of information, the method further comprising: receiving, from the base station, the second set of information based at least in part on the request for the second set of information. 7 . The method of claim 1 , wherein: the UE comprises an unregistered UE without a valid non-access stratum security context; and the indication of the first set of information is transmitted in an access stratum security mode complete message. 8 . The method of claim 1 , further comprising: receiving a UE-specific key for an initial access stratum message, wherein the UE-specific key is based at least in part on one or more identifiers of the UE. 9 . The method of claim 8 , wherein the UE comprises a registered UE with a valid non-access stratum security context, and wherein transmitting the indication of the first set of information comprises: security protecting the indication of the first set of information based at least in part on the UE-specific key, wherein the security protecting comprises encrypting the indication of the first set of information, integrity protecting the indication of the first set of information, or a combination thereof 10 . The method of claim 9 , wherein security protecting the indication of the first set of information based at least in part on the UE-specific key further comprises: deriving a temporary encryption key for the initial access stratum message based at least in part on the UE-specific key, a pseudo-random number, an algorithm identifier, or a combination thereof; encrypting the indication of the first set of information using the temporary encryption key and a system frame number value associated with the first set of information; and transmitting, to the base station, an indication of the system frame number value and the pseudo-random number, the algorithm identifier, or a combination thereof. 11 . The method of claim 9 , further comprising: receiving an updated UE-specific key for the initial access stratum message, wherein the updated UE-specific key is based at least in part on the one or more identifiers of the UE, a key index, or a combination thereof 12 . The method of claim 9 , wherein the indication of the first set of information is transmitted in a radio resource control connection message. 13 . The method of claim 8 , further comprising: receiving a key index value associated with the UE-specific key; and transmitting the key index value with the indication of the first set of information. 14 . The method of claim 8 , further comprising: detecting an additional base station; transmitting, to the additional base station, an initial radio resource control connection setup message indicating detection of the additional base station, wherein the initial radio resource control connection setup message is security protected based at least in part on the UE-specific key; and determining whether the additional base station is an authorized base station of the network based at least in part on the initial radio resource control connection setup message. 15 . The method of claim 8 , wherein the one or more identifiers of the UE comprise a globally unique temporary identity, a serving temporary mobile subscriber identity, a temporary mobile subscriber identity, or a combination thereof 16 . The method of claim 8 , wherein the UE-specific key is received in a secure non-access stratum message. 17 . The method of claim 1 , wherein: the determining comprises determining that the first set of information is authentic; and the communicating comprises communicating with the network via the base station based at least in part on the determining that the first set of information is authentic. 18 . The method of claim 1 , wherein: the determining comprises determining that the first set of information is inauthentic; and the communicating comprises: detaching from the base station based at least in part on the determining that the first set of information is inauthentic; reattaching to an additional base station; and communicating with the network via the additional base station. 19 . The method of claim 18 , further comprising: reporting, to the additional base station, an identity of the base station, at least a portion of the first set of information, or a combination thereof based at least in part on the determining that the first set of information is inauthentic. 20 . The method of claim 1 , further comprising: receiving, from the base station, an indication that security protection for the first set of information is enabled, wherein the indication is received in a non-access stratum security mode command message. 21 . The method of claim 1 , wherein the indication of the first set of information is integrity protected. 22 . A method for wireless communications at a base station, comprising: transmitting, to a user equipment (UE), a first set of information associated with communicating with a network, wherein the first set of information lacks protection via ciphering, integrity protection, or a combination thereof; receiving, from the UE, an indication of a second set of information received at the UE and associated with communicating with the network, wherein the indication is protected via integrity protection; determining whether to re-transmit, to the U
Protecting confidentiality, e.g. by encryption · CPC title
Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS] · CPC title
Counter-measures against attacks; Protection against rogue devices · CPC title
Connection setup · CPC title
Integrity · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.