Preventing subscriber identification module spoofing in the mobile user plane

The PFCP proxy system verifies message authenticity to prevent SIM spoofing, ensuring secure communication by validating user device addresses and tunnel endpoint identifiers, thus protecting sensitive information from unauthorized access.

JP2026517879APending Publication Date: 2026-06-02ARRCUS INC

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
ARRCUS INC
Filing Date
2024-05-09
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

SIM spoofing poses a significant security risk as attackers gain unauthorized access to another person's SIM card, potentially compromising sensitive information like bank accounts or email accounts protected by two-factor authentication.

Method used

Implementing a Packet Forwarding Control Protocol (PFCP) proxy within the network architecture to snoop messages and verify user device addresses, tunnel endpoint identifiers, and network node addresses to ensure messages are validly created by the user device and not from an attacking device.

Benefits of technology

Prevents SIM spoofing by validating message authenticity, thereby enhancing security and protecting sensitive information from unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026517879000001_ABST
    Figure 2026517879000001_ABST
Patent Text Reader

Abstract

The purpose is to prevent SIM spoofing within the mobile user plane. The system includes a session management function (SMF) and a user plane function (UPF) within the radio access network, the UPF communicating with the SMF. The system includes a packet forwarding control protocol (PFCP) proxy between the SMF and the UPF, the PFCP proxy snooping PFCP messages between the SMF and the UPF.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to computing networks, and more particularly to preventing subscriber identity module (SIM) spoofing within a mobile user plane.

Background Art

[0002] Subscriber identity module (SIM) spoofing is a type of fraud in which an attacker gains access to another person's SIM card. A SIM card is a chip inserted into a user device that communicates with a cellular network such as a mobile phone, tablet, or laptop computer. The SIM card is used to identify the user to the cellular network and to access or make calls to data on the network. SIM spoofing can have serious consequences for the victim, as an attacker can use the victim's phone number and SIM card to gain access to sensitive information such as bank accounts or email accounts protected by two-factor authentication.

[0003] SIM spoofing can occur through a variety of means, including the attacker physically possessing the SIM card or attempting to trick the cellular network into believing that the attacker is a data packet from a specific SIM card.

Summary of the Invention

Problems to be Solved by the Invention

[0004] Because SIM spoofing can lead to significant information leakage and serious security consequences for the victim, it is important to develop systems, methods, and devices for identifying and preventing SIM spoofing attacks.

Means for Solving the Problems

[0005] In view of the above, a system, method, and device for preventing SIM spoofing within a mobile user plane are disclosed herein.

[0006] Non-limiting and non-exclusive embodiments of this disclosure are described with reference to the following figures, in which the same reference numerals refer to the same parts throughout all figures unless otherwise specified. The merits of this disclosure will be better understood by referring to the following description and accompanying drawings. [Brief explanation of the drawing]

[0007] [Figure 1] This is a schematic diagram illustrating an exemplary system of network devices communicating over the internet via a 5G radio access network (RAN). [Figure 2] This is a schematic block diagram of the communication system between components of a network architecture. [Figure 3] This is a schematic block diagram of the process flow for recording communications within a network architecture. [Figure 4] This is a schematic diagram of a system that prevents SIM spoofing within the mobile user plane. [Figure 5A] This is a schematic diagram of the control plane process flow and system that prevents SIM spoofing within the mobile user plane, where the process flow relies on a Type 1 Session Conversion (ST1) route. [Figure 5B] This is a schematic diagram of the control plane process flow and system that prevents SIM spoofing within the mobile user plane, where the process flow relies on a Type 2 Session Conversion (ST2) route. [Figure 6A] This is a schematic diagram of the data plane process flow and system that prevents SIM spoofing within the mobile user plane, where the process flow relies on the ST1 route. [Figure 6B] This is a schematic diagram of the data plane process flow and system that prevents SIM spoofing within the mobile user plane, where the process flow relies on the ST2 route. [Figure 7] This is a schematic diagram of a system that prevents SIM spoofing within the mobile user plane. [Figure 8] This is a schematic diagram of the control plane process flow and system for preventing SIM spoofing within the mobile user plane. [Figure 9] This is a schematic diagram of the data plane process flow and system that prevents SIM spoofing within the mobile user plane. [Figure 10] This figure shows an exemplary protocol data unit (PDU) session entry. [Figure 11] This is a schematic flowchart illustrating a method for preventing SIM spoofing within the mobile user plane. [Figure 12] This is a schematic flowchart illustrating a method for preventing SIM spoofing within the mobile user plane. [Figure 13] This is a schematic diagram showing the components of an exemplary computer device. [Modes for carrying out the invention]

[0008] This document discloses a system, method, and device for preventing subscriber identification module (SIM) spoofing within a mobile user plane (MUP). The system, method, and device described herein can be implemented in particular within a 5G radio access network (RAN), where user devices such as mobile phones, tablets, and laptops are connected to the internet (or other networks) via the 5G RAN.

[0009] A SIM card, or subscriber identification module card, is a small chip inserted into a mobile phone (or other user device connected to a cellular network) to identify the phone to the network. SIM cards function as a crucial component of mobile communications, enabling users to make phone calls, send text messages, and access data services. A SIM card contains important user information, such as the user's phone number, network service provider, and other identifying information. Once a user inserts their SIM card into their mobile phone, the phone becomes network-connected, allowing the user to make phone calls and access data services.

[0010] SIM spoofing is a type of fraud in which an attacker gains unauthorized access to another person's mobile phone number and SIM card. SIM spoofing occurs through various means, including stealing a physical SIM card or using "tricks" to make a router believe that data packets originated from a device containing a specific SIM card, even if the data packets were actually sent entirely from another device. SIM spoofing can have serious consequences for victims because the attacker can use the victim's phone number and SIM card to gain access to sensitive information such as two-factor authentication email accounts or bank accounts.

[0011] The systems, methods, and apparatus described herein are designed to prevent SIM spoofing within the mobile user plane. The systems described herein deploy a Packet Forwarding Control Protocol (PFCP) proxy between components of the network architecture. The PFCP proxy snoops messages within the network architecture to obtain user device addresses, network node addresses, and tunnel endpoint identifiers. The data points snooped by the PFCP proxy are used to verify that messages received from user devices were actually validly created by those user devices and not by an attacking device attempting to perform a SIM spoofing attack.

[0012] The following is provided as further background for the disclosure presented herein. In a computer network environment, network devices such as switches or routers are used to transmit information from one destination to another. In embodiments, data packages and messages are generated at a first location, such as a person's home computer. Data packages and messages are generated by a person who interacts with a web browser to provide information to a remote server accessible over the Internet, or to request information from a remote server. In embodiments, data packages and messages may be information entered by a person in a form accessible on a web page connected to the Internet. Data packages and messages need to be sent from the person's computer to a remote server located geographically far away. Direct communication between the person's home router and the remote server is unlikely. Therefore, data packages and messages must travel by "hopping" through different network devices to reach the destination of the remote server. The person's home router must determine the route by which the data packages and messages are transmitted through multiple different Internet-connected devices until they reach the destination of the remote server.

[0013] The process of determining the optimal path from a first location to a destination and forwarding data packages and messages to the next destination is a critical function performed by network devices such as switches or routers. The connections between network devices within a network are called network topology. Network topology is the arrangement of elements such as links and nodes within a communication network. Network topology can include wired links, wireless links, or a combination of wired and wireless links between nodes within a network. Some examples of wired links include coaxial cables, telephone lines, power lines, ribbon cables, and optical fibers. Some examples of wireless links include satellite, cellular signals, radio signals, and free-space optical communications. Network topology includes a representation of all nodes in the network (e.g., computers, routers, switches, and other devices) and a representation of the links between nodes. Systems, methods, and devices for improving network topology and network routing are disclosed herein.

[0014] For a further understanding of this disclosure, several descriptions of various network computing devices and protocols are provided.

[0015] A BGP instance is a device for routing information within a network. A BGP instance can take the form of a route reflector appliance. A BGP instance can run on a switch, router, or a BGP speaker on a switch. At a high level, a BGP instance sends all paths it has learned about a prefix to the best path controller. The best path controller responds with a set of optimal paths from these paths. The best path controller is authorized to change the next hop and attributes of any path. Upon receiving the optimal path, the BGP instance updates the Local Routing Information Base (RIB) and advertises the optimal path to its neighbors.

[0016] A router connects networks. Switches and routers perform similar functions but have different functions on the network. A router is a network device that transfers data packets between computer networks. A router performs a traffic directing function on the Internet. Data transmitted via the Internet, such as web pages, emails, or other forms of information, is sent in the form of data packets. Packets are usually transferred from one router to another via the networks that make up the Internet network (e.g., the Internet) and finally reach the destination node. A router is connected to two or more data lines from different networks. When a data packet arrives on one of the lines, the router reads the network address information in the packet and determines the final destination. Next, the router uses the information in the router's routing table or routing policy to direct the packet to the next network on the journey. A BGP speaker is a router enabled by the Border Gateway Protocol (BGP).

[0017] A customer edge (CE) router is a router placed inside a house and provides an interface between the provider's core network and the customer's LAN. CE routers, provider routers, and provider edge routers are components within a Multiprotocol Label Switching configuration. Provider routers are placed inside the core of a provider or carrier's network. Provider edge routers are placed at the edge of the network. Customer edge routers are connected to provider edge routers, and provider edge routers are connected to other provider edge routers on provider routers.

[0018] A routing table, or routing information base (RIB), is a data table stored within a network computer or router that creates a list of routes to a specific network destination. In some cases, a routing table includes route metrics such as distance and weight. A routing table also contains information about the network topology immediately surrounding the router where it is stored. Building a routing table is the primary goal of a routing protocol. Statistical routes are entries created in the routing table by non-automatic means and are fixed regardless of the results of some network topology discovery procedures. A routing table can include at least three information fields, including network ID, metric, and next hop. The network ID is the destination subnet. The metric is the routing metric of the path a packet will travel through as it is sent. A route moves towards the gateway with the lowest metric. The next hop is the address of the next station to which the packet will be sent on its way to the destination. A routing table may further include quality of service associated with the route, links that filter the criteria list associated with the route, interfaces for Ethernet cards, etc.

[0019] To illustrate the concept of a routing table, it can be analogous to using a map to propagate packages. A routing table is like using a map to propagate packages to their final destination. When a node needs to send data to another node on the network, the node first needs to know where to send it from. If the node cannot connect directly to the destination node, the node needs to send the data to other nodes along the appropriate route to the destination node. Most nodes don't try to calculate which route will work. Instead, the node sends an IP packet to a gateway in the LAN, and the gateway then decides how to route the data to the correct destination. Each gateway needs to track the direction in which various packages of data are propagated, and for this purpose it uses a routing table. A routing table is a database that tracks paths like a map, and these paths are used to determine the direction in which traffic is forwarded. Gateways can also share the contents of these routing tables with other nodes that are requesting information.

[0020] For hop-by-hop routing, each routing table creates a list of addresses of the next devices along the path to the destination, e.g., the next hop, for all reachable destinations. Assuming the routing tables are consistent, the algorithm for relaying packets to the next hop to the destination can carry the data anywhere in the network. Hop-by-hop is a feature of the IP internetwork layer and the Open Systems Interconnection (OSI) model.

[0021] The Open Systems Interconnection (OSI) model is a conceptual model that characterizes and standardizes the communication functions of computer systems, regardless of their underlying internal structure and technology. The goal of the OSI model is interoperability of diverse communication systems through standard communication protocols. The OSI model divides communication systems into abstraction layers. Each layer works for the layers above it, and the layers below it are useful. For example, a layer that provides error-free communication across a network requests the layers below it to provide the necessary paths for applications above it and to receive and transmit the packets that make up the content of those paths. Two instances of the same layer are visualized as being connected by horizontal connections within that layer. Communication protocols enable entities within one host to interact with corresponding entities of the same layer within another host. Service definitions, such as those in the OSI model, abstractly describe the functions provided by (N-1) layers to (N) layers, where N is one of the layers of protocols operating within the local host.

[0022] Route control is a type of network management aimed at improving internet connectivity, reducing bandwidth costs, and streamlining overall network operation. Some route control services include a suite of hardware-based and software-based products and services that work together to improve overall internet performance and fine-tune available internet bandwidth at minimal cost. Route control can be successful in scenarios where a network or autonomous system procures internet bandwidth from multiple providers. Route control can assist in selecting the optimal path for data transmission.

[0023] Some network communication systems are large, enterprise-level networks with thousands of processing nodes. These thousands of processing nodes share bandwidth from multiple Internet Service Providers (ISPs) to handle massive amounts of internet traffic. Such systems can be extremely complex and require proper configuration to achieve acceptable internet performance. If the system is not properly configured for optimal data transmission, internet access speeds can decrease, and system bandwidth consumption and traffic can increase. This problem can be addressed or mitigated by implementing a set of services, also known as routing control.

[0024] One embodiment of a routing control mechanism consists of hardware and software. The routing control mechanism monitors all outgoing traffic via connections with Internet service providers (ISPs). It assists in selecting the optimal path for efficient data transmission. The routing control mechanism calculates the performance and efficiency of all ISPs and can select only the ISP that performs optimally in the applicable area. The routing control device can be configured according to predefined parameters related to cost, performance, and bandwidth.

[0025] A well-known algorithm for determining the optimal path for data transmission is called the Border Gateway Protocol (BGP). BGP is a path-vector protocol that provides routing information for autonomous systems on the internet. If BGP is not properly configured, serious problems can arise in terms of availability and security. Furthermore, an attacker can redirect large blocks of traffic by modifying BGP route information, causing traffic to reach a specific router before it reaches its intended destination. By implementing the BGP optimal path algorithm, it is possible to determine the best path to install in the Internet Protocol (IP) routing table for traffic forwarding. A BGP router can be configured to receive multiple paths to the same destination.

[0026] The BGP optimal path algorithm assigns the first valid path as the current optimal path. The BGP optimal path algorithm compares the next path in the list with the optimal path until BGP reaches the end of the list of valid paths. This list provides the rules used to determine the optimal path. For example, the list may include directives such as prioritizing the path with the highest weight, prioritizing paths without local priority, prioritizing paths originating locally by network or aggregate BGP, prioritizing the shortest path, or prioritizing the path with the fewest multi-exit discriminator. The BGP optimal path selection process can be customized.

[0027] In the context of BGP routing, each routing domain is called an autonomous system (AS). BGP helps select a path across the internet to connect two routing domains. BGP typically selects a route that passes through the fewest number of autonomous systems, known as the shortest AS path. In one embodiment, once BGP is enabled, a router obtains a list of internet routes from a BGP neighbor, which may be an ISP. BGP then scrutinizes the list to find a route that has the shortest AS path. These routes may be entered into the router's routing table. Typically, the router selects the shortest path to the AS. BGP uses path attributes to determine how to route traffic to a particular network.

[0028] Equal Cost Multipath (ECMP) routing is a routing strategy in which next-hop packets forwarded to a single destination can occur over multiple "optimal paths." These multiple optimal paths are equal based on routing metric calculations. Multipath routing can be used with many routing protocols because routing is a hop-by-hop decision limited to a single router. Multipath routing can substantially increase bandwidth by load balancing traffic over multiple paths. However, when the strategy is actually deployed, numerous problems are known with ECMP routing. Systems, methods, and devices for improving ECMP routing are disclosed here.

[0029] A Virtual Local Area Network (VLAN) is a broadcast domain that is partitioned and isolated within a computer network at the data link layer. VLANs apply tags to network frames and process these tags within the network system to create the functionality and appearance of network traffic as if it were partitioned between separate networks, even though it is physically on a single network. VLANs allow network applications to remain isolated even when connected to the same physical network, without the need to deploy multiple sets of cables and network devices.

[0030] To further understand the principles based on this disclosure, the following will refer to and describe the illustrated embodiments using specific terminology, but this is not intended to limit the scope of this disclosure. Any changes and further modifications to the features of this disclosure illustrated herein, and any additional applications of the principles of this disclosure illustrated herein, are readily conceivable to those skilled in the art and are included within the claims.

[0031] Before disclosing and describing structures, systems, and methods for tracking the lifecycle of objects in a network computing environment, this disclosure is not limited to the specific structures, configurations, process steps, and materials disclosed herein, and such structures, configurations, process steps, and materials may be modified. Furthermore, since the scope of this disclosure is limited only by the claims and their equivalents, the terms used herein are used solely for the purpose of describing specific embodiments and are not intended to be limiting.

[0032] In describing the subject matter of this disclosure and making claims, the following terms shall be used in accordance with the definitions set forth below.

[0033] In this specification and in the claims, the singular forms (with the articles "a," "an," and "the") refer to multiple subjects unless otherwise specified in the context.

[0034] The terms “equipped with,” “possessed,” “included,” “characterized,” and their grammatical equivalents used herein are non-exclusive or unrestrictive terms that do not exclude additional elements or process steps not described herein.

[0035] The phrase "consisting of" and its grammatical equivalent used herein exclude any elements or processes not described in the claims.

[0036] The phrase "substantially consisting of" and its grammatical equivalents used herein limit the claims to materials or processes that do not substantially affect the identified materials or processes, or the fundamental and novel properties or features of the claimed disclosure.

[0037] Referring to the drawing, Figure 1 is a schematic diagram of a system 100 that connects a device to the Internet via a Radio Access Network (RAN). System 100 includes a 5G Radio Access Network (RAN) 102, which includes a number of nodes for communicating with user equipment 116. Each of the nodes in the 5G RAN 102 includes, in particular, the gNodeB 104 described herein. The 5G RAN 102 further includes a virtual station framework 106, a RAN control unit 108, and a 3GPP stack 110. The 5G RAN 102 communicates with a router 112, which then communicates with a BGP control unit 114.

[0038] The 5G RAN102 network consists of a control plane and a user plane. The control plane is used to configure data paths and data path policies for each user device (UE) 116 that communicates with the 5G RAN102. The user plane is used to transmit data packets to and from the user devices 116. In some cases, network slicing is implemented within the user plane (rather than the control plane), but the actual network slicing and packet forwarding on the target network slice occur within the user plane. PFCP (Packet Forwarding Control Protocol) functions as the control protocol for the 5G RAN102.

[0039] Router 112 is a network device that forwards data packets between computer networks. Router 112 performs a traffic direction function on the Internet. Router 112 may have interfaces for different types of physical layer connections, such as copper cables, optical fibers, or wireless transmission. Router 112 can support different network layer transmission standards. By using each network interface, data packets can be forwarded from one transmission system to another. Router 112 may also be used to connect two or more logical groups of computer devices called subnets, each having a different network prefix. As shown in Figure 1, Router 112 can provide connectivity within an enterprise, between an enterprise and the Internet, or between Internet service provider networks. Several Router 112s may be configured to interconnect various Internet service providers and may be used within large enterprise networks. Smaller Router 112s generally provide Internet connectivity for home and office networks. The router 112 shown in Figure 1 can represent any router suitable for network transmission, such as an edge router, provider edge router, cell site router, subscriber edge router, inter-provider border router, core router, internet backbone, port forwarding, or voice / data / fax / video processing router.

[0040] The system 100 shown in Figure 1 is merely an example, and many different configurations and systems can be built to transmit data between a network and computing devices. Because network formation offers high customizability, it is desirable to further enhance customizability when determining the optimal path for transmitting data between computers or between networks. From this perspective, we disclose a system, method, and device for offloading optimal path calculation to an external device in order to further enhance customizability when determining an optimal path algorithm that is well-suited to a particular enterprise or a specific grouping of computers.

[0041] Figure 2 is a schematic block diagram of the communication system 200 between components of the network architecture, which can be applied in particular to 5G service network architectures. System 200 includes a session management function (SMF) 202, a packet forwarding control protocol (PFCP) proxy 204, and a user plane function (UPF) 206.

[0042] PFCP (Packet Forwarding Control Protocol) is a communication protocol used within 5G RAN102 to manage and control the flow of data traffic. The PFCP proxy 204 is a network entity that acts as a relay between the 5G core network and user equipment (UE) 116 or other network entities. The PFCP proxy 204 is responsible for forwarding PFCP messages within the 5G core network and implementing policies that control the flow of data traffic. The session management function 202 and user plane function 206 utilize PFCP to establish data paths and / or data path policies for the default user equipment 116. The PFCP proxy 204 is placed between the session management function 202 and the user plane function 206 and forwards PFCP messages to the session management function 202 and the user plane function 206. The PFCP proxy 204 plays a crucial role in enabling 5G network slicing, which allows the creation of multiple logical networks on a single physical infrastructure. PFCP proxy 204 can be used to route PFCP messages based on policies defined by the network operator.

[0043] The PFCP proxy 204 traps protocol data unit (PDU) session information exchanged between the session management function 202 and the user plane function 206. The PFCP proxy 204 retrieves PDU session information for each IMSI (International Mobile Subscriber Identity). Multiple PDU sessions for a default device (with a default IMSI) are created with different SEIDs (Security Element Identifiers) to assign multiple IP addresses to the default device.

[0044] In a 5G mobile network, SMF stands for Session Management Function. SMF202 is a network function responsible for managing sessions between user equipment 116 and the 5G core network. SMF202 is responsible for creating, modifying, and terminating sessions between user equipment 116 and the 5G core network. SMF202 also manages session authentication and security functions, and handles the allocation and release of resources required for the session. SMF202 is a core component of the 5G network and is responsible for ensuring that sessions are established and maintained effectively and securely. SMF202 interacts with the isolated data plane to create, update, and delete PDU sessions. Additionally, SMF202 manages the session context with UPF (User Plane Function) 206. A PFCP proxy 204 is located between SMF202 and UPF206. SMF202 sends messages to UPF206 over the N4 reference interface using the Packet Forwarding Control Protocol (PFCP). These messages are processed through PFCP proxy 204 before reaching UPF206.

[0045] In a 5G mobile network, UPF stands for User Plane Function. UPF206 is responsible for processing user plane traffic, which is the actual data traffic transmitted between user equipment 116 and the rest of the network. UPF206 is responsible for forwarding user plane packets between user equipment 116 and the rest of the network, and for applying quality of service policies to the traffic. UPF206 also performs packet inspection, filtering, and manipulation functions, and can perform packet buffering and retransmission functions.

[0046] Figure 3 is a schematic block diagram of process flow 300, which records communications within a network architecture such as a 5G service network architecture. Process flow 300 includes tracking all PDU session information changes for each IMSI.

[0047] The International Mobile Subscriber Identification Number (IMSI) 302 is a unique identifier assigned to each mobile network subscriber and is used to identify and authenticate subscribers on the network. In most cases, the IMSI 302 is a 15-digit number assigned to the mobile subscriber's SIM card. When a mobile subscriber powers on and connects to a mobile network, the network uses the IMSI 302 to authenticate the subscriber and determine the services and functions that the subscriber is authorized to use. The IMSI 302 is used in combination with other identifiers, such as the Mobile Station International Subscriber Directory Number (MSISDN), which is the telephone number associated with the SIM card, to enable mobile communication services such as voice, messaging, and data services.

[0048] IMSI302 is also used in the process of authenticating subscribers to the network, helping to ensure the security of mobile communications. When a mobile phone connects to a network, the network requests that the SIM card provide IMSI302 and other authentication information. If authentication is successful, the subscriber is granted access to the network.

[0049] In a 5G mobile network, a Protocol Data Unit (PDU) session is a type of data session established between user equipment 116 and the 5G core network. A PDU session 304 is used to transmit data packets between user equipment 116 and the 5G core network. The PDU session 304 is established within the 5G core network by SMF 202 and managed by UPF 206. The PDU session 304 is used to support various types of data traffic, such as internet traffic, multimedia traffic, and other types of data traffic. A PDU session 304 can be composed of specific quality of service parameters, which determine the level of service provided to the data traffic. These parameters may include metrics such as data rate, latency, packet loss, and other factors that determine the quality of the data session.

[0050] The system described herein is implemented to detect a change in the gNodeB104N3 address of the default user device 116 (i.e., the default IMSI) when the user device 116 moves to another 5G RAN 102. Additionally, the system described herein is implemented for alarm detection in response to the number of PDU sessions of the default user device 116 (i.e., the default IMSI) exceeding the configuration limit. Multiple PDU sessions of the default user device 116 will have different gNodeB104N3 addresses with different user device 116 addresses over a period of n seconds, which increases the possibility of SIM spoofing.

[0051] Figures 4, 5A, 5B, 6A, and 6B are schematic diagrams of process flows and systems implemented to prevent SIM spoofing in the mobile user plane (MUP). Figure 4 is a schematic diagram showing an overview of system 400 for preventing SIM spoofing. Figures 5A and 5B are schematic diagrams of exemplary process flows for the control plane, where process flow 500 shown in Figure 5A relates to the Type 1 session translation (ST1) route, and process flow 550 shown in Figure 5B relates to the Type 2 session translation (ST2) route. Figures 6A and 6B are schematic diagrams of exemplary process flows for the data plane, where process flow 600 shown in Figure 6A relates to the ST1 route, and process flow 650 shown in Figure 6B relates to the ST2 route. Therefore, process flows 500 and 600 shown in Figures 5A and 6A are related to the ST1 route and correspond to each other. Similarly, process flows 550 and 650 shown in Figures 5B and 6B correspond to each other and are related to the ST2 route, respectively.

[0052] System 400 includes an SMF202 that communicates with UPF206 via a PFCP proxy 204. The PFCP proxy 204 communicates with a BGP (Border Gateway Protocol) control unit 404. The SMF202 receives communications from the Access and Mobility Management Function (AMF) 402. The AMF402 communicates with gNodeB104, which is a node in the cellular network that provides connectivity between user equipment (UE) 116 and an Advanced Packet Core (EPC) via a router 112. The gNodeB104 functions equivalently to a base station in a conventional cellular network. The gNodeB104 receives traffic from multiple user equipment 116, including exemplary UE1 and UE2 shown in Figure 4. System 400 includes an attacker 406 attempting SIM spoofing or SIM swap fraud, where a phone number is transferred to another device without authorization. System 400 includes a mobile backhaul 408.

[0053] The BGP controller 404 generates routes for each user device 116 (i.e., for each unique IMSI associated with each user device 116). The BGP controller 404 updates the router 112 in front of gNodeB104 with the generated routes.

[0054] Router 112 receives a GTP (GPRS Tunneling Protocol) packet from gNodeB104. Upon receiving the GTP packet, Router 112 checks the internal packet encapsulated within it. If there is no Type 1 Session Translation (ST1) route corresponding to the source address in the internal packet, Router 112 discards the received packet, assuming it was received from an invalid user.

[0055] Router 112 includes one or more provider edge (PE) routers or cell site routers (CSRs). Router 112 receives all user device 116 routes (i.e., ST1 routes) and then verifies the internal source IP (Internet Protocol) address of each user device 116. This verification process may include reverse-path-forwarding (RPF) checks. RPF checks are performed to reduce the forwarding of IP packets that are spoofing addresses. Unicast RPF checks perform a forwarding table lookup of the source address of the IP packet and check the incoming interface. Router 112 determines whether the packet arrived from the path the sender uses to reach the destination. If the packet is from a valid path, Router 112 forwards the packet to the destination address. If the packet is not from a valid path, Router 112 discards the packet. In particular, Router 112 determines whether a routing entry exists corresponding to the internal source IP address of user device 116, and if no routing entry exists, Router 112 discards the received packet. Unicast RPF checks support the IPv4 and IPv6 protocol families, as well as the Virtual Private Network (VPN) address family.

[0056] Mobile backhaul 408 is the process of connecting the RAN102 of a mobile network to the core network. RAN102 is part of the mobile network that provides wireless access to users, while the core network is part of the network that provides services and manages traffic. Mobile backhaul 408 enables the efficient and reliable transmission of traffic between RAN102 and the core network. Mobile backhaul 408 can consist of various types of connections, including fiber optic, microwave, and satellite links. Mobile backhaul 408 connects the cell site air interface to the wireless network and then to a data center that hosts applications and content accessed by mobile users.

[0057] The systems and methods described herein utilize Type 1 Session Translation (ST1) routes and Type 2 Session Translation (ST2) routes. The BGP ST1 route identifier BGP-MUP NLRI includes a route identifier (8 octets), prefix length (1 octet), prefix (variable), and architecture identifier (variable). The BGP3gpp-5g ST1 route identifier BGP-MUP NLRI includes a tunnel destination identifier (TEID) (4 octets), QFI (1 octet), destination address length (1 octet), and destination address (variable). The BGP ST2 route identifier BGP-MUP NLRI includes a route identifier (8 octets), destination length (1 octet), destination address (variable), and architecture identifier (variable).

[0058] The BGP speaker, functioning as a BGP controller 404, generates an ST1 route from the corresponding session information via the northbound API. When advertising the ST1 route, the BGP controller 404 should connect to a route target that communicates with the user device 116 and is imported into the routing instance of the corresponding direct segment.

[0059] A BGP speaker acting as a MUP controller generates an ST2 route from the corresponding session information via a default configuration or the northbound API. In the specific case of 3GPP 5G, configuring an ST2 route involves obtaining a destination consisting of the core-side TEID and the GTP tunnel destination address, with the effective length of the destination, as input parameters. The controller determines the route identifier for the ST2 route based on the operator policy. When advertising an ST2 route, the controller should connect to the BGP MUP extension community corresponding to the direct segment. The subtype of the extension community is the direct segment identifier. This segment identifier is generated from information received via a default configuration or the northbound API.

[0060] Figures 5A and 5B show process flows 500 and 550 for the control plane of 5G RAN102. Process flow 500 shown in Figure 5A includes the generation of the ST1 route, and process flow 550 shown in Figure 5B includes the generation of the ST2 route. Figures 6A and 6B show process flows 600 and 650 for the data plane of 5G RAN102. Process flow 600 shown in Figure 6A includes decision-making based on the ST1 route, and process flow 650 shown in Figure 6B includes decision-making based on the ST2 route. Thus, Figures 5A and 6A are related to the ST1 route, respectively, and Figures 5B and 6B are related to the ST2 route, respectively.

[0061] The control plane process flow 500 shown in Figure 5A begins at step 502, in which the user equipment (UE) 116 is connected to gNodeB 104. The process flow 500 continues to step 504, in which gNodeB 104 signals to the Access and Mobility Management Function (AMF) 402. In step 506, the AMF 402 signals to the Session Management Function (SMF) 202. In step 508, the SMF 202 and the User Plane Function (UPF) 206 establish a session for the user equipment 116. In step 510, the PFCP proxy 204 snoops the PFCP messages between the SMF 202 and UPF 206 to obtain the address of the user equipment 116, the Tunnel Terminal Identifier (TEID), and the address of gNodeB 104. In step 512, the BGP controller 404 generates a type 1ST route that can carry the address of user device 116, the TEID, and the address of gNodeB104. In step 514, the BGP controller 404 updates the type 1ST route. In step 516, the router 112 (one or more provider edge routers or cell site routers) stores the type 1ST route in the corresponding routing table.

[0062] The data plane process flow 600 shown in Figure 6A corresponds to the control plane process flow 500 shown in Figure 5A and relates to the use of ST1 routes. Process flow 600 begins in step 602, in which gNodeB104 encapsulates the internal IP packet 416 generated by the user device 116 within internal IP packet 416, user datagram protocol (UDP) packet 418, GPRS tunneling protocol (GTP) packet 420, and IP (Internet Protocol) packet 422. Process flow 600 continues to step 604, in which router 112 (one or more provider edge routers or cell site routers) checks the source address of IP packet 422. Router 112 checks the source address of internal IP packet 416 when the GTP packet 420 reaches router 112. In step 606, router 112 looks up the route announced by BGP controller 404 via type 1ST route. If a packet is generated by a valid user device 116, a corresponding route should exist because the user device 116 address is announced by the BGP controller 404 via the local store and type 1ST route on router 112. In step 608, router 112 forwards GTP packet 420 to the mobile backhaul 408 or deletes GTP packet 420. If a route exists, router 112 forwards GTP packet 420 to the mobile backhaul 408. If a route does not exist, router 112 deletes or filters the received GTP packet 420.

[0063] The control plane process flow 550 shown in Figure 5B relates to the use of ST2 routes. This process flow 550 performs the same steps as steps 502, 504, 506, 508, and 510 described in Figure 5A. Process flow 550 differs from process flow 500 based on the route type; process flow 500 uses ST1 type routes, while process flow 550 uses ST2 type routes. In process flow 550, the BGP controller 404 generates a Type 2 Session Translation (ST2) route capable of carrying the user equipment 116 address, TEID, and gNodeB104 address in step 513. In step 515, the BGP controller 404 updates router 112 with the ST2 route. In step 517, router 112 stores the ST2 route in the corresponding routing table.

[0064] The data plane process flow 650 shown in Figure 6B corresponds to the control plane process flow 550 shown in Figure 5B and relates to the use of ST2 routes. This process flow 650 proceeds similarly to the process flow 600 shown in Figure 6A, and in step 602, gNodeB 104 encapsulates the IP packet generated by user equipment 116. In step 605, router 112 checks the TEID in the GTP packet 420 header of the packet coming from gNodeB 104. In step 607, router 112 looks up the route announced by BGP controller 404 via a Type 2 Session Translation (ST2) route. Subsequently, upon receiving the GTP packet, router 112 checks the TEID in the GTP header. If an ST2 route exists and corresponds to the TEID in the GTP header, router 112 then determines in step 609 that the packet is OK. In addition, if the ST2 route does not correspond to the TEID in the GTP header, then router 112 discards the received GTP packet in step 609.

[0065] In ST1 process flows 500 and 600, the internal source address is checked based on the ST1 route, and the ST2 route can carry the TEID and UPF206 address for uplink. In ST2 process flows 550 and 650, instead of the ST1 route, router 112 receives the ST2 route from BGP controller 404. The ST1 route also carries the TEID, but the TEID of the ST1 route is used for downlink traffic from UPF206 to gNodeB104. The ST2 route includes the TEID for uplink traffic from gNodeB104 to UPF206.

[0066] Figures 7 to 9 are schematic diagrams of the system and process flow for implementing a SIM spoofing prevention mechanism for the mobile user plane (MUP). Figure 7 is a schematic diagram showing an overview of system 700 for preventing SIM spoofing. Figure 8 is a schematic diagram of process flow 800 for the control plane. Figure 9 is a schematic diagram of process flow 900 for the data plane.

[0067] System 700 includes the same components as those described in relation to Figure 4. However, in the implementation shown in Figure 7, the BGP controller 404 calculates the BGP flow specification (Border Gateway Protocol flow specification) based on the IP specification range assigned to all user devices 116, and then provides the BGP flow specification to the router 112. Instead of receiving all user device 116 routes, the BGP controller 404 calculates the BGP flow specification. In this model, the router 112 does not need to remember all user device 116 routes. Based on the BGP flow specification updated by the BGP controller 404, the router 112 can filter and delete packets from invalid users.

[0068] In the implementation shown in Figure 7, the BGP control unit 404 generates a BGP flow specification based on the IP address range used for all user equipment 116 routes. A BGP flow specification is a network protocol that uses BGP (Border Gateway Protocol) to provide finer control over traffic flow within a routed domain. BGP flow specifications are designed to improve the scalability and security of distributed networks by enabling administrators to selectively route or deny traffic based on specific criteria such as source or destination IP address, port, packet size, and protocol. Network administrators can leverage BGP flow specifications to quickly respond to changing network demands with globally or locally applicable policies. This improves security by blocking malicious traffic before it reaches its destination and reduces latency.

[0069] Furthermore, in the implementation shown in Figure 7, when router 112 receives a GTP packet from gNodeB104, the provider edge router checks the internal IP packet encapsulated within the GTP based on the BGP flow specification.

[0070] The process flow 800 for the control plane is shown in Figure 8, starting from step 802, in which user device 116 connects to gNodeB 104. In step 804, gNodeB 104 signals to AMF 402. In step 806, AMF 402 signals to SMF 202. In step 808, SMF 202 and UPF 206 establish a session for the specific user device 116. In step 810, PFCP proxy 204 snoops the PFCP messages between SMF 202 and UPF 206 to obtain the address, TEID, and address of gNodeB 104 of user device 116. In step 812, BGP controller 404 generates a BGP flow specification for the IP address range based on the address of user device 116. In step 814, BGP controller 404 updates the BGP flow specification route. In step 816, router 112 programs a packet filter based on the received BGP flow specification.

[0071] The process flow 900 for the data plane is shown in Figure 9 and begins in step 902, in which gNodeB104 encapsulates the internal IP packet 416 generated by the user device 116 within the internal IP packet 416, the user datagram protocol (UDP) packet 418, the GPRS tunneling protocol (GTP) packet 420, and the IP (Internet Protocol) packet 422. The process flow 900 continues to step 904, in which the router 112 (one or more provider edge routers or cell site routers) checks the source address of the IP packet 422. When the GTP packet 420 reaches the router 112, the router 112 checks the source address of the internal IP packet 416. In step 906, the router 112 matches the source address in the internal IP packet 416 with a given address range updated by the BGP control unit 404 in the BGP flow specification. If the packet is generated by a valid user device 116, the source address of the internal IP packet 416 matches a given address range updated by the BGP control unit 404 in the BGP flow specification. In step 908, router 112 forwards or deletes the GTP packet 420. If the address is included in the given address range in the BGP flow specification, router 112 then forwards the GTP packet 420 to the mobile backhaul 408. If the address is not included in the given address range in the BGP flow specification, router 112 then deletes or filters the received GTP packet 420. The packet filtering information is announced by the BGP control unit 404 instead of the user device 116 route, and therefore this implementation does not require a significant amount of routing entities.

[0072] Figure 10 shows an exemplary PDU session entry. The PFCP proxy 204 traps PDU session information exchanged between the SMF 202 and UPF 206. The PFCP proxy 204 retrieves PDU session information for each user device 116 (i.e., for each IMSI). Multiple PDU sessions for a given user device 116 are created with different SEIDs in order to assign multiple IP addresses to a given device.

[0073] Figure 11 is a schematic flowchart of method 1100 for preventing SIM spoofing in the mobile user plane. Method 1100 includes establishing a session for a user device to communicate with the SMF and UPF (step 1102). Method 1100 includes snooping messages between the SMF and UPF to obtain one or more of the user device's address, the tunnel termination identifier (TEID), or the address of a node in the radio access network (step 1104). Method 1100 includes generating a route to carry one or more of the user device's address, the TEID, or the address of a node in the radio access network (step 1106). Method 1100 includes identifying the source address of a data packet received from the user device (step 1108). Method 1100 includes verifying that the data packet was validly transmitted by the user device by comparing the generated route with the source address of the data packet (step 1110).

[0074] Figure 12 is a schematic flow diagram of Method 1200 for preventing SIM spoofing in the mobile user plane. Method 1200 includes establishing a session for the user device to communicate with the SMF and UPF (step 1202). Method 1200 includes snooping messages between the SMF and UPF to obtain one or more of the user device's address, tunnel destination identifier (TEID), or the address of a node in the radio access network (step 1204). Method 1200 includes generating a BGP flow specification for the range of IP addresses associated with the user device (step 1206). Method 1200 includes identifying the source address of the data packet received from the user device (step 1208). Method 1200 includes verifying that the data packet was validly transmitted by the user device by comparing the BGP flow specification with the source address of the data packet (step 1210).

[0075] Figure 13 is a block diagram of an exemplary computing device 1300. The computing device 1300 can be used to perform various procedures, such as those described herein. In one embodiment, the computing device 1300 can perform the functions of an asynchronous object manager and can run one or more application programs. The computing device 1300 may be any of the many types of computing devices, such as a desktop computer, an in-dash computer, a vehicle control system, a notebook computer, a server computer, a handheld computer, or a tablet computer.

[0076] The arithmetic device 1300 includes one or more processors 1302, one or more memory devices 1304, one or more interfaces 1306, one or more mass storage devices 1308, one or more input / output devices 1310, and a display device 1330, all of which are connected to the bus 1312. The processor 1302 includes one or more processors or controllers that execute instructions stored in the memory devices 1304 and / or the mass storage devices 1308. The processor 1302 may also include various types of computer-readable media such as cache memory.

[0077] The memory device 1304 includes various computer-readable media such as volatile memory (e.g., random access memory (RAM) 1314) and / or non-volatile memory (e.g., read-only memory (ROM) 1316). The memory device 1304 may also include rewritable ROM such as flash memory.

[0078] The high-capacity storage device 1308 includes various computer-readable media such as magnetic tape, magnetic disks, optical disks, and solid-state memory (flash memory, etc.). As shown in Figure 9, a specific high-capacity storage device is a hard disk drive 1324. The high-capacity storage device 1308 may also include various drives to enable reading from and / or writing to various computer-readable media. The high-capacity storage device 1308 includes removable media 1326 and / or non-removable media.

[0079] The input / output (I / O) devices 1310 include a variety of devices that enable inputting data and / or other information to or from the arithmetic device 1300. These I / O devices 1310 include a cursor control device, a keyboard, a keypad, a microphone, a monitor or other display device, a speaker, a printer, a network interface card, a modem, and the like.

[0080] The display device 1330 includes any type of device capable of displaying information to one or more users of the computing device 1300. Examples of the display device 1330 include monitors, display terminals, and video projection devices.

[0081] Interface 1306 includes various interfaces that enable the computing device 1300 to interact with other systems, devices, or computing environments. Interface 1306 may include any number of different network interfaces 1320, such as interfaces to a local area network (LAN), a wide area network (WAN), a wireless network, and the Internet. Other interfaces include a user interface 1318 and a peripheral device interface 1322. Interface 1306 may also include one or more user interface elements 1318. Furthermore, interface 1306 may include one or more peripheral interfaces, such as interfaces for a printer, a pointing device (mouse, trackpad, or any suitable user interface currently known to those skilled in the art, or any suitable user interface known to those skilled in the art), a keyboard, etc.

[0082] Bus 1312 enables the processor 1302, memory device 1304, interface 1306, mass storage device 1308, and I / O device 1310 to communicate with each other and with other devices or components connected to bus 1312. Bus 1312 represents one or more of several types of bus structures, such as a system bus, PCI bus, IEEE bus, and USB bus.

[0083] Here, for illustrative purposes, programs and other executable program components are shown as separate blocks; however, such programs and components may reside at different points in time within different memory components of the computing device 1300 and be executed by the processor 1302. Alternatively, the systems and procedures described herein may be implemented in hardware, or in combination of hardware, software, and / or firmware. For example, one or more application-specific integrated circuits (ASICs) can be programmed to perform one or more of the systems and procedures described herein. [Examples]

[0084] The following examples relate to further embodiments.

[0085] Example 1 is a method. The method includes establishing a session for a user device that communicates with a Session Management Function (SMF) and a User Plane Function (UPF). The method includes snooping messages between the SMF and the UPF to obtain one or more of the user device's address, a tunnel endpoint identifier, or the address of a node in the radio access network. The method includes generating a route for transmitting one or more of the user device's address, the tunnel endpoint identifier, or the address of the node in the radio access network. The method includes providing the route to a router.

[0086] Example 2 is the same method as in Example 1, and further includes connecting the user equipment to the node in the wireless access network.

[0087] Embodiment 3 is a method similar to Embodiment 1 or 2, further comprising causing the node in the wireless access network to transmit a signal to the Access and Mobility Management Function (AMF) in response to the node in the wireless access network receiving a packet from the user equipment.

[0088] Embodiment 4 is a method similar to any of Embodiments 1 to 3, further comprising causing the AMF to transmit a signal to the SMF before establishing the session for the user equipment to communicate with the SMF and the UPF.

[0089] Example 5 is a method similar to any of Examples 1 to 4, wherein snooping the messages between the SMF and the UPF includes a Packet Forwarding Control Protocol (PFCP) proxy snooping PFCP messages between the SMF and the UPF.

[0090] Embodiment 6 is a method similar to any of Embodiments 1 to 5, wherein generating the route includes generating the route using a Border Gateway Protocol (BGP) control unit, the control unit is further configured to update the corresponding Type 1ST route with one or more of the user equipment address, the tunnel endpoint identifier, or the address of the node in the radio access network.

[0091] Example 7 is a method similar to any of Examples 1 to 6, further comprising receiving internal Internet Protocol (IP) packets from the user device to the node in the wireless access network, and encapsulating the internal IP packets in user datagram protocol packets, GPRS tunneling protocol (GTP) packets, and IP packets, respectively.

[0092] Example 8 is a method similar to any of Examples 1 to 7, further including causing the router to verify the source address of the internal IP packet.

[0093] Example 9 is a method similar to any of Examples 1 to 8, further including determining whether the internal IP packet was generated by the user device by determining whether the corresponding route for the user device has been announced by the BGP control device, and forwarding the GTP packet to the mobile backhaul in response to the determination that the corresponding route for the user device has been announced by the BGP control device.

[0094] Example 10 is a method similar to any of Examples 1 to 9, wherein the mobile backhaul is a transport network configured to connect the core network to the wireless access network.

[0095] Example 11 is a method similar to any of Examples 1 to 10, further including determining whether the internal IP packet was generated by the user device by determining whether the corresponding route for the user device has been announced by the BGP control device, and discarding the GTP packet in response to the BGP control device determining that the corresponding route for the user device has not been announced.

[0096] Example 12 is a method similar to any of Examples 1 to 11, in which the GTP packets are discarded to prevent subscriber identification module (SIM) spoofing.

[0097] Example 13 is a method similar to any of Examples 1 to 12, wherein the user device communicates with a 5G wireless access network.

[0098] Example 14 is a method similar to any of Examples 1 to 13, wherein the user device is a cellular device capable of communicating with the node in the wireless access network.

[0099] Example 15 is a method similar to any of Examples 1 to 14, wherein the node in the wireless access network is a gNodeB in a 5G wireless access network.

[0100] Example 16 is a method similar to any of Examples 1 to 15, wherein the user device is associated with a unique IMSI (International Mobile Subscriber Identification Number), and establishing the session for the user device includes establishing a session for receiving packets from the unique IMSI.

[0101] Example 17 is a method similar to any of Examples 1 to 16, wherein the route is a Type 1ST route.

[0102] Example 18 is a method similar to any of Examples 1 to 17, wherein the router is a provider edge router.

[0103] Example 19 is a method similar to any of Examples 1 to 18, wherein the router is a cell site router.

[0104] Example 20 is a method similar to any of Examples 1 to 19, further including instructing the router to store the route in the corresponding routing table.

[0105] Example 21 is a method. The method includes generating a Border Gateway Protocol (BGP) flow specification based on a range of Internet Protocol (IP) addresses associated with a route for one or more user devices. The method includes verifying the encapsulation of an internal IP packet based on the BGP flow specification in response to receiving a packet from a node in a radio access network.

[0106] Example 22 is a method similar to Example 21, wherein generating the BGP flow specification includes being done by a BGP control unit, and the BGP control unit communicates with a router to update existing BGP flow specifications for the one or more user devices.

[0107] Example 23 is a method similar to Example 21 or 22, further including causing the router to filter incoming packets based on the BGP flow specification.

[0108] Example 24 is a method similar to any of Examples 21 to 23, and further includes establishing a session for the user device to communicate with the Session Management Function (SMF) and the User Plane Function (UPF).

[0109] Example 25 is a method similar to any of Examples 21 to 24, further comprising snooping messages between the SMF and the UPF to obtain one or more of the user device address, tunnel endpoint identifier, or the address of the node in the radio access network.

[0110] Example 26 is a method similar to any of Examples 21 to 25, wherein snooping the messages between the SMF and the UPF includes a Packet Forwarding Control Protocol (PFCP) proxy snooping PFCP messages between the SMF and the UPF.

[0111] Example 27 is a method similar to any of Examples 21 to 26, further comprising connecting each of the one or more user devices to the node in the wireless access network.

[0112] Example 28 is a method similar to any of Examples 21 to 27, further comprising causing the node in the wireless access network to transmit a signal to the Access and Mobility Management Function (AMF) in response to the node receiving a packet from one or more user devices.

[0113] Example 29 is a method similar to any of Examples 21 to 28, further comprising receiving an internal Internet Protocol (IP) packet from at least one of the one or more user devices to the node in the wireless access network, and encapsulating the internal IP packet in a user datagram protocol packet, a GPRS tunneling protocol (GTP) packet, and an IP packet, respectively.

[0114] Example 30 is a method similar to any of Examples 21-29, further including causing the router to verify the source address of the internal IP packet.

[0115] Example 31 is a method similar to any of Examples 21 to 30, in which verifying the encapsulation of the internal IP packet based on the BGP flow specification includes determining whether the range of IP addresses for the one or more user devices matches the source address of the internal IP packet.

[0116] Example 32 is a method similar to any of Examples 21 to 31, and further includes discarding the GTP packet in response to determining that the source address of the internal IP packet does not match the BGP flow specification.

[0117] Example 33 is a method similar to any of Examples 21 to 32, in which the GTP packets are discarded to prevent subscriber identification module (SIM) spoofing.

[0118] Example 34 is a method similar to any of Examples 21 to 33, and further includes forwarding the GTP packet to the mobile backhaul in response to determining that the source address of the internal IP packet matches the BGP flow specification.

[0119] Example 35 is a method similar to any of Examples 21 to 34, wherein the mobile backhaul is a transport network configured to connect the core network to the wireless access network.

[0120] Example 36 is a method similar to any of Examples 21 to 35, in which the verification of the encapsulation of the internal IP packets based on the BGP flow specification is performed by a router communicating with the node in the wireless access network.

[0121] Example 37 is a method similar to any of Examples 21 to 36, wherein the node in the wireless access network is a gNodeB in a 5G wireless access network.

[0122] Example 38 is a method similar to any of Examples 21 to 37, wherein the router is a provider edge router.

[0123] Example 39 is a method similar to any of Examples 21 to 38, wherein the router is a cell site router.

[0124] Example 40 is a method similar to any of Examples 21 to 39, wherein the user device is associated with a unique IMSI (International Mobile Subscriber Identification Number), and establishing the session for the user device includes establishing a session for receiving packets from the unique IMSI.

[0125] Embodiment 41 is a system. The system includes a session management function (SMF) within a wireless access network. The system includes a user plane function (UPF) within the wireless access network, the UPF communicating with the SMF. The system includes a packet forwarding control protocol (PFCP) proxy between the SMF and the UPF, the PFCP proxy snooping PFCP messages between the SMF and the UPF.

[0126] Example 42 is a system similar to Example 41, further including a node in the wireless access network, the node receiving data packets from user devices communicating via the wireless access network.

[0127] Example 43 is a system similar to Example 41 or 42, further including a router that communicates with the node, the router including one or more provider edge routers or cell site routers.

[0128] Example 44 is a system similar to Examples 41-43, further including an Access and Mobility Management Function (AMF), wherein the node transmits a signal to the AMF in response to receiving a data packet from the user equipment.

[0129] Example 45 is a system similar to Examples 41-44, wherein the AMF transmits a signal to the SMF in response to receiving the data packet from the node.

[0130] Example 46 is a system similar to Examples 41-45, where the PFCP proxy communicates with a Border Gateway Protocol (BGP) control device, and the BGP control device communicates with the router.

[0131] Example 47 is a system similar to Examples 41-46, in which the PFCP proxy snoops the PFCP messages between the SMF and the UPF and obtains one or more of the user device address, the tunnel endpoint identifier, or the address of the node in the wireless access network.

[0132] Example 48 is a system similar to Examples 41-47, in which the PFCP proxy snoops the PFCP messages between the SMF and the UPF to obtain the user device address, the tunnel endpoint identifier, and the address of the node in the wireless access network, respectively.

[0133] Example 49 is a system similar to Examples 41-48, wherein the BGP control device generates routes for transmitting the address of the user device, the tunnel endpoint identifier, and the address of the node in the radio access network.

[0134] Example 50 is a system similar to Examples 41-49, in which the BGP control device provides the routes to the router, and the router updates its routing table.

[0135] Example 51 is a system similar to Examples 41-50, in which the router verifies the source address of the data packet received from the user device, and the router determines whether the data packet was effectively generated by the user device based on the source address and the route received from the BGP control device.

[0136] Example 52 is a system similar to Examples 41-51, in which the router deletes the data packet in response to determining that the data packet was not effectively generated by the user device, and then forwards the data packet to its destination in response to determining that the data packet was effectively generated by the user device.

[0137] Example 53 is a system similar to Examples 41-52, in which the BGP control device generates a BGP flow specification based on a range of IP addresses associated with one or more user devices.

[0138] Example 54 is a system similar to Examples 41-53, wherein the node in the wireless access network receives internal Internet Protocol (IP) packets from user equipment, and the node encapsulates the internal IP packets in user datagram protocol packets, GPRS tunneling protocol (GTP) packets, and IP packets, respectively.

[0139] Example 55 is a system similar to Examples 41-54, in which the router verifies the source address of the internal IP packet.

[0140] Example 56 is a system similar to Examples 41-55, wherein the router verifies the encapsulation of the internal IP packet based on the BGP flow specification and determines whether the source address of the internal IP packet matches the range of IP addresses associated with one or more user devices.

[0141] Example 57 is a system similar to Examples 41-56, in which the router discards the GTP packet in response to determining that the internal IP packet does not match the BGP flow specification, and forwards the GTP packet to its destination in response to determining that the internal IP packet matches the BGP flow specification.

[0142] Example 58 is a system similar to Examples 41-57, in which the node in the wireless access network encapsulates internal IP packets received from the user equipment within internal IP packets, User Datagram Protocol (UDP) packets, GPRS Tunneling Protocol (GTP) packets, and IP packets.

[0143] Example 59 is a system similar to Examples 41-58, further including a user device that provides data packets to the nodes in the wireless access network, and an attacker attempting to spoof the identifier of the user device.

[0144] Example 60 is a system similar to Examples 41-59, in which the PFCP proxy snoops the PFCP messages between the SMF and the UPF to prevent spoofing by the attacker.

[0145] The above description is for illustrative and explanatory purposes only. This disclosure is not exclusively limited to the detailed form described herein. Many modifications and variations are possible by referring to the above teachings. Furthermore, any or all of the above modifications can be arbitrarily combined to form further combined examples of this disclosure.

[0146] Furthermore, while specific embodiments of the Disclosure are described and illustrated, the Disclosure is not limited to the specific forms or arrangements of the parts described and illustrated. The scope of the Disclosure is defined by the claims of this Application, or by any future claims, other applications based on this Application, and equivalents thereof.

[0147] Any feature of the above-described configurations, examples, and embodiments can be combined in a single embodiment that includes a combination of features obtained from any of the configurations, examples, and embodiments disclosed herein.

[0148] The various features disclosed herein offer significant advantages and advancements in the art. The following claims are some examples of these features.

[0149] In the aforementioned detailed description of this disclosure, various features of the disclosure are grouped into a single embodiment for the purpose of streamlining the disclosure. This method of disclosure should not be interpreted as reflecting an intention that the claimed disclosure requires more features than those explicitly described in each claim. That is, the features of the embodiments of the invention are fewer than all the features of the single embodiment disclosed earlier.

[0150] The above configurations are merely illustrative examples of the application of the principles of this disclosure. Those skilled in the art will be able to conceive of many variations and alternative configurations without departing from the spirit and scope of this disclosure, and the claims are intended to cover such modifications and configurations.

[0151] Therefore, although this disclosure is shown in drawings and described in detail above, it will be apparent to those skilled in the art that a number of modifications, including but not limited to variations in size, materials, shape, form, function, operation, assembly, and use, can be conceived without departing from the principles and concepts described herein.

[0152] Furthermore, the functions described herein can be performed, where appropriate, in one or more of the following: hardware, software, firmware, digital components, or analog components. For example, one or more application-specific integrated circuits (ASICs) or field-programmable gate arrays (FPGAs) can be programmed to perform one or more of the systems and procedures described herein. Throughout the description and claims, specific terms are used to refer to specific system components. It will be apparent to those skilled in the art that components may be called by different names. This document is not intended to distinguish between components with different names but the same function.

[0153] The above description is for illustrative and explanatory purposes only. This disclosure is not exclusively limited to the detailed form described herein. Many modifications and variations are possible by referring to the above teachings. Furthermore, any or all of the above modifications can be arbitrarily combined to form further combined examples of this disclosure.

[0154] Furthermore, while specific embodiments of the Disclosure are described and illustrated, the Disclosure is not limited to the specific forms or arrangements of the parts described and illustrated. The scope of the Disclosure is defined by the claims of this Application, or by any future claims, other applications based on this Application, and equivalents thereof. [Explanation of symbols]

[0155] 100 Systems 200 Systems 300 Process Flows 400 System 500 Process Flows 550 Process Flows 600 Process Flows 650 Process Flows 700 System 800 Process Flows 900 Process Flows 1100 methods 1200 methods 1300 computing devices 1312 Bus

Claims

1. Session management function (SMF) within a wireless access network, User plane function (UPF) within the aforementioned wireless access network, A packet forwarding control protocol (PFCP) proxy between the SMF and the UPF, A system that includes, The UPF communicates with the SMF, The PFCP proxy is characterized by snooping PFCP messages between the SMF and the UPF.

2. Furthermore, the system according to claim 1, further comprising a node in the wireless access network, wherein the node receives data packets from user devices communicating via the wireless access network.

3. The system according to claim 2, further comprising a router that communicates with the node, wherein the router includes one or more provider edge routers or cell site routers.

4. The system according to claim 2, further comprising an access and mobility management function (AMF), wherein the node transmits a signal to the AMF in response to receiving a data packet from the user equipment.

5. The system according to claim 4, characterized in that the AMF transmits a signal to the SMF in response to receiving the data packet from the node.

6. The system according to claim 3, characterized in that the PFCP proxy communicates with a Border Gateway Protocol (BGP) control device, and the BGP control device communicates with the router.

7. The system according to claim 6, characterized in that the PFCP proxy snoops the PFCP messages between the SMF and the UPF and obtains one or more of the user device address, the tunnel endpoint identifier, or the address of the node in the wireless access network.

8. The system according to claim 6, characterized in that the PFCP proxy snoops the PFCP messages between the SMF and the UPF and obtains the address of the user device, the tunnel endpoint identifier, and the address of the node in the wireless access network, respectively.

9. The system according to claim 8, characterized in that the BGP control device generates a route for transmitting the address of the user device, the tunnel endpoint identifier, and the address of the node in the wireless access network, respectively.

10. The system according to claim 9, wherein the BGP control device provides the route to the router, and the router updates its routing table.

11. The router verifies the source address of the data packet received from the user device, and then, The system according to claim 10, wherein the router determines whether the data packet was effectively generated by the user device based on the source address and the route received from the BGP control device.

12. In response to determining that the data packet was not effectively generated by the user device, the router deletes the data packet, and then, The system according to claim 11, characterized in that, in response to determining that the data packet has been effectively generated by the user device, the router forwards the data packet to its destination.

13. The system according to claim 8, characterized in that the BGP control device generates a BGP flow specification based on a range of IP addresses associated with one or more user devices.

14. The node in the aforementioned wireless access network receives internal Internet Protocol (IP) packets from user equipment, and, The system according to claim 13, characterized in that the node encapsulates the internal IP packets within user datagram protocol packets, GPRS tunneling protocol (GTP) packets, and IP packets, respectively.

15. The system according to claim 14, characterized in that the router verifies the source address of the internal IP packet.

16. The system according to claim 15, characterized in that the router verifies the encapsulation of the internal IP packet based on the BGP flow specification and determines whether the source address of the internal IP packet matches the range of IP addresses associated with one or more user devices.

17. In response to determining that the internal IP packet does not match the BGP flow specification, the router discards the GTP packet, and then, The system according to claim 16, characterized in that, in response to determining that the internal IP packet matches the BGP flow specification, the router forwards the GTP packet to the destination.

18. The system according to claim 1, characterized in that the node in the wireless access network encapsulates internal IP packets received from user equipment within the internal IP packets, User Datagram Protocol (UDP) packets, GPRS Tunneling Protocol (GTP) packets, and IP packets.

19. Furthermore, a user device that provides data packets to the node in the wireless access network, An attacker attempting to spoof the identifier of the user device, The system according to claim 1, characterized by including the following:

20. The system according to claim 19, characterized in that the PFCP proxy snoops the PFCP messages between the SMF and the UPF in order to prevent spoofing by the attacker.