Method for identifying the status of a telecommunication access node and related device
By comparing the information sets of access nodes in the core telecommunications mobile network, the problem of identifying malicious femtonodes in 5G networks is solved, ensuring network security and the protection of user equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2025-12-16
- Publication Date
- 2026-06-16
Smart Images

Figure CN122227356A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of fifth-generation (5G) mobile telecommunications networks. Background Technology
[0002] This section introduces aspects that can help facilitate a better understanding of the invention disclosure. Therefore, the statements in this section should be read in this light and should not be construed as an admission that something is or is not prior art.
[0003] Mobile telecommunications networks, such as the network-based 3rd Generation Partnership Project (3GPP), continue to evolve and change. Industry groups, such as Working Group 3 of 3GPP System Architecture (SA), are responsible for developing security and privacy specifications for 3GPP networks and systems. For example, the Technical Report (TR) published by Working Group 3 of 3GPP SA3, entitled "Research on Security Aspects in the Smart Energy Vertical Sector" (referred to as TR 33.745), examines the security issues and requirements involved in integrating smart energy use cases, such as smart grids and IoT-based energy management systems, within the framework of fifth-generation (5G) networks. For simplicity, it is assumed that the disclosures in TR 33.745 are already familiar. Furthermore, the disclosures in TR 33.745 are incorporated herein by reference.
[0004] One of the topics covered by TR 33.745 is addressing the risks posed by malicious attackers (e.g., hackers) seeking unauthorized access to mobile networks and / or data tampering.
[0005] More specifically, TR 33.745 seeks solutions to potential new security requirements where malicious attackers may claim to be genuine 5G New Radio (NR) femtocells in order to request specific services (service theft) or information (data breach) to launch further attacks on the 5G core network.
[0006] For ease of understanding, in telecommunications, a femtocell typically refers to a small, low-power cellular base station designed for use in homes, offices, or other small areas to improve, for example, indoor coverage and reception. Sometimes, a femtocell is referred to as a "femtonode."
[0007] Femtocells connect to the service provider’s network (e.g., a 5G network) and attempt to improve cellular coverage in areas where macro base station signals may be weaker.
[0008] Since femtonodes deployed at end-user locations (i.e., devices that serve as the primary components of a femtocell) can be operator-provided or third-party devices, it is important to ensure that there are no malicious / damaged femtonodes (i.e., the possibility that a particular femtonode may include malicious capabilities). Therefore, it is necessary to identify such malicious femtonodes in order to (i) prevent such devices from accessing services provided by the network operator, (ii) prevent such malicious devices from accessing end-user equipment (UE) and data, and (iii) protect the UE and the network from the impact of such malicious femtonodes.
[0009] Currently, TR 33.745 Clause 6.2 "Solution #2: IKEv2 EAP-AKA-based Authentication" describes how 5G NR femtonodes (hereinafter referred to as "femtonodes") and devices in the 5G core network called Security Gateways (SeGWs) (hereinafter referred to as "gateways") authenticate each other using PKI certificates (X.509). After successful authentication, a secure communication channel called an Internet Protocol Security (IPsec) "tunnel" is established between the femtonode and the gateway to provide encryption, authentication, and data integrity between the femtonode and the gateway.
[0010] After establishing the IPsec tunnel, all "services" (UE, control and management signals and data) between the femtonode and the gateway are transmitted through the IPsec tunnel.
[0011] However, it has been recognized that femtonodes may be deployed in untrusted environments (e.g., within residential buildings or corporate networks), making them targets for malicious end-users / femtonode owners.
[0012] Therefore, in some ways, if a malicious end user / femtonode owner improperly tampers with parameters, such as the supported list of Closed Access Group Identifiers (CAG ID, CagID, or cagID) used to access femtonodes, the relevant access modes, and / or the location of femtonodes, the tampered parameters and their values can also be transmitted to the authorized UE and 5G core network through an IPsec tunnel.
[0013] Currently, there is no mechanism for 5G core networks (operators) to identify and locate such tampering behavior carried out by malicious end users.
[0014] Therefore, it is desirable to provide methods and devices for identifying and locating such malicious end users / femtonodes and associated cells in order to protect the 5G core network and its connected UEs from such malicious users / femtonodes and cells.
[0015] Further, it is desired to detect when a malicious end-user / femtonode owner has attempted to connect to the 5G core network and / or has already connected to the 5G core network, in order to prevent such malicious end-user / femtonode owners from requesting and accessing services (service theft) or information (data leakage) provided by the 5G core network operator, and to protect the UE from the influence of such malicious end-user / femtonode owners.
[0016] In summary, the goal is to identify the state of femtonodes (malicious / damaged fems and non-malicious / undamaged fems) within a mobile 5G telecommunications network in order to identify which femtonodes are damaged (malicious) and which are undamaged.
[0017] Femtonodes are simply one type of "access node" that facilitates connections from the UE to the mobile telecommunications network. Therefore, similar issues may apply to other access nodes. Furthermore, preventing compromised access nodes from accessing the network is not limited to 5G mobile telecommunications networks. Future networks, such as 6G mobile telecommunications networks, may have similar problems, where compromised access nodes may attempt to maliciously interfere with the network.
[0018] In summary, the goal is to identify the status of compromised access nodes within a mobile telecommunications network in order to distinguish which access nodes are compromised (malicious) and which are uncompromised. Summary of the Invention
[0019] This disclosure describes example methods and related devices for detecting malicious or compromised access nodes in mobile communication networks.
[0020] An example method for identifying the state of a telecommunications access node may include: receiving a message from the access node at a first network function (NF) element of a core telecommunications mobile network (“core network”), the message from the access node including at least an access identifier and a first set of access information associated with the access node; storing the first set of access information in a memory of the first NF element; and obtaining the stored first set of access information from the memory of the first NF element, and comparing the stored first set of access information with another set of access information received directly or indirectly from a second NF element of the core network to identify whether the access node is a compromised access node.
[0021] In such a method, the first set of stored access information may include at least one of the following: a femto indicator, location information associated with the access node, a supported CagList associated with the access node, and an access mode associated with the access node, and the other set of access information may include at least one of the following: another femto indicator, another location information associated with the access node, another supported CagList associated with the access node, and another access mode associated with the access node.
[0022] In one embodiment, the access node may include a new radio (NR) femtonode.
[0023] In this embodiment, messages from the access node include: NGAP NG SETUP REQUEST messages, or NGAP INITIAL UE MESSAGE messages that include non-access stratum (NAS) messages.
[0024] Furthermore, this example method may also include: generating a query message from a first NF element and sending the query message directly to a second NF element, wherein the query message includes an access identifier received by the first NF element from an access node; receiving the query message in the second NF element, the query message including the access identifier directly from the first NF element; using the received access identifier, searching the memory of the second NF element to locate previously provided undamaged access information corresponding to the received access identifier (hereinafter referred to as the "second access information set"); sending the second access information set directly to the first NF element, wherein the second access information set includes another access information set; and when a comparison between the first access information set and the other access information set results in the access node being identified as an undamaged access node due to the consistency of the compared access information, generating a success message and sending the success message to the access node or one or more user equipments served by the access node.
[0025] Alternatively, such a method may further include: when a comparison of a first set of access information with another set of access information results in the access node being identified as a compromised access network node due to inconsistencies in at least a portion of the compared access information, generating a failure message and sending the failure message to the access node or one or more user equipments served by the access node.
[0026] In the embodiments just discussed, it should be understood that the first NF element may include the access and mobility management function (AMF) element of the core network, and the second NF element may include the unified data repository (UDR) element of the core network.
[0027] In this embodiment, it should be understood that the access identifier may include the identifier of the access node.
[0028] In another alternative, the example method may include: generating a first intermediate query message from a first NF element and sending the first intermediate query message to a Policy Control Function (PCF) element, the first intermediate query message including at least an access identifier received by the first NF element from an access node; and generating a second intermediate query message in response to receiving the first intermediate query message at the PCF element and sending the second intermediate query message from the PCF element to a second NF element, wherein the second intermediate query message includes at least an access identifier received by the PCF element from the first NF element.
[0029] The alternative method may also include: receiving a second intermediate query message including an access identifier from a PCF element at a second NF element; using the received access identifier, searching the memory of the second NF element to locate previously provided undamaged access information corresponding to the received access identifier (hereinafter referred to as the "third access information set"); and sending the third access information set to the PCF element.
[0030] Alternatively, the alternative method may include: receiving a third access information set from a second NF element at a PCF element, generating a response message, and sending the response message to a first NF element, wherein the response message includes the third access information set (hereinafter referred to as the "fourth access information set"), and wherein the fourth access information set is another access information set.
[0031] Finally, the example methods discussed above may include: when the comparison between the first access information set and the fourth access information set results in the access node being identified as an undamaged access node due to the consistency of the compared access information, a success message is generated and sent to one or more user equipments served by the access node; or when the comparison between the first access information set and the fourth access information set results in the access node being identified as a damaged access network node due to the inconsistency of at least a portion of the compared access information, a failure message is generated and sent to the access node or one or more user equipments served by the access node.
[0032] Another example method for identifying the state of an access node may include: generating an initial intermediate request message from a first NF element and sending the initial intermediate request message to an authentication function element, wherein the initial intermediate request message includes a first access information set, the first access information set including at least an access identifier received by the first NF element from the access node; and receiving the initial intermediate request message at the authentication function element, generating a secondary intermediate request message, and sending the secondary intermediate request message to a second NF element of the core network, wherein the secondary intermediate request message includes an access identifier received by the authentication function element from the first NF element.
[0033] The method may further include: in a second NF element, receiving a secondary intermediate request message including an access identifier from an authentication function element; using the received access identifier, searching the memory of the second NF element to locate previously electronically provided undamaged access information corresponding to the received access identifier (hereinafter referred to as the "fifth access information set"); generating the fifth access information set from the second NF element and sending the fifth access information set to the authentication function element; in the authentication function element, receiving the fifth access information set from the second NF element; and comparing the received fifth access information set with a first access information set received by the authentication function element from a first NF element to identify whether the access node is a damaged access node.
[0034] Furthermore, if the comparison indicates that the fifth access information set is consistent with the first access information set, the authentication function element identifies the access node as undamaged, and the authentication function element is configured to generate a first success message and send the first success message to the first NF element; and / or if the comparison indicates that the fifth access information set is inconsistent with the first access information set, the authentication function element identifies the access node as damaged, and the authentication function element is configured to generate a first failure message and send the first failure message to the first NF element.
[0035] Furthermore, such a method may include: in response to receiving a first success message, configuring a first NF element to generate a second success message and sending the second success message to an access node or one or more UEs served by the access node; or, in response to receiving a first failure message, configuring a first NF element to generate a second failure message and sending the second failure message to an access node or one or more UEs served by the access node.
[0036] Similar to other methods, the access identifier may include the identifier of the access node, the first NF element may include the AMF element of the core network, the second NF element may include the UDR element of the core network, and the access node may include a New Radio (NR) femtonode.
[0037] In this method, the authentication function element may include the Authentication Server Function (AUSF) element of the core network.
[0038] Furthermore, in this method, the first access information set includes at least one of the following: a femto indicator, location information associated with the access node, a supported CagList associated with the access node, and an access mode associated with the access node, while the fifth access information set may include at least one of the following: another femto indicator, another location information associated with the access node, another supported CagList associated with the access node, and another access mode associated with the access node.
[0039] The methods described above (and herein) are merely some example methods discovered by the inventors. In yet another method, the state of an access node can be identified by: receiving messages from one or more undamaged access nodes (hereinafter referred to as "neighboring nodes") adjacent to the first access node in a first NF element of the core telecommunications mobile network ("core network"), each message including at least access information (hereinafter referred to as "neighboring access information set") corresponding to an access identifier associated with the first access node; storing each received message in the memory of the first NF element; receiving messages from the first access node in the first NF element, each message from the first access node including at least an access identifier and an access information set associated with the first access node ("first access information set"); and obtaining each stored message from the memory of the first NF element, and comparing the corresponding neighboring access information set in each obtained message with the first access information set to determine whether the first access node is a damaged access node.
[0040] In such a method, each adjacent access information set includes at least one of the following: a femto indicator, location information associated with the first access node, a supported CagList associated with the first access node, and an access mode associated with the first access node; and the first access information set may include at least one of the following: a femto indicator, location information associated with the first access node, a supported CagList associated with the first access node, and an access mode associated with the first access node.
[0041] Similar to other methods, the first access node may include a new radio (NR) femtonode, and the first NF element may include access and mobility management function elements of the core network.
[0042] In addition, messages from the first access node include: NGAP NG SETUP REQUEST messages, or NGAP INITIAL UE MESSAGE messages that include non-access stratum (NAS) messages.
[0043] In this embodiment, the access identifier may include the identifier of the first access node, and one or more of the adjacent nodes include a macro base station.
[0044] This method may further include: when the comparison of the set of adjacent access information in each obtained message with the first set of access information results in the first access node being identified as an undamaged access node due to the consistency of the compared access information, a success message is generated and sent to the first access node or one or more user equipments served by the first access node; or when the comparison of the set of adjacent access information in each obtained message with the first set of access information results in the first access node being identified as a damaged access network node due to the inconsistency of at least a portion of the compared access information, a failure message is generated and sent to the first access node or one or more user equipments served by the first access node.
[0045] The inventors have also discovered a method for actively identifying the state of a telecommunications access node. Such a method may include: at the UE, receiving a first notification message from one or more undamaged access nodes, the first notification message including at least an access identifier indicating that a cell associated with the access identifier is served by a damaged access node; identifying the cell associated with the access identifier; storing the identified cell in the UE's memory; and excluding the cell as a candidate cell in further UE mobility decisions.
[0046] In this embodiment, the first notification message may include at least one of the following: system information broadcast by one or more undamaged access nodes; MAC control elements sent by one or more undamaged access nodes; or DCI sent by one or more undamaged access nodes.
[0047] In addition, the access identifier may include at least one of the following: access node identifier; NR femtonode identifier; one or more cell identifiers; tracking area identifier; RAN notification area identifier.
[0048] Such a method may further include: receiving a second notification message from a network function element at one or more undamaged access nodes, the second notification message including an access identifier, and the method further includes: performing at least one of the following: preventing the served UE from handing over to a neighboring cell associated with the received access identifier; or sending a first notification to the UE.
[0049] In this embodiment, network functional elements may include core network functional elements (e.g., AMF elements).
[0050] One or more of the above example methods can be applied to a security gateway. For example, one such example method may include: receiving a failure message at an access node from a first NF, the failure message including an indication to release a transport network or IPsec connection toward the first NF; and, upon receiving the indication, triggering an SCTP release or an IPsec tunnel release.
[0051] Furthermore, this method may include: receiving an indication that the access node is compromised from a first NF at another access node connected to the access node; and releasing the connection or transport connection with the access node in response to receiving the indication. Additionally, this method may include: identifying the compromised access node at the first NF; and triggering the release of the SCTP connection or IPSEC connection associated with the access node by the first NF based on the identification.
[0052] In addition, this method may include: receiving a failure message from a first NF at a first access node, the failure message including an indication to release the transport network or IPSEC connection; and in response to receiving the indication, triggering an SCTP release or IPSEC tunnel release toward the first NF.
[0053] Alternatively, such methods may include: receiving an indication from a first NF that the first access node is compromised at another access node connected to the first access node; releasing a connection or transport connection with the first access node in response to receiving the indication; identifying the access node as a compromised access node at the first NF; and triggering the release of an SCTP connection or IPSEC connection associated with the access node by the first NF based on the identification. Attached Figure Description
[0054] The invention is illustrated by way of example and is not limited to the accompanying drawings, in which similar reference numerals indicate similar elements, and wherein: Figure 1 An example mobile telecommunications network is depicted.
[0055] Figure 2A An example message flow is depicted according to the example methods provided in this disclosure.
[0056] Figure 2B An example message flow is depicted according to the second example method provided in this disclosure.
[0057] Figure 2C An example message flow is depicted according to the third example method provided in this disclosure.
[0058] Figure 3 A simplified block diagram depicting the network elements of a mobile telecommunications network.
[0059] Figure 4A simplified block diagram of the user equipment (UE) of a mobile telecommunications network is depicted.
[0060] Specific embodiments of this disclosure are disclosed below with reference to various accompanying drawings and sketches. The descriptions and illustrations have been prepared with the intention of enhancing understanding. For example, Figure 1 The term "network" does not represent an actual network, device, or apparatus, but rather features provided to explain the methods and apparatus of this disclosure.
[0061] To effectively enable those skilled in the art to make, use, and best practice the exemplary embodiments described herein, simplicity and clarity are sought in the illustrations and descriptions. Those skilled in the art will understand that various modifications and changes can be made to the specific embodiments described herein without departing from the spirit and scope of this disclosure. Therefore, the text and drawings are to be considered illustrative and exemplary rather than restrictive or entirely covert, and all such modifications to the specific embodiments described herein are intended to be included within the scope of this disclosure. Detailed Implementation
[0062] The following detailed description describes exemplary embodiments and is not intended to limit it to the explicitly disclosed combinations. Therefore, unless otherwise stated, the features disclosed herein can be combined with each other to form additional combinations not shown separately for brevity purposes.
[0063] As used herein and in the appended claims, the terms “comprising,” “including,” or variations thereof are intended to refer to non-exclusive inclusion, such that a process, method, article of manufacture, or apparatus that includes a list of elements may include not only those elements in the list but also other elements not expressly listed or inherent to such a process, method, article of manufacture, or apparatus.
[0064] As used herein, the term “a” or “one” is defined as one or more. As used herein, the term “multiple” is defined as two or more. As used herein, the term “another” is defined as at least a second or more.
[0065] As used herein, the terms “include” and / or “have” are defined as including (i.e., open-ended language).
[0066] In the accompanying drawings, similar reference numerals are used throughout to indicate similar features.
[0067] Unless otherwise stated, the term "or" is used in this document in a substitute and combined sense.
[0068] The terms “illustrative” and “exemplary” are used for illustrative purposes only and do not indicate a quality level.
[0069] As used herein, the term “user equipment” or UE refers to an apparatus that includes, in particular, electronic components (e.g., a modem) used as radio frequency transceivers to wirelessly (i) transmit signals, messages and data to one or more elements (e.g., devices, apparatuses) of a mobile telecommunications network using an air interface, and (ii) receive signals, messages and data from one or more elements of the network using an air interface.
[0070] As used herein, the appropriate use of the letters “a” and “n” in the phrase indicates the first and last element or step in a group of elements or steps, such as (for example) access nodes 30a to 30n.
[0071] As used herein, the term “element” means: (a) a specific implementation of electronic hardware circuitry (e.g., in analog and / or digital circuitry) capable of performing one or more functions (such as network functions (NF) or UE functions); and / or (b) a combination of electronic circuitry and computer program products including software and / or firmware instructions stored on one or more electronic memories that work together to cause a device or apparatus to perform one or more NFs, UE functions, or method steps described herein; and / or (c) an electronic circuitry, such as, for example, an electronic microprocessor, a portion of a microprocessor, a processor, a portion of a processor, an electronic integrated circuit, or an electronic application processor (collectively referred to herein as a “processor”), which executes stored instructions (e.g., software or firmware) obtained from at least one electronic memory that, when executed by the processor, cause the device or element itself to perform one or more features, NFs, UE functions, or steps of a method.
[0072] As used herein, the names “first,” “second,” “third,” and other relational terms (if any) are used only to distinguish one network function (NF), UE function, access node function, or step from another function or step, and do not necessarily require or imply any actual such relationship, order, or importance between these functions or steps.
[0073] As used herein, the phrase "electronic memory" (referred to herein as "memory") means non-transitory electronic storage media (e.g., volatile or non-volatile memory devices). Examples of non-transitory electronic storage media include, but are not limited to: random access memory (RAM); programmable read-only memory (PROM); erasable programmable read-only memory (EPROM); flash-EPROM; magnetic computer-readable media (e.g., floppy disk, hard disk, magnetic tape, any other magnetic media); optical computer-readable media (e.g., optical disc read-only memory (CD-ROM); digital versatile optical disc (DVD); Blu-ray disc (BD), etc., or combinations thereof), or any other non-transitory medium from which an electronic processor may obtain stored instructions, which, when executed, cause the device to perform one or more functions or steps in the process.
[0074] When used in this article, the phrase “damaged nanonode” or “damaged access node” refers to a malicious node, while the phrase “undamaged nanonode” or “undamaged access node” refers to a non-malicious or valid node.
[0075] Now for reference Figure 1 The illustration depicts an example mobile communication network 10 (e.g., a 5GC or 6GC core radio network). In an embodiment, network 10 may include one or more UEs 20a to 20n, one or more access nodes 30a to 30n, and multiple core network function (NF) elements, including, for example: (i) a first NF element 40 (labeled as "..."). Figure 1 In NF (1) (ii) Authentication Function Element 50, (iii) Policy Control Function (PCF) Element 60, and (iv) Second NF Element 70 (labeled " Figure 1 In NF 2” (e.g., database). A security gateway (SeGW) 80 and authentication, authorization, and accounting elements 90 are also shown.
[0076] In some embodiments, when referring to each element 40 to 90, it should be understood that the term "element" may or may not be used. For example, in one embodiment, network 10 may be a 5GC network, and the first NF element 40 (" NF 1) may include an Access and Mobility Management Function (AMF) element, which may be simply referred to as "Element 40" or "AMF 40". Similarly, Authentication Element 50 may include an Authentication Server Function (AUSF), which may be simply referred to as "Element 50" or "AUSF 50", PCF Element 60 may be referred to as "Element 60", and the second NF element 70 (" NF2) may include a Unified Data Repository (UDR) element, which may be simply referred to as "Element 70" or "UDR 70". Similarly, in another embodiment, network 10 may include a 6GC network, wherein the corresponding network elements may include different naming functions. For example, the first NF element 40 may include a mobility management function element, which may be referred to as "MMF element 40".
[0077] Although Figure 1 Telecommunication elements 40 to 70 are depicted as four separate and distinct elements, but it should be understood that this is merely exemplary. Alternatively, one or more of elements 40 to 70 may be combined together, or further, may be separated into additional elements.
[0078] Furthermore, each network function performed by each of elements 40 to 70 may include operations and / or physical elements, specific network nodes or elements, or specific functions or sets of functions performed by one or more elements (such as virtualized network elements, VNFs). A physical element or node may be configured to perform multiple NFs. Network functions may be implemented as network elements on dedicated hardware, as software examples running on dedicated hardware, or as virtualized functions instantiated on a suitable platform (e.g., on cloud infrastructure).
[0079] Each of the elements 20a to 20n, 30a to 30n, and 40 to 70 of network 10 can be configured to perform known network functions and steps as well as the innovative functions and steps described herein.
[0080] To illustrate the innovative features, functions, and steps provided in this disclosure, for example, a single UE 20a, a single reference access node 30a, and adjacent access nodes 30b to 30n will be discussed (now), but it should be understood that this discussion applies to each UE 20a to 20n and each access node 30a to 30n.
[0081] In the embodiments, one or more of UEs 20a to 20n may include Internet of Things (IoT) devices, mobile phones, laptops, personal computers, electronic servers, home appliances, and industrial equipment, to name just a few non-limiting examples of UEs.
[0082] Now for reference Figure 2A This describes an example flow of messages or communications involving elements of a mobile network 10 that can be used to identify the state of access nodes. Figure 2A In the illustrated embodiment, the network includes a 5GC mobile telecommunications network, although this is merely exemplary, as the methods and related devices described herein can be applied to other networks, such as 6GC networks.
[0083] Nevertheless, for ease of understanding, the innovative methods and related devices will be described by illustrating their applicability to elements of the 5GC network.
[0084] In such a 5GC network, access nodes 30a to 30n may include new radio (NR) femtonodes, and the first NF element 40 (“ NF 1) may include an AMF element, authentication element 50 may include an AUSF element, and the second NF element 70 (" NF 2) may include UDR elements (PCR 60 retains the same name and is used for the purpose and function). That is, these two sets of descriptors can be used (e.g., access nodes 30a to 30n or femtonodes 30a to 30n, first NF 40 or AMF40, second NF 70 or UDR 70, etc.).
[0085] In particular, the inventors have discovered a method for identifying the state of NR femtonodes (access nodes) by applying a verification process that determines whether the NR femtonode (access node) is compromised and thus malicious, or uncompromised and therefore not malicious.
[0086] Subsequently, the phrase NR femtonode can be shortened to "femtonode" or simply "femto".
[0087] When the phrase “verify” (or its tense forms, verify, valid) is used in this document, it should be understood to refer to a method involving identifying whether a particular access node (e.g., a femtonode) is compromised, or the state of an access node (e.g., a femtonode).
[0088] In this embodiment, it is assumed that the operator of core network 10 has previously electronically pre-provided or pre-configured information in UDR 70 corresponding to the undamaged femtonodes 30b to 30n (e.g., Home Next Generation Node B base station key or identifier (HgNBID), the femtonode's supportedCagIdList (where "Cag" is an abbreviation for "Closed Access Group"), the locationInfo associated with the femtonode, the femtonode's accessMode, FemtoIndicator, secondaryAuthentication, etc.). For illustration, it is also assumed that femtonode 30a will be authenticated (i.e., identified as a damaged or undamaged access node).
[0089] In step 1, femtonode 30a can be configured to electronically generate a request message (e.g., an NGAP NGSETUP REQUEST message) and send the request message to AMF element 70. In one embodiment, the request message may include an access identifier (e.g., an HgNBID key) and a first set of access node information associated with femtonode 30a (hereinafter referred to as "access information"). In an embodiment, the first set of access information may include at least one of the following: a femto indicator, location information associated with femtonode 30a, a supported CagList associated with femtonode 30a (e.g., supported by the femtonode's cell), and an access mode associated with femtonode 30a.
[0090] As used throughout this specification, the phrase “access identifier” means an identifier (value, bit, etc.) associated with an access node (e.g., a femtonode). This can typically be an identifier of the access node itself.
[0091] Alternatively or additionally, in step 1a, UE 20a may electronically generate a Non-Access Stratum (NAS) message and send the NAS message to femtocell 30a. Upon receiving the NAS message, femtocell 30a may electronically generate and send an initial UE message carrying the NAS message (e.g., an NGAP initial UE message) to AMF 70. In embodiments, the initial UE message may again include an access identifier (e.g., an HgNBID key) and a first set of access information, wherein the first set of access information may again include at least one of the following: a femtocell indicator, location information associated with femtocell 30a, a supported CagList associated with femtocell 30a, and an access mode associated with femtocell 30a.
[0092] Before going further, it's helpful to understand the relationship between the access identifier (e.g., the HgNBID key) and other access information (e.g., femtostat value, supportedCagIdList value, LocationInfo value, and accessMode value). In this embodiment, each specific identifier (HgNBID key) is associated with the following values: femtostat, supportedCagIdList associated with the access node, LocationInfo associated with the access node, and accessMode associated with the access node. Therefore, by providing the AMF 40 with the HgNBID key associated with femtonode 30a, the AMF 40 (or AUSF 50 as further described below) can then trigger a mechanism (one or more methods / procedures) to identify whether femtonode 30a is compromised.
[0093] Furthermore, it should be understood that AMF 40 can be configured (by its operator) to electronically verify whether femto30a is damaged via receiving an NGAPNG SETUP REQUEST message from femto30a (i.e., in step 1) or an NGAP INITIAL UE MESSAGE message including a NAS message (i.e., in step 1a), or both (i.e., via steps 1 and 1a).
[0094] Continuing, after electronically receiving a message from femtonode 30a, AMF 40 can also be configured to electronically store the first set of access information received in such a message in its electronic memory (see [link to electronic memory]). Figure 3 Example memory 603). For ease of understanding, the information received by AMF 40 corresponding to femtosecond 30a can be referred to as the "first access information set". Therefore, it can be said that AMF 40 (i.e., the first NF element) electronically stores the first access information set in its electronic memory.
[0095] Subsequently, as described below, AMF 40 can be configured to electronically obtain a first set of access information from its electronic memory and electronically compare it with another set of access information received by AMF 40 directly or indirectly from UDR 70 (i.e., the second NF element) to identify the state of femto device 30a, i.e., whether femto device 30a is an compromised femtonode (e.g., whether it has been compromised). AMF 40 can do this using one or more procedures. It should be noted that femtonodes can be assigned / assigned to specific geographic locations. Therefore, femtonodes can infrequently change their locations. Therefore, femtonode location information can be stored in UDR 70 as part of a data entry / information element (e.g., 5gNrFemtoInfoIE) associated with the femtonode.
[0096] In this embodiment, in step 2a, an innovative direct communication connection can be established between the AMF 40 and the UDR 70. More specifically, in a typical 5GC telecommunications network, the AMF communicates with the Unified Data Management (UDM) element rather than the UDR. Nevertheless, the inventors propose an innovative communication connection between the AMF 40 and the UDR 70.
[0097] More specifically, in such an embodiment, AMF 40 can be configured to electronically generate a query request message (e.g., Nudr_DM_Query Request) (hereinafter referred to as the "query message") and send it directly to UDR 70. The query message includes an access identifier (e.g., an HgNBID key) received by AMF 40 from femtonode 30a.
[0098] Upon receiving a query message containing an access identifier (HgNBID key) electronically, UDR 70 can be configured to, in step 2b, use the received access identifier in its electronic memory (see [link to electronic memory]). Figure 3 The UDR 70 performs an electronic search in its example memory 603 to locate undamaged access information corresponding to the received access identifier, which was previously electronically provided by the operator of network 10 and electronically stored in the electronic memory of the UDR 70. This located access information can be referred to as the second set of access information to distinguish it from the first set of access information. In other words, the UDR 70 can locate the second set of access information corresponding to the received access identifier.
[0099] After electronically locating the second access information set, in step 2c, the UDR 70 can also be configured to directly and electronically transmit the second access information set (and its corresponding values) to the AMF 40 via a first response message (e.g., a Nudr_DM_Query Response message). In this sense, the second access information set is an example of an "other" access information set that the AMF 40 can receive and compare with the first access information set, wherein the other access information set may include at least one of the following: another femtoindex, another supported CagIdList, another location information (LocationInfo) associated with the access node, and another access mode (accessMode) associated with the access node.
[0100] After receiving the second access information set directly from UDR 70, AMF 40 (i.e., its electronic processor 602; see below) Figure 3 The AMF 40 can be configured to electronically compare the second set of access information with the first set of access information received by the AMF 40 from the femtonode 30a to identify the state of the femtonode 30a, i.e., whether the femtonode 30a is a compromised femtonode (e.g., whether it has been compromised). If the comparison indicates that the first set of access information matches the second set of access information, the AMF 40 initially identifies the femtonode 30a as an uncompromised femtonode. Therefore, the AMF 40 can be configured to electronically generate a "success" message and send the "success" message to the access node (femtonode 30a) or to one or more UEs 20a to 20n (e.g., UE 20a) served by the provided access node if the comparison of the access information sets results in the identification of the access node as an uncompromised access node.
[0101] However, if the second set of access information received by AMF 40 from UDR 70 is inconsistent with the first set of access information received by AMF 40 from femtonode 30a, then AMF 40 identifies femtonode 30a as a damaged node. Therefore, AMF 40 can be configured to electronically generate a "failure" message and send it to the access node (femtonode 30a) or one or more UEs 20a to 20n (e.g., UE 20a) served by the access node if, during the comparison of access information sets, inconsistency in at least a portion of the compared access information results in the identification of the access node as a damaged access node.
[0102] In either case, the AMF 40 can store the results in its electronic memory for later use. For ease of understanding, "success" and "failure" messages are displayed in... Figure 2A Steps 11 and 12 are mentioned and collectively referred to as Step A. Although shown as Step A, it should be understood that Step A can be executed once AMF 40 (the first NF element) or other elements in network 10 have completed the above-described comparison. In other words, Step A can be executed after any steps other than Step 10.
[0103] Alternatively, in step 3a, AMF 40 (i.e., the first NF element) can be configured to communicate indirectly with UDR 70 (i.e., the second NF element) by electronically generating a first intermediate query message (e.g., Npcf_5gNrFemto_Create Request) and sending it to PCF 60, instead of generating a message and sending it directly to UDR 70. The first intermediate query message may include at least the access identifier (e.g., HgNBID key) of AMF element 40 received from femtosecond 30a (i.e., the access node).
[0104] After electronically receiving the first intermediate query message, in step 3b, PCF 60 may be configured to electronically generate a second intermediate query message and send it to UDR 70. In an embodiment, the second intermediate query message may include at least the access identifier (HgNBID key) received by PCF 60 from AMF 40.
[0105] After receiving the second intermediate query message, including the access identifier, electronically from PCF 60, in step 3c, UDR 70 can be configured to: use the received access identifier (HgNBID key) in its electronic memory (see... Figure 3The UDR 70 performs an electronic search in the example memory 603 to locate undamaged access information (hereinafter referred to as the "third access information set") previously electronically provided by the operator of the core network 10, corresponding to the received access identifier. In other words, the UDR 70 can locate the third access information set corresponding to the received access identifier.
[0106] After locating the corresponding third access information set, in step 3d, UDR 70 can also be configured to electronically send the located third access information set and its corresponding value to PCF 60 via a response message (e.g., Nudr_DM_Query Response message).
[0107] After receiving the corresponding third access information set from UDR 70, in step 3e, PCF 60 can be configured to electronically enforce certain policy rules and electronically generate an additional response message (e.g., Npcf5gNrFemtoAuthorizationCreate Response) and send it to AMF 40, where the response may include the third access information set. To distinguish this transmission of information, this transmission is referred to as transmitting or sending the "fourth femto information set".
[0108] In this sense, the fourth access information set can be regarded as a second example of "another" access information set that the AMF 40 ultimately receives and compares with the first access information set, as described elsewhere in this document and below.
[0109] After receiving the fourth femtodata set from PCF 60, in step 4, AMF 40 can be configured to electronically compare the fourth access data set with the first access data set received from femtonode 30a to identify the state of femtonode 30a, i.e., determine whether femtonode 30a is a compromised femtonode (e.g., whether it has been compromised). If the comparison indicates that the first access data set matches the fourth access data set, AMF 40 initially identifies femtonode 30a as an uncompromised femtonode. Therefore, AMF 40 can be configured to electronically generate a "success" message and send the "success" message to the access node (femtonode 30a), or one or more UEs 20a to 20n (e.g., UE 20a) served by the access node (femtonode 30a).
[0110] However, if the fourth set of access information is inconsistent with the first set of access information received by the AMF 40 from the femtonode 30a, the AMF 40 identifies the femtonode 30a as a damaged node. Therefore, the AMF 40 can be configured to electronically generate a "failure" message and send it to the access node (femtonode 30a), or to one or more UEs 20a to 20n (e.g., UE 20a) served by the access node, if the comparison of the access information sets results in the access node being identified as a damaged access node due to inconsistencies in at least a portion of the compared access information.
[0111] In either case, the AMF 40 may store the results in its electronic memory for use in subsequent steps 10 through 12 (see below).
[0112] So far, the described method involves the AMF 40 (first NF element) performing an electronic comparison to identify whether an access node (e.g., femtonode 30a) is compromised. However, this is merely exemplary. Alternatively, the authentication element 50 (e.g., AUSF 50) can be used to perform a similar comparison. By doing so, the burden of authenticating access nodes, etc., is removed from the AMF 40 (first NF element) and moved to another network element, such as the authentication element 50 (e.g., AUSF).
[0113] More specifically, in an embodiment, in step 5a, AMF 40 can be configured to communicate indirectly with UDR 70 by electronically generating an initial intermediate request message (e.g., FemtoAuthorizeRequest) and sending it to authentication element 50 instead of generating a message and sending it directly to UDR 70. In a 5GC network embodiment, element 50 may include AMF 40.
[0114] The initial intermediate request message may include at least the first set of access information received by AMF element 40 from femto node 30a and an access identifier (e.g., HgNBID key) (i.e., the value HgNBId, and at least one of the following: FemtoIndicator, LocationInfo associated with the femto, the supported CagIdList associated with the femto cell, and the femto access mode).
[0115] Upon receiving the initial intermediate request message, in step 5b, AUSF 50 may be configured to electronically generate a secondary intermediate request message (e.g., Nudr_DM_Query Request) and send it to UDR 70 (the second NF element). In an embodiment, the secondary intermediate request message may include at least an access identifier (e.g., an HgNBID key) received by AUSF 50 from AMF 40 (the first NF element).
[0116] After receiving a secondary intermediate request message including the access identifier from AUSF 50, in step 5c, UDR 70 can be configured to: electronically search its electronic memory using the access identifier (see...). Figure 3 Example memory 603) is used to locate undamaged access information (e.g., HgNBID key; hereinafter referred to as the "fifth access information set") previously electronically provided by the operator of core network 10, corresponding to the received access identifier. In other words, UDR 70 can locate the fifth access information set corresponding to the received access identifier.
[0117] After locating the fifth access information set, in step 5d, UDR 70 (second NF element) can also be configured to generate the fifth access information set and its corresponding values, and electronically send them to authentication element 50 (e.g., AUSF 50) via a response message (e.g., Nudr_DM_Query Response message).
[0118] After receiving the fifth set of access information electronically from UDR 70, in step 5e, AUSF 50 can be configured to electronically compare the received fifth set of access information with the first set of access information received by AUSF 50 from AMF 40. AMF 40 then receives access information from femtonode 30a to identify the state of femtonode 30a, i.e., whether femtonode 30a is a compromised femtonode (e.g., whether it has been compromised).
[0119] The first access information set includes at least one of the following: a femto indicator, location information associated with the access node, a supported CagList associated with the access node, and an access mode associated with the access node, while the fifth access information set includes at least one of the following: another femto indicator, another location information associated with the access node, another supported CagList associated with the access node, and another access mode associated with the access node.
[0120] In an embodiment, if the comparison indicates that the fifth access information set matches the first access information set, then AUSF 50 initially identifies the femtonode 30a as an undamaged femtonode. Therefore, in step 5f, AUSF 50 can be configured to electronically generate a first "success" message and send it to the first NF element (AMF 40). However, if the comparison indicates that the fifth access information set does not match the first access information set, then AUSF 50 initially identifies the femtonode 30a as a damaged femtonode. Therefore, in step 5f, AUSF 50 can be configured to electronically generate a first "failure" message and send it to the first NF element (AMF 40).
[0121] After receiving the first success message from AUSF 50, AMF 40 can be configured to electronically generate a second success message and send it to access node 30a (femtonode 30a) or one or more UEs 20a to 20n (e.g., UE 20a) served by access node 30a (in step 11). Alternatively, after receiving the first failure message from AUSF 50, AMF 40 can be configured to electronically generate a second failure message and send it to access node 30a (femtonode 30a) or one or more UEs 20a to 20n (e.g., UE 20a) served by access node 30a (in step 12).
[0122] The above discussion pertains to the UE 20a and the access node (e.g., femtonode 30a) to be verified (or not verified, depending on the circumstances). Furthermore, the inventors have discovered additional, innovative methods involving undamaged neighboring access nodes (e.g., undamaged neighboring femtonodes 30b to 30n). It should be understood that these additional innovative methods are independent of the methods previously discussed, but each method may use some steps of the same or similar steps (i.e., one method may be completed without completing another). Moreover, it should be noted that, for example, one or more of the methods discussed herein may be combined into a single overall method.
[0123] In an embodiment, in step 6, AMF 40 (first NF element) can be configured to identify undamaged nodes 30b to 30n (hereinafter referred to as "neighboring nodes") adjacent to access node 30a, wherein one or more of the neighboring nodes may include, for example, a macro base station. Subsequently, in step 7, AMF 40 can be configured to electronically generate an acquisition message (e.g., 5gNrFemtoretrieveData) and send it to one or more of the identified undamaged neighboring nodes to obtain information about access node 30a from the neighboring nodes. In an embodiment, the acquisition message may include an access identifier (e.g., an HgNBID key) identifying femtonode 30a.
[0124] For clarity, in this embodiment, access node 30a is referred to as the "first access node" (e.g., an NR femtonode). Therefore, it can be said that adjacent nodes 30b to 30n are adjacent to the first access node 30a.
[0125] In step 7, each of one or more neighboring nodes that has received an acquisition message from AMF 40 can also be configured to electronically search its electronic memory (in) using the received access identifier. Figure 4 The example electronic memory shown (element 705) locates access information corresponding to the first access node 30a (this information may have been provided in advance or derived from an earlier UE report).
[0126] In this embodiment, such information may be contained in a “neighbor table” stored by each neighboring node. For ease of understanding, this access information is referred to as a “neighbor access information set” to distinguish it from other access information sets discussed herein.
[0127] Furthermore, each neighboring node 30b to 30n may also be configured to electronically generate its own neighboring access information set (if any) within a received response message (e.g., 5gNrFemtoRetriveData) and send it to AMF40. In an embodiment, the neighboring access information set may include at least information associated with the first access node 30a (e.g., at least one of the following: FemtoIndicator, LocationInfo associated with the first access node, supportedCagIdList associated with the first access node, and accessMode associated with the first access node).
[0128] In step 8, AMF 40 may be configured to electronically receive one or more acquisition response messages from one or more undamaged access nodes 30b to 30n (neighboring nodes), wherein each message may include at least access information corresponding to an access identifier (i.e., a set of neighboring access information) associated with the first access node. AMF 40 may be configured to electronically store each received message in its memory (i.e., the memory of the first NF element).
[0129] Additionally, AMF 40 may have previously received an initial UE message (e.g., an NG SETUP REQUEST message from step 1 or an INITIAL UE MESSAGE message from step 1a) via the first access node 30a in step 1a. This initial UE message includes at least an access identifier and a set of access information associated with the first access node (“first access information set”). More specifically, the first access information set may also include at least one of the following: a femtoindex, location information associated with the first access node, a supported CagList associated with the first access node, and an access mode associated with the first access node. As previously mentioned, for example, a message from access node 30a may originate from access node 30a or may originate from UE 20a. In other words, a message from the first access node 30a may include an NGAP NG SETUP REQUEST message or an NGAP INITIAL UE MESSAGE message that includes a non-access stratum (NAS) message.
[0130] Subsequently, AMF 40 can be configured to electronically retrieve each stored message from its electronic memory (i.e., the memory of the first NF element), and then compare the corresponding set of adjacent access information in each retrieved message with the first set of access information to determine whether the first access node is a compromised access node. If the comparison indicates that the set of adjacent access information in each retrieved message matches the first set of access information, then AMF 40 determines that the first access node 30a is an uncompromised access node. Therefore, AMF 40 can be configured to electronically generate a "success" message and send the "success" message to the first access node 30a or one or more UEs 20a to 20n (e.g., UE 20a) served by the access node.
[0131] However, if the comparison indicates that the set of adjacent access information in each obtained message is inconsistent with the first set of access information, then AMF 40 determines that the first access node 30a is a compromised access node. Therefore, AMF 40 can be configured to electronically generate a "failure" message and send the "failure" message to the first access node 30a or one or more UEs 20a to 20n served by the access node (e.g., UE 20a).
[0132] In an embodiment, if the comparison result leads to a match, the AMF 40 can be configured to electronically access its electronic memory to obtain the results of steps 4 and 5e discussed above. If the results in steps 4, 5e, and 10 all indicate that a match has occurred, then in step 11, the AMF 40 electronically identifies femtonode 30a as an undamaged femtonode and can also be configured to electronically generate an NG establishment response "success" message and send it to femtonode 30a, or alternatively, electronically generate a NAS response "success" message and send it to one or more UEs 20a to 20n (e.g., UE 20a) served by femtonode 30a, which further authorizes one or more UEs 20a to 20n (e.g., UE 20a) to communicate with femtonode 30a.
[0133] However, if AMF 40 accesses its electronic memory and obtains the results of steps 4 and 5e, and AMF 40 determines that the result of any one of steps 4, 5e, and 10 does not indicate that a match has occurred, then in step 12, AMF 40 identifies femtonode 30a as a damaged femtonode. In this case, AMF 40 can also be configured to electronically generate an NG setup failure response message (e.g., NG SETUP FAILURE) and send it to femtonode 30a, which does not authorize femtonode 30a to access core network 10; or alternatively, to electronically generate a NAS response "failure" message and send it to one or more UEs 20a to 20n (e.g., UE 20a) served by femtonode 30a, which does not authorize one or more UEs 20a to 20n (e.g., UE 20a) to communicate via femtonode 30a. In addition, AMF 40 can be configured to stop electronically exchanging messages with femtonode 30a because it identifies that node as compromised.
[0134] The embodiments discussed above illustrate some examples of how the core network 10 identifies the state of femtonodes to determine whether access node 30a (e.g., a femtonode) is compromised.
[0135] Furthermore, the inventors have discovered one or more methods for elements of network 10 to actively send one or more warning messages to undamaged femtonodes 30b to 30n and UEs 20a to 20n to indicate that a femtonode (e.g., femtonode 30a) is a damaged femtonode.
[0136] Now for reference Figure 2B In one embodiment, a second UE (e.g., UE 20b) may consider communicating with the compromised femtonode 30a during the mobility decision-making process. Given this possibility, the inventors anticipate that UE 20b may attempt to exchange communication with both the compromised femtonode 30a and the uncompromised femtonodes 30b to 30n. Therefore, the inventors have developed an active method for alerting UE 20b (and other UEs 20c to 20n) that femtonode 30a is a compromised femtonode.
[0137] For example, assuming that AMF 40 has completed one or more of the methods described previously, or another effective process, it can be said that AMF 40 has electronically stored the value indicating that the femtonode 30a is a damaged femtonode.
[0138] Subsequently, in step 100, AMF 40 may be configured to generate a status update request indication and send it, in a status update request message (e.g., a 5gNrFemtoneighborStatusUpdate Request message) or any other suitable NGAP message, to each undamaged node 30b to 30n adjacent to the damaged access node 30a. In an embodiment, the indication includes an "access identifier" associated with the damaged access node 30a. In one example, the access identifier may be an identifier of access node 30a (e.g., a femtonode). However, in other examples, the access identifier may typically include one or more cell identifiers, tracking area identifiers, or RAN notification area identifiers belonging to the cell of access node 30a.
[0139] In this embodiment, the message explicitly or implicitly instructs each undamaged access node 30b to 30n that the damaged access node 30a should be removed from the "neighboring femtonodes" list stored by each undamaged access node 30b to 30n. Therefore, by removing the damaged access node 30a from the list of each neighboring femtonode, neighboring nodes 30b to 30n will not attempt to communicate with the damaged access node 30a (e.g., for any handover process of UE 20b or 20c to 20n, the undamaged access nodes 30b to 30n will not consider the damaged access node 30a).
[0140] More generally, a state update request message can be summarized as a type of notification message received by one or more undamaged access nodes 30b to 30n from a core network function element (e.g., AMF 40), wherein the notification message may include an access identifier and an indication regarding any cell associated with that access identifier that UE 20b may move to, which is served by a damaged access node (e.g., femtonode 30a). In one example, the access identifier may be an identifier of access node 30a. In another example, the access identifier may be a cell identifier. To notify UE 20b, one or more undamaged access nodes 30b to 30n may be configured to electronically generate and transmit (i.e., relay) a notification message to UE 20b.
[0141] More specifically, in an embodiment, undamaged access nodes 30b to 30n can generate another notification message to be broadcast to nearby UEs (such as UE 20b). The notification message can be broadcast in a cell identified by the received access identifier. The notification message broadcast in a cell may include at least the access identifier and an indication that the cell associated with that access identifier is served by the damaged access node (e.g., node 30a). In some examples, the access identifier may include the access node identifier of node 30a (e.g., a femtonode), or more generally, one or more cell identifiers, tracking area identifiers, or RAN notification area identifiers belonging to a cell of access node 30a.
[0142] To distinguish between the two notification messages, the notification message sent by the undamaged access node to UE 20b can be referred to as the "first notification message," while the notification message received by nodes 30b to 30n from AMF 40 can be referred to as the second notification message.
[0143] Subsequently, UE 20b can be configured to receive a first notification message from nodes 30b to 30n, store an access identifier or one or more cell identifiers from a list of cells associated with that access identifier in its electronic memory, and subsequently exclude cells identified by or associated with that access identifier as candidate cells in further mobility decisions. In embodiments, the first notification message may include at least one of the following: system information broadcast by one or more undamaged access nodes 30b to 30n; a MAC control element (Media Access Control element) sent by one or more undamaged access nodes 30b to 30n; or DCI (Downlink Control Information) sent by one or more undamaged access nodes 30b to 30n.
[0144] In summary, when sent to UEs 20a to 20n in step 400, the broadcast first notification message instructs UEs within its broadcast range (e.g., UE 20b) to exclude cells belonging to the compromised access node 30a from mobility decisions (i.e., they will not be considered during cell reselection decisions). The inventors believe that this proactive approach taken by network 10 may help prevent UEs 20a to 20n from attempting to communicate with the compromised access node 30a associated with a fraudulent cell identifier. Furthermore, the second notification received by neighboring access nodes 30b to 30n will prevent neighboring access nodes from attempting to hand over the UE to the compromised access node 30a.
[0145] More specifically, in step 500, upon receiving the first notification message, UE 20b (or any UE 20a to 20n within the broadcast range of the undamaged access nodes 30b to 30n) can be configured to remove (i.e., delete) cells belonging to the damaged access node 30a and associated with the fraudulent access identifier from its cell search criteria, which are stored as electronic instructions in the electronic memory of UE 20b. In some examples, the access identifier is a cell identifier or an identifier of access node 30a.
[0146] If it is desired to avoid permanently removing access node 30a or the cell associated with the access identifier, the inventors have also proposed innovative alternatives.
[0147] More specifically, the unique CAG ID of the suspected compromised access node 30a can be temporarily deactivated. In this case, AMF 40 can generate and trigger a UE configuration update (UCU) procedure, in which AMF 40 updates the list of allowed CAG IDs for UEs 20a to 20n, thereby removing the unique CAG ID used by the compromised access node 30a from the list of allowed CAG IDs for UEs 20a to 20n.
[0148] Furthermore, if the CAG ID is used by other undamaged access nodes 30b to 30n, the network can reassign the new CAG ID to an undamaged trusted access node. Subsequently, AMF 40 can be configured to trigger a UCU procedure to update the permitted CAG list for UEs 20a to 20n. When sent to UEs 20a to 20n and the undamaged access nodes 30b to 30n, the new CAG ID list will cause UEs 20a to 20n and the undamaged access nodes 30b to 30n to remove the old CAG ID list that includes the damaged access node 30a, thus retaining only the new CAG ID list that does not include the damaged access node 30a to be used by UEs 20a to 20n and the undamaged access nodes 30b to 30n.
[0149] In summary, after one or more undamaged access nodes 30b to 30n receive such a second notification message (which may include an access identifier) from a network functional element, two approaches may subsequently occur: either prevent the served UE from handing over to a neighboring cell associated with the received access identifier, or send a first notification to UE 20b.
[0150] Figure 2A The embodiments described do not include the use of a security gateway (SeGW). However, since such a gateway can be utilized in network 10, the inventors have provided a method for implementing the previously described... Figure 2A Alternatives to the verification methods discussed.
[0151] Now for reference Figure 2C It depicts a simplified message flow diagram that includes both SeGW 80 and the authentication, authorization, and accounting elements 90.
[0152] In one embodiment, Figure 2A The methods shown (steps 1 to 12) can be supplemented within an electronically established Internet Key Exchange (IKE) tunnel between SGw 80 and access node 30a. This IKE tunnel is a temporary, secure (encrypted) communication channel used to transmit data and signals to negotiate, establish, and manage security associations (used to establish an IPsec tunnel between SGw 80 and access node 30a).
[0153] In an embodiment, if AMF 40 identifies access node 30a as a damaged femtonode based on completing steps 1 to 12 discussed above within the IKE tunnel, in step 12a, AMF 40 may generate a Delete IPsec TunnelSetup message ('delete message') and send it to the damaged access node 30a.
[0154] In an embodiment, the deletion message may include a value (i.e., a bit) representing an electronic instruction that, when received by the femtonode 30a, causes the IKE tunnel to be released in step 12b.
[0155] As described above, AMF 40 within network 10 generates and sends a deletion message. Although other elements of network 10 could also generate and send such messages, the inventors chose AMF 40 as the initiator of the message because SeGW 80 might be a third-party gateway device that is unable to receive and execute such deletion messages (or may itself be compromised).
[0156] Alternatively, if the IKE tunnel has not yet been established or does not exist, the operator of Network 10 may be able to access the transport network using the management / OAM IP address.
[0157] In addition, AMF 40 can generate and send SCTP shutdown to release or "remove" the NG interface.
[0158] Now for reference Figure 3 A simplified block diagram of a network device 600 including elements of a 5G mobile network 10 (e.g., AMF 40, AUSF 50, PCF 60, UDR 70) according to an example embodiment is depicted.
[0159] For clarity, as described herein, the phrase “network device” refers to an element of 5GC network 10 and its corresponding NF.
[0160] In this embodiment, network device 600 may be configured to provide one or more network-based operations and features, and to perform related steps within the 5G network 10. Furthermore, network device 600 may be configured to perform multiple core network functions (NFs). For example, device 600 may be incorporated into one or more of elements 40 to 70 described above and herein.
[0161] In an embodiment, network device 600 may include components for performing one or more innovative NFs, features, and steps. In an embodiment, such a device may include a combination of electronic components, such as network interface 601, at least one electronic processor 602, and electronic memory 603. Network interface 601 may include wired and / or wireless transceivers to enable access to other elements, nodes, and / or functions, including base stations, elements, the Internet, functions, and / or other elements. Memory 603 may include volatile and / or non-volatile memory (including program code) that, when executed by at least one processor 602, provides, in particular, the methods disclosed herein, including but not limited to… Figures 2A to 2C The method shown.
[0162] Now for reference Figure 4 A simplified block diagram of a client device 700 is shown, which may include user equipment 20a (or 20b to 20n), femtocell 30a, adjacent femtocells 30b to 30n, SeGW 80, or AAA element 90. User equipment 700, or a portion thereof, may be implemented in other network devices or elements, including base stations / WLAN APs and other network elements.
[0163] In an embodiment, the client device 700 may include means for performing one or more innovative functions, features, and steps. In an embodiment, such means may include a combination of electronic components, such as at least one antenna 701 communicating with an electronic transmitter 702 and an electronic receiver 703. Alternatively, the means 700 may include separate transmitting and receiving antennas (not shown for simplicity). The client device 700 may also include additional means, such as at least one electronic processor 704, configured to provide communication signals to and receive communication electronic signals from the transmitter and receiver, respectively, and to control the functionality of the device. The processor 704 may be configured to control the functionality of the transmitter and receiver by implementing control signaling to the transmitter and receiver via electrical leads or wirelessly. Similarly, the processor 704 may be configured to control other elements of the client device 700 by implementing control signaling via electrical leads or by wirelessly connecting the processor 704 to other components, such as a display (not shown for simplicity) or electronic memory 705.
[0164] Processors 602, 704 can be embodied in various ways, including electronic circuitry, at least one electronic processing core, one or more microprocessors with an accompanying digital signal processor, one or more electronic processors without an accompanying digital signal processor, one or more coprocessors, one or more multi-core processors, one or more electronic controllers, electronic processing circuitry, one or more computers, various other electronic processing elements including integrated circuits (e.g., application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc.), or some combination thereof. Therefore, although in Figure 3 and 4 While shown as a single processor, in some example embodiments, processor 602,704 may include multiple electronic processors or processing cores.
[0165] Continuing and reiterating regarding the client-side device 700, the device 700 can be configured to operate using one or more air interface standards, communication protocols, modulation types, access types, etc. Signals transmitted and received by the processor 704 may include signaling information according to the air interface standard of the applicable cellular system, and / or any number of different wired or wireless networking technologies, including but not limited to Wi-Fi, WLAN technologies such as IEEE 802.11, 802.16, 802.3, ADSL, DOCSIS, etc. Furthermore, these signals may include voice data, user-generated data, user-requested data, etc. As is known in the art, one or more memory elements 705 may be used to store information such as NSWOWF keys, temporary UE identifiers, UE context information, and to interact with the processor 704.
[0166] For example, the user equipment 700 and / or its cellular modem can operate according to various communication protocols, such as first-generation (1G) communication protocols, second-generation (2G or 2.5G) communication protocols, third-generation (3G) communication protocols, fourth-generation (4G) communication protocols, fifth-generation (5G) communication protocols, and Internet Protocol Multimedia Subsystem (IMS) communication protocols (e.g., Session Initiation Protocol (SIP)). For example, the device 700 can operate according to 2G wireless communication protocols such as IS-136, Time Division Multiple Access (TDMA), Global System for Mobile Communications (GSMO), GSM, IS-95, Code Division Multiple Access (CDMA), etc. Furthermore, for example, the user equipment 700 can operate according to 2.5G wireless communication protocols such as General Packet Radio Service (GPRS) and Enhanced Data GSM Environment (EDGE). Furthermore, for example, device 600 can operate according to 3G wireless communication protocols, such as Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), Wideband Code Division Multiple Access (WCDMA), Time Division Synchronous Code Division Multiple Access (TD-SCDMA), etc.
[0167] The device 700 may also be able to operate according to (i) 3.9G wireless communication protocols (such as Long Term Evolution (LTE), Evolved Universal Terrestrial Radio Access Network (E-UTRAN) etc.) and (ii) 4G wireless communication protocols (such as Advanced LTE, 5G etc.) as well as similar wireless communication protocols that may be developed subsequently.
[0168] It should be understood that processors 602 and 704 may include additional means, such as circuitry for implementing the audio / video and logic functions of devices 600 and 700. As a non-limiting example, processor 704 may include a digital signal processor device, a microprocessor device, an analog-to-digital converter, a digital-to-analog converter, etc. The control and signal processing functions of user device 700 may be distributed among these devices according to their respective capabilities.
[0169] Typically, processors 602 and 704 can obtain and access software or firmware stored as electronic instructions to enable their respective devices 600 and 700 to perform at least certain functions, features, and / or steps.
[0170] For example, processors 602 and 704 may include functions for performing the above-described functions. Figures 2A to 2C The unit shown is the femtosecond verification / invalidation method.
[0171] Furthermore, the processor 704 can be configured to complete a connection process that allows the user device 700 to send and receive web content, such as location-based content, according to protocols such as Wireless Application Protocol (WAP), Hypertext Transfer Protocol (HTTP), HTTP, etc.
[0172] It should be understood that Figure 3 and 4 Each of the devices 600, 700 shown includes units for performing one or more innovative functions, features, and steps, including but not limited to UE, femtonode, SeGW, AAA functions, features, and steps, or network-side function (e.g., NF) features and steps as set forth in the following claims. In embodiments, such devices may include combinations of electronic components such as one or more electronic transmitters, receivers, electronic comparator circuits, electronic input / output (I / O) circuits, electronic conductors (e.g., electronic buses), at least one electronic processor 602, 704, and at least one electronic memory 603, 705 including stored electronic instructions (i.e., computer program code), wherein the respective at least one processor 602, 704, in conjunction with the respective at least one memory 603, 705 and the respective computer program code, is executed and / or arranged such that the respective device 600, 700 performs at least the functions, features, and steps described herein, including but not limited to... Figures 1 to 2C The functions, features, and steps are shown.
[0173] This disclosure provides the following examples.
[0174] Example 1. A method for identifying the state of a telecommunications access node, comprising: receiving a message from the access node at a first network function (NF) element of a core telecommunications mobile network (“core network”), the message from the access node including at least an access identifier and a first set of access information associated with the access node; storing the first set of access information in a memory of the first NF element; and obtaining the stored first set of access information from the memory of the first NF element, and comparing the stored first set of access information with another set of access information received directly or indirectly from a second NF element of the core network to identify whether the access node is a compromised access node.
[0175] Example 2. According to the method of Example 1, the first set of access information stored includes at least one of the following: a femto indicator, location information associated with the access node, a supported CagList associated with the access node, and an access mode associated with the access node.
[0176] Example 3. According to the method of Example 1, wherein another set of access information includes at least one of the following: another femto indicator, another location information associated with the access node, another supported CagList associated with the access node, and another access mode associated with the access node.
[0177] Example 4. The method described in Example 1, wherein the access node includes a new radio (NR) femtonode.
[0178] Example 5. The method described in Example 1, wherein the message from the access node includes: an NGAP NG SETUPREQUEST message, or an NGAP INITIAL UE MESSAGE message that includes a non-access stratum (NAS) message.
[0179] Example 6. The method according to Example 1 further includes: generating a query message from the first NF element and sending the query message directly to the second NF element, wherein the query message includes an access identifier received by the first NF element from the access node.
[0180] Example 7. The method according to Example 6 further includes: in the second NF element, receiving a query message, the query message including an access identifier directly from the first NF element; using the received access identifier, searching the memory of the second NF element to locate previously provided undamaged access information corresponding to the received access identifier (hereinafter referred to as the "second access information set"); and sending the second access information set directly to the first NF element, wherein the second access information set includes another access information set.
[0181] Example 8. The method according to Example 1 further includes: when the comparison between the first set of access information and another set of access information results in the access node being identified as an undamaged access node due to the consistency of the compared access information, a success message is generated and the success message is sent to the access node or one or more user equipments served by the access node.
[0182] Example 9. The method according to Example 1 further includes: when a comparison of the first set of access information with another set of access information results in the access node being identified as a damaged access network node due to inconsistency of at least a portion of the compared access information, generating a failure message and sending the failure message to the access node or one or more user equipments served by the access node.
[0183] Example 10. The method described in Example 1, wherein the first NF element includes access and mobility management function elements of the core network.
[0184] Example 11. The method described in Example 1, wherein the second NF element includes a unified data repository element of the core network.
[0185] Example 12. The method described in Example 1, wherein the access identifier includes the identifier of the access node.
[0186] Example 13. The method according to Example 1 further includes: generating a first intermediate query message from a first NF element and sending the first intermediate query message to a Policy Control Function (PCF) element, the first intermediate query message including at least an access identifier received by the first NF element from an access node; and generating a second intermediate query message in response to receiving the first intermediate query message at the PCF element and sending the second intermediate query message from the PCF element to a second NF element, wherein the second intermediate query message includes at least an access identifier received by the PCF element from the first NF element.
[0187] Example 14. The method according to Example 13 further includes: receiving a second intermediate query message including an access identifier from a PCF element at a second NF element; using the received access identifier, searching the memory of the second NF element to locate previously provided undamaged access information corresponding to the received access identifier (hereinafter referred to as the "third access information set"); and sending the third access information set to the PCF element.
[0188] Example 15. The method according to Example 14 further includes: receiving a third access information set from a second NF element at a PCF element, generating a response message, and sending the response message to a first NF element, wherein the response message includes the third access information set (hereinafter referred to as the "fourth access information set"), and wherein the fourth access information set is another access information set.
[0189] Example 16. The method according to Example 15 further includes: when the comparison between the first access information set and the fourth access information set results in the access node being identified as an undamaged access node due to the consistency of the compared access information, a success message is generated and the success message is sent to one or more user equipments served by the access node.
[0190] Example 17. The method according to Example 15 further includes: when a comparison between the first access information set and the fourth access information set results in the access node being identified as a damaged access network node due to inconsistency of at least a portion of the compared access information, generating a failure message and sending the failure message to the access node or one or more user equipments served by the access node.
[0191] Example 18. A method for identifying the state of an access node, comprising: generating an initial intermediate request message from a first NF element and sending the initial intermediate request message to an authentication function element, wherein the initial intermediate request message includes a first access information set, the first access information set including at least an access identifier received by the first NF element from the access node; and receiving the initial intermediate request message at the authentication function element, generating a secondary intermediate request message, and sending the secondary intermediate request message to a second NF element of the core network, wherein the secondary intermediate request message includes an access identifier received by the authentication function element from the first NF element.
[0192] Example 19. The method according to Example 18 further includes: in a second NF element, receiving a secondary intermediate request message including an access identifier from an authentication function element; using the received access identifier, searching the memory of the second NF element to locate undamaged access information (hereinafter referred to as the "fifth access information set") that has been previously electronically provided and corresponds to the received access identifier; and generating the fifth access information set from the second NF element and sending the fifth access information set to the authentication function element.
[0193] Example 20. The method according to Example 19 further includes: receiving a fifth set of access information from a second NF element in an authentication function element; comparing the received fifth set of access information with a first set of access information received by the authentication function element from a first NF element to identify whether the access node is a damaged access node; if the comparison indicates that the fifth set of access information is consistent with the first set of access information, the authentication function element identifies the access node as undamaged, and the authentication function element is configured to generate a first success message and send the first success message to the first NF element; and if the comparison indicates that the fifth set of access information is inconsistent with the first set of access information, the authentication function element identifies the access node as damaged, and the authentication function element is configured to generate a first failure message and send the first failure message to the first NF element.
[0194] Example 21. The method according to Example 20 further includes: in response to receiving a first success message, the first NF element is configured to generate a second success message and send the second success message to an access node or one or more UEs served by the access node; or in response to receiving a first failure message, the first NF element is configured to generate a second failure message and send the second failure message to an access node or one or more UEs served by the access node.
[0195] Example 22. The method according to Example 18, wherein the access identifier includes the identifier of the access node.
[0196] Example 23. The method described in Example 18, wherein the first NF element includes access and mobility management function elements of the core network.
[0197] Example 24. The method described in Example 18, wherein the second NF element includes a unified data repository element of the core network.
[0198] Example 25. The method described in Example 18, wherein the authentication function element includes the authentication server function of the core network.
[0199] Example 26. The method described in Example 18, wherein the access node includes a new radio (NR) femtonode.
[0200] Example 27. The method according to Example 18, wherein the first access information set includes at least one of the following: a femto indicator, location information associated with the access node, a supported CagList associated with the access node, and an access mode associated with the access node.
[0201] Example 28. The method according to Example 18, wherein the fifth access information set includes at least one of the following: another femto indicator, another location information associated with the access node, another supported CagList associated with the access node, and another access mode associated with the access node.
[0202] Example 29. A method for identifying the state of an access node, comprising: receiving, in a first NF element of a core telecommunications mobile network (“core network”), messages from one or more undamaged access nodes (“neighboring nodes”) adjacent to a first access node, each message including at least access information (“neighboring access information set”) corresponding to an access identifier associated with the first access node; storing each received message in a memory of the first NF element; receiving, in the first NF element, messages from the first access node including at least an access identifier and an access information set associated with the first access node (“first access information set”); and obtaining each stored message from the memory of the first NF element, and comparing the corresponding neighboring access information set in each obtained message with the first access information set to determine whether the first access node is a damaged access node.
[0203] Example 30. The method according to Example 29, wherein each adjacent access information set includes at least one of the following: a femto indicator, location information associated with the first access node, a supported CagList associated with the first access node, and an access mode associated with the first access node.
[0204] Example 31. The method according to Example 29, wherein the first access information set includes at least one of the following: a femtoindicator, location information associated with the first access node, a supported CagList associated with the first access node, and an access mode associated with the first access node.
[0205] Example 32. The method described in Example 29, wherein the first access node includes a new radio (NR) femtonode.
[0206] Example 33. The method according to Example 29, wherein the message from the first access node includes: an NGAP NGSETUP REQUEST message, or an NGAP INITIAL UE MESSAGE message including a non-access stratum (NAS) message.
[0207] Example 34. The method according to Example 29, wherein the access identifier includes the identifier of the first access node.
[0208] Example 35. The method according to Example 29, wherein one or more of the neighboring nodes include a macro base station.
[0209] Example 36. The method according to Example 29 further includes: when the comparison of the set of adjacent access information in each obtained message with the first set of access information results in the first access node being identified as an undamaged access node due to the consistency of the compared access information, a success message is generated and the success message is sent to the first access node or one or more user equipments served by the first access node.
[0210] Example 37. The method according to Example 29 further includes: when a comparison of the set of adjacent access information in each obtained message with the first set of access information results in the first access node being identified as a damaged access network node due to inconsistency of at least a portion of the compared access information, a failure message is generated and the failure message is sent to the first access node or one or more user equipments served by the first access node.
[0211] Example 38. The method according to Example 29, wherein the first NF element includes access and mobility management function elements of the core network.
[0212] Example 39. A method for identifying the state of a telecommunications access node, comprising: at a UE, receiving a first notification message from one or more undamaged access nodes, the first notification message including at least an access identifier indicating that a cell associated with the access identifier is served by a damaged access node; identifying the cell associated with the access identifier; storing the identified cell in a UE memory; and excluding the cell as a candidate cell in further UE mobility decisions.
[0213] Example 40. The method according to Example 39, wherein the first notification message includes at least one of the following: system information broadcast by one or more undamaged access nodes; MAC control elements sent by one or more undamaged access nodes; or DCI sent by one or more undamaged access nodes.
[0214] Example 41. The method according to Example 39, wherein the access identifier includes at least one of the following: an access node identifier; an NR femtonode identifier; one or more cell identifiers; a tracking area identifier; and a RAN notification area identifier.
[0215] Example 42. The method according to Example 39 further includes: receiving a second notification message from a network function element at one or more undamaged access nodes, the second notification message including an access identifier, and the method further includes: performing at least one of the following: preventing the served UE from handing over to a neighboring cell associated with the received access identifier; or sending a first notification to the UE.
[0216] Example 43. The method described in Example 42, wherein the network functional elements include core network functional elements.
[0217] Example 44. The method described in Example 43, wherein the core network elements include an Access Management Function (AMF) element.
[0218] Example 45. The method according to Example 1 further includes: receiving a failure message from a first NF at an access node, the failure message including an indication to release a transport network or IPSEC connection toward the first NF; and triggering an SCTP release or IPSEC tunnel release upon receiving the indication.
[0219] Example 46. The method according to Example 1 further includes: receiving an indication that the access node is damaged from a first NF at another access node connected to the access node; and releasing the connection or transmission connection with the access node in response to receiving the indication.
[0220] Example 47. The method according to Example 1 further includes: identifying the access node with a damaged access node at the first NF; and triggering the release of the SCTP connection or IPSEC connection associated with the access node by the first NF based on the identification.
[0221] Example 48. The method according to Example 29 further includes: receiving a failure message from a first NF at a first access node, the failure message including an indication to release a transport network or IPSEC connection; and triggering an SCTP release or IPSEC tunnel release toward the first NF in response to receiving the indication.
[0222] Example 49. The method according to Example 29 further includes: receiving an indication that the first access node is damaged from a first NF at another access node connected to the first access node; and releasing the connection or transmission connection with the first access node in response to receiving the indication.
[0223] Example 50. The method according to Example 29 further includes: identifying the access node as a compromised access node at a first NF; and triggering the release of an SCTP connection or IPSEC connection associated with the access node by the first NF based on the identification.
[0224] While the foregoing description and associated drawings have described certain exemplary embodiments in the context of certain example combinations of elements, functions, or steps, it should be understood that different combinations of elements, functions, and / or steps may be provided by alternative embodiments without departing from the scope of the appended claims. In this regard, for example, combinations of elements, functions, and / or steps that are different from those explicitly described above are also contemplated as being set forth in some of the appended claims. Although specific terms may be used herein, they are used only in a general and descriptive sense and not for purposes of limitation.
[0225] The language of the following claims is incorporated herein by reference in an expanded form, that is, from the broadest to the narrowest, each possible combination is indicated by reference to a plurality of dependent claims described as unique independent embodiments.
[0226] The benefits, other advantages, and solutions to challenges have been described above with respect to specific embodiments of this disclosure. However, the benefits, advantages, and solutions to challenges, as well as any elements, functions, and / or steps that may lead to or result in such benefits, advantages, or solutions, or make such benefits, advantages, or solutions more apparent, should not be construed as key, essential, or necessary features or elements of any or all claims.
Claims
1. A method for identifying the status of a telecommunications access node, comprising: A message is received from the access node at a first network function (NF) element in the core telecommunications mobile network, the message from the access node including at least an access identifier and a first set of access information associated with the access node; The first access information set is stored in the memory of the first NF element; as well as The first set of access information stored in the memory of the first NF element is obtained, and the first set of access information stored in the memory is compared with another set of access information received directly or indirectly from the second NF element of the core telecommunications mobile network to identify whether the access node is a damaged access node.
2. The method according to claim 1, wherein the stored first access information set includes at least one of the following: a femtostat, location information associated with the access node, a supported CagList associated with the access node, and an access mode associated with the access node.
3. The method of claim 1, wherein the other access information set includes at least one of the following: another femto indicator, another location information associated with the access node, another supported CagList associated with the access node, and another access mode associated with the access node.
4. The method of claim 1, wherein the access node comprises a new radio NR femtonode.
5. The method of claim 1, wherein the message from the access node comprises: NGAP NGSETUP REQUEST message, or NGAP INITIAL UE MESSAGE message including non-access stratum (NAS) messages.
6. The method according to claim 1, further comprising: A query message is generated by the first NF element and sent directly to the second NF element, wherein the query message includes the access identifier received by the first NF element from the access node.
7. The method according to claim 6, further comprising: In the second NF element, the query message is received, the query message including the access identifier directly from the first NF element; Using the received access identifier, search the second NF element memory to locate the previously provided undamaged access information corresponding to the received access identifier. The undamaged access information is sent directly to the first NF element, wherein the undamaged access information includes the other set of access information.
8. The method according to claim 1, further comprising: When the comparison between the first set of access information and the other set of access information results in the access node being identified as an undamaged access node due to the consistency of the compared access information, a success message is generated and sent to the access node or one or more user equipments served by the access node.
9. The method according to claim 1, further comprising: When the comparison between the first set of access information and the other set of access information results in the identification of the access node as a damaged access network node due to inconsistencies in at least a portion of the compared access information, a failure message is generated and sent to the access node or one or more user equipments served by the access node.
10. The method of claim 1, wherein the first NF element includes the access and mobility management function elements of the core network.