Method, system, and computer-readable medium for verifying a session management function (SMF) registration request

The method and system verify SMF registration requests in 5G networks by comparing network identifiers to prevent unauthorized access and fraud, ensuring secure network operations.

JP7713518B2Active Publication Date: 2025-07-25ORACLE INT CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023524453
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-10-21
Filing Date
2021-05-18
Publication Date
2025-07-25
Estimated Expiration
2041-05-18

AI Technical Summary

Technical Problem

Communication networks, particularly 5G networks, are vulnerable to malicious activities such as revenue fraud and data interception due to unverified Session Management Function (SMF) registration requests, allowing unauthorized entities to gain access and steal subscriber information.

Method used

A method and system for verifying SMF registration requests by comparing network identifiers from the request with trusted sources, such as UDR, to determine validity and take mitigation actions if the request is invalid.

Benefits of technology

Prevents malicious activities by ensuring valid SMF registration requests, thereby reducing revenue fraud and data theft, enhancing network security and fraud prevention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007713518000001
    Figure 0007713518000001
  • Figure 0007713518000002
    Figure 0007713518000002
  • Figure 0007713518000003
    Figure 0007713518000003
Patent Text Reader

Abstract

A method, system, and computer-readable medium are disclosed for validating a session management function (SMF) registration request. One method occurs in a network node. The method includes receiving a registration request from a first SMF in a home network, the registration request indicating a first network identifier that identifies a visited network to which a user device is roaming; determining whether the registration request is valid by comparing the first network identifier with a second network identifier associated with an access and mobility management function (AMF) that serves the user device; and performing at least one action based on the determining step.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Priority Claim This application claims the benefit of priority of U.S. Patent Application Serial No. 17 / 076,482, filed on October 21, 2020. The disclosure of the said application is hereby incorporated by reference in its entirety.

[0002] The subject matter described herein relates to methods and systems for preventing fraud related to communication networks. More specifically, the subject matter described herein relates to a method, system, and computer-readable medium for verifying a session management function (SMF) registration request.

Background Art

[0003] Background Communication networks can be targeted by malicious actors for various reasons, such as financial gain, espionage, or political goals. For example, vulnerabilities associated with "next-generation" and current networks (e.g., the third generation partnership project (3GPP (registered trademark)) fifth generation (5G) core network) enable some entities to commit revenue fraud, intercept or eavesdrop on unauthorized data, and / or steal subscriber personal information. When such problems occur, innocent parties can often be held responsible for correcting and / or mitigating the damage. Network operators generally use security devices, firewalls, and / or other devices to help prevent unauthorized access to their networks and customers, but many problems can still exist within those networks due to inherent security issues associated with the protocols and / or procedures used in these networks.

Summary of the Invention

Means for Solving the Problems

[0004] Summary A method, system, and computer-readable medium for verifying a session management function (SMF) registration request are disclosed. One method occurs at a network node. The method includes receiving, from a first SMF in a home network, a registration request indicating a first network identifier that identifies a visited network where a user device is roaming; determining whether the registration request is valid by comparing the first network identifier with a second network identifier associated with an access and mobility management function (AMF) that provides services to the user device; and performing at least one action based on the determining.

[0005] One system includes a network node. The network node includes at least one processor and a memory. The network node is configured to receive, from a first SMF in a home network, a registration request indicating a first network identifier that identifies a visited network where a user device is roaming, determine whether the registration request is valid by comparing the first network identifier with a second network identifier associated with an AMF that provides services to the user device, and perform at least one action based on the determining.

[0006] The subject matter described in this specification can be implemented in software combined with hardware and / or firmware. For example, the subject matter described in this specification can be implemented in software executed by a processor. In an exemplary implementation, the subject matter described in this specification can be realized using a computer-readable medium storing computer-executable instructions that, when executed by a computer's processor, cause the computer to perform steps. Exemplary computer-readable media suitable for implementing the subject matter described in this specification include non-transitory devices such as disk memory devices, chip memory devices, programmable logic devices, and application-specific integrated circuits. Additionally, the computer-readable media for implementing the subject matter described in this specification may be located on a single device or computing platform, or may be distributed across multiple devices or computing platforms.

[0007] As used herein, the term "node" refers to a physical computing platform that includes one or more processors and memory.

[0008] As used herein, the term "function" or "module" refers to software combined with hardware and / or firmware to implement the features described in this specification.

[0009] The subject matter described in this specification will now be described with reference to the accompanying drawings.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

DETAILED DESCRIPTION OF THE INVENTION

[0011] Detailed Description The subject matter described in this specification relates to a method, system, and computer-readable medium for verifying a Session Management Function (SMF) registration request. Vulnerabilities exist in various communication networks, including mobile communication networks. For example, a malicious network node (e.g., a malicious AMF or SMF) may be programmed or otherwise configured to generate an unauthorized session creation request (e.g., an Nsmf_PDU_Session_Create message) and send it to the home network of one or more subscribers. In this example, the unauthorized message may be for creating a protocol data unit (PDU) session and may include a subscriber and / or user device identifier (e.g., a subscription permanent identifier (SUPI) or an international mobile subscriber identity (IMSI)), and location information (e.g., a public land mobile network (PLMN) identifier) indicating that the subscriber is roaming in that network. In response to receiving this message, the SMF in the home network may generate a registration request (e.g., an Nudm_UECM_Registration message) and send it to the unified data management (UDM) to register itself as handling the PDU session. Since the UDM does not verify the SMF registration request, the home network or a node therein may act on the unauthorized message by providing subscriber data (e.g., a subscriber profile) and / or other information (which can be used to commit revenue fraud, perform data interception, steal subscriber profile details, and / or perform other malicious actions) to the malicious network node.

[0012] According to some aspects of the subject matter described herein, a technique, method, system, or mechanism for verifying an SMF registration request is disclosed. For example, a network node (e.g., a UDM node) may use a registration verification algorithm to determine whether an SMF registration request is invalid (e.g., fraudulent, incorrect, inappropriate, etc.). In some embodiments, the registration verification algorithm may involve comparing a first network identifier located in the registration request (e.g., a PLMN identifier of the visited network) with a second network identifier associated with an access and mobility management function (AMF) that provides services to the user device (e.g., a PLMN identifier). In some embodiments, if the SMF registration request is determined to be invalid (e.g., by determining that the first network identifier and the second network identifier do not match), or if it is determined that the request may be invalid, the network node may take one or more actions such as discarding the message, preventing the registration, notifying the network operator of potential malicious behavior, or other mitigation actions.

[0013] Advantageously, malicious behavior and their adverse effects (e.g., revenue fraud) can be avoided and / or prevented by verifying the SMF registration request and taking one or more mitigation actions when the SMF registration request is determined to be invalid or may be invalid. It will be understood that the various aspects of the subject matter described herein may be implemented in a 5G system network architecture, or in a network architecture that includes both 5G network elements and non-5G network elements.

[0014] The various embodiments of the subject matter described herein will now be referred to in detail. Examples thereof are shown in the accompanying drawings. Wherever possible, the same reference numbers will be used throughout the drawings to refer to the same or similar parts.

[0015] FIG. 1 is a diagram illustrating an exemplary communication environment 100 for verifying SMF registration requests. FIG. 1 includes a UE 102 (e.g., a mobile device, a computer, a tablet computing platform, or a smartphone) that can roam or move between different parts of the communication environment 100. In some embodiments, the communication environment 100 may include one or more nodes associated with a fifth generation (5G) network having at least some functionality defined in one or more 3rd Generation Partnership Project (3GPP) technical specifications (TS), such as 3GPP TS 23.502 V16.6.0 (2020-09), 3GPP TS 23.501 V16.6.0 (2020-09), or 3GPP TS 29.502 V16.5.0 (2020-09).

[0016] The communication environment 100 may include a home network (e.g., a home public land mobile network (HPLMN)) and a visited network (e.g., a visited public land mobile network (VPLMN)). The home network may be associated with the UE 102 and may be the UE's default network. On the other hand, the visited network may be a network that the UE 102 can use, attempt to use, or appear to use while roaming outside the coverage area of the home network. In some embodiments, the home network and the visited network may include nodes for communicating with an external network such as the Internet 116.

[0017] In some embodiments, the home network and / or its associated nodes may be configured to handle data services (e.g., Internet access or PDU sessions) even when the subscriber is using a visited network for voice services, for example. For example, the home network may handle data services for a roaming subscriber by routing data flow service requests through the visited network, regardless of whether the visited network can provide the same service.

[0018] The visited network includes an access network 104, an AMF 106, a visited network SMF (V-SMF) 107, and a visited network user interface (WAN). Zap Visited network use lane function r p lane function (V-UPF) 112. The access network 104 may represent a radio access network (e.g., a next-generation radio access network (NG-RAN)) and may include various nodes for communicating with the UE 102 and elements in the communication environment 100. Exemplary nodes in the access network 104 may include a next generation node B (gNB), a next generation evolved node B (ng-eNB), or other transceiver nodes that may perform radio access functions. The access network 104, or a node therein, may be used for communication between the UE 102 and a node in the visited network or communication environment 100, such as the AMF 106. For example, the gNB or other node (e.g., a gateway) may communicate UE-related messages (e.g., authentication or mobility-related messages) to the AMF 106 or other node.

[0019] AMF106 represents a node or gateway that facilitates communication between the access network 104 and other nodes (e.g., V-UPF112) or the network. In some embodiments, AMF106 may communicate user traffic to other nodes in the communication environment 100. In some embodiments, AMF106 may also perform one or more mobility management functions similar to those performed by a mobility management entity (MME) in, for example, a 4G network. In some embodiments, AMF106 may forward session management requirements and / or related messages to V-SMF107 via, for example, the N11 interface.

[0020] V-SMF107 may represent one or more any suitable entities for performing one or more session management functions. For example, V-SMF107 may interact with nodes in a separate data plane to create, update, and / or remove a PDU session and / or to manage session context using V-UPF112. In some embodiments, V-SMF107 may communicate session-related information to a home network SMF (H-SMF) 108 or other nodes in the communication environment 100 to facilitate various session management functions. For example, during a home network routing scenario and after receiving an Nsmf_PDUSession_CreateSMContext request from AMF106, V-SMF107 may send an Nsmf_PDUSession_Create request to H-SMF108 that includes various information (such as a visited network PLMN identifier, a PDU session identifier, a UE identifier, and a V-SMF identifier). In this example, after storing the association between the PDU session identifier and V-SMF107, H-SMF108 may send a registration request (such as using a Nudm_UECM_Registration request) to UDM110 to perform authentication and / or to register itself as handling the PDU session.

[0021] V-UPF112 may be any suitable entity for providing access to the Internet 116 or other data networks, such as an Internet access point. In some embodiments, AMF106 may route IP traffic and / or related messages destined for the Internet 116 via V-UPF112 in the visited network. In some embodiments, for example, when the home network is to handle data services for a roaming subscriber, AMF106 may route IP traffic and / or related messages destined for the Internet 116 via the home network instead of via V-UPF112.Zap Lane function (for home network use r p can be routed via the lane function: H-UPF) 114.

[0022] The home network can include various nodes such as, for example, H-SMF 108, UDM 110, H-UPF 114, and Integration data repository: unified UDR) 11 8 and and so on. In some embodiments, the home network can be configured as the subscriber's default roaming provider. In some embodiments, the home network can be configured to allow the subscriber to change their roaming provider, for example, for a period or a predetermined period.

[0023] H-SMF 108 can represent one or more arbitrary suitable entities for performing one or more session management functions. For example, H-SMF 108 can interact with nodes in a separate data plane to create, update, and / or remove a PDU session and / or manage the session context using V-UPF 112. In some embodiments, H-SMF 108 can facilitate various session management functions associated with V-SMF 107, for example, when UE 102 is roaming. For example, during a home network routing scenario and after receiving an Nsmf_PDUSession_Create request from V-SMF 107, H-SMF 108 stores the association between the PDU session identifier and V-SMF 107, and then can send a registration request (using, for example, an Nudm_UECM_Registration request) to UDM 110 for authentication and / or to register itself as handling the PDU session.

[0024] H-UPF 114 can be any suitable entity for providing access to the Internet 116 or other data networks, such as an Internet access point. In some embodiments, for example, when the home network is handling data services for a roaming subscriber, the AMF 106 can route IP traffic and / or related messages destined for the Internet 116 via the H-UPF 114 in the home network.

[0025] The UDM 110 can represent one or more any suitable entities for managing user data, for example, for access authorization, user registration, and / or data network profiles. In some embodiments, the UDM 110 can include a stateful implementation where subscriber data is stored locally, or can be a stateless or semi-stateful implementation where subscriber data is stored remotely, for example, at the UDR 118. In some embodiments, the UDM 110 or related entities (such as the UDR 118) may maintain and / or provide one or more subscriber data management (SDM) or customer relationship management (CRM) functions. The UDM 110 or related entities (such as the UDR 118) can manage or provide subscriber-related information such as user IDs, control information for user authentication and authorization, UE location information, and user profile data. In some embodiments, the UDM 110 can include or interact with an authentication server function (AUSF) that performs authentication services for UEs such as the UE 102.

[0026] UDR118 may represent one or more any suitable entities for storing data for access authorization, user registration, and / or data network profile information. For example, UDR118 may maintain or store subscriber-related information such as user ID, control information for user authentication and authorization, UE location information, and user profile data. In this example, UDR118 may include or utilize a database containing details about the subscriber identity module (SIM) card associated with UE102, the services available to UE102, and the current location of UE102 (e.g., the current service providing node).

[0027] In some embodiments, when UDM110 or UDR118 involves multiple nodes, each node may manage and / or maintain information about a part of the subscribers, for example, information about hundreds of thousands to millions of subscribers, and the various nodes in the communication environment 100 may be configured to identify and investigate the appropriate node for information about a specific subscriber.

[0028] In some embodiments, UDM110 may perform session and / or network registration procedures in response to receiving a registration request or other message. For example, when UE102 is roaming in a visited network, a registration request may be sent from H-SMF108 in response to receiving a session creation request from V-SMF107.

[0029] In some embodiments, UDM 110 may include functionality for performing verification analysis on, for example, a registration message sent by H-SMF 108. For example, UDM 110 may be configured to analyze the header or payload portion of the SMF registration message and search for location information regarding the visited network (e.g., where UE 102 is roaming). In this example, UDM 110 may perform verification analysis that includes executing one or more verification algorithms and / or rules to determine whether the SMF registration message or related information is valid or appears to be valid.

[0030] In some embodiments, the network identifier or related information may include any information that can be used to identify the location of UE 102 or the associated subscriber. For example, the network identifier or related information may include a PLMN identifier, a mobile country code (MCC), a mobile network code (MNC), a location area code (LAC), a network identifier, a cell global identifier (CGI), a base station identifier (BSID), an access node identifier, a cell identity (CI), a service area code (SAC), a routing area identity (RAI), a routing area code (RAC), a tracking area identity (TAI), a tracking area code (TAC), an eUTRAN CGI (EGCI), location coordinates (e.g., global positioning system (GPS) information), and / or relative location information.

[0031] In some embodiments, the verification analysis or related algorithms may determine whether the SMF registration request is valid (or appears to be valid) by comparing the network identifier or related information indicated as being where UE102 is located by the registration request, with another network identifier or related information indicated as being where UE102 is located by another source (e.g., UDR118). For example, determining that the SMF registration request is valid may involve confirming that the SMF registration request indicates the same visited network as another or separate known and trusted source (e.g., UDR118).

[0032] For example, the verification analysis may involve comparing a first PLMN identifier indicated by or included in the SMF registration request, with a second PLMN identifier obtained by querying or accessing UDR118. In this example, the second PLMN identifier may identify the network in which AMF106 is serving the same UE associated with the registration request. For example, this information may be trusted by a trusted node or procedure and / or may have been previously provided to UDR118. Continuing with this example, if the first network identifier and the second network identifier match (e.g., they identify the same network), the verification analysis or related algorithms may determine that the SMF registration request is valid. However, if the first network identifier and the second network identifier do not match (e.g., they identify different networks), the verification analysis or related algorithms may determine that the SMF registration request is invalid.

[0033] In some embodiments, UDM 110 may be configured to perform one or more actions based on verification analysis or related determinations. For example, in response to a determination that an SMF registration request is valid, UDM 110 may initiate or perform a registration based on the registration request. In another example, in response to a determination that an SMF registration request is invalid, UDM 110 may screen, filter, or discard the SMF registration request or related messages, prevent registration based on the registration request, manage or send a notification message indicating that the registration request is invalid to a management or security node, manage or send a notification message indicating that a related node is potentially malicious to a management or security node, or copy or store a portion of the registration request.

[0034] It will be understood that FIG. 1 is for illustrative purposes only and that the various nodes and / or modules, locations, and / or functionality described above with respect to FIG. 1 may be changed, modified, added to, or removed.

[0035] FIG. 2 is a diagram showing an exemplary node 200 for verifying an SMF registration request. Node 200 may represent or include any one or more suitable entities for performing aspects of verifying an SMF registration request. In some embodiments, node 200 may represent or include UDM 110, UDR 118, AUSF, or another node or function.

[0036] Referring to FIG. 2, node 200 may include one or more communication interfaces 202 for communicating messages via a communication environment 100, such as a 5G core network. In some embodiments, communication interface 202 may include a first communication interface for communicating with UDR 118 and a second communication interface for communicating with H-SMF 108.

[0037] Node 200 may include a registration validation engine (RVE) 204. The RVE 204 can be any suitable entity (e.g., software executed on at least one processor) for performing one or more aspects of validating an SMF registration request. In some embodiments, the RVE 204 may include functionality for identifying messages that include subscriber location information, such as mobility management messages from roaming subscribers. For example, the RVE 204 may identify relevant messages by filtering messages based on header data and / or payload data.

[0038] In some embodiments, the RVE 204 may include functionality for performing a validation analysis on a registration message sent, for example, by the H-SMF 108. For example, the RVE 204 may be configured to analyze the header or payload portion of an SMF registration message and search for location information regarding the visited network (e.g., where the UE 102 is roaming). In this example, the RVE 204 may perform a validation analysis that includes executing one or more validation algorithms and / or rules to determine whether the SMF registration message or related information is valid or appears to be valid.

[0039] In some embodiments, the network identifier or related information may include any information that can be used to identify the location of the UE 102 or associated subscriber. For example, the network identifier or related information may include a PLMN identifier, MCC, MNC, LAC, network identifier, CGI, BSID, access node identifier, CI, SAC, RAI, RAC, TAI, TAC, EGCI, location coordinates (e.g., GPS information), and / or relative location information.

[0040] In some embodiments, the verification analysis or related algorithms may determine whether the SMF registration request is valid (or appears to be valid) by comparing the network identifier or related information indicated as where UE102 is located by the registration request with another network identifier or related information indicated as where UE102 is located by another source (e.g., UDR118). For example, determining that the SMF registration request is valid may involve confirming that the SMF registration request indicates the same visited network as another or separate known and trusted source (e.g., UDR118).

[0041] For example, the verification analysis may involve comparing a first PLMN identifier indicated by or included in the SMF registration request with a second PLMN identifier obtained by querying or accessing UDR118. In this example, the second PLMN identifier may identify the network in which AMF106 is serving the same UE associated with the registration request. Continuing with this example, if the first network identifier and the second network identifier match (e.g., they identify the same network), the verification analysis or related algorithms may determine that the SMF registration request is valid. However, if the first network identifier and the second network identifier do not match (e.g., they identify different networks), the verification analysis or related algorithms may determine that the SMF registration request is invalid.

[0042] In some embodiments, RVE204 may be configured to perform one or more actions based on a verification analysis or a related determination. For example, in response to a determination that an SMF registration request is valid, RVE204 may perform or initiate a registration based on the registration request. In another example, in response to a determination that an SMF registration request is invalid, RVE204 may screen, filter, or discard the SMF registration request or a related message, prevent registration based on the registration request, manage or send a notification message indicating that the registration request is invalid to a security node, manage or send a notification message indicating that a related node is potentially malicious to a security node, or copy or store a portion of the registration request.

[0043] Node 200 may access data storage 206 (e.g., read from data storage 206 and / or write information to data storage 206). Data storage 206 can be any suitable entity (e.g., a computer-readable medium or memory) for storing various data. In some embodiments, data storage 206 may include verification rules and / or policies related to registration. Data storage 206 may include information or logic for determining whether an SMF registration request is valid or invalid. Exemplary information or logic that can be used in determining whether an SMF registration request is valid or invalid may include previous (e.g., prior) location information associated with the UE or a related node (e.g., AMF106 or V-SMF107), and / or logic for accessing or querying one or more related databases or nodes (e.g., UDR118) to obtain various subscriber-related information (e.g., an identifier for identifying the AMF currently providing service to the UE, and / or an identifier for identifying the network associated with that AMF).

[0044] Data storage 206 may include network information related to the UE. For example, data storage 206 may include a mapping of a PLMN identifier, an APN, or other network identifier with valid location information (e.g., MCC and / or MNC). In some embodiments, the home network may store an approved access list of valid network identifiers, or related information that a roaming subscriber can use to receive data services or other services. In this example, node 200 or another node may access the network information related to the UE to determine whether a registration request is associated with an appropriate network identifier. If the location information is associated with an appropriate network identifier in the approved access list, the registration request may be determined to be valid.

[0045] In some embodiments, the home network may store a blocked access list of invalid network identifiers, or related information that a roaming subscriber cannot use to receive data services or other services. In this example, node 200 or another node may access the network information related to the UE to determine whether a registration request is associated with an inappropriate network identifier. If the location information is associated with a network identifier in the blocked access list, the registration request may be determined to be invalid.

[0046] It will be understood that FIG. 2 and its related description are for illustrative purposes and that node 200 may include additional and / or different modules, components, or functionality.

[0047] FIG. 3 is a diagram showing exemplary messages associated with processing an SMF registration request. In some embodiments, a session creation request may be provided or initiated by a V-SMF 300 whose control by malicious actors and / or use for malicious activities (e.g., revenue fraud and / or data interception) is unknown. In some embodiments, the V-SMF 300 may have or appear to have functionality similar to that described above with respect to the V-SMF 107.

[0048] Referring to FIG. 3, a part of the PDU session creation procedure for a roaming scenario routed to the home is generally represented. An exemplary PDU session creation procedure for a roaming scenario routed to the home is defined in section 4.3.2.2.2 of 3GPP TS 23.502 V16.6.0 (2020-09).

[0049] In step 301, a potentially unauthorized session creation request (e.g., an Nsmf_PDU_Session_Create message) may be sent from the V-SMF 300 to the H-SMF 108. In some embodiments, the session creation request may include a visited network PLMN identifier, a PDU session identifier, a UE identifier, and / or a V-SMF identifier.

[0050] In step 302, a registration request (e.g., a Nudm_UECM_Registration request) may be sent from the H-SMF 108 to the UDM 110. For example, after receiving a session creation request from the V-SMF 300, the H-SMF 108 may store the association between the PDU session identifier and the V-SMF 300, and then send a registration request (e.g., using a Nudm_UECM_Registration request) to the UDM 110 to register itself as handling the PDU session.

[0051] In step 303, successful registration and subscription data retrieval can occur. For example, successful registration can occur when a successful response to a registration request is received by H-SMF 108. In this example, V-SMF 300 may be able to obtain subscription data from UDM 110 or UDR 118 via H-SMF 108.

[0052] As shown, in the message flow of FIG. 3, potential security risks are apparent. For example, for a given PDU session identifier associated with roaming UE 102, when H-SMF 108 registers itself with UDM 110, H-SMF 108 does not query UDM 110 to verify that the AMF that triggered the registration request (e.g., by sending an Nsmf_PDUSession_CreateSMContext request to V-SMF 300) is registered with the UDM for that UE (the Nsmf_PDUSession_CreateSMContext request triggers V-SMF 300 to send an Nsmf_PDU_Session_Create message, which in turn triggers H-SMF 108 to send an Nudm_UECM_Registration request). Also, UDM 110 enables successful SMF registration even if AMF 106 is not performing access registration using the UECM registration procedure. Thus, since UDM 110 does not verify SMF registration requests, an attacker could send a fake Nsmf_PDUSession_Create request to H-SMF 108, and for this reason, would register themselves with UDM 110.

[0053] It will be understood that FIG. 3 is for illustrative purposes and that different and / or additional messages and / or actions may be used. It will also be understood that the various messages and / or actions described herein may occur in different orders or sequences.

[0054] FIG. 4 is a diagram showing exemplary messages associated with validating an SMF registration request. In some embodiments, a session creation request may be provided or initiated by a V-SMF 300 whose control by a malicious actor and / or use for malicious behavior (e.g., revenue fraud and / or data interception) is unknown. In some embodiments, the V-SMF 300 may have or appear to have functionality similar to that described above with respect to the V-SMF 107.

[0055] In some embodiments, the UDM 110 may determine whether the received SMF registration request is valid and may take various actions based on this determination. In some embodiments, the UDM 110 may include an RVE 204 and may be configured to analyze the SMF registration request.

[0056] Referring to FIG. 4, a portion of a PDU session creation procedure for a home-routed roaming scenario using SMF registration request analysis is generally represented.

[0057] In step 401, a potentially unauthorized session creation request (e.g., an Nsmf_PDU_Session_Create message) may be sent from the V-SMF 300 to the H-SMF 108. In some embodiments, the session creation request may include a visited network PLMN identifier, a PDU session identifier, a UE identifier, and / or a V-SMF identifier.

[0058] In step 402, a registration request (e.g., an Nudm_UECM_Registration request) may be sent from the H-SMF 108 to the UDM 110. For example, after receiving a session creation request from the V-SMF 300, the H-SMF 108 may store the association between the PDU session identifier and the V-SMF 300 and then send a registration request (e.g., using an Nudm_UECM_Registration request) to the UDM 110 to register itself as handling the PDU session.

[0059] In some embodiments, for example, after the UDM 110 receives a registration request from the H-SMF 108, the UDM 110 may verify the registration request by demonstrating that the AMF registered to provide services to a given UE has the same network identifier (e.g., a PLMN identifier) as that of the requester or the triggering V-SMF 300. In such embodiments, the network identifier associated with the AMF registered to provide services to a given UE may be received in the Amf3GppAccessRegistration data from the UDR 118, for example, using a GET request. If the PLMN identifiers match, the UDM 110 may proceed to process the registration request. However, if the PLMN identifiers do not match, the UDM 110 may take one or more mitigation actions. For example, it may not proceed to process the registration request.

[0060] In step 403, a data request may be sent from the UDM 110 to the UDR 118 to request the network identifier associated with the AMF that provides services to the UE corresponding to the registration request.

[0061] In step 404, a data response may be sent from the UDR 118 to the UDM 110 to provide the requested network identifier associated with the AMF that provides services to the UE corresponding to the registration request.

[0062] In step 405, the UDM 110 may verify the registration request by demonstrating that the network identifier obtained from the UDR 118 matches the network identifier indicated by the registration request.

[0063] In step 406, if it is determined that the registration request is valid, registration and subscription data retrieval may succeed. For example, registration success may occur when a success response to the registration request is received by H-SMF 108. In this example, V-SMF 300 may be able to obtain subscription data from UDM 110 or UDR 118 via H-SMF 108.

[0064] It will be understood that FIG. 4 is for illustrative purposes and that different and / or additional messages and / or actions may be used. It will also be understood that the various messages and / or actions described herein may occur in different orders or sequences.

[0065] FIG. 5 is a diagram illustrating an exemplary process 500 for validating an SMF registration request. In some embodiments, the exemplary process 500 described herein, or a portion thereof, may be performed by, or with, UDM 110, node 200, RVE 204, and / or another module or node.

[0066] Referring to the exemplary process 500, at step 502, a registration request indicating a first network identifier that identifies a visited network to which the user device is roaming from a first SMF in the home network may be received.

[0067] In some embodiments, the registration request may include a Nudm_UECM_Registration request. At step 504, it may be determined whether the registration request is valid by comparing the first network identifier with a second network identifier associated with an AMF that provides services to the user device.

[0068] In some embodiments, the second network identifier may be included in Amf3GppAccessRegistration data obtained from UDR 110.

[0069] In some embodiments, the step of determining that the second SMF or the registration request is valid may include the step of determining that the first network identifier and the second network identifier match.

[0070] In some embodiments, the step of determining that the registration request is invalid may include the step of determining that the first network identifier and the second network identifier do not match.

[0071] In step 506, at least one action may be performed based on the determination step. For example, if it is determined that the location information is invalid, one or more mitigation actions may be performed, for example, to prevent or minimize malicious behavior.

[0072] In some embodiments, the step of performing at least one action based on a verification determination related to registration may include the step of performing registration based on the registration request in response to the step of determining that the registration request is valid.

[0073] In some embodiments, the step of performing at least one action based on a verification determination related to registration may, in response to the step of determining that the registration request is invalid, discard the registration request, prevent registration based on the registration request, send a notification message indicating that the registration request is invalid to the management or security node, send a notification message indicating that the related node is potentially malicious to the management or security node, or include the step of copying or storing a part of the registration request.

[0074] In some embodiments, the first network identifier or the second network identifier may include a PLMN identifier or a PLMN code.

[0075] In some embodiments, a network node may be included, and the network node may include a UDM node, an AUSF, or a UDR.

[0076] It will be understood that process 500 is for illustration purposes and that different and / or additional actions may be used. It will also be understood that the various actions described herein may occur in different orders or sequences.

[0077] Although some aspects of the subject matter described herein have been described in relation to 5G networks, it will be understood that various other networks may utilize some aspects of the subject matter described herein. For example, any network that utilizes a registration request and / or includes a UDM-like node and / or a UDR-like node may use the features, mechanisms, and techniques described herein to verify (e.g., screen or filter) the registration request.

[0078] Note that UDM 110, node 200, RVE 204, and / or the functionality described herein may constitute a special-purpose computing device. Also, UDM 110, node 200, RVE 204, and / or the functionality described herein can improve the field of network security and / or fraud prevention. For example, malicious behavior and their adverse effects (e.g., revenue fraud) can be mitigated and / or prevented by verifying an SMF registration request and performing one or more mitigation actions when the SMF registration request is determined to be invalid or potentially invalid.

[0079] The disclosure of each of the following references is hereby incorporated by reference in its entirety to the extent that it does not conflict with the present specification and to the extent that it supplements, explains, provides the background of, or teaches the methods, techniques, and / or systems employed herein. References: 1. 3GPP TS 23.501; 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System (5GS); Stage 2 (Release 16) V16.6.0 (2020-09) 2. 3GPP TS 23.502; 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16) (2020-03) V16.6.0 (2020-09) 3. 3GPP TS 29.502, Technical Specification Group Core Network and Terminals; 5G System, Session Management Service, Stage 3, (Release 16) V16.5.0 (2020-09) It will be understood that various details of the subject matter described herein may be changed without departing from the scope of the subject matter described herein. Further, the above description is for illustrative purposes only and not for purposes of limitation.

Claims

1. A method for verifying a session management function (SMF) registration request, the method comprising: at a network node, receiving, from a first session management function (SMF) in a home network, a registration request indicating a first network identifier identifying a visited network where a user device is roaming; after receiving the registration request, obtaining a second network identifier and sending a data request to a reliable unified data repository (UDR); receiving, from the reliable UDR, the second network identifier associated with an access and mobility management function (AMF) that provides services to the user device, as a response to the data request; determining whether the registration request is valid by comparing the first network identifier with the second network identifier; performing at least one action based on the determining step, wherein the determining step includes determining that the registration request is valid when the first network identifier and the second network identifier match, and determining that the registration request is invalid when the first network identifier and the second network identifier do not match.

2. The method according to claim 1, wherein the second network identifier is included in Amf3GppAccessRegistration data obtained from the reliable UDR.

3. The method according to claim 1 or 2, wherein the performing at least one action step includes performing registration based on the registration request when the registration request is valid.

4. The method according to any one of claims 1 to 3, wherein the performing at least one action step includes, when the registration request is invalid, discarding the registration request, preventing registration based on the registration request, sending a notification message indicating that the registration request is invalid to a management or security node, sending a notification message indicating that a related node is potentially malicious to a management or security node, or copying or storing a part of the registration request.

5. The method according to any one of claims 1 to 4, wherein the first network identifier or the second network identifier includes a public land mobile network (PLMN) identifier or a PLMN code.

6. The method according to any one of claims 1 to 5, wherein the registration request includes a Nudm_UECM_Registration request.

7. The method according to any one of claims 1 to 6, wherein the network node includes an integrated data management (UDM) node, an authentication server function (AUSF), or an integrated data repository (UDR).

8. A system for verifying a session management function (SMF) registration request, the system comprising: a network node including at least one processor and a memory; wherein the network node: receives a registration request indicating a first network identifier for identifying a visited network to which a user device is roaming from a first session management function (SMF) in a home network; after receiving the registration request, obtains a second network identifier and sends a data request to a reliable integrated data repository (UDR); receives, from the reliable UDR, the second network identifier associated with an access and mobility management function (AMF) that provides services to the user device as a response to the data request; determines whether the registration request is valid by comparing the first network identifier and the second network identifier; is configured to perform at least one action based on the determination; the determination includes determining that the registration request is valid when the first network identifier and the second network identifier match, and determining that the registration request is invalid when the first network identifier and the second network identifier do not match.

9. The system according to claim 8, wherein the second network identifier is included in Amf3GppAccessRegistration data obtained from the reliable UDR.

10. The system according to claim 8 or 9, wherein the network node is configured to perform registration based on the registration request when the registration request is valid.

11. If the registration request is invalid, the network node discards the registration request, prevents registration based on the registration request, sends a notification message indicating that the registration request is invalid to the management or security node, sends a notification message indicating that the related node is potentially malicious to the management or security node, or is configured to copy or store a part of the registration request. The system according to any one of claims 8 to 10.

12. The system according to any one of claims 8 to 11, wherein the first network identifier or the second network identifier includes a public land mobile network (PLMN) identifier or a PLMN code.

13. The system according to any one of claims 8 to 12, wherein the registration request includes a Nudm_UECM_Registration request.

14. The system according to any one of claims 8 to 13, wherein the network node includes an integrated data management (UDM) node, an authentication server function (AUSF), or an integrated data repository (UDR).

15. A computer-readable program for causing at least one processor to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for processing PDU session establishment procedure and AMF node

    JP2019521607A

  • Access Information for Node Configuration

    US20200329524A1

  • Method For Performing Verification By Using Shared Key, Method For Performing Verification By Using Public Key And Private Key, And Apparatus

    US20200344604A1

  • Authorizing access to user data

    WO2018202284A1

  • Message transmission between core network domains

    WO2019224157A1