Methods, systems, and computer-readable media for 5g user equipment (ue) history mobility tracking and security screening using mobility patterns

By generating and analyzing UE mobility patterns in 5G networks and utilizing SEPP for security screening, the problem of network spoofing attacks is solved, ensuring communication security and correct routing.

CN116325658BActive Publication Date: 2026-04-10ORACLE INT CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-30
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In 5G networks, attackers can use network deception to forge UE registration information, causing communications to be redirected to the attacker's network. Existing firewall devices have difficulty effectively detecting the actual location of the UE, resulting in communication theft.

Method used

By collecting and analyzing UE registration data at network data aggregation nodes, a mobility pattern is generated. The Security Edge Protection Agent (SEPP) is then used to perform security screening based on the mobility pattern, identify abnormal registrations, and block or verify new UE registrations.

Benefits of technology

It effectively reduces the success rate of network spoofing attacks, ensures that communications are correctly routed to the UE's home network, and prevents communications from being stolen.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116325658B_ABST
    Figure CN116325658B_ABST
Patent Text Reader

Abstract

A method for historical 5G user equipment (UE) mobility tracking and security screening includes receiving, at a network data aggregation node comprising at least one processor, UE registration data from 5G network functions (NFs) as the UE connects to different network locations. The method also includes aggregating, at the network node, registration data from the 5G NFs for individual UEs to produce a mobility pattern for the UEs. The method also includes receiving, at the network node, a request for the mobility pattern for a UE from a 5G NF located in a home network for the UE in response to receiving a message for a new registration of the UE. The method also includes responding to the request by sending the mobility pattern to the 5G NF located in the home network for the UE.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CLAIM OF PRIORITY

[0002] This application claims priority to U.S. Patent Application Serial No. 17 / 008,528, filed August 31, 2020, the disclosure of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] The subject matter described herein relates to enhancing security in 5G mobile communication networks. More specifically, the subject matter described herein relates to methods, systems, and computer readable media for 5G UE historical mobility tracking and security screening using mobility patterns. BACKGROUND

[0004] In a 5G telecommunications network, a network node that provides a service is referred to as a producer network function (NF). A network node that consumes a service is referred to as a consumer NF. Depending on whether a network function is consuming a service or providing a service, it can be both a producer NF and a consumer NF.

[0005] A given producer NF can have many service endpoints, where a service endpoint is a contact point for one or more NF instances hosted by the producer NF. A service endpoint is identified by a combination of an Internet Protocol (IP) address and a port number, or a fully qualified domain name that resolves to an IP address and a port number on a network node that hosts the producer NF. An NF instance is an instance of a producer NF that provides a service. A given producer NF can include more than one NF instance. It should also be noted that multiple NF instances can share the same service endpoint.

[0006] Producer NFs register with a network function repository function (NRF). The NRF maintains a service profile of available NF instances that identifies the services supported by each NF instance. Consumer NFs can subscribe to receive information about producer NF instances that have registered with the NRF.

[0007] In addition to consumer NFs, another type of network node that can subscribe to receive information about NF service instances is a service communication proxy (SCP). An SCP subscribes with the NRF and obtains reachability and service profile information about producer NF service instances. Consumer NFs connect to the service communication proxy, and the service communication proxy load balances traffic among producer NF service instances that provide the required service, or routes traffic directly to the destination producer NF instance.

[0008] In addition to SCPs, other examples of intermediate proxy nodes or groups of network nodes that route traffic between producer NFs and consumer NFs include Security Edge Protection Proxies (SEPPs), service gateways, and nodes in a 5G service mesh. SEPPs are network nodes used to protect control plane traffic exchanged between different 5G Public Land Mobile Networks (PLMNs). Thus, SEPPs message filter, police, and topology hide all application programming interface (API) messages.

[0009] Service gateways are nodes that sit in front of a group of producer NFs that provide a given service. Service gateways can load balance incoming service requests among the producer NF instances that provide the service in a similar manner to SCPs.

[0010] Service meshes are the name for a group of intermediate proxy nodes that enable communication between producer NFs and consumer NFs. Service meshes can include one or more SCPs, SEPPs, and service gateways.

[0011] One weakness in the current 5G network architecture is that a nefarious actor can be able to use network spoofing to send signaling commands to other networks stating that a mobile device is roaming in their network and should be forwarded to a new serving network. This allows for the interception of text messages and voice calls. Network operators currently rely on firewall devices to detect these anomalies, but it is nearly impossible to determine if a mobile device is actually located in the network it is stating it is located in through a location update or corresponding 5G UE location registration message.

[0012] In firewall devices used today, a speed check is used to determine if a mobile device can register in one location and register in another location shortly thereafter. This requires a significant amount of administrative work to input the distances from a home network to every major city in the world and thus is not a viable solution.

[0013] In view of these difficulties, there is a need for methods, systems, and computer readable media for 5G UE historical mobility tracking and security screening. SUMMARY

[0014] A method for historical 5G user equipment (UE) mobility tracking and security screening includes receiving, at a network data aggregation node including at least one processor, UE registration data from 5G network functions (NFs) as the UE connects to different network locations. The method also includes aggregating, at the network node, registration data for individual UEs from the 5G NFs to produce mobility patterns for the UEs. The method also includes receiving, at the network node from a 5G NF located in a home network of a UE, a request for a mobility pattern for the UE in response to receiving a message to newly register the UE. The method also includes responding to the request by sending, to the 5G NF located in the home network of the UE, the mobility pattern.

[0015] According to another aspect of the subject matter described herein, receiving UE registration data includes receiving, from at least one of the 5G NFs, a mobility pattern for the UE.

[0016] According to another aspect of the subject matter described herein, the network data aggregation node includes a network data analytics platform (NWDAF) or a unified data repository (UDR).

[0017] According to another aspect of the subject matter described herein, the network data aggregation node includes a non-3GPP defined network data aggregation platform.

[0018] According to another aspect of the subject matter described herein, aggregating registration data to generate mobility patterns includes, for each mobility pattern, for each registration instance for the UE, storing an indicator of a location of the UE, a timestamp of when the UE registered at the location, and a type allocation code (TAC).

[0019] According to another aspect of the subject matter described herein, the 5G NF located in the home network of the UE includes a security edge protection proxy (SEPP), and further including receiving, at the SEPP, the mobility pattern and determining, based on the mobility pattern, whether the message to newly register indicates a UE registration pattern anomaly.

[0020] According to another aspect of the subject matter described herein, a method for 5G historical mobility tracking and security screening includes, at the SEPP, in response to determining that the message to newly register indicates a UE registration pattern anomaly, blocking the message to newly register.

[0021] According to another aspect of the subject matter described in this document, a method of 5G historical mobility tracking and security screening includes, at a SEPP, in response to determining that a message to make a new registration indicates that a UE is registering abnormally, initiating paging of the UE at a location specified in the UE registration, and in response to successful paging of the UE at the location specified in the UE registration, forwarding the message to make the new registration to a unified data management (UDM) function in a home network of the UE.

[0022] According to another aspect of the subject matter described in this document, a UE includes an Internet of Things (IoT) device.

[0023] According to another aspect of the subject matter described in this document, a mobility pattern includes a type allocation code (TAC) of the UE, and the method further includes determining, at the SEPP, a device type from the TAC, comparing the mobility pattern to mobility patterns of devices of the same or similar type as the UE, and determining whether the registration is abnormal based on a result of the comparison.

[0024] According to another aspect of the subject matter described in this document, a system for historical 5G user equipment (UE) mobility tracking and security screening is provided. The system includes a network data aggregation node including at least one processor. The system also includes a 5G UE mobility pattern generator to receive registration data from 5G network functions (NFs) as a UE connects to different network locations, aggregate the registration data of the UE to produce a mobility pattern of the UE, receive a request for the mobility pattern of the UE generated in response to a message to make a new registration of the UE from a 5G NF located in a home network of the UE, and send the mobility pattern to the 5G NF in the home network of the UE in response to the request.

[0025] According to another aspect of the subject matter described in this document, receiving UE registration data includes receiving a mobility pattern of the UE from at least one of the 5G NFs.

[0026] According to another aspect of the subject matter described in this document, in aggregating the registration data from the 5G NFs to generate the mobility pattern, the 5G UE mobility pattern generator is configured to, for each registration instance of the UE, store an indicator of a location of the UE, a timestamp of when the UE registered at the location, and a type allocation code (TAC).

[0027] According to another aspect of the subject matter described in this document, a system for 5G historical mobility tracking and security screening includes a security edge protection proxy (SEPP) to receive a mobility pattern and determine, based on the mobility pattern, whether a message to make a new registration indicates that a UE is registering abnormally.

[0028] According to another aspect of the subject matter described in this document, the SEPP is configured to block the new UE registration in response to determining that the new registration indicates a UE registration pattern anomaly.

[0029] According to another aspect of the subject matter described in this document, the SEPP is configured to initiate paging of the UE at a location specified in the UE registration in response to determining that a message for a new registration indicates a UE registration anomaly, and to forward the message for the new registration to a unified data management (UDM) function in a home network of the UE in response to successful paging of the UE at the location specified in the UE registration.

[0030] According to another aspect of the subject matter described in this document, the mobility pattern includes a type allocation code (TAC) of the UE, and wherein the SEPP is configured to determine a device type from the TAC, compare the mobility pattern to mobility patterns of devices of the same or similar type as the UE, and determine whether the registration is abnormal based on a result of the comparison.

[0031] According to another aspect of the subject matter described in this document, a non-transitory computer-readable medium having stored thereon executable instructions that, as a result of being executed by a processor of a computer, cause the computer to control the computer to perform steps. The steps include receiving, at a network data aggregation node including at least one processor, UE registration data from 5G network functions (NFs) as UEs connect to different network locations. The steps also include aggregating, at the network node, registration data for individual UEs to produce mobility patterns of the UEs. The steps also include receiving, at the network node from 5G NFs located in a home network of a UE, a request for a mobility pattern of the UE in response to receiving a message for a new registration of the UE. The steps also include responding to the request by sending the mobility pattern to the NFs located in the home network of the UE.

[0032] The subject matter described in this document can be implemented in hardware, software, firmware, or any combination thereof. As such, the terms "function," "node," or "module" as used herein refer to hardware, which can also include software and / or firmware components, for implementing the described features. In one exemplary implementation, the subject matter described in this document can be implemented using a computer-readable medium having computer-executable instructions stored thereon that, when executed by a computer, control the computer to perform steps. Exemplary computer-readable media suitable for implementing the subject matter described in this document include non-transitory computer-readable media, such as disk memory devices, chip memory devices, programmable logic devices, and application specific integrated circuits. In addition, a computer-readable medium that implements the subject matter described in this document can be located on a single device or computing platform or distributed across multiple devices or computing platforms.

[0033] Broadly speaking, the present invention provides a method for historical 5G user equipment (UE) mobility tracking. The invention generates a mobility pattern associated with a particular UE, which is then provided to a requesting 5G network function (NF) located in the UE's home network. The mobility pattern can be used for security screening of UE registrations - in particular, abnormal registrations can be detected by examination of the mobility pattern. The security screening can be performed by the requesting NF to determine whether the UE's registration is abnormal. Advantageously, the mobility pattern generated by the invention can be used in this way to reduce the success rate of network spoofing attacks. BRIEF DESCRIPTION OF DRAWINGS

[0034] The subject matter described herein will now be explained with reference to the drawings, wherein:

[0035] Figure 1 is a network diagram illustrating an exemplary 5G network architecture;

[0036] Figure 2 is a network diagram illustrating an exemplary attack scenario in which an attacker sends a false UE registration to a home network to direct subsequent communications for the UE to the attacker;

[0037] Figure 3 is a network diagram illustrating a network data analytics function (NWDAF) or aggregation node that generates a mobility pattern for a UE, and a SEPP that screens a UE registration using the mobility pattern;

[0038] Figure 4 is a network diagram of the same network as shown in Figure 3 , in which a UE registration is screened based on mobility pattern information, and the UE registration is allowed because the SEPP determines from the mobility pattern information that the registration is not abnormal;

[0039] Figure 5 is a network diagram illustrating the same network as Figure 3 , in which a UE registration is screened based on mobility pattern information, and the UE registration is blocked because the SEPP determines from the mobility pattern information that the registration is abnormal;

[0040] Figure 6 is a block diagram illustrating an exemplary architecture for an aggregation node and a SEPP for 5G historical mobility tracking and security screening based on mobility patterns;

[0041] Figure 7 is a flow diagram illustrating an exemplary process performed by an aggregation node in generating a mobility pattern and providing the mobility pattern to a requesting node;

[0042] Figure 8is a flow diagram illustrating an exemplary process by the SEPP in obtaining mobility patterns from the aggregation node and screening UE registration based on the mobility patterns;

[0043] Figure 9 is a signaling message flow diagram illustrating exemplary signaling associated with 5G mobility; and

[0044] Figure 10 is a network diagram illustrating an exemplary unified data repository (UDR) for 5G mobility tracking in accordance with aspects of the subject matter described herein. DETAILED DESCRIPTION

[0045] The subject matter described herein relates to methods, systems, and computer readable media for 5G UE historical mobility tracking using mobility patterns (e.g., for security screening). Figure 1 is a block diagram illustrating an exemplary 5G system network architecture. Figure 1 The architecture in includes the NRF 100 and the SCP 101, which can be located in the same home public land mobile network (HPLMN). As described above, the NRF 100 can maintain profiles of available producer NF service instances and their supported services, and allow consumer NFs or SCPs to subscribe and be notified of registration of new / updated producer NF service instances. The SCP 101 can also support selection and service discovery of producer NF instances. The SCP 101 can perform load balancing of connections between consumer NFs and producer NFs. Further, using the methods described herein, the SCP 101 can perform selection and routing based on preferred NF locations.

[0046] The NRF 100 is a repository of service profiles of NFs or producer NF instances. To communicate with a producer NF instance, a consumer NF or SCP must obtain the NF or service profile or producer NF instance from the NRF 100. The NF or service profile is a JavaScript Object Notation (JSON) data structure defined in Third Generation Partnership Project (3GPP) Technical Specification (TS) 29.510. The NF or service profile definition includes at least one of a fully qualified domain name (FQDN), an Internet Protocol (IP) version 4 (IPv4) address, or an IP version 6 (IPv6) address. In Figure 1 In, any node (except the NRF 100) can be a consumer NF or a producer NF, depending on whether they are requesting a service or providing a service. In the illustrated example, the nodes include a policy control function (PCF) 102 that performs policy-related operations in the network, a unified data management (UDM) function 104 that manages user data, and an application function (AF) 106 that provides application services. Figure 1The nodes shown in FIG. 1 also include a session management function (SMF) 108 that manages sessions between an access and mobility management function (AMF) 110 and a PCF 102. The AMF 110 performs mobility management operations similar to those performed by a mobility management entity (MME) in a 4G network. An authentication server function (AUSF) 112 performs authentication services for user equipment (UEs) seeking access to the network, such as a user equipment (UE) 114.

[0047] A network slice selection function (NSSF) 116 provides network slice services for devices seeking to access particular network capabilities and characteristics associated with a network slice. A network exposure function (NEF) 118 provides application programming interfaces (APIs) for application functions seeking information about Internet of Things (IoT) devices and other UEs attached to the network. The NEF 118 performs similar functions to a service capability exposure function (SCEF) in a 4G network.

[0048] A radio access network (RAN) 120 connects the user equipment (UE) 114 to the network via a wireless link. The radio access network 120 can be accessed using a g-Node B (gNB) (not shown in FIG. 1) or other wireless access point. Figure 1 A user plane function (UPF) 122 can support various proxy functions for user plane services. One example of such a proxy function is a multi-path transmission control protocol (MPTCP) proxy function. The UPF 122 can also support performance measurement functions that can be used by the UE 114 to obtain network performance measurements. Figure 1 Also illustrated in FIG. 1 is a data network (DN) 124 through which the UE accesses data network services, such as Internet services.

[0049] The SEPP 126 filters incoming traffic from another PLMN and performs topology hiding for traffic leaving the home PLMN. The SEPP 126 can communicate with an SEPP in a foreign PLMN that manages security for the foreign PLMN. Thus, traffic between NFs in different PLMNs can pass through two SEPP functions, one for the home PLMN and one for the foreign PLMN.

[0050] As noted above, one problem that arises in 5G networks is that an attacker can spoof the identity of the network serving a mobile subscriber in a UE registration message, causing the home network to store a false location for the UE, as a result, subsequent communications intended for the real UE can be directed to the attacker. Figure 2 An example attack scenario is illustrated in which an attacker sends a fake UE registration and uses the fake UE registration to intercept communications to the UE. In addition to the above regarding Figure 1In addition to the described 5G NFs, in Figure 2 The network also includes radio access network nodes 202A, 202B, 204A, and 204B in The architecture of the radio access network nodes 202A, 202B, 204A, and 204B depends on how the gNB functionality is implemented in the network. The gNB functionality can be implemented using a baseband unit (BBU), where the functionality of the gNB is not divided into separate nodes or into separate distributed unit (DU) and control unit (CU) nodes. The CU is a logical node that includes gNB functionality such as transport of user data, mobility, control, radio access network sharing positioning, etc. The DU is a logical node that implements a subset of the gNB functionality depending on the functional split. The operation of the DU is controlled by the CU. The radio unit (RU) is just another name for the CU.

[0051] Referring to the message flow in Figure 2 In step 1, the attacker 200 impersonates the AMF by sending a fake UE registration to the UE's home network. The fake UE registration identifies the UE's location as the attacker's network. However, the UE does not exist in the attacker's network.

[0052] The SEPP 126A located in the UE's home network receives the fake UE registration. In this example, assume that the SEPP 126A does not implement security screening based on mobility pattern information. Therefore, in step 2, the SEPP 126A in the home network sends the fake UE registration to the UDM 104 in the home network.

[0053] The UDM 104 also does not implement security screening of UE registrations based on mobility patterns. Therefore, in step 3, the UDM 104 updates the UE's location in the database record that the UDM maintains for the UE to the attacker network. Other nodes use the UE's location stored by the UDM 104 to communicate with the UE. However, because Figure 2 The location stored for the UE in

[0054] In step 4, a legitimate caller UE 206 initiates a communication (e.g., a voice call or a text message) with a UE whose registration has been compromised. The initiation of the communication causes the AMF 110B located in the calling UE's network to send a location query to the UE's home network (step 4). The SEPP 126B located in the caller's network forwards the location query to the home network of the called UE. The SEPP 126A receives the location query and forwards the location query to the UDM 104 in step 5.

[0055] In step 6, the UDM 104 looks up the UE identified in the location query in its database and generates a location response that includes the registered location of the UE. In this case, the registered location is the attacker’s network. The UDM 104 sends the response with the false UE location to the requesting AMF via the SEPPs 126A and 126B. The SEPP 126B forwards the response with the false UE location to the AMF 110B. In step 7, the AMF 110B forwards communications from the UE 206 to the location specified in the location response message, which in this case is the location of the attacker 200. Thus, without some security screening, the attacker 200 can redirect voice calls, text messages, or other communications intended for the UE whose registration has been hijacked to the attacker’s network.

[0056] To reduce the likelihood of successfully redirecting communications to an attacker’s network, the subject matter described herein includes collecting mobility pattern information for UEs and using the mobility pattern information to perform security screening of registrations sent by the UEs. Figure 3 is a network diagram illustrating the use of an aggregation node to generate mobility pattern information that can be used to screen false UE registrations. Referring to Figure 3 , the aggregation node 300 can be a computing platform that collects UE registration information from the registrations of UEs 302, 304, and 306 as the UEs register with different networks. In the illustrated example, the UEs include IoT devices and mobile computing devices, including mobile handsets, tablet computers, laptop computers, and the like. The aggregation node 300 can be implemented using a computing platform that is capable of collecting UE registration data, aggregating the registration data, generating mobility patterns from the UE registration data, and providing the mobility patterns to querying NFs for UE registration security screening. In one example, the aggregation node 300 can be implemented using a NWDAF as defined in 3GPP TS 29.520. The NWDAF allows consumer NFs to subscribe to receive notifications of events from the NWDAF and also allows consumer NFs to request one-time notifications of events. This request-response communication model is more suitable for Figure 3 architectures in which the SEPP requests mobility patterns from the aggregation node 300 in response to receiving a new UE registration. It should also be noted that although the aggregation node 300 can be implemented by a NWDAF, the subject matter described herein is not limited to using a NWDAF to generate mobility patterns. In alternative implementations, a non-3GPP defined network function can be used to receive UE registration data, generate mobility patterns, and provide the mobility patterns to requesting network functions.

[0057] In Figure 3In the message flow shown in FIG. 3, when any of the UEs 302, 304, or 306 connects to the network via one of the radio access network nodes 202A and 202B or via the Wi-Fi / broadband / satellite gateway 308, the serving AMF sends a UE registration to the UDM 104 located in the home network of the UE and sends a copy of the registration or registration data extracted from the UE registration to the network data aggregation node 300. In Figure 3 In step 1, the UEs 304 and 306 connect to the home network, and the home AMF 110A sends a copy of the registration information for each registered UE to the network data aggregation node 300. The UE registration information includes an indicator of the UE location (in this example, the UE location is the home network of the UE), a timestamp of the registration, and a type allocation code (TAC) that identifies the type of the UE device. In the illustrated example, the registration information for the UE 304 includes a UE location identifier of the home network, a timestamp of TS1, and a TAC of 1. The registration information for the UE 306 includes a UE location identifier that identifies the home network, a timestamp of TS1.1, and a TAC of 2, because the UE 306 is an IoT device, which is a different type of device than the UE 304.

[0058] In step 2, the network data aggregation node 300 receives or updates the mobility pattern information for the registered UEs. For example, the network data aggregation node 300 can maintain a mobility pattern database for all UEs that the network data aggregation node 300 tracks. When the network data aggregation node 300 receives registration data for a UE, the network data aggregation node 300 performs a lookup in its mobility pattern database to determine whether a mobility pattern record exists for the UE. If the record does not exist, the network data aggregation node 300 can generate a new mobility pattern record for the UE. If the record exists, the network data aggregation node 300 can update the existing mobility pattern record for the UE based on the newly received UE registration data.

[0059] In the illustrated example, assume that the registration is a new (first time) registration for the UEs 304 and 306. Accordingly, the network data aggregation node 300 will create the following mobility pattern records for the UEs 304 and 306:

[0060]

[0061] Table 1: Mobility pattern for UE 304 after first registration

[0062]

[0063] Table 2: Mobility pattern for UE 306 after first registration

[0064] Continuing Figure 3In the example of FIG. 2, UEs 304 and 306 roam into a visited network and connect to the visited network via radio access network nodes 204B and 202B. In step 3, the serving AMF 110B sends a new UE registration to the home network of UEs 304 and 306 (one new UE registration for each of UEs 304 and 306) and sends a copy of the UE registration data to network data aggregation node 300. In the illustrated example, the aggregated data includes an identifier of the visited network as the UE location, a timestamp of TS2, and TACs of 1 and 2 for UEs 304 and 306, respectively.

[0065] Network data aggregation node 300 receives the UE registration data, determines that mobility pattern records already exist for these UEs, and updates the mobility pattern records for UEs 304 and 306. Tables 3 and 4 below illustrate the updated mobility patterns that can be stored for UEs 304 and 306.

[0066]

[0067] Table 3: Updated mobility pattern for UE 304 after second registration

[0068]

[0069] Table 4: Updated mobility pattern for UE 306 after second registration

[0070] The requesting network node can use the data illustrated in Tables 1-4 to determine whether a UE’s registration is abnormal and to perform a security screening of the UE registration. Figure 4 FIG. 2 illustrates the use of mobility patterns to screen a UE registration, in which the UE registration is determined to be not abnormal and is allowed. Referring to FIG. 2, Figure 4 In step 1, assume that UE 304 roams from a home network into a visited network. When UE 304 connects to the visited network via radio access nodes 204B and 202B, the serving AMF 110B sends a UE registration message to UDM 104 located in the home network of UE 304. The UE registration identifies the UE location as visited network #1 and includes a timestamp TS3 and a TAC of 1. In step 2, the UE registration is forwarded to the home network via SEPP 126B in the visited network and SEPP 126A in the home network of the UE.

[0071] In step 3, in response to receiving the UE registration, SEPP 126A in the home network sends a mobility pattern query to aggregation node 300. In step 4, aggregation node 300 responds to the mobility pattern query with a query response that includes the mobility pattern.

[0072] SEPP 126A compares the UE location, timestamp, and type assignment code in the registration with the mobility pattern received from the aggregation node 300. In this example, assume that the UE is visiting a network that the UE has visited before. Thus, the SEPP 126A determines that the UE registration is not abnormal, and in step 5, forwards the UE registration to the UDM 104 in the UE’s home network.

[0073] Figure 5 Figure illustrates a case where a UE registration is blocked based on mobility pattern information. Referring to Figure 5 In step 1, the attacker 200 imitates an AMF by sending a fake UE registration to the UE’s home network. In the fake UE registration, the attacker includes an identifier of the attacker’s network instead of the location where the real UE is registered.

[0074] In step 2, the SEPP 126A receives the fake UE registration and sends a mobility pattern query to the aggregation node 300. The mobility pattern query identifies the UE and the location of the UE included in the registration message.

[0075] The aggregation node 300 receives the mobility pattern query, looks up in its mobility pattern database using the UE identifier obtained from the mobility pattern query, and retrieves the mobility pattern of the UE. In step 3, the aggregation node 300 responds to the mobility pattern query with a query response that includes the mobility pattern. The response can optionally include an indication of a UE registration abnormality based on a determination made by the aggregation node 300.

[0076] The SEPP 126A receives the response and determines that the response is abnormal. In a simple example, the SEPP 126A can determine that the response is abnormal if the UE location specified in the registration does not match any previous UE registration location indicated in the mobility pattern. In this example, the SEPP 126A determines that the mobility pattern does not correspond to a network that the UE has registered with in the past. Thus, in step 4, the SEPP 126A blocks the fake UE registration. The SEPP 126A can also implement further verification before blocking the UE registration. Examples of further verification will be described in more detail below.

[0077] Figure 6 is a block diagram illustrating an example architecture of the aggregation node 300 and the SEPP 126A for security screening using mobility patterns. Referring to Figure 6, the aggregation node 300 and the SEPP 126A each include at least one processor 600 and memory 602. The aggregation node 300 includes a mobility pattern generator 604 that generates mobility patterns based on UE registration data received from AMFs and stores the mobility patterns in a mobility pattern database 606. Alternatively, the mobility pattern generator 604 can receive UE registration data from SEPPs in networks in which UEs are roaming, rather than from AMFs in networks in which UEs are roaming. In yet another alternative, the mobility pattern generator 604 can receive UE registration data from home network SEPPs to populate the mobility pattern database 606 in response to incoming registration requests by roaming subscribers of the home network. The mobility pattern generator 604 can utilize mobility pattern information in the mobility pattern database 606 to respond to mobility pattern queries from home network SEPPs.

[0078] The SEPP 126A includes a UE registration security screener 608 that receives UE registrations from AMFs, formulates queries to the network data aggregation node 300, receives mobility pattern information from the aggregation node 300, and determines whether to block UE registrations based on the mobility pattern information. The UE registration security screener 608 can block UE registrations that are identified as anomalous based on the mobility pattern information. The UE registration security screener 608 can also conduct UE location verifications after initially determining that a UE registration is anomalous. In one example, the UE registration security screener 608 can initiate a page for the UE at a location specified in the UE registration. If the UE is successfully paged, this indicates that a real UE is present at the location specified in the UE registration, and the UE registration security screener 608 can thereby allow the registration. If the UE is not successfully paged, the UE registration security screener 608 can block the registration as a false registration. In another example, the UE registration security screener 608 can allow a registration that is identified as anomalous, but send a message to a network operator that includes registration data (network identifiers, UE identifiers, TACs, etc.) for the anomalous registration.

[0079] Figure 7 is a flowchart illustrating an example procedure performed by the aggregation node 300 in generating mobility patterns and providing the mobility patterns to requesting NFs. Referring to Figure 7At step 700, the aggregation node 300 receives UE registration data from 5G NFs as the UE connects to different network locations. For example, the aggregation node 300 can receive UE registration data, such as registration location, timestamp, and type assignment code, from an AMF as the UE registers with a network served by the AMF. Additionally or alternatively, the aggregation node 300 can receive a mobility pattern defined in section 5.3.4.2 of 3GPP TS 23.501. 3GPP TS 23.501 indicates that a mobility pattern is a concept that can be used by an AMF to characterize and optimize UE mobility. The AMF determines and updates the mobility pattern of a UE based on the subscription of the UE, statistical data of UE mobility, network local policy, UE assistance information, or any combination of these items. The statistical data of UE mobility can be historical or expected UE mobility trajectory. If a NWDAF is deployed, the statistical data can also be analytics data, i.e., statistical data or prediction provided by the NWDAF. According to the subject matter described herein, the SEPP can use the mobility pattern information for UE registration security screening, which is not mentioned as a use of mobility pattern in 3GPP TS 23.501.

[0080] Returning to Figure 7 At step 702, the aggregation node aggregates the registration data of UEs received from 5G NFs to produce mobility patterns of individual UEs. For example, the aggregation node 300 can aggregate UE registration data from different AMFs to produce mobility patterns of UEs, examples of which are shown above and in Tables 1-4. The aggregation node 300 can store the mobility patterns in the mobility pattern database 606.

[0081] At step 704, the network data aggregation node receives a mobility pattern query from a 5G NF located in a home network of a UE. For example, the SEPP 126A can send a mobility pattern query to the aggregation node 300. The mobility pattern query can be generated in response to a request generated by an AMF currently serving the UE to register a current location of the UE with a home network UDM or a request generated by an attacker impersonating the AMF seeking to update the location of the UE to point to the attacker’s network. The SEPP 126A can cache a UE registration request pending determination of whether the registration request is abnormal based on mobility pattern information. The mobility pattern query can identify the UE for which registration is being requested. For cases where the aggregation node 300 determines whether a registration request is abnormal, the mobility pattern query can optionally include a network location of the UE extracted from the registration request.

[0082] In step 706, the aggregation node 300 responds to the mobility pattern query by sending the mobility pattern to a 5G NF located in the home network of the UE. For example, the aggregation node 300 can look up the mobility pattern of the UE in the mobility pattern database 606 and send the mobility pattern to the SEPP 126A located in the home network of the UE. In addition, the aggregation node 300 can provide an indication in the response whether the aggregation node 300 classified the registration as abnormal.

[0083] Figure 8 FIG. 21 is a flowchart illustrating an exemplary procedure for security screening based on mobility pattern information by a home network SEPP. Referring to FIG. 21, in step 2100, the SEPP receives a request to register a UE. For example, the SEPP 126A can receive a request to register a legitimate UE or a fake registration from an attacker. Figure 8

[0084] In step 802, in response to the registration request, the SEPP sends a mobility pattern query message to a network data aggregation node. For example, the SEPP 126A can send a mobility pattern query message to the aggregation node 300. The mobility pattern query message can identify the UE whose registration is being requested and, optionally, a location where the registration is requested. This location can be provided for cases where the aggregation node 300 determines whether the registration is abnormal. If the determination is made only by the SEPP 126A, then the location of the UE does not need to be sent as part of the mobility pattern query. In determining whether the registration request is abnormal, the SEPP 126A can cache the registration request and refrain from forwarding the registration request to a UDM in the home network.

[0085] ​In step 804, the SEPP 126A receives a response from the network data aggregation node including mobility patterns for the UE. For example, the SEPP 126A can receive mobility pattern information from the aggregation node 300, such as the mobility pattern information shown above in Tables 1-4. The mobility pattern information can indicate a historical pattern of registration for the UE identified in the request. The mobility pattern can additionally or alternatively indicate a mobility pattern for UEs of the same device type as the UE device type identified in the mobility pattern request. Mobility patterns for UEs of the same device type can be used to determine whether a registration for a particular UE, such as an IoT device, is abnormal when compared to mobility patterns for other UEs of the same device type. For example, a registration for a mobile handset with voice calling capabilities can be expected to have different ranges of values for various parameters in the registration request compared to a registration from an IoT device, where the IoT device is a sensor. Another check for an IoT device can be to determine whether the device type is a mobile device. For example, when a fixed IoT device wakes up to send its data, the device can be expected to always register from the same location. Registration of the same fixed IoT device to multiple network locations can indicate that the registration is abnormal.

[0086] In step 806, the SEPP 126A determines whether the registration is abnormal based on the mobility patterns. For example, if the location of the registration indicates a location in a network that the UE has never registered from in the past, the SEPP 126A can identify the registration as abnormal. In another example, the SEPP 126A can implement more complex algorithms, such as machine learning algorithms, to determine whether the UE registration is abnormal.

[0087] In step 808, if the registration is not determined to be abnormal, control proceeds to step 810, in which the registration is allowed. If the registration is allowed, the SEPP 126A will forward the registration request to a UDM in the home network of the UE. The UDM will update the location of the UE in its database, and subsequent communications to the UE will be sent to that location until the registration is cancelled or updated by a new registration.

[0088] If the registration is determined to be abnormal as described above, in some instances the SEPP can implement further verification to determine whether to allow the registration. For example, if the UE is a mobile phone that is registering for the first time in a new city, then the registration can be valid if the user is travelling to the city for the first time. Thus, in step 812, it is determined whether to implement further verification of the registration. If further verification is not implemented, control proceeds to step 814, in which the SEPP blocks the registration. Blocking the registration can include refraining from forwarding the registration to the UDM, and optionally including responding to the node that made the request (either the real AMF or the attacker).

[0089] In step 812, if further verification is implemented, control proceeds to step 816 in which further verification of the registration of the UE is performed. In one example, the SEPP 126A can initiate a page of the UE. Initiating a page of the UE can include sending a page request message to the UE via the network location identified in the registration request. A page response will be sent back to the requesting SEPP 126A. If the page response indicates that the UE was successfully paged, this indicates that a real UE exists at the location specified in the registration request.

[0090] Thus, in step 818, if the UE location is verified, control proceeds to step 820 in which the registration is allowed. If the SEPP 126A receives a response indicating that the page was not successful, this indicates that a real UE does not exist at the location specified in the registration request, indicating that the registration is fake. Thus, if the UE location is not verified by receiving a response indicating successful paging of the UE, control proceeds to step 814 in which the registration is blocked.

[0091] It should be noted that the subject matter described herein is not limited to blocking registration of a UE identified as anomalous. In addition to or instead of blocking registration, the SEPP 126A can notify a network operator by sending a message to an operations, administration, and maintenance (OA&M) system of the network operator. In cases where the registration is identified as anomalous but allowed, the network operator can choose to block subsequent registrations identifying the same UE if, after further analysis, it is determined that the registration was fake.

[0092] The subject matter described herein is not limited to identifying a UE registration as anomalous based on a comparison of historical mobility patterns of the same UE. In alternative implementations, the network data aggregation node 300 can collect UE registration data for multiple UEs of the same type and provide the requesting node with UE registration data for UEs of the same type as the UE attempting registration. In such cases, the requesting node, such as the home network SEPP 126A, compares the registration data of the UE attempting registration to the UE mobility pattern(s) of UEs of the same type as the UE requesting registration. If the registration data of the UE attempting registration is statistically different from the mobility patterns of UEs of the same type, the UE registration can be blocked. If the registration data of the UE attempting registration is not statistically similar to the mobility patterns of UEs of the same type, the registration can be blocked.

[0093] As described above, the network data aggregation node 300 is configured to perform 5G historical mobility tracking using signaling messages exchanged between 5G network nodes to support 5G UE mobility. Figure 9is a signaling message flow diagram illustrating exemplary 5G messages associated with mobility of a UE. Referring to Figure 9 When the UE 304 connects to the network via the RAN 120, the RAN 120 performs AMF selection and sends a registration request message to the serving AMF 110B. The serving AMF 110B performs AUSF selection and signals to the AUSF 112 in the UE’s home network to authenticate the UE. Once the UE is authenticated, the serving AMF sends a Nudm_UECM_Registration_Request message 900 to the UDM 104 located in the UE’s home network. This message can be sent via a SEPP (not shown in Figure 9 ) in the network of the AMF 110B. The serving AMF 110B can send a copy of the registration data from the Nudm_UECM_Registration_Request message 900 to the network data aggregation node 300, and the network data aggregation node 900 can store the registration data in the UE mobility pattern database 606. The home network SEPP (not shown in Figure 9 ) can query the UE mobility pattern database to determine whether to allow the Nudm_UECM_Registration_Request message 900 to be sent to the UDM 104 to register the user. Figure 9 The remaining signaling in is related to policy control and session setup for the UE in the case that the UE’s registration is allowed to proceed to the UDM. If the registration is blocked, the remaining signaling after the registration is avoided.

[0094] In the example above, the aggregation node 300 is described as being implemented using a NWDAF or a non-3GPP defined aggregation platform. In another example, the aggregation node 300 can be implemented using a 5G UDR. Figure 10 is a network diagram illustrating a 5G UDR and its interfaces to other 5G network nodes. In Figure 10 , the UDR 1000 stores subscription data, policy data, structured data for exposure, and application data. This data can be collected from the UDM 104, PCF 102, and NEF 118. Interfaces between the UDM 104 and the AMF 110, SMF 108, AUSF 112, and short message service function (SMSF) 1002 are also illustrated.

[0095] If the UDR 1000 implements the functionality of the aggregation node 300 described above, the UDR 1000 can populate the mobility pattern database 606 with UE registration data obtained from the UDM 104. Furthermore, as described above, the UDR 1000 can utilize the data in the mobility pattern database 606 to respond to mobility pattern queries.

[0096] Therefore, generating mobility patterns using historical UE registration information and then using these patterns to screen UE registrations can prevent some network attacks and enhance data integrity within the home network. Using mobility patterns is also more computationally efficient than calculating distances between networks and using those distances for speed checks.

[0097] Implementing mobility pattern generation at a network data aggregation platform (such as NWDAF, UDR, or a non-3GPP data aggregation platform) is advantageous because such implementations offload the storage, processing, and retrieval required for generating mobility patterns from nodes that are also responsible for establishing and maintaining sessions between UEs (such as AMF). Implementing security screening at the home network SEPP is advantageous because the SEPP is located at the natural entry and exit points of the network.

[0098] Even in the example above, where mobility patterns are generated by the network data aggregation node and the determination of registration anomalies is performed by SEPP, the topics described herein are not limited to this type of implementation. In alternative implementations, mobility pattern generation and registration anomaly determination can be performed by the network data aggregation node. In such implementations, the message flow can be... Figure 3 The message flow shown is the same, except that the network data aggregation node's response to the mobility mode query may include determining whether the registration is abnormal. Upon receiving a response with this determination, SEPP may 1) accept the determination, 2) perform UE location verification as described above, and accept or reject the determination based on the verification result. That is, if the network data aggregation node determines that the registration is abnormal, but the UE's location is verified through successful paging, SEPP may record the determination made by the network data aggregation node, record that the UE was successfully paging, and allow the registration to continue into the UE's home network. If the network data aggregation node determines that the registration is abnormal and the UE was not successfully paging, SEPP may block the registration. If the network data aggregation function determines that the registration is not abnormal, SEPP may allow the registration, or only allow the registration after successfully verifying the UE's location through successful paging.

[0099] The publicly available information of the following references is incorporated herein by reference in its entirety:

[0100] References

[0101] 1. 3GPP TS 23.501; 3 rd3GPP TS 23.501 ; 3

[0102] 2. 3GPP TS 23.502; 3 rd 3GPP TS 23.501 ; 3

[0103] 3. 3GPP TS 29.510; 3 rd 3GPP TS 23.501 ; 3

[0104] 4. 3GPP TS 29.500; 3 rd 3GPP TS 23.501 ; 3

[0105] 5. 3GPP TS 29.520, 3 rd3GPP TS 28.541, Generation Partnership Project, Technical Specification Group Core Network and Terminals; 5G System; Network Data Analytics Services; Stage 3 (Release 16), V16.4.0 (2020-06)

[0106] It should be understood that various details of the disclosed subject matter can be changed without departing from the scope of the presently disclosed subject matter. Furthermore, the foregoing description is for the purpose of illustration only, and not for the purpose of limitation.

Claims

1. A method for historical 5G user equipment (UE) mobility tracking and security screening, the method comprising: receiving, at a network data aggregation node comprising at least one processor, UE registration data from 5G network functions (NFs) as a UE connects to different network locations; aggregating, at the network node, registration data for individual UEs to produce mobility patterns for the UEs, wherein aggregating the registration data to produce the mobility patterns comprises, for each mobility pattern, for each registration instance for a UE, storing an indicator of a location of the UE, a timestamp of when the UE registered at the location, and a type allocation code (TAC); in response to receiving a message for a new registration for a UE, receiving, at the network node, a request for a mobility pattern for the UE from a 5G NF located in a home network of the UE; and responding to the request by sending the mobility pattern to the 5G NF located in the home network of the UE, wherein the 5G NF located in the home network of the UE comprises a security edge protection proxy (SEPP), and further comprising: receiving, at the SEPP, the mobility pattern and determining, based on the mobility pattern, that the message for the new registration indicates that the UE registration pattern is abnormal, wherein determining that the message for the new registration indicates that the UE registration pattern is abnormal comprises: determining a device type from the TAC; comparing the mobility pattern to mobility patterns for devices of the same or similar type as the UE; and determining, based on a result of the comparison, whether the registration is abnormal; and in response to determining, at the SEPP, that the message for the new registration indicates that the UE registration pattern is abnormal, blocking the message for the new registration or initiating a page for the UE at a location specified in the UE registration, and in response to a successful page for the UE at the location specified in the UE registration, forwarding the message for the new registration to a unified data management (UDM) function in the home network of the UE.

2. The method of claim 1, wherein receiving UE registration data comprises receiving the mobility pattern from at least one of the 5G NFs.

3. The method of claim 1 or 2, wherein the network data aggregation node comprises a network data analytics platform (NWDAF) or a unified data repository (UDR).

4. The method of claim 1 or 2, wherein the network data aggregation node comprises a non-3GPP defined network data aggregation platform.

5. The method of claim 1 or 2, wherein the UE comprises an Internet of Things (IoT) device.

6. A system for historical 5G user equipment (UE) mobility tracking and security screening, the system comprising: a network data aggregation node comprising at least one processor; and 5G UE mobility pattern generator for receiving registration data from 5G network functions, NFs, as a UE connects to different network locations, aggregating registration data for individual UEs to produce mobility patterns for the UEs, wherein aggregating registration data to produce mobility patterns comprises, for each mobility pattern, for each registration instance for a UE, storing an indicator of a location of the UE, a timestamp of when the UE registered at the location, and a type allocation code, TAC, wherein the 5G UE mobility pattern generator is configured to, in response to receiving a message for a new registration for a UE, receive a request for a mobility pattern for the UE from a 5G NF located in a home network for the UE, and respond to the request by sending the mobility pattern to the home network for the UE, wherein the 5G NF located in the home network for the UE comprises a security edge protection proxy, SEPP, and the SEPP is configured to: receive the mobility pattern; determine, based on the mobility pattern, that the message for the new registration indicates that the UE is registering in an abnormal pattern, wherein determining that the message for the new registration indicates that the UE is registering in an abnormal pattern comprises: determining a type of device from the TAC; comparing the mobility pattern to mobility patterns for devices of the same or similar type as the UE; and determining, based on a result of the comparison, whether the registration is abnormal; and in response to determining that the message for the new registration indicates that the UE is registering in an abnormal pattern, blocking the message for the new registration or initiating a page for the UE at a location specified in the registration for the UE, and in response to a successful page for the UE at the location specified in the registration for the UE, forwarding the message for the new registration to a unified data management, UDM, function in the home network for the UE.

7. The system of claim 6, wherein receiving UE registration data comprises receiving mobility patterns for UEs from at least one of the 5G NFs.

8. The system of claim 6 or 7, wherein the network data aggregation node comprises a network data analytics platform, NWDAF, or a unified data repository, UDR.

9. The system of claim 6 or 7, wherein the network data aggregation node comprises a non-3GPP defined network data aggregation platform.

10. A non-transitory computer-readable medium having stored thereon executable instructions that, when executed by a processor of a computer, control the computer to perform steps comprising: receiving, at a network data aggregation node comprising at least one processor, UE registration data from 5G network functions, NFs, as a UE connects to different network locations; aggregating, at the network node, registration data for individual UEs from 5G NFs to produce mobility patterns for the UEs, wherein aggregating registration data to produce mobility patterns comprises: for each mobility pattern, for each registration instance for a UE, storing an indicator of a location of the UE, a timestamp of when the UE registered at the location, and a type allocation code, TAC; in response to receiving the message for new registration of the UE, receiving, at the network node, a request for a mobility pattern of the UE from a 5G NF located in a home network of the UE; and responding to the request by sending the mobility pattern to the 5G NF located in the home network of the UE, wherein the 5G NF located in the home network of the UE comprises a security edge protection proxy, SEPP, and further comprising: receiving, at the SEPP, the mobility pattern and determining, based on the mobility pattern, that the message for new registration indicates that the UE registration is abnormal, wherein determining that the message for new registration indicates that the UE registration is abnormal comprises: determining a device type from the TAC; comparing the mobility pattern to mobility patterns of devices of the same or similar type as the UE; and determining, based on a result of the comparison, whether the registration is abnormal; and at the SEPP, in response to determining that the message for new registration indicates that the UE registration is abnormal, blocking the message for new registration or initiating paging of the UE at a location specified in the UE registration, and in response to successful paging of the UE at the location specified in the UE registration, forwarding the message for new registration to a unified data management, UDM, function in the home network of the UE.

Citation Information

Patent Citations

  • Methods, systems, and computer readable media for validating user equipment (UE) location

    US20190007788A1