US 12,010,650 B2
FBS redirection attack method using unicast message injection in LTE and the system thereof
Yongdae Kim, Daejeon (KR); CheolJun Park, Daejeon (KR); Hojoon Yang, Daejeon (KR); Sangwook Bae, Daejeon (KR); Mincheol Son, Daejeon (KR); Jiho Lee, Daejeon (KR); and Hongil Kim, Daejeon (KR)
Assigned to Korea Advanced Institute of Science and Technology, Daejeon (KR)
Filed by Korea Advanced Institute of Science and Technology, Daejeon (KR)
Filed on Oct. 15, 2021, as Appl. No. 17/451,123.
Claims priority of application No. 10-2020-0133927 (KR), filed on Oct. 16, 2020; and application No. 10-2020-0169702 (KR), filed on Dec. 7, 2020.
Prior Publication US 2022/0124673 A1, Apr. 21, 2022
Int. Cl. H04W 68/02 (2009.01); H04W 56/00 (2009.01)
CPC H04W 68/02 (2013.01) [H04W 56/001 (2013.01)] 6 Claims
OG exemplary drawing
 
1. A fake base station (FBS) redirection attack method using unicast message injection in a long term evolution (LTE) wireless section, the FBS redirection attack method comprising:
synchronizing a fake base station (FBS) with a signal of a commercial base station connected with a target device being an attack target;
transmitting an international mobile subscriber identity (IMSI) paging message from the FBS to the target device using an IMSI of the target device; and
injecting a unicast message from the FBS including a frequency of the FBS into the target device, before a base station re-access process is completed in the target device which decodes the IMSI paging message,
wherein the synchronizing includes synchronizing with the signal of the commercial base station, in a state where security activation between the target device and the commercial base station is completed,
wherein the injecting of the unicast message includes injecting the unicast message of a radio resource control (RRC) connection release message, before the target device completes a process of re-accessing a base station, and wherein the target device processes the RRC connection release message of plain text, deletes the security context, and requests access from the FBS,
wherein the RRC connection release message includes an IdleModeMobilityControlInfo (IMMCI) field for delivering connection priorities of cells when the target device reselects a cell and a redirectedCarrierInfo field for connecting a user with a specific cell and includes a frequency and an evolved absolute radio frequency channel number (EARFCN) of the FBS in the field.