Controlling access to restricted local operator services by a user device

By comparing the MCC of PLMN ID in a 5G network and performing user confirmation, the problem of roaming user equipment accessing fake base stations is solved, and security protection for restricted local access is achieved, preventing personal information leakage and fraud.

CN114009077BActive Publication Date: 2025-07-11NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080043767.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-06-14
Filing Date
2020-05-20
Publication Date
2025-07-11
Estimated Expiration
2040-05-20

AI Technical Summary

Technical Problem

In 5G networks, when roaming user equipment performs restricted local access, the prior art is difficult to effectively prevent user equipment from connecting to fake base stations, resulting in personal information leakage and security threats.

Method used

By comparing the MCC in the PLMN ID obtained by the user equipment with the stored PLMN ID, ensuring that the user performs manual confirmation before accessing the restricted local operator services, preventing automatic connection to the fake base station, and limiting the update of the PLMN ID when the location changes, providing additional user interface verification to ensure secure access.

Benefits of technology

It effectively prevents user equipment from connecting to fake base stations, protects user personal information, enhances the security of the communication system, and prevents active attacks and fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114009077B_ABST
    Figure CN114009077B_ABST
Patent Text Reader

Abstract

An improved technique is provided for security management in a communication system, particularly with respect to accessing restricted local operator services in the case of a roaming user equipment. In one example of a user equipment in a communication system, the method includes: initiating a request to access a restricted local operator service, obtaining a network identifier including a first country code, and comparing the obtained network identifier with a stored network identifier including a second country code. Determining whether the first country code and the second country code are different. At least a first action is performed in response to an affirmative determination, and at least a second action is performed in response to a negative determination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This field generally relates to communication systems, and more specifically but not exclusively to security management within such systems. Background Art

[0002] This section presents aspects that may facilitate a better understanding of the present invention. Accordingly, statements in this section should be read from this perspective and should not be construed as an admission of what is present or not present in the prior art.

[0003] The fourth generation (4G) wireless mobile communication technology (also known as Long Term Evolution (LTE) technology) is designed to provide high-capacity mobile multimedia with high data rates, particularly for human interaction. Next-generation or fifth-generation (5G) technology is intended to be used not only for human interaction but also for machine-type communication in so-called Internet of Things (IoT) networks.

[0004] While 5G networks are intended to enable a large number of IoT services (e.g., a very large number of devices with limited capabilities) and mission-critical IoT services (e.g., requiring high reliability), improvements to legacy mobile communication services are supported in the form of enhanced mobile broadband (eMBB) services, thereby providing improved wireless Internet access for mobile devices.

[0005] In an exemplary communication system, a user equipment (5G UE in a 5G network or more generally a UE), such as a mobile terminal (subscriber), communicates via an air interface with a base station or access point of an access network (referred to as 5G AN in a 5G network). The access point (e.g., a gNB or a non-3GPP interworking function (N3IWF) or a trusted non-3GPP gateway (TNGF) or a wireless access gateway function (W-AGF) depending on the type of 5G access network: supporting New Radio (NR) defined by 3GPP, supporting untrusted non-3GPP access to 5GC, supporting trusted non-3GPP access to 5G Core (5GC) or supporting wireless access to 5GC) is illustratively part of the access network of the communication system. For example, in a 5G network, the access network is referred to as 5G AN and is described in 5G Technical Specification (TS) 23.501, V16.0.2, titled "Technical Specification Group Services and System Aspects; System Architecture for the 5G System", the disclosure of which is incorporated herein by reference in its entirety. Generally, the access point (e.g., a gNB or N3IWF or TNGF or W-AGF depending on the type of 5G access network) provides the UE with access to a core network (CN or 5GC), which then provides the UE with access to other UEs and / or data networks (such as a packet data network (e.g., the Internet)).

[0006] TS 23.501 then defines the 5G service-based architecture (SBA), which models services as network functions (NFs) that communicate with each other using Representational State Transfer Application Programming Interfaces (Restful APIs).

[0007] Furthermore, 5G Technical Specification (TS) 33.501, V15.4.0, titled "Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System" describes security management details associated with 5G networks, the disclosure of which is incorporated herein by reference in its entirety.

[0008] In any communication system, security management is an important consideration. For example, communication security when a roaming UE is requesting restricted access to a public land mobile network (PLMN) is an example of a security management issue. The security of such communication poses several challenges in existing 5G methods. Summary of the Invention

[0009] Exemplary embodiments provide improved techniques for security management in a communication system, particularly with respect to network access performed by a roaming user equipment. More specifically, one or more exemplary embodiments use a mobile country code (MCC) to provide communication security for non-subscriber user equipment seeking restricted local access to a mobile network.

[0010] For example, in one exemplary embodiment according to a user equipment, the method includes: initiating a request to access a restricted local operator service, obtaining a network identifier including a first country code, and comparing the obtained network identifier with a stored network identifier including a second country code. Determining whether the first country code and the second country code are different. At least a first action is performed in response to an affirmative determination, and at least a second action is performed in response to a negative determination.

[0011] Another exemplary embodiment is provided in the form of a non-transitory computer-readable storage medium having executable program code implemented therein, the executable program code causing a processor to perform the above steps when executed by the processor. Yet another exemplary embodiment includes an apparatus having a processor and a memory configured to perform the above steps.

[0012] These and other features and advantages of the embodiments described herein will become more apparent through the drawings and the following detailed description. Brief Description of the Drawings

[0013] Figure 1 A communication system is illustrated, with one or more exemplary embodiments implemented therewith.

[0014] Figure 2 A processing architecture of a user equipment and a network node according to an exemplary embodiment is illustrated.

[0015] Figure 3 A method for a user equipment to obtain host and system information blocks from a network according to an exemplary embodiment is illustrated.

[0016] Figure 4 Is a flowchart of a part of a method for providing security for a user equipment seeking restricted local access to a mobile network according to an exemplary embodiment.

[0017] Figure 5It is a flowchart showing another part of a method for providing security for a user equipment seeking restricted local access to a mobile network according to an illustrative embodiment. Detailed Description

[0018] Embodiments will be described herein in the context of an example communication system and associated techniques for providing security in a communication system (e.g., for a user equipment seeking restricted local access to a mobile network). However, it should be understood that the scope of the claims is not limited to the particular types of communication systems and / or processes disclosed. Embodiments may be implemented in a variety of other types of communication systems using alternative processes and operations. For example, although described in the context of a wireless cellular system utilizing 3GPP system elements (such as 3GPP Next Generation System (5G)), the disclosed embodiments may be adapted in a straightforward manner to a variety of other types of communication systems.

[0019] According to illustrative embodiments implemented in a 5G communication system environment, one or more 3GPP Technical Specifications (TS) and Technical Reports (TR) provide additional explanations of user equipment and network nodes (e.g., network elements / functions) and / or operations (such as the 3GPP TS 23.501 and 3GPP TS 33.501 cited above) that interact with one or more illustrative embodiments. Other 3GPP TS / TR documents provide other conventional details that would be implemented by a person of ordinary skill in the art. However, while the illustrative embodiments are well-suited for implementation associated with the 3GPP standards related to 5G as described above, alternative embodiments are not intended to be limited to any particular standard.

[0020] In addition, the illustrative embodiments will be explained herein in the context of the Open System Interconnection model (OSI model), which is a model that conceptually characterizes the communication functions of a communication system (such as, for example, a 5G network). The OSI model is typically conceptualized as a hierarchical stack, where a given layer serves the layer above it and is served by the layer below it. Generally, the OSI model includes seven layers, where the top layer of the stack is the application layer (layer 7), followed by the presentation layer (layer 6), session layer (layer 5), transport layer (layer 4), network layer (layer 3), data link layer (layer 2), and physical layer (layer 1). A person of ordinary skill in the art will recognize the functions and interworking of the various layers, and thus, other details of each layer will not be described herein. However, it will be recognized that while the illustrative embodiments are well-suited for implementations that utilize the OSI model, alternative embodiments are not necessarily limited to any particular communication function model.

[0021] The illustrative embodiments relate to the management of non-subscriber user equipment seeking restricted network access associated with the service-based architecture (SBA) of a 5G network. Before describing these illustrative embodiments, a general description of the main components of a 5G network will be provided below in the context of Figure 1 and Figure 2 will be described.

[0022] Figure 1 FIG. shows a communication system 100 in which the illustrative embodiments are implemented. It is to be understood that the elements shown in communication system 100 are intended to represent the main functions provided within the system, such as UE access functions, mobility management functions, authentication functions, serving gateway functions, etc. Thus, Figure 1 the boxes shown in refer to specific elements in a 5G network that provide the main functions. However, in other embodiments, other network elements may be used to implement some or all of the main functions represented. Similarly, it is to be understood that not all functions of a 5G network are depicted in Figure 1 . Rather, the functions are depicted to facilitate the explanation of the illustrative embodiments. Subsequent figures may depict some additional elements / functions.

[0023] Thus, as shown, communication system 100 includes a user equipment (UE) 102 that communicates via an air interface 103 with an access point 104 (a gNB or N3IWF or TNGF or W-AGF depending on the type of 5G access network). In some embodiments, UE 102 is a mobile station, and for example, such a mobile station may include a mobile phone, a computer, or any other type of communication device. Thus, the term "user equipment" as used herein is intended to be interpreted broadly so as to cover a variety of different types of mobile stations, subscriber stations, or more specifically communication devices, including examples such as a combination of a data card inserted into a laptop computer or other device (such as a smart phone or other cellular device). In one or more illustrative embodiments, the user equipment refers to an IoT device. Such communication devices are also intended to cover devices commonly referred to as access terminals. In other embodiments, the UE may be hosted by a home gateway that is wirelessly connected to the 5G core.

[0024] In one embodiment, the UE 102 consists of a Universal Integrated Circuit Card (UICC) part and a Mobile Equipment (ME) part. The UICC is the user-dependent part of the UE and contains at least one Universal Subscriber Identity Module (USIM) and suitable application software. The USIM securely stores the permanent subscription identifier and its associated keys for identifying and authenticating the subscriber to the access network. The ME is the user-dependent part of the UE and contains Terminal Equipment (TE) functions and various Mobile Terminal (MT) functions. The UICC can be a physical card, such as a smart card configured to be inserted into a smart card slot of the ME. The UICC can alternatively be an Embedded UICC (eUICC).

[0025] Note that in one example, the permanent subscription identifier is the International Mobile Subscriber Identity (IMSI) of the UE. In one embodiment, the IMSI is a fixed 15-bit length and consists of a 3-bit Mobile Country Code (MCC), a 3-bit Mobile Network Code (MNC), and a 9-bit Mobile Station Identification Number (MSIN). In a 5G communication system, the IMSI is referred to as the Subscription Permanent Identifier (SUPI). In the case of the IMSI as the SUPI, the MSIN provides the subscriber identity. Thus, typically only the MSIN part of the IMSI needs to be encrypted. The MNC part and the MCC part of the IMSI provide routing information used by the serving network to route to the correct home network. When the MSIN of the SUPI is encrypted, it is referred to as the Subscription Concealed Identifier (SUCI).

[0026] The access point 104 is illustratively part of the access network of the communication system 100. For example, such an access network includes a 5G system having multiple base stations and one or more associated radio network control functions. The base stations and the radio network control functions are in some embodiments logically separate entities, but in some embodiments are implemented in the same physical network element (such as, for example, a base station router or a cellular access point).

[0027] In this illustrative embodiment, the access point 104 is operatively coupled to a Mobility Management Function 106. In a 5G network, the Mobility Management Function is implemented by the Access and Mobility Management Function (AMF). In some embodiments, the Security Anchor Function (SEAF) is also implemented using the AMF, which connects the UE to the Mobility Management Function. As used herein, the Mobility Management Function is an element or function in the Core Network (CN) part of the communication system that also manages or otherwise participates in the access and mobility (including authentication / authorization) operations of the UE (through the access point 104) in other network operations. More generally, the AMF is also referred to herein as the Access and Mobility Management Entity.

[0028] In this illustrative embodiment, the AMF 106 is operatively coupled to the subscriber function 108, which resides in the subscriber's home network or elsewhere. As shown, some of these functions include the Unified Data Management (UDM) function and the Authentication Server Function (AUSF). More generally, the AUSF and UDM (either alone or jointly) are also referred to herein as authentication entities. Additionally, the subscriber function includes, but is not limited to, the Network Slice Selection Function (NSSF), the Network Exposure Function (NEF), the Network Repository Function (NRF), and the Policy Control Function (PCF).

[0029] "Third party" is intended to mean a party other than the subscriber of the UE or the operator of the core network. For example, in one or more illustrative embodiments, the third party is an enterprise (such as a company, corporation, group, individual, etc.). In some embodiments, the subscriber of the UE is an employee of an enterprise (or its related enterprise), and the employee maintains a mobile subscription together with the operator of the core network or another mobile network. Note that the UE associated with the subscription typically subscribes to the so-called Home Public Land Mobile Network (HPLMN), in which some or all of the subscriber functions 108 reside. If the UE is roaming (not in the HPLMN) and / or not subscribed to a PLMN, it is typically connected to a Visited Public Land Mobile Network (VPLMN) (also referred to as the serving network). Some or all of the mobility management functions 106 may reside in the VPLMN, in which case the functions in the VPLMN communicate with the functions in the HPLMN as needed. However, in a non-roaming scenario, the mobility management function 106 and the subscriber function 108 may reside in the same communication network or elsewhere.

[0030] The access point 104 is also operatively coupled to the serving gateway function, namely the Session Management Function (SMF) 110, which is operatively coupled to the User Plane Function (UPF) 112. The UPF 112 is operatively coupled to a Packet Data Network (PDN), such as the Internet 114. As is known in 5G and other communication networks, the user plane (UP) or data plane carries network user traffic, while the control plane (CP) carries signaling traffic. The SMF 110 supports functionality related to UP subscriber sessions, such as the establishment, modification, and release of Protocol Data Unit (PDU) sessions. The UPF 112 supports functionality that facilitates UP operations, such as packet routing and forwarding, interconnection with data networks (such as Figure 1 114 in the example), policy enforcement, and data buffering.

[0031] It should be recognized that Figure 1 is a simplified illustration, as not all communication links and connections between network functions (NFs) and other system elements are shown in Figure 1is illustrated. Given the various 3GPP TS / TRs, one of ordinary skill in the art will recognize the various links and connections that are not explicitly shown in Figure 1 or may otherwise be subsumed therein.

[0032] Other typical operations and functions of certain network elements are not described in detail herein because they are not central to the illustrative embodiments, but can be found in appropriate 3GPP 5G literature. It should be recognized that Figure 1 the particular arrangement of system elements in Figure 1 is merely exemplary, and in other embodiments, other types and arrangements of additional or alternative elements may be used to implement the communication system. For example, in other embodiments, system 100 includes other elements / functions that are not explicitly shown herein. Similarly, although only a single element / function is shown in

[0033] Note also that while Figure 1 the system elements are illustrated as singular functional blocks, the various sub-networks that make up a 5G network are partitioned into so-called network slices. A network slice (network partition) includes a set of a series of network functions (NFs) (i.e., a function chain) of each corresponding service type that uses network function virtualization (NFV) on a common physical infrastructure. For a given service, such as an eMBB service, a massive IoT service, and a mission-critical IoT service, network slices are instantiated as needed. Thus, when an instance of a network slice or function is created, that network slice or function is instantiated. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices of the underlying physical infrastructure. UE 102 is configured to access one or more of these services via an access point 104 (a gNB or N3IWF or TNGF or W-AGF depending on the type of 5G access network). An NF may also access the services of other NFs.

[0034] The illustrative embodiments provide a method for providing communication security for non-subscriber user equipment seeking restricted local access to a mobile network. As described above, if a UE is roaming (not in the HPLMN) and / or not subscribed to a PLMN, it is typically connected to a VPLMN (serving network). Also as described herein, the embodiments correspond to a roaming UE attempting to access a serving network such as a VPLMN.

[0035] Figure 2FIG. 200 is a block diagram of a processing architecture 200 of a user equipment 202 and a network node 204 (e.g., a network function participant) in a method for providing access to a restricted local service in an illustrative embodiment. As will also be explained below, in the method according to the illustrative embodiment, there are more than two participants involved, such as a UE, an AMF, a NEF, and an AUSF. For example, a network function may be provided by a combination of participants, where a mobility management function 106 and a subscriber function 108 reside. Figure 2 Illustrated is a processing architecture associated with a user equipment 202 and a network node 204 that communicate directly or indirectly. In an illustrative embodiment, each participant in the method for providing access to a restricted local service is understood to be configured using the same or similar processing architecture shown in Figure 2 FIG.

[0036] As shown in the figure, the user equipment 202 includes a processor 212 coupled to a memory 216 and an interface circuitry 210. The processor 212 of the user equipment 202 includes a restricted local access processing module 214, which can be implemented at least in part in the form of software executed by the processor 212. The processing module 214 performs functions associated with providing communication security for a non-subscriber user equipment seeking restricted local access to a service network described herein in connection with subsequent figures and otherwise. The memory 216 of the user equipment 202 includes a PLMN identity (PLMN ID) storage module 218 that stores identity information of a PLMN. Also as described herein, when the user equipment 202 powers on, performs a network search, and receives network information, the PLMN identity information is obtained by the user equipment 202. In an illustrative embodiment, for example, the PLMN ID includes an MCC and an MNC used by a network, such as a service network.

[0037] Also as shown in the figure, the network node 204 includes a processor 222 coupled to a memory 226 and an interface circuitry 220. The processor 222 of the network node 204 includes a restricted local access processing module 224, which can be implemented at least in part in the form of software executed by the processor 222. The processing module 224 performs functions described herein in connection with subsequent figures and otherwise associated with providing communication security for a non-subscriber user equipment seeking restricted local access to a service network. The memory 226 of the network node 204 includes a PLMN ID storage module 228 that stores identity information of a PLMN.

[0038] For example, the processors 212 and 222 of the user equipment 202 and the network node 204 may include, for example, a microprocessor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), or other types of processing devices or integrated circuits, as well as portions or combinations of these elements. Such integrated circuit devices and portions or combinations thereof are examples of the term "circuitry" as used herein. Various other arrangements of hardware and associated software or firmware may be used to implement the illustrative embodiments.

[0039] The memories 216 and 226 of the user equipment 202 and the network node 204 may be used to store one or more software programs that are executed by the respective processors 212 and 222 to implement at least a portion of the functionality described herein. For example, functions such as those described herein in connection with the subsequent figures and otherwise may be implemented in a straightforward manner using software code executed by the processors 212 and 222, which functions are associated with providing communication security for non-subscriber user equipment seeking restricted local access to the serving network and other functionality.

[0040] Thus, a given memory in the memories 216 or 226 may be regarded as an example, which is more generally referred to herein as a computer program product or still more generally as a processor-readable storage medium having executable program code embedded thereon. Other examples of processor-readable storage media may include, in any combination, magnetic disks or other types of magnetic or optical media. The illustrative embodiments may include an article of manufacture including such a computer program product or other processor-readable storage medium.

[0041] For example, the memories 216 or 226 may more specifically include, for example, electronic random access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. For example, the latter may include non-volatile memory such as flash memory, magnetic RAM (MRAM), phase change RAM (PC-RAM), or ferroelectric RAM (FRAM). The term "memory" as used herein is intended to be construed broadly and may, for example, additionally or alternatively encompass read-only memory (ROM), disk-based memory, or other types of storage devices, as well as portions or combinations of these devices.

[0042] The interface circuitry 210 and 220 of the user equipment 202 and the network node 204 illustratively includes a transceiver or other communication hardware or firmware that allows the associated system elements to communicate with each other in the manner described herein.

[0043] From Figure 2As can be seen, the user equipment 202 is configured to communicate with the network node 204 via its respective interface circuitry 210 and 220, and vice versa. Such communication involves the user equipment 202 sending data to the network node 204 and the network node 204 sending data to the user equipment 202. However, in alternative embodiments, other network elements or other components may be operatively coupled between and to the user equipment 202 and the network node 204. The term "data" as used herein is intended to be construed broadly so as to cover any type of information that may be sent between the user equipment and the network node, including but not limited to messages, tokens, identifiers, keys, indicators, user data, control data, etc.

[0044] It is to be recognized that Figure 2 the particular arrangement of the components shown is merely an example, and many alternative configurations are used in other embodiments. For example, any given network element / function or more generally any given network node may be configured to incorporate additional or alternative components and support other communication protocols.

[0045] In view of the above illustrative architecture, illustrative embodiments of a method for providing communication security for non-subscriber user equipment seeking restricted local access to a mobile network using an MCC will also be described below. Prior to such a description, some of the main drawbacks that at least partially motivated the development of the illustrative embodiments will be described in the context of a 5G network.

[0046] Restricted Local Operator Service (RLOS), which may also be referred to as Provision of Access to Restricted Local Operator Service (PARLOS), supports incoming roaming UEs that do not have a prior subscription to a PLMN. Such incoming UEs are provided with so-called manual roaming, where the UE is linked to the serving network (e.g., VPLMN) via the Interactive Voice Response (IVR) of the manual roaming service provider. Once the financial payment information (such as a prepaid account or credit card) is verified via the IVR, the UE will be able to make calls at a small fee. The small fee is typically paid by the payment mechanism provided by the user associated with the UE.

[0047] Manual roaming is an FCC obligation for U.S. operators. More specifically, manual roaming requires that in the absence of a roaming agreement with a PLMN operator, U.S. networks must only provide basic outgoing voice calls for users of UEs that can connect to the network's base stations (e.g., supporting the same band type). Since there is no pre-existing subscription agreement between the PLMN and the user associated with the UE, and the PLMN is expected to provide RLOS restricted services without authenticating the UE, only application-level security can be set up between the RLOS server and the UE.

[0048] To enable services input via RLOS, the serving PLMN may request certain personal information from the user, such as, for example, name, address, location, and payment information. Without adequate protection, the personal information can be intercepted by a third party, who can use the personal information for fraudulent purposes. Therefore, when providing RLOS services, transmitting personal information over an unprotected communication link is a security threat.

[0049] In 3GPP TR 33.815, V0.5.0, entitled “Technical Specification Group Services and System Aspects; Security Aspects; Study on Security Aspects of PARLOS” (the disclosure of which is incorporated herein by reference in its entirety), the key issues of the security aspects related to PARLOS services are identified, the threats related to the issues are defined, and solutions are proposed. The solution relies on the UE providing a public key to the serving network, which the serving network uses to encrypt K ASME , this K ASME will be used to protect the traffic between the UE and the serving network. The solution provides confidentiality and integrity protection for non-access stratum (NAS) and access stratum (AS) signaling, preventing passive attacks (e.g., if an attacker is eavesdropping on the data exchanged between the UE and the network), but not preventing active attacks (e.g., the attacker is operating as a false base station). Additional details regarding RLOS are described in Appendix J of 3GPP TS 33.401 v16.2.0, the disclosure of which is incorporated herein by reference in its entirety.

[0050] In countries where RLOS manual roaming does not exist and / or is not required or regulated, the UE may not want to connect to a false base station and network because the false base station will advertise a PLMN ID (e.g., MCC+MNC) belonging to a country that requires RLOS support (e.g., the United States). For example, the MNC from one of the PLMN operators in the PLMN operator (which is public knowledge and broadcast by the network) can be reused by the false base station. Therefore, even if a particular country does not support the legitimate use of the RLOS feature, an attacker may be able to successfully cause the UE to connect to the false base station by using the false base station. By providing RLOS services and manual roaming, the false base station can extract critical personal information, such as, for example, name and credit card information, which may be misused. Therefore, there is a need to prevent unnecessary connections of the UE to false base stations that broadcast trusted PLMN IDs (e.g., MCC+MNC) that belong to another country that requires RLOS and where the false base station is not located.

[0051] Exemplary embodiments provide new methods for preventing a UE from connecting to a fake base station, thereby preventing active attacks to obtain sensitive personal information from the user of the UE. Exemplary embodiments provide mechanisms to prevent scenarios where a UE identifies and selects a PLMN of one country while the UE is actually in another country.

[0052] According to one or more embodiments, a method for providing communication security for non-subscriber user equipment seeking restricted local access to a mobile network may include the following features:

[0053] 1. The user of the device (e.g., UE) affirmatively invokes the RLOS feature through the user interface so that the UE does not automatically initiate an RLOS connection or connect to a fake base station within an unauthorized jurisdiction.

[0054] 2. The user is required to affirmatively confirm the country, city, and / or other geographical identifiers through the user interface, representing the current location of the user (and the UE) each time the user invokes the RLOS feature, so that the UE does not connect to a false RLOS server or a fake RLOS site identified as being from another country.

[0055] 3. Detect a change in the PLMN ID by the UE from the PLMN ID stored in the UE, and request manual confirmation from the user through the user interface of the country and / or MCC in which the UE is operating.

[0056] 4. The UE will not change the currently specified and / or stored PLMN ID associated with a first country to a PLMN ID associated with another country until the UE powers on and off or enters and exits the flight mode. In other words, the UE will change the PLMN ID or MCC only when entering and exiting the flight mode or when transitioning from the powered-off state to the powered-on state.

[0057] According to one or more embodiments, the UE implements to ensure that the UE will not automatically select and connect to a PLMN that publishes an MCC different from the actual country where the UE is physically present.

[0058] Refer to Figure 3, which shows a method 300 for a user equipment 302 to obtain host and system information blocks from a network 304. For example, generally, the user equipment 302 should apply the system information (SI) acquisition process after cell selection (such as power-on), cell reselection, returning from outside the coverage area (such as exiting the flight mode), after synchronization is completed and reconfigured, after entering the network through another radio access technology (RAT), after receiving an indication that the system information has changed, after receiving a public warning system (PWS) notification, and when the UE does not have a valid version of the stored system information block (SIB). The SI acquisition process may include: transmitting a system information request from the user equipment 302 to the network 304 (such as a PLMN), and providing a master information block (MIB), SIB, and system information message from the network 304 to the user equipment 302. The user equipment 302 may obtain SI from the periodic broadcast of SI by the network 304 or by sending an SI request to a base station. The network broadcasts a PLMN ID, which includes, for example, an MCC and an MNC. The MCC may be extracted from the PLMN ID or from the response to the SI request.

[0059] For example, when the user equipment 302 obtains the MIB, SIB type 1 (SIB 1), and / or SI message in the serving cell from the network 304, the user equipment 302 stores the obtained SIB 1. The user equipment 302 may also store the associated areaScope (if any), the first PLMN-Identity in the PLMN-IdentityInfoList, the cellIdentity, the systemInformationAreaID (if any), and the valueTag (if any), as indicated in the si-SchedulingInfo of the SIB.

[0060] Figure 4 is a flowchart 400, which illustrates a part of a method for providing security for a user equipment seeking restricted local access to a mobile network according to an illustrative embodiment. Referring to block 401, the user equipment applies the SI acquisition process after power-on, where network search is performed, and the network identifier (such as a PLMN ID) included in the SIB 1 is obtained from the network by the user equipment. In block 403, the SIB 1 including the PLMN ID is stored in the memory of the user equipment. According to the illustrative embodiment, the PLMN ID includes an MCC and an MNC.

[0061] Referring to block 405, after powering off and then powering on again, after returning to the coverage area (e.g., after entering and exiting airplane mode), or after moving to another country and / or network, the user equipment applies another SI acquisition process, in which a network search is performed and the network identifier (such as PLMN ID) contained in SIB 1 is obtained from the network by the user equipment. In block 407, the most recently obtained PLMN ID (including MCC and MNC) is compared with the stored PLMN ID to determine whether there is a difference from the stored PLMN ID. If there is a difference, then according to block 408, the user of the user equipment is alerted to this difference and prompted to manually confirm via, for example, the user interface on the user equipment in the country where the user equipment is currently located and / or the MCC value. If the country confirmed by the user matches the MCC in the most recently obtained PLMN ID, the user equipment can conclude that the PLMN ID is genuine (e.g., not from a fake base station using a fake country code), store the most recently obtained PLMN ID to replace the previously stored PLMN ID, and allow access to the restricted local operator service. If the country confirmed by the user does not match the MCC in the most recently obtained PLMN ID, the user equipment can conclude that the PLMN ID is not genuine (e.g., from a fake base station using a fake country code), maintain the previously stored PLMN ID, and deny access to the restricted local operator service.

[0062] If there is no difference between the stored PLMN ID and the most recently obtained PLMN ID, normal operation continues according to block 409.

[0063] Figure 5 FIG. 500 is a flowchart illustrating another part of a method for providing security for a user equipment seeking restricted local access to a mobile network according to an illustrative embodiment. Referring to blocks 501, 503, and 505, similar to Figure 4 blocks 401, 403, and 405 in In block 501, the user equipment applies an SI acquisition process after powering on, in which a network search is performed and the network identifier (such as PLMN ID) contained in SIB 1 is obtained from the network by the user equipment. In block 503, SIB 1 including the PLMN ID is stored in the memory of the user equipment. After powering off and then powering on again, after returning to the coverage area (e.g., after entering and exiting airplane mode), or after moving to another country and / or network, in block 505, the user equipment applies another SI acquisition procedure, in which a network search is performed and the network identifier, such as PLMN ID, contained in SIB 1 is obtained from the network by the user equipment.

[0064] In block 507, a user of a user equipment invokes an RLOS call via, for example, a user interface of the user equipment. According to an embodiment, the user equipment may require an affirmative invocation of the RLOS feature to prevent the user equipment from automatically initiating an RLOS connection without user review and to avoid connecting to a false base station in an unauthorized jurisdiction. The requirement to affirmatively invoke the RLOS feature provides an additional layer of protection that is not currently available.

[0065] Similar to block 407, in block 508, the most recently obtained PLMN ID (which also includes the MCC and MNC) is compared with the stored PLMN ID to determine if there is a difference from the stored PLMN ID. If there is a difference, then in block 509, the RLOS procedure is terminated, access to the restricted local operator service is denied, and the user of the user equipment is alerted to the difference in the RLOS service and its denial. In the case of a difference, the user equipment may conclude that the PLMN ID is not genuine (e.g., from a false base station using a false country code) and maintain the previously stored PLMN ID.

[0066] If there is no difference between the stored PLMN ID and the most recently obtained PLMN ID, the user equipment allows the RLOS process to continue in block 510 and may use the restricted local operator service for the call.

[0067] In combination Figures 3 to 5 The specific processing operations and other system functionality described in connection with the schematic diagrams are presented only by way of illustrative example and should not be construed as limiting the scope of the present disclosure in any way. Alternative embodiments may use other types of processing operations and messaging protocols. For example, the order of steps may be different in other embodiments, or certain steps may be performed at least partially in parallel with another step rather than serially. Also, one or more steps may be repeated periodically, or multiple instances of the method may be performed in parallel with each other.

[0068] Advantageously, as described herein, the illustrative embodiments provide techniques for restricting RLOS calls only to permitted countries by analyzing the MCC value in the PLMN ID to determine if the country code associated with the current location of the user equipment is being used. If a difference is found between the stored PLMN ID and the obtained PLMN ID, the method includes a validation procedure to determine if the PLMN ID was generated by a false base station. If it is determined that a false base station is attempting to establish an RLOS connection, the embodiments advantageously provide mechanisms for terminating the RLOS process or alerting the user to potential fraud.

[0069] According to one or more embodiments, if a difference is found between the stored network identifier and the obtained network identifier, the user of the user equipment is prompted to confirm whether the first country code indicates the country in which the user equipment is located.

[0070] Additionally, to prevent an automatic initiation of a request for a restricted local operator service, a positive input from the user of the user equipment is required before initiating the request to initiate a command for an access request. Further, it may be required that the user of the user equipment positively indicate the country in which the user equipment is located before initiating an access request or enabling the user equipment to access a restricted local operator service. When potential fraud has been determined, prevent the replacement of the stored network identifier with a most recently obtained network identifier having a different country code. Additionally, according to one or more embodiments, considering the situation where the location has actually changed to another country where RLOS may be authorized, allow such replacement to occur only after the user equipment has been powered off and on or has returned from outside the coverage area.

[0071] Therefore, it should be emphasized again that the various embodiments described herein are presented only by way of illustrative examples and should not be considered as limiting the scope of the claims. For example, alternative embodiments may utilize different communication system configurations, user equipment configurations, base station configurations, authentication and key agreement protocols, key pair provisioning and usage procedures, messaging protocols, and message formats, different from those described above in the context of the illustrative embodiments. These and many other alternative embodiments within the scope of the appended claims will be apparent to those skilled in the art.

Claims

1. A user equipment for communication, comprising: at least one processor; at least one memory, including computer program code; the at least one memory and the computer program code are configured to, together with the at least one processor, cause the user equipment to at least: initiate a request for a restricted local operator service for accessing a Public Land Mobile Network (PLMN), wherein the user equipment is roaming and there is no pre-existing subscription agreement between the PLMN and the user of the user equipment, and the restricted local operator service is expected to be provided to the user equipment by the PLMN without authenticating the user equipment; acquire a network identifier including a first country code, wherein the acquired network identifier corresponds to the PLMN, and the user equipment is further caused to: before enabling the user equipment to access the restricted local operator service, require the user of the user equipment to affirmatively invoke at least one feature of the restricted local operator service; compare the acquired network identifier with a stored network identifier including a second country code; determine whether the first country code and the second country code are different; in response to an affirmative determination, at least perform a first action, wherein the first action includes: prompting the user of the user equipment to confirm whether the first country code indicates the country where the user equipment is located, and based on the user's confirmation that the first country code indicates the country where the user equipment is located, replacing the stored network identifier with the acquired network identifier and enabling access to the restricted local operator service; and in response to a negative determination, at least perform a second action, wherein the second action includes enabling access to the restricted local operator service; wherein the at least one processor, the at least one memory and the computer program code are part of the user equipment.

2. The user equipment according to claim 1, wherein the first action includes reminding the user of the user equipment of the difference between the first country code and the second country code.

3. The user equipment according to claim 1, wherein the first action includes denying access to the restricted local operator service.

4. The user equipment according to claim 1, wherein the at least one memory and the computer program code are further configured to, together with the at least one processor, cause the user equipment to at least require the user of the user equipment to affirmatively input a command for initiating the request for access before initiating the request.

5. The user equipment according to claim 1, wherein the at least one memory and the computer program code are further configured to, together with the at least one processor, cause the user equipment to at least require the user of the user equipment to affirmatively indicate the country where the user equipment is located before initiating the request for access or enabling the user equipment to access the restricted local operator service.

6. The user equipment according to claim 1, wherein the at least one memory and the computer program code are further configured to, together with the at least one processor, cause the user equipment to at least prevent replacing the stored network identifier including the second country code with a network identifier including a country code different from the second country code until the user equipment is powered off and on, or returns from out of coverage.

7. The user equipment according to claim 1, wherein each of the first country code and the second country code includes a Mobile Country Code (MCC).

8. A method of communication by a user equipment, comprising: initiating a request for a restricted local operator service for accessing a Public Land Mobile Network (PLMN), wherein the user equipment is roaming and there is no pre-existing subscription agreement between the PLMN and the user of the user equipment, and the restricted local operator service is expected to be provided to the user equipment by the PLMN without authenticating the user equipment; acquiring a network identifier including a first country code, wherein the acquired network identifier corresponds to the PLMN, and the method further comprises: before enabling the user equipment to access the restricted local operator service, requiring the user of the user equipment to affirmatively invoke at least one feature of the restricted local operator service; comparing the acquired network identifier with a stored network identifier including a second country code; determining whether the first country code and the second country code are different; performing at least a first action in response to an affirmative determination, wherein the first action comprises: prompting the user of the user equipment to confirm whether the first country code indicates the country in which the user equipment is located, and based on the confirmation by the user that the first country code indicates the country in which the user equipment is located, replacing the stored network identifier with the acquired network identifier and enabling access to the restricted local operator service; and performing at least a second action in response to a negative determination, wherein the second action comprises enabling access to the restricted local operator service; wherein the user equipment includes a processor and a memory, and the processor and the memory are configured to execute the above steps.

9. The method according to claim 8, wherein the first action comprises reminding the user of the user equipment of the difference between the first country code and the second country code.

10. The method according to claim 8, wherein the first action comprises denying access to the restricted local operator service.

11. The method according to claim 8, further comprising requiring the user of the user equipment to affirmatively input a command for initiating the request for access before initiating the request.

12. The method according to claim 8, further comprising requiring the user of the user equipment to affirmatively indicate the country in which the user equipment is located before initiating the request for access or enabling the user equipment to access the restricted local operator service.

13. The method according to claim 8 further includes preventing replacement of the stored network identifier including the second country code with a network identifier including a country code different from the second country code until the user equipment is powered off and on, or returns from outside the coverage area.

14. The method according to claim 8, wherein each of the first country code and the second country code includes a Mobile Country Code (MCC).

15. An article of manufacture for communication, comprising a non-transitory computer-readable storage medium having executable program code implemented therein, the executable program code causing the user equipment, when executed by a processor associated with the user equipment, to: initiate a request for a restricted local operator service for accessing a Public Land Mobile Network (PLMN), wherein the user equipment is roaming and there is no pre-existing subscription agreement between the PLMN and the user of the user equipment, and the restricted local operator service is expected to be provided to the user equipment by the PLMN without authenticating the user equipment; acquire a network identifier including a first country code, wherein the acquired network identifier corresponds to the PLMN, and the user equipment is further caused to: before enabling the user equipment to access the restricted local operator service, require the user of the user equipment to affirmatively invoke at least one feature of the restricted local operator service; compare the acquired network identifier with a stored network identifier including a second country code; determine whether the first country code and the second country code are different; in response to an affirmative determination, perform at least a first action, wherein the first action includes: prompting the user of the user equipment to confirm whether the first country code indicates the country in which the user equipment is located, and based on the user's confirmation that the first country code indicates the country in which the user equipment is located, replacing the stored network identifier with the acquired network identifier and enabling access to the restricted local operator service; and in response to a negative determination, perform at least a second action, wherein the second action includes enabling access to the restricted local operator service.

16. The article of manufacture according to claim 15, wherein the first action includes reminding the user of the user equipment of the difference between the first country code and the second country code.

17. The article of manufacture according to claim 15, wherein the first action includes denying access to the restricted local operator service.

18. The article of manufacture according to claim 15, wherein the executable program code, when executed by the processor, further causes the user equipment to require the user of the user equipment to affirmatively input a command for initiating the request for access before initiating the request.

19. The article according to claim 15, wherein the executable program code, when executed by the processor, further causes the user equipment to require the user of the user equipment to affirmatively indicate the country in which the user equipment is located before initiating the request for access or enabling the user equipment to access the restricted local operator service.

20. The article according to claim 15, wherein the executable program code, when executed by the processor, further causes the user equipment to prevent replacing the stored network identifier including the second country code with a network identifier including a country code different from the second country code until the user equipment is powered off and on, or enters and returns from the coverage area.

21. The article according to claim 15, wherein each of the first country code and the second country code includes a mobile country code MCC.

Citation Information

Patent Citations

  • Quick network searching method and device for mobile terminal

    CN105554851A

  • Method and apparatus for discovery and access of restricted local services for unauthenticated ues

    US20190053139A1