A method for cellular network roaming security and a network device for monitoring network traffic
By using actual transport data to set a threshold travel time, the method accurately distinguishes between legitimate and fake roaming, addressing inaccuracies in existing methods and improving network security and user experience.
Patent Information
- Application Number
- GB2024006491
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-09
- Publication Date
- 2025-11-12
AI Technical Summary
Existing methods for identifying fake cellular network roaming are inaccurate due to theoretical calculations of travel time between locations, neglecting real-world factors like transport terminal locations, variations in travel speeds, and weather, leading to security issues and user frustration.
Determine a threshold travel time based on actual transport data, including departure and arrival times, to differentiate between legitimate and fake roaming by comparing the actual time taken to travel between locations with a calculated threshold time duration.
This approach provides more accurate identification of fake roaming, reducing security risks and user inconvenience by using real-world data to set a reliable threshold for travel time, thereby enhancing network security and user experience.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[002] Network operators operating in a particular country often have roaming agreements with network operators operating in other countries. These roaming agreements allow a cellular customer to automatically attach to a network other than their home network when travelling outside coverage of the home network, which allows the customer to use network services (for example, making and receiving voice calls, sending and receiving data or accessing other services, including home data services). This is known as roaming.
[003] Roaming is very useful for customers, as they can travel to different countries and use their data as they would normally when using their home network. However, roaming can introduce security issues. For example, bad actors can claim to be a customer connecting to a network (often using fake or spoofed Subscriber Identity Module, SIM, or Universal Integrated Circuit Card, UICC) in a real country, meaning that any messages, calls and so on that should be processed via the home network of the customer will be routed instead via the network of the fake SIM. The bad actor can then pretend to be the customer on the network.
[004] This can be hugely problematic for authentication methods such as, for example, multi-factor authentication (MFA, also known as two-factor authentication or 2FA). For example, if a bad actor has managed to obtain some personal data from a customer of a legitimate network, such as their bank details, being able to spoof the customer device can be hugely detrimental to the effectiveness of these authentication methods. Specifically, the bad actor can use the personal data of the customer to attempt to access services and, when the service tries to authenticate the access attempt, it may instead be the bad actor that receives the SMS (or other network communication message) that includes information enabling access to the service (for example, a password, code or personal identification number, PIN).
[005] The bad actors may be facilitated in their attempts to spoof a SIM by the fact that, when customers travel between different countries, their cellular device may be detached from the network for a period of time. This period of time may be several hours or more when travelling between non-adjacent countries - for example, during intercontinental flights.
[006] To address the security issue, network operators may therefore implement a reasonableness check when a device attempts to attach to a visitor network. For example, determining a minimum time that a user should take to travel between a pair of countries may allow evident cases of bad actors to be identified. Specifically, if a first communication between a user equipment (UE) and the network indicates that a user is in the United Kingdom but a second, subsequent communication ten minutes later indicates that the user is currently in Madagascar, it is clear that a user cannot feasibly have travelled between the UK and Madagascar in ten minutes. The attempt to route network traffic via a network in Madagascar may therefore be prevented. However, other cases may be less clear cut, as it can be difficult to accurately determine an appropriate minimum time for travel between two countries. Incorrectly determining an appropriate minimum time could lead to fake roamers being allowed to customer data or preventing a legitimate customer from accessing a visitor network when travelling abroad.
[007] Overcoming the issues noted above is desirable. SUMMARY
[008] Against this background, there is provided a method for cellular network roaming security and a network device for monitoring network traffic. Additional aspects appear in the description and claims.
[009] Network traffic includes user data, which is the data to be transmitted (that is, the actual message, also known as the payload), and control information for transmitting the user data. The control information may include, for example, a source and destination network address, sequencing information and error detection information, as well as other types of information. The network traffic may also be associated with a time of transmission, a time of delivery, user equipment (UE) or universal integrated circuit card (UICC) information (for example, an international mobile subscriber identity, IMSI or temporary mobile subscriber identity, TMSI) and so on. A UE may be any device used by an end-user to communicate via a network. For example, it may be a cellular device, tablet device, laptop or another mobile device.
[010] The location of a UE transmitting or receiving the network data can be determined from the network traffic - for example, based on the location of a base station that a UE is in communication with, via the TMSI or by measuring power levels and / or antenna patterns of signals received at a base station. The location of the UE may only be approximated. In other words, the location may be a region or area rather than a specific point.
[011] Changes in location (which may also be approximate) can also be determined based on network traffic. For example, first network traffic may indicate that a UE is in London and second, subsequent network traffic may indicate that the UE is in Manchester. The change in location may be assessed at a broader level - for example, between counties, states or countries. From this information, an amount of time between the UE being at the first location and the UE being at the second location can be established.
[012] Data relating to transport is often recorded by organisations as part of their operations and even some interested individuals may record this data. This transport data often includes information such as a scheduled departure and arrival time, an actual (as opposed to a scheduled) departure and arrival time of the transport, a type of transport, an origin and a destination, and so on. Actual departure and arrival times may differ from scheduled departure and arrival times due to various factors including delays in departure, early departure or weather conditions.
[013] It is possible to determine, based on the actual departure and arrival time, an amount of time that would be taken to travel by a mode of transport. The data itself may include this information or it can be calculated based on the data.
[014] The inventors have recognised that this amount of time can serve as an expected, minimum or threshold amount of time to travel between two different locations. The threshold amount of time is compared to the amount of time between the UE being at the first location and the second location. When the amount of time between the UE being at the first location and the second location is less than the expected amount of time, this indicates that a user has travelled between the two locations faster than may actually be possible. This may indicate that a bad actor is using fake roaming to access the network. Accordingly, the UE is prevented from accessing the cellular network or removed from the network.
[015] In accordance with a first aspect, there is provided a method for cellular network roaming security comprising steps of: obtaining a threshold time duration to travel by transport between an origin location and a destination location wherein the threshold time duration is determined based on data comprising a recorded transport departure time and a recorded transport arrival time; and based on determining that the threshold time duration is greater than a time duration established based on network traffic indicating a first location of user equipment (UE) in the origin location at a first time and a second location of the UE in the destination location at a second time, controlling cellular network access of the UE.
[016] A more accurate or appropriate threshold time duration for travelling via transport between two locations may be achieved by using recorded (that is, actual) transport arrival and departure times. Accordingly, the method may allow more accurate determination of cases of legitimate roaming and / or fake roaming, due to the improved identification of a an appropriate threshold time duration.
[017] Controlling the UE access may comprise preventing the UE from accessing a cellular network, removing the UE from the cellular network or connecting the UE to the cellular network (for example, via an attach procedure). Thus, in response to a determination that the threshold time duration is greater than the established time duration (indicating that the UE has travelled between the two locations quicker than may be possible), the method may comprise preventing the UE from accessing the cellular network or removing the UE from the cellular network.
[018] The network traffic indicating the second location may comprise a network attach request.
[019] The method may further comprise updating one or more rules of a firewall or intruder detection system to prevent the UE from accessing the cellular network or remove the UE from the cellular network when the threshold time duration is greater than the established time duration. A firewall or intruder detection system may be implemented in a cellular network in a straightforward manner and so may provide a straightforward way of controlling UE access to the network.
[020] The transport may comprise an aircraft and the recorded transport departure time is a recorded flight departure time and the recorded transport arrival time is a recorded flight arrival time. Aircraft may be the fastest and / or most common transport available for travel between two locations. Therefore, obtaining a threshold time duration based on a recorded flight departure and arrival time may enable a minimum time duration to be determined in a straightforward manner.
[021] The aircraft may be a scheduled commercial aircraft, a private aircraft or a military aircraft. Private and military aircraft may have cruising speeds faster than that of a commercial aircraft. Therefore, obtaining a threshold time duration based on a private or military aircraft may allow a more accurate threshold time duration to be determined. This may in turn allow for more accurate UE access control (correctly identifying cases of fake roaming and legitimate roaming).
[022] The origin location and / or destination location may be a country, geographic region (which may be a city or town) or network cell. The method may thus allow a threshold time duration to be determined based on different granularities. A finer granularity threshold time duration may allow more accurate UE control access based on specifics indicated by network traffic (for example, a particular UE location). A broader granularity threshold time duration may allow a sufficiently accurate time duration to be identified with limited or reduced computer resources and / or network traffic. That is, it may not be necessary to determine an exact location of a user or UE. A country-level determination of how a UE could have moved between two countries may be sufficient.
[023] Optionally, obtaining the threshold time duration may comprise receiving the data comprising the recorded transport departure time and the recorded transport arrival time and determining the threshold time duration based on the received data. Thus, data sources including recorded transport departure and arrival times but not journey durations can be used. Such data sources may be more prolific.
[024] In other implementations, obtaining the threshold time duration may comprise receiving the threshold time duration. This may allow UE access to be controlled more quickly, since additional calculations are not required.
[025] Optionally, determining the threshold time duration comprises determining an allowable deviation from the threshold time duration. For example, differences in wind speeds, wind directions or other factors that may affect a journey time can be accounted for. This may be implemented based on data statistics such as, for example, a standard deviation, mean, median and so on of a journey duration. Including an allowable deviation may limit or reduce instances of false positives, leading to a legitimate user being prevented from accessing a cellular network.
[026] In some implementations, the data may comprise a plurality of recorded transport departure and arrival times of transport travelling between the origin location and the destination location. The method may accordingly further comprise calculating a time duration of each journey to determine the threshold time duration. The threshold time duration may be set as shortest of the calculated time durations or may be determined based on the shortest calculated time duration(s). For instance, a threshold time duration may be determined based on a k-th percentile time duration. For example, a first, fifth, tenth or another percentile value may be used. Other methods of setting a threshold time duration based on the calculated time durations may be implemented.
[027] Since there may be variations in journey durations due to various factors including, for example, weather, delays and cancellations, including a plurality of recorded transport departure and arrival times in the data and calculating a time duration of each (or some) of the journeys to determine the threshold time duration may allow a more accurate threshold time duration to be determined. For example, a threshold time duration may be determined as three hours based on one particular flight, but a later flight may have lasted only 2.5 hours. Therefore, a UE that moved between two locations in less than three hours may be a legitimate roamer.
[028] Network traffic indicating a time of arrival at the first and / or second location (for example, a time that an attach request was received by a transceiver or base station) may be used to select a threshold time duration. In the example above, if a UE reported itself in Birmingham at 12:37 UTC and in Berlin at 15:07 UTC but the flight that lasted 2.5 hours did not arrive until 17:52 UTC, the UE may still be identified as fraudulent.
[029] The data may further comprise a location identifier for each recorded transport departure and arrival time and the method further comprises determining one or more calculated time durations within a pre-determined threshold of the threshold time duration and, for each of the one or more determined time durations, identifying the corresponding origin location identifier and the corresponding destination location identifier. Thus, transport terminals that result in the shortest acceptable time duration(s) are identified.
[030] The method may then further comprise requesting one or more further recorded transport departure times for each corresponding origin location identifier and one or more further recorded transport arrival times for each corresponding destination location identifier to determine a further threshold time duration. Once the shortest acceptable time duration(s), at least for a particular date or time period, have been identified, it may not be necessary to obtain data for transport terminals that are unlikely to result in time durations within a pre-determined threshold of the threshold time duration. For example, Newcastle International Airport to Toulouse-Blagnac Airport may always have a travel duration greater than that of London Gatwick Airport to Paris Charles De Gaulle. Thus, when updating a threshold time duration (for example, on a different date or for a different time period), recorded flight departure and arrival data may not be retrieved for Newcastle International Airport to Toulouse-Blagnac Airport. Where the data is retrieved via an API, reducing the number of queries can reduce the number of calls required to the API. The results can thus be received more quickly and network traffic can be limited or reduced. [031 ] The request for one or more further recorded transport departure and arrival times may be requested in response to receiving further network traffic indicating a third location of a further UE at a third time and a fourth location at a fourth time.
[032] Optionally, the origin location and destination locations may both be countries and the method may further comprise determining each viable transport route between the origin country and the destination country based on the location identifiers to determine the threshold time duration. For example, all permutations of viable airport codes and flights may be analysed and the range of time durations determined. The threshold time duration may then be calculated based on the range of time durations. A transport route may be viable if transport terminals indicated by the location identifier is operational and operates between the origin transport terminal and destination transport terminal.
[033] The method may further comprise storing the calculated time durations in a cache. This may allow previous results to be retrieved more quickly, which may in turn allow for quicker identification of potential fake roaming instances.
[034] Preferably, determining the one or more calculated time durations within a predetermined threshold of the threshold time duration comprises determining one or more calculated time durations less than the pre-determined threshold.
[035] Optionally, the method may further comprise, in response to determining that the further threshold time duration differs from the threshold time duration by more than a threshold amount, updating the cache to include the further threshold time duration. The threshold time duration can therefore be updated in a straightforward manner.
[036] Optionally, the location identifier may be included in the data by: determining one or more origin transport terminals within a threshold distance of the first location and one or more destination transport terminals within a threshold distance of the second location; and / or identifying one or more transport terminals within a city or country of the origin location and one or more destination transport terminals within a city or country of the destination location.
[037] This may be a straightforward manner of obtaining relevant location identifiers for the received network traffic.
[038] The location identifier may preferably comprise an airport code and the transport terminal may be an airport.
[039] The one or more origin airports and one or more destination airports may include only commercial airports. Commercial flights may be more common and more likely to be used by network customers than private or military flights. Therefore, excluding private or military flights may allow a more appropriate threshold time duration to be implemented (although private and / or military flight data may be used to determine an allowable deviation from the threshold time duration).
[040] In one implementation, receiving the data may comprise sending a request to an application programming interface, API, for the data and receiving, from the API and in response to the request, the data. APIs may provide a more advanced and quicker system for gathering data or completing processes than manually inputting data in a spreadsheet.
[041] Optionally, the request includes a date and the received data includes one or more recorded transport departure times occurring on the date and, optionally, one or more recorded transport arrival times occurring on the date. More than one travel journey may occur on a particular date and the durations of these journeys may vary during the day (for example, due to weather, cancellations or other factors). There variations can be taken into account by obtaining more than one recorded departure and / or arrival time when they occur.
[042] The method may further comprise converting the recorded transport departure time and the recorded transport arrival time into a standard time to calculate the threshold time duration. This may simplify the process of obtaining the threshold time duration.
[043] The method of any previous claim, further comprising obtaining the threshold time duration in response to receiving an alert indicating suspicious activity of the UE. Suspicious activity may be indicated by one or more fault logs, firewall or intrusion detection system reports, a manual check or by other indications.
[044] The threshold time duration may be a minimum time duration. Thus, the limit for an acceptable established time duration can be provided. In other examples, the threshold time duration may be greater than a minimum time duration. For example, a particularly fast jet stream may have occurred on a particular date that should not be taken into account in general, even potentially at a different time on the same date.
[045] In accordance with a second aspect, there is provided a network device for monitoring network traffic (or for cellular network roaming security) configured to: receive network traffic from user equipment, UE, indicating a first location of the UE in an origin location at a first time and a second location of the UE in a destination location at a second time and determine a time duration between the first time and the second time; compare the time duration to a threshold time duration to travel by transport between the origin location and the destination location, the threshold time duration obtained based on data including a recorded transport departure time and a recorded transport arrival time; and based on determining that the threshold time duration is greater than the time duration, control cellular network access of the UE.
[046] The network device may comprise, be part of or be in communication with a firewall or intrusion detection system. Thus, a straightforward manner of controlling UE access to the network may be provided. The firewall or intrusion detection system may be located at any appropriate point in the network (and more than one firewall and / or intrusion detection system may be provided).
[047] The network device may be configured to perform any of the method steps above.
[048] A processor may be configured to perform any of the method steps above.
[049] The methods described above may be implemented as a computer program comprising instructions to operate a computer or computer system (or other hardware and / or software configured to implement the method). The computer program may be stored on a computer-readable medium (for example, a non-transitory computer-readable medium). When executed, the instructions of the computer program may cause the computer (or a processor of the computer) to carry out the method steps above.
[050] It should be noted that any feature described herein may be used with any particular aspect or embodiment of the invention. Moreover, the combination of any specific apparatus, structural or method features is also provided, even if that combination is not explicitly disclosed.
[051] The invention will now be described with reference to the attached drawings depicting different embodiments thereof, the drawings being provided purely by way of example and not limitation. BRIEF DESCRIPTION OF DRAWINGS
[052] The invention may be put into practice in a number of ways, and preferred embodiments will now be described by way of example only and with reference to the accompanying drawings, in which: Figure 1 illustrates an example flight paths between Canada and Norway; Figure 2 shows an example system in which cellular network roaming security methods may be implemented; Figure 3 illustrates a flow chart of a method for cellular network roaming security; Figure 4 shows a block diagram of a network in which the disclosed methods may be implemented; and Figure 5 shows a schematic diagram of an example network implementation for cellular network roaming security.
[053] It should be noted that the Figures are illustrated in schematic form for simplicity and are not necessarily drawn to scale. Like features are provided with the same (or similar) reference numerals. DESCRIPTION OF PREFERRED EMBODIMENTS
[054] As described above, a network operator may implement a reasonableness or sanity check to prevent clear cases of fake roaming. One method implemented by network operators involves determining a minimum time that a customer should take to travel between pairs of countries. In this method, the minimum time is determined based on two components: a shortest distance between countries and a maximum speed of travel. These components are manually input into a spreadsheet to calculate the minimum time.
[055] However, the inventors have identified a number of issues with this approach, which may lead to fake roaming not being accurately identified (that is, identifying fake roaming where there is none or failing to identity fake roaming where it is present).
[056] Firstly, the calculation is theoretical. Whilst it may be possible to modify the assumed maximum speed of travel, it is nevertheless still an approximation. Significant time is required to manually check any alerts or flags generated based on the theoretical calculation and modify the minimum travel time between any individual pair of countries.
[057] The shortest distance between countries does not take into consideration how a person would physically travel between two countries (for instance, where transport terminals are physically located in the countries). That is, the shortest distance between two countries may not represent a path that a person would need to take to travel between the two countries - for example, due to obstacles such as mountains, water or otherwise impassible or not easily passable territory, a person may not be able to travel the shortest distance between two countries. In addition, a shortest distance may be indicated as a straight line under an assumption that the distances are small enough that Euclidean geometry assumptions can be made. However, on larger scales, a geodesic curve represents the shortest path between two points in or on the Earth’s surface. Such inaccuracies may allow bad actors imitating the UE of a legitimate customers to access the network, which is a security issue.
[058] Furthermore, the inventors have recognised that even using transport terminal location data would lead to inaccuracies. For example, as shown in Figure 1, the shortest flight distance between Canada and Norway (between Alert Airport, Alert, Nunavut, Canada and Svalbard Airport, Svalbard, Norway) is approximately 1,190 km which may take an average of 1 hour and 19 minutes to travel between. However, it is far more likely that passengers would travel between these countries via other airports, such as, for example, between Montreal Airport and Oslo Airport. The distance between these airports is much greater (approximately 5,484 km) and would take much longer to traverse (perhaps taking an average of 11 hours and 40 minutes). Assessing potential fake roaming attempts against the shorter distance is more likely to lead to security issues.
[059] In addition, different forms of transport may have different maximum and / or average speeds. Even the same type of transport may have different maximum and / or average speeds. For example, long-haul flights tend to have a higher average speed than short-haul flights and military aircraft may be faster than commercial aircraft. Thus, inputting a maximum speed of travel to determine a minimum amount of time to travel without regard for flights or journeys that actually occurred may either result in accuracies that can lead to potential security issues or require significant manual checking to confirm any results.
[060] Furthermore, this approach does not take into account variation caused by weather. For example, a train may be delayed or cancelled due to flooding, meaning that the actual time it would take to travel between an origin and a destination is greater than expected, or strong winds in a favourable direction may result in an aircraft arriving ahead of schedule, meaning that the actual time is less than expected. Failing to take into account these variances results in inaccuracies in determining which network attach requests are legitimate and responding accordingly. This can cause security issues and frustrate users who are blocked from the network based on the theoretical travel time but have legitimately travelled between two locations faster than expected.
[061] Some network operators instead use the distance between capital cities to identify incidents of fake roaming. However, this suffers from similar disadvantages to those discussed above. For example, using the capital city of a large country, such as Russia for example, may lead to many inaccuracies in identifying cases of fake roaming. For example, a person crossing between China and Russia via a land border may be treated as a fake roamer due to the distance between the respective capital cities.
[062] Another method implemented by network providers is to check for a last-known location of a device when the device attempts to attach to a visited network and send a message to the last-known location to check whether the device is still there. If a communication is received from the device indicating that it is still in the last-known location, then the new update from the visited network can be determined to be fake. However, this check adds significant delay to the attach process and significant complexity to the network.
[063] The inventors have realised that at least some of these disadvantages can be addressed by determining an expected amount of time to travel between two locations based on recorded (in other words, actual) transport data.
[064] With reference to Figure 2, there is illustrated an example of network roaming in which the methods and systems disclosed herein may be implemented.
[065] As shown in Figure 2, a first user 202 has a first UE 206 in a first location U. The first UE 206 may be in communication with a first transceiver or base station 210, as shown in Figure 2, but may be in communication with a different network element in other examples.
[066] A second user 204 has a second UE 208 in a second location L2. Under normal circumstances (that is, in cases where legitimate roaming is occurring), the first user 202 is the same as the second user 204, just in a different place at another time. In cases of fake roaming though, the user 204 may be an imposter of the user 202. As shown in Figure 2, the second UE 208 (which, in cases of legitimate roaming, may be the same as the first UE 206) is in communication with a second transceiver or base station 212, but may be in communication with another network element.
[067] The base stations 210, 212 may be gNBs or eNBs, or may be another type of node (for example, for 6G cellular network technologies and / or beyond). Each base station 210, 212 can contain one or more radio units that typically operate on different frequencies or radio bands. Furthermore, each radio unit or remote radio unit (RRU) may provide cellular services for different cellular network technologies (for example, 2G, 3G, 4G, and / or 5G or beyond).
[068] As discussed above, the first user 202 and the second users 204 may be the same user 202, 204 (for example, in cases of legitimate roaming) or may be different users (for example, where the user 204 is an imposter of the user 202). In the case where the first user 202 and the second user 204 are the same user, the user 202, 204 has travelled from the first location Li to the second location L2 by transport. In the example illustrated in Figure 2, the transport is an aircraft 214, but it will be appreciated that the user 202, 204 may use another form of transport such as, for example, public transport, which may include a bus or coach, train (overground and / or underground), tram or light rail, rapid transit and / or ferry, or another form of transport.
[069] The aircraft 214 may be a commercial aircraft scheduled to take off at a time ti and recorded as departing at time t2 (which may or may not be the same as time ti). Similarly, the aircraft is scheduled to take off at time ts and is recorded as arriving at time t4, which may or may not be the same as ts. The recorded departing time t2 may be a gate departure (off block) or runway (take-off) time. The recorded arrival time t4 may be a gate arrival (on block) or runway (landing) time.
[070] As per aircraft guidelines, the user 202, 204 may switch off the UE 206, 208 or configure the UE 206, 208 to operate in a flight-safe mode in which radio-frequency (RF) signal transmission technologies (for example, Bluetooth, telephony and Wi-Fi) are disabled. The UE 206, 208 may thus be unable to transmit or receive communications with a network element (for example, the transceiver or base station 210) and accordingly, location data of the UE 206, 208 may not be available for a period of time. In the case of intercontinental flights, this period of time may be as long as several hours or more. It will be appreciated that there may be other reasons that location data of the UE 206, 208 may not be available for a long period of time. For example, a transceiver or base station may be too far for a UE 206, 208 to successfully receive or transmit communications to and / or from. This may be the case where, for example, a user is travelling through a tunnel (for example, on a train) or is at sea.
[071] The next communication received by a network (for example, via the second transceiver or base station 212) from the UE 206, 208 may therefore be when the user 202, 204 turns on the UE 206, 208 or deactivates the flight-safe mode at the second location L2. Accordingly, for a time duration t between t2 and t4, there may be no location data to indicate that the UE 202, 204 has been travelling between the locations Li and L2, (which are separated by a distance d).
[072] Alternatively, the first user 202 and the second user 204 may be different. The second user 204 may thus be attempting to imitate the first UE 206 of the first user 202. As such, there is also no location data to indicate that the UE 202 has been travelling between the locations Li and L2, because the first user 202 has not actually travelled to the location L2.
[073] The locations Li and L2 may be approximate locations - for example, an area or region (for instance, a cell or secondary cell) around the transceivers or base stations 210, 212, a city in which the transceiver or base station 210, 212 is located, a country in which the UE 206, 208 is located. The country may, for example, be determined based on a TMSI or other UE / UICC information instead of a transceiver or base station location or may be determined based on a serving mobile country code (MCC) information or an originating network node address in mobility management signalling. The first digit of an MCC identifies a geographic region, for example.
[074] In other examples, the locations Li and L2 may be more granular. For example, the UE location may be approximated more granularly by interpolating signals between adjacent antenna towers or using trilateration or multilateration. Other methods of determining the UE location may be used.
[075] The region around the transceivers or base stations 210, 212 need not be centred on the transceivers or base stations 210, 212. For example, the region may be a cell or secondary cell. As a cell or secondary cell may include a plurality of transceivers or base stations, the cell may not be centred on the transceiver or base station 210, 212 that the UE 206, 208 is in communication with. For example, three transceivers may typically be implemented in a network cells.
[076] As will be discussed in further detail with reference to Figure 3, the UE location data may be used to determine location identifiers for the transport terminals that a user may have travelled between.
[077] With reference to Figure 3, there is illustrated a flow chart of a method for cellular network roaming security that may be used in the situations described above in relation to Figure 2, for example.
[078] At step 301, a threshold time duration to travel between an origin and a destination is obtained. The threshold time duration is determined based on data comprising a recorded transport departure time and a recorded transport arrival time. In other words, the threshold time duration is based on real-world data, rather than scheduled or predicted data. Real transport data may be a more accurate representation of the actual time it takes to travel between two locations than using an assumed speed of travel and distance travelled or even scheduled data. The threshold time duration may be obtained in response to receiving an alert indicating suspicious activity of the UE or related to the UE. Suspicious activity may be indicated by one or more fault logs, firewall or intrusion detection system reports, a manual check or by other indications.
[079] Obtaining the threshold time duration may comprise receiving the data comprising the recorded transport departure and arrival times from an external device (for example, a server) and determining (for example, calculating or measuring) the threshold time duration based on the received data. Other data may be provided with the data. For example, location identifiers for the origin and destination locations may be included.
[080] Either or both of the recorded transport departure and arrival times may be local times that are not directly comparable. For example, an actual flight departure time may be recorded as 19:04 GMT and an actual flight arrival time may be recorded as 21:37 GET. These recorded times may be represented according to the format described in ISO 8601 (2024-04-24T19:04:05+00:00 and 2024-04-24T21:37:01+01:00, for instance). In such cases, the recorded transport departure and / or arrival time may be converted into a standard time in order to calculate the threshold time duration. In other examples, the actual flight departure and arrival times may already be provided in a standard time format (for example, 2024-04-24T19:04:05Z and 2024-04-24T20:04:05Z).
[081] In other examples, obtaining the threshold time duration may comprise receiving the threshold time duration itself (as well as, optionally, other data). For example, a database may store the threshold time duration as previously calculated or determined based on the recorded departure and arrival times.
[082] The obtained data may include data statistics. For example, the data may include one or more of: a standard deviation, mean, median and so on for one or more instances of data. The obtained data may thus account for differences in wind speeds or directions or other factors that may affect a journey time. This may be used in generating an error margin, as will be discussed in further detail below.
[083] The data may be received from an application programming interface, API. For example, a request for the data may be sent to the API and, in response to the request, the API may send the data. An API may be able provide local and / or global transport data for real-time and historical journeys. Requests to the API for data may be made using an HTTP GET URL structure and responses may be provided in lightweight JSON format. Other forms or request and data output are possible. APIs may provide a more advanced and quicker system for gathering data or completing processes than manually inputting data in a spreadsheet.
[084] More than one API may be used to obtain the data. For example, an API may only provide recorded departure and arrival times for scheduled commercial flights. One or more further APIs may be used to provide data for unscheduled private and / or military flights. One or more additional APIs may be used for different modes of transport (for instance, train departure and arrival times). In other examples, more than one type or mode of transport may be provided by a single API. Scheduled commercial flights and unscheduled private and / or military flights may be provided by the same API, for example.
[085] Private and military aircraft may travel faster than commercial aircraft. For example, whilst a commercial aircraft may typically have a cruising speed in the range of 900 to 1000 km / h, private aircraft may have a cruising speed in the range of 800 to 1200 km / h and a military aircraft may have a cruising speed of over 1000 km / h. Including recorded departure and arrival times for these types of aircraft in the received data may therefore allow incorrect identifications of fake roaming (false positives) to be reduced, minimised or prevented. For example, a threshold time duration determined based on scheduled commercial flights may indicate that the established time duration is too short and that the UE is a security risk, but there may have been a faster military flight that corresponds to the established time duration. In other words, (potential) security incidents can be identified more accurately by including multiple types of a mode of transport, some of which may not be available to the public or which may not operate according to a fixed schedule.
[086] In some examples, the request to the API or database may be provided by a file that uses a data exchange format (for instance, a CSV, YAML, XML, RDF file and so on). For example, a user may select or input one or more origins and one or more destinations into a CSV file. A computer script may use the CSV file (or other file type) as an input to submit a request to the API.
[087] The request may include a date or another period of time (for instance, a 12-hour period, a 1 -hour period, a week, a month or another period). The received data may include one or more recorded transport departure times occurring on that date or during that period of time. The received data may also include one or more recorded transport arrival times occurring on the date or during the period of time. In other examples, the received data may include one or more recorded transport arrival times occurring on another date. For example, a travel time between an origin and a destination may be long enough that, based on the scheduled departure time, the scheduled arrival time may be the next day. This may also be the case when no direct transport link between the origin and destination is available and a connecting mode of transport is required.
[088] The origin and destination may be in different countries or may be in the same country. For example, the travel may occur between cities, network cells or other regions in the same country. In other words, the first location may be any one of: a city or other geographic region (for instance, a town or village, national park, metropolitan area, county, state, and so on), network cell (for example, a master cell, secondary cell, picocell, and so on), country or another region. Similarly, the second location may be any one of a city or other geographic region, network cell, country or another region.
[089] As more than one transport journey may occur on a particular date, a plurality of recorded transport departure and arrival times may be included in the data provided by the API or database. For instance, the returned data may comprise all departures and / or arrivals occurring on the particular date. This may allow a minimum threshold time duration to be determined for a same or similar journey between an origin and destination. For example, whilst a train journey may have been recorded or calculated to take three hours, it may be possible to travel by aircraft in two hours. Thus, it can be determined that a UE which travelled between the origin and the destination in a time interval of between two and three hours is not, or is unlikely to be, a security risk.
[090] A similar journey may be a journey in which one of the origin, destination and mode of transport are the same as a previous journey, where the specific origin and / or destination differ from a previous journey but a higher granularity origin and / or destination are the same, where a similar mode of transport is used. For example, a journey from London to Edinburgh (England to Scotland) may be treated as similar to a journey from Birmingham to Glasgow (also England to Scotland), or an overground train journey may be considered similar to a light rail journey. A user may define other examples of journeys that are considered similar.
[091] Returning results for all departures and / or arrivals between an origin location and a destination location may produce excessive results. Therefore, only some recorded transport departure and arrival times may be provided.
[092] For example, the received data may only be obtained based on operating (that is, non-decommissioned) transport terminals. Thus, obsolete or out-of-date information may not be provided and results can be provided more quickly and network traffic may be reduced or limited, since fewer calls to the API or database requests may be needed.
[093] In another example, only transport journeys for a certain mode of transport (for example, aircraft journeys), or only some modes of transport, may be provided. Similarly, some forms of the mode(s) of transport may not be included. For example, only commercial flights may be included. It may not be necessary or effective to return results for all modes of transport as, for example, journeys via some modes of transport may be sufficiently infrequent or unlikely to be used by a majority of the population that including this data in order to determine a threshold travel time may limit the accuracy in identifying cases of fake roaming. This may reduce the data processing required for a query whilst maintaining (or not significantly reducing) accuracy.
[094] In other examples, a combination of the above data filtering may be used.
[095] In examples in which a plurality of recorded transport departure and arrival times are obtained (for example, via the API), the method may further comprise calculating a time duration of each journey to determine the threshold time duration. In other examples, a time duration may be calculated for only some of the plurality of recorded transport departure and arrival times.
[096] The recorded transport departure and arrival times may include, for example, journeys between Dover and Calais, London and Paris (for example, between London Gatwick and Charles De Gaulle Airport, Luton and Charles De Gaulle Airport, and London St. Pancras and Paris Nord) and Birmingham and Toulouse. Time durations for each or some of these recorded journeys may be calculated. The calculated time durations may be used at the same or a wider level of granularity as the recorded journey. For example, the time duration may be used to establish a threshold time duration for a journey between Dover and Calais or between England and France.
[097] Calculating a time duration for some or all of the journeys may allow a minimum threshold time duration to be determined. For example, whilst a particular flight may have been recorded or calculated to take three hours, favourable weather for the same or a similar journey may mean that a different flight on the same day only lasted two hours. The shortest or one or more of the shortest time durations may then be used as the threshold time duration.
[098] The recorded transport departure and arrival times may each be associated with a location identifier. The location identifier may be or comprise, for example, an International Air Transport Association (IATA) code, International Civil Aviation Organisation (ICAO) code, station code (railway terminal code), port code or another code that identifies a transport terminal. The location identifier may designate a transport terminal or metropolitan area. For example, the IATA code LON designates a plurality of airports in London.
[099] Following an initial set of results in which a plurality of recorded transport departure and arrival times and corresponding location identifiers are included in the set of results, the one or more calculated time durations may be stored in a cache or another data store.
[0100] The method may then further comprise identifying one or more calculated time durations that are within a pre-determined threshold of the threshold time duration. Since the threshold time may represent a minimum time duration for a journey between two locations (for example, two countries), identifying the calculated time durations that are within a predetermined threshold of this minimum time duration may allow identification of the most or more relevant journeys for future threshold time durations.
[0101] In particular, although there may be transport journeys taking much longer, if the shortest journey time between two countries is 2 hours, there may be no need to obtain the recorded departure and arrival times for the longer transport journeys, since the threshold time duration is likely to remain much shorter. As discussed above, journey durations are subject to change in view of various factors including weather, cancellations, public holidays and so on. Therefore, although a particular transport journey may be the fastest travel on a particular date, on another date, another transport journey may in fact be shorter. Hence, one or more of the shortest (rather than just the shortest) time durations may be used to determine the threshold or minimum time duration. For instance, the threshold time duration may be determined based on a k-th percentile time duration of the calculated time durations. For example, a first, fifth, tenth or another percentile value may be used. Other methods of setting a threshold time duration based on the calculated time durations may be implemented. For instance, the one or more of the shortest time durations may not include the shortest time duration. The shortest time duration may, for example, be subject to change regularly or otherwise anomalous so that including this data point for determination of the threshold time duration may lead to inaccuracies in correctly identifying whether fake roaming is occurring.
[0102] The method may comprise requesting, receiving or obtaining one or more further recorded transport departure and arrival times for each corresponding location identifier. In other words, since the one or more of the shortest journeys between two locations may have been identified already (those falling within a pre-determined threshold of the threshold time duration), only these transport journeys may be checked in order to update (or maintain) the threshold time duration. Thus, identifying the calculated time durations that are within a predetermined threshold of the threshold time duration may enable calculating only some (rather than all) of the time durations from future data. The one or more further recorded transport departure and arrival times may be requested, received or obtained in response to receiving further network traffic that indicates a third location of a further UE (which may be the same as the first UE or a different UE) at a third time and a fourth location of the further UE at a distinct, fourth time,
[0103] The location identifier may be included in the data by determining one or more origin transport terminals within a threshold distance of the first UE location and one or more destination transport terminals within a threshold distance of the second UE location. For example, if the network traffic indicates that the UE is in communication with a particular node in Dover, the method may comprise determining that Dover port is within a threshold distance of the particular node. The Dover port code may then be included in the data.
[0104] In other examples, the location identifier may be included in the data by identifying one or more transport terminals within a city or country of the origin location and destination location. For example, the origin location may be a particular serving cell in Manchester, England. The method may thus comprise identifying one or more transport terminals in Manchester, England and / or the United Kingdom.
[0105] In examples where a data exchange format file is used, the shortest or one or more shortest times may be appended to the data exchange format file for the origin and destination (or for a higher granularity origin and destination such as, for example, a pair of countries). The data exchange format file can then be used to update one or more rules implemented by a device to prevent network traffic to a UE (for example, by failing to respond to an attach request, removing the UE from the cellular network or otherwise ceasing communication with the UE) or allow the UE to connect to the network.
[0106] The device may be a network device that comprises, is part of or is in communication with a firewall or intrusion detection system, as will be discussed in further detail with reference to Figures 4 and 5. The shortest or one or more shortest time durations may then be used as an allowed minimum time duration for a firewall or intrusion detection system. The firewall or intrusion system may comprise hardware and a computer program. The firewall or intrusion detection system may act to prevent a UE from attaching to a network. For example, the firewall or intrusion detection system may discard data and / or ignore communications received from the UE.
[0107] In step 302, it is determined whether the threshold time duration is greater than a time duration established based on network traffic indicating a first location of UE at a first time and a second location of the UE at a second time. The locations of the UE may be determined as discussed above with reference to Figure 2 or another method may be used.
[0108] In determining whether the threshold time duration is greater than the established time duration, a deviation may be allowed. In other words, even if it is determined that the established time duration is less than the threshold time duration (which may indicate that fake roaming is being implemented), the deviation may be small enough that it is not a clear case of fake roaming, as such deviations may occur for a legitimate user. For instance, a user may switch off or disable transmissions to I from a UE ahead of aircraft take-off. In other examples, a user may leave the UE switched on (or keep transmissions enabled) for a time after take-off or switch the UE on (or enable transmissions again) before landing. Any of these examples may result in a difference of time between the journey duration according to the recorded flight departure and arrival times and the time for which the UE was uncontactable. Allowing for a deviation from the threshold time duration means that the UE may not be prevented from attaching to the visitor network or removed from the visitor network.
[0109] In other examples, the allowable deviation may be based on a different type of the same mode of transport or a different mode of transport. For example, where the threshold time duration was established based on actual commercial flight data but a private and / or military flight also occurred, although the threshold time duration may not be established based on the private and / or military flight data (as this may cause too many inaccuracies or otherwise be undesirable), the private and / or military flight data may be used to define an allowable deviation. Not using the private and / or military flight data to determine the threshold time duration but including this information indirectly via the allowable deviation may allow boundary cases in which fake roaming may or may not be taking place to be more clearly identified in a straightforward manner. Similarly, the threshold time duration may be established based on train data (as trains may run more regularly between the origin and destination locations than other transport, for example, so it may be more likely that a user travelled via train) but flight data may be used to establish an allowable deviation.
[0110] Such boundary cases may be monitored more closely for further indications that the UE is an impostor. For example, additional rules may be implemented by a firewall or intrusion detection system for the UE. If one or more of these rules also indicates that the UE is suspicious, the UE may then be removed from the visitor network or prevented from attaching to the visitor network.
[0111] At step 303, based on the determination at step 302, cellular network access for the UE is controlled. For instance, upon determining that the threshold time duration is greater than the time duration established based on the network traffic, the UE may be prevented from accessing a cellular network or removed from the cellular network. Thus, a potential fake roaming attempt can be stopped or prevented. In the alternative, upon determining that the threshold time duration is less than the time duration established based on the network traffic, the UE may be allowed to connect or attach to the cellular network.
[0112] The method described with reference to Figure 3 may be initiated via a graphical user interface (GUI). For example, a user may input a pair of locations (for example, two different countries) via the GUI. One or more processors of a computer may receive the input from the GUI to implement the method. A notification may be provided to the user via the GUI during or after implementation of the method. For example, a notification that potential fake roaming has been identified, the UE has been prevented from attaching to the cellular network, the UE has been removed from the cellular network, and so on. The GUI may also or instead output other information. For example, all departures and / or arrivals for a particular location identifier may be provided. This may allow a cyber defence team to review and optionally modify UE access decisions.
[0113] Figure 4 illustrates an example simplified schematic of a telecommunications network 400. For example, the telecommunications network 400 can be a wireless cellular telecommunications network.
[0114] The network 400 comprises a UE 406, a Radio Access Network (RAN) 418, core network 422 comprising a network device 420. The network device 420 may more specifically be on the edge of the core network 422 and a network of a roaming partner (not shown).
[0115] The RAN 418 can comprise different technologies depending on the generation telecommunications network. Typically, the RAN 418 comprises base stations, antennas, base station subsystems and any other technology that is configured to connect a UE 406 to a core network 422. For example, in an LTE network, the RAN 418 is an E-UTRAN, which comprises an eNB (E-UTRAN Node B). The eNB is responsible for handling radio communications between a UE 406 and the core network 422 across an air interface (the core network 422 being an Evolved Packet Core (EPC) in an LTE network). An eNB is configured to control UEs 406 in one or more cells. LTE is a cellular system in which the eNBs provide coverage over one or more cells. Typically, there is a plurality of eNBs within an LTE network.
[0116] The core network 422 is the infrastructure that interconnects multiple base stations and base stations subsystems together and is responsible for routing voice and data between UEs 406 and also for routing traffic to one or more external networks (not shown). Depending on the generation of the telecommunications network 100, the external network can comprise any suitable network(s). Examples include the Internet, Packet Data Network(s), and a public switched telephone network (PSTN). The core network 422 may include additional components that enable features such as roaming, handoff, and so on.
[0117] The core network 422 may comprise several node types. There may be more than one of each node type in the core network 422, which may depend on the number of UEs 406, the geographical area of the network and the volume of data to be transported across the network. Depending on their function, some of the node types may connect to the RAN 418, some may connect to other node types of the core network 422, some may connect to the one or more external networks, and some may connect to one or more of the RAN 418, other node types of the core network 422 and the one or more external networks.
[0118] The network device 420 may be configured to monitor network traffic and receives network traffic from the UE 406. The network traffic indicates a first location of the UE 406 in an origin location at a first time. Network traffic is also received at a distinct (for example, subsequent or prior) time that indicates a second location of the UE 406 in a destination location at a second, distinct time. The network device 420 determines a time duration between the first time and the second time.
[0119] The network device 420 is further configured to compare the determined time duration to a threshold time duration to travel by transport between the origin location and the destination location. As described above with reference to Figures 2 and 3, the threshold time duration is obtained based on data including a recorded (that is, actual) transport departure and arrival time.
[0120] Based on the comparison, the network device 420 is configured to control access of the UE 406 to the core network 422. For example, upon determining that the threshold time duration is greater than the determined time duration, the network device 420 may be configured to prevent the UE 406 from accessing the core network 422 or remove the UE 406 from the core network 422. The network device 420 may be configured, in the reverse case where it is determined that the threshold time duration is shorter than the determined time duration, to connect the UE 406 to the core network 422.
[0121] Although Figure 4 illustrates the core network 422 comprising a network device 420, it will be appreciated that in other examples, the network device 420 may be positioned elsewhere. For example, the network device 420 may be part of a Radio Access Network (RAN) 418 instead of (or in addition to) being part of the core network 422.
[0122] With reference to Figure 5, there is illustrated a simplified schematic of a telecommunications network 500 in accordance with the present disclosure. The network 500 may be similar to the network 400 described with reference to Figure 4 in many respects and may be a wireless cellular telecommunications network.
[0123] The network 500 comprises a UE 506, a transceiver or base station 512, a firewall or intrusion detection system 520 (which may also be termed simply a firewall 520 herein), core network 522 and roaming network 524. The UE 506 is in communication with the transceiver or base station 512, which may be part of a RAN.
[0124] A firewall 520 is present in the network 500. The firewall 520 can be included between one or more interfaces of the network 500. As illustrated in Figure 5, the firewall 520 may be implemented between the core network 522 and the roaming network 524. More specifically, the firewall 520 may be implemented in the core network 522 at the edge of the core network 522 and the roaming network 524. In other words, the firewall 520 may be a network edge firewall. For example, the firewall 520 may be included on S5-Gn and S8-Gp (roaming) interfaces.
[0125] The firewall 520 may be included as part of a network device (for example, network device 420), be in communication with the network device or the network device may comprise the firewall 520. One or more rules may be implemented by the firewall 520 to control access of the UE 506 to the core network 522.
[0126] The methods and systems described herein may be more accurate and time efficient than known methods and systems. Furthermore, the methods and systems described herein can be integrated into cyber defence workflow in a straightforward manner. For example, users do not need to manually input a pair of locations (for example, countries) or spend time finding a fastest possible time duration by scrolling through a spreadsheet. Instead, the present disclosure may only require a user to provide a data exchange format file (a CSV file, for instance) and then run a computer program that uses the data exchange format file as an input. The computer program may allow for more than one query to be made simultaneously. This may mean that the computer program can be run only once a day to collect queries for the whole day. This may improve efficiencies in identifying security issues in a network.
[0127] The methods described herein may be implemented with computer system configurations including hand-held devices, microprocessor systems, microprocessor- based or programmable consumer electronics, minicomputers, mainframe computers and the like. The embodiments can also be practiced in distributed computing environments, where tasks are performed by remote processing devices that are linked through a network.
[0128] The computer system may include a processor, such as a central processing unit (CPU). The processor may execute logic in the form of a software program. The computer system may include a memory including volatile and non-volatile storage medium. The different parts of the system may be connected using a network (e.g. wireless networks and wired networks). The computer system may include one or more interfaces. The computer may contain a suitable operating system such as UNIX (including Linux) or Windows (RTM), for example.
[0129] Certain embodiments can also be embodied as computer-readable code on a non-transitory computer-readable medium. The computer readable medium may be any data storage device than can store data, which can thereafter be read by a computer system. Examples of the computer readable medium include hard drives, network attached storage (NAS), read-only memory, random-access memory, CD-ROMs, CD-Rs, CD-RWs, magnetic tapes, and other optical and non-optical data storage devices. The computer readable medium can also be distributed over a network coupled computer systems so that the computer readable code is stored and executed in a distributed fashion. Although embodiments according to the disclosure have been described with reference to particular types of devices and applications (particularly networks and UEs) and the embodiments have particular advantages in such case, as discussed herein, approaches according to the disclosure may be applied to other types of device and / or application.
[0130] Each feature disclosed in this specification, unless stated otherwise, may be replaced by alternative features serving the same, equivalent or similar purpose. Thus, unless stated otherwise, each feature disclosed is one example only of a generic series of equivalent or similar features.
[0131] All of the aspects and / or features disclosed in this specification may be combined in any combination, except combinations where at least some of such features and / or steps are mutually exclusive. In particular, the preferred features of the disclosure are applicable to all aspects and embodiments of the disclosure and may be used in any combination. Likewise, features described in non-essential combinations may be used separately (not in combination).
[0132] It will be appreciated that there is an implied “about” prior to times and so on discussed in the present teachings, such that slight and insubstantial deviations are within the scope of the present teachings. Furthermore, values referred to as being “equal” may in fact differ by less than a threshold amount. The threshold amount may be 5%, for example. The threshold may also be greater than 5% (e.g., 10%, 20% or 50%) or less than 5% (for example, 2% or 1 %), depending on the context.
[0133] As used herein, including in the claims, unless the context indicates otherwise, singular forms of the terms herein are to be construed as including the plural form and vice versa. For instance, unless the context indicates otherwise, a singular reference herein including in the claims, such as “a” or “an” (such as a UE) means “one or more” (for instance, one or more UEs).
[0134] Throughout the description and claims of this disclosure, the words “comprise”, “including”, “having” and “contain” and variations of the words, for example “comprising” and “comprises” or similar, mean “including but not limited to”, and are not intended to (and do not) exclude other components. Also, the use of “or” is inclusive, such that the phrase “A or B” is true when “A” is true, “B is true”, or both “A” and “B” are true.
[0135] The use of any and all examples, or exemplary language (“for instance”, “such as”, “for example” and like language) provided herein, is intended merely to better illustrate the disclosure and does not indicate a limitation on the scope of the disclosure unless otherwise claimed. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.
[0136] The terms “first” and “second” may be reversed without changing the scope of the invention. That is, an element termed a “first” element (e.g., a first location, a first UE, and so on) may instead be termed a “second” element (e.g., a second location, a second UE, and so on) and an element termed a “second” element (e.g., a second location, a second UE, and so on) may instead be considered a “first” element (e.g. a first location, a first UE, and so on).
[0137] Any steps described in this specification may be performed in any order or simultaneously unless stated or the context requires otherwise. Moreover, where a step is described as being performed after a step, this does not preclude intervening steps being performed.
[0138] It is also to be understood that, for any given component or embodiment described herein, any of the possible candidates or alternatives listed for that component may generally be used individually or in combination with one another, unless implicitly or explicitly understood or stated otherwise. It will be understood that any list of such candidates or alternatives is merely illustrative, not limiting, unless implicitly or explicitly understood or stated otherwise.
[0139] In this detailed description of the various embodiments, for the purposes of explanation, numerous specific details are set forth to provide a thorough understanding of the embodiments disclosed. One skilled in the art will appreciate, however, that these various embodiments may be practiced with or without these specific details. Furthermore, one skilled in the art can readily appreciate that the specific sequences in which methods are presented and performed are illustrative and it is contemplated that the sequences can be varied and still remain within the scope of the various embodiments disclosed herein.
[0140] All literature and similar materials cited in this application, including but not limited to patents, patent applications, articles, books, treaties and internet web pages are expressly incorporated by reference in their entirety for any purpose. Unless otherwise described, all technical and scientific terms used herein have a meaning as is commonly understood by one of ordinary skill in the art to which the various embodiments described herein belongs.
Claims
1. A method for cellular network roaming security comprising steps of:obtaining a threshold time duration to travel by transport between an origin location and a destination location, wherein the threshold time duration is determined based on data comprising a recorded transport departure time and a recorded transport arrival time; andbased on determining whether the threshold time duration is greater than a time duration established based on network traffic indicating a first location of user equipment (UE) in the origin location at a first time and a second location of the UE in the destination location at a second time, controlling cellular network access of the UE.
2. The method of claim 1, wherein controlling cellular network access of the comprises: in response to a determination that the threshold time duration is greater than the established time duration, preventing the UE from accessing a cellular network or removing the UE from the cellular network; and / orin response to a determination that the threshold time duration is less than the established time duration, connecting the UE to the cellular network.
3. The method of claim 1 or claim 2, further comprising updating one or more rules of a firewall or intruder detection system to prevent the UE from accessing the cellular network or remove the UE from the cellular network when the threshold time duration is greater than the established time duration.
4. The method of any previous claim, wherein the transport comprises an aircraft and the recorded transport departure time is a recorded flight actual departure time and the recorded transport arrival time is a recorded flight actual arrival time.
5. The method of claim 4, wherein the transport is a scheduled commercial aircraft, a private aircraft or a military aircraft.
6. The method of any previous claim, wherein the origin location and / or destination location is a country, geographic region or network cell.
7. The method of any previous claim, wherein obtaining the threshold time durationcomprises receiving the data comprising the recorded transport departure time and the recorded transport arrival time and determining the threshold time duration based on the received data.
8. The method of claim 7, wherein determining the threshold time duration comprises determining an allowable deviation from the threshold time duration.
9. The method of claim 7 or claim 8, wherein the data comprises a plurality of recorded transport departure and arrival times of transport travelling between the origin location and the destination location and the method further comprises calculating a time duration of each journey to determine the threshold time duration.
10. The method of claim 9, wherein the data further comprises a location identifier for each recorded transport departure and arrival time.
11. The method of claim 10, wherein the location identifier is included in the data by: determining one or more origin transport terminals within a threshold distance of the first location and one or more destination transport terminals within a threshold distance of the second location; and / oridentifying one or more transport terminals within a city or country of the origin location and one or more destination transport terminals within a city or country of the destination location.
12. The method of claim 11 when dependent on claim 4 or claim 5, wherein the location identifier comprises an airport code and the transport terminal is an airport, wherein optionally the one or more origin airports and one or more destination airports include only commercial airports.
13. The method of any of claims 10 to 12, wherein the method further comprises: determining one or more calculated time durations within a pre-determined threshold of the threshold time duration and, for each of the one or more determined time durations, identifying the corresponding origin location identifier and the corresponding destination location identifier; andrequesting one or more further recorded transport departure times for each corresponding origin location identifier and one or more further recorded transport arrival times for each corresponding destination location identifier to determine a further threshold time duration.
14. The method of any of claims 10 to 13, wherein the origin location and destination locations are countries and wherein the method further comprises determining each viabletransport route between the origin country and the destination country based on the location identifiers to determine the threshold time duration.
15. The method of any of claims 9 to 14, further comprising storing the calculated time durations in a cache.
16. The method of claim 15 when dependent on claim 13, further comprising, in response to determining that the further threshold time duration differs from the threshold time duration by more than a threshold amount, updating the cache to include the further threshold time duration.
17. The method of any claims 7 to 16, wherein receiving the data comprises sending a request to an application programming interface, API, for the data and receiving, from the API and in response to the request, the data.
18. The method of claim 17, wherein the request includes a date and the received data includes one or more recorded transport departure times occurring on the date and, optionally, one or more recorded transport arrival times occurring on the date.
19. The method of any of 7 to 18, further comprising converting the recorded transport departure time and the recorded transport arrival time into a standard time to calculate the threshold time duration.
20. The method of any previous claim, further comprising obtaining the threshold time duration in response to receiving an alert indicating suspicious activity of the UE.
21. The method of any previous claim, wherein the threshold time duration is a minimum time duration.
22. A network device for monitoring network traffic configured to:receive network traffic from user equipment, UE, indicating a first location of the UE in an origin location at a first time and a second location of the UE in a destination location at a second time and determine a time duration between the first time and the second time;compare the time duration to a threshold time duration to travel by transport between the origin location and the destination location, the threshold time duration obtained based on data including a recorded transport departure time and a recorded transport arrival time; andbased on determining that the threshold time duration is greater than the time duration, control cellular network access of the UE.
23. The network device of claim 22, wherein the network device comprises, is part of or 5 is in communication with a firewall or intrusion detection system.
24. A computer program comprising instructions which, when executed by a computer, cause the computer to carry out the method of claims 1 to 21.10 25. A computer-read able medium comprising instructions which, when executed by acomputer, cause the computer to carry out the method of claims 1 to 21.
Citation Information
Patent Citations
Method, system, and computer-readable medium for implementing time-distance security measures for downstream roaming subscribers using Diameter edge agents
JP2021534633A
Methods, systems, and computer readable media for conducting a velocity check for outbound subscribers roaming to neighboring countries
US20220369091A1