Method, device and system for registering a terminal in a communication network
The method and device enable multiple valid registrations and prevent identity spoofing by validating terminal identities and managing network resources, addressing security and service loss issues in communication networks.
Patent Information
- Application Number
- JP2024520034
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-05
- Filing Date
- 2022-09-23
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2042-09-23
AI Technical Summary
Existing communication networks allow only single registration per terminal, leading to security vulnerabilities like identity spoofing and loss of network services when USIM authentication information is duplicated, and do not support multiple simultaneous registrations across different access networks.
A method and device for managing terminal registrations in a communication network that tracks and validates previous registrations, allowing multiple simultaneous connections while detecting identity spoofing and coordinating resource allocation, by checking the validity and number of existing registrations and access networks.
Ensures valid multiple registrations, prevents identity spoofing, and optimizes resource use by validating terminal identities and managing simultaneous connections across networks, enhancing network security and service availability.
Smart Images

Figure 0007813355000001 
Figure 0007813355000002 
Figure 0007813355000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to the registration of a terminal in a communication network, and more particularly to enabling a terminal to register multiple times and simultaneously in a communication network, for example a Home Public Land Mobile Network (HPLMN) parent network, by simultaneously connecting to one or more, usually different, Visited Public Land Mobile Network (VPLMN) visited networks, while ensuring network and terminal security. The method more particularly aims to allow multiple connections to the communication network while protecting the resources of the network. [Background technology]
[0002] According to known techniques, a terminal equipped with a SIM (Subscriber Identity Module) card is allowed to register with a communications network only once.
[0003] It should be recalled that the mutual authentication between the cellular communication network and the user equipment (terminal) is carried out by a Universal Subscriber Identity Module (USIM) module contained in a Universal Integrated Circuit Card (UICC), commonly called a "SIM card", which is inserted in the terminal and contains authentication information (also called credentials) consisting, among other things, of an International Mobile Subscriber Identity (IMSI) corresponding to the user's permanent identifier and a private key, which, depending on the version of the communication network in question, is also stored in a server of the network called an Authentication Center (AC) associated to a Home Location Register (HLR), a Home Subscriber Server (HSS) or a Unified Data Management (UDM).
[0004] The process of manufacturing and distributing USIMs and providing AuCs aims to ensure that a given user's authentication information is a shared secret between a single USIM and AuC.
[0005] In accordance with the current operation of communication networks, as specified in the standards, in particular the 2G / 3G, 4G, and even 5G standards (3GPP TS 23.501 version 17.0.0 of 03 / 2021 and TS 23.502 version 17.0.0 of 03 / 2021), when a terminal successfully authenticates itself in a communication network with the same IMSI (or SUPI: Subscription Permanent Identifier) identifier as a terminal already registered in the network, this terminates the registration of the terminal previously registered with this IMSI (or SUPI) identifier. This terminal then loses the ability to use the network's services. It should be taken into account that this mechanism for terminating a first registration may be desirable, for example, if a user inserts a SIM card used in a first terminal into a second terminal without properly powering off the first terminal. In this case, the user uses the second terminal to access services via the communication network, so terminating the registration of the first terminal is necessary and therefore valid. This also applies if a user powers off their terminal and then powers it back on at a different location some time later: in this case, a new registration may be received by the new AMF, while the old AMF to which the terminal was previously connected still retains the context and does not manage the termination of the registration for the terminal. In this case, termination of the first registration is also desirable.
[0006] However, this implementation has proven problematic. Indeed, if these processes for instantiating the authentication method are flawed, USIM authentication information can be duplicated and used to register a second terminal in the communication network, for example, to perform identity spoofing. The second terminal using this spoofed authentication information then receives a message authenticating a banking transaction intended for the first terminal, for example, which poses a significant security risk for the first terminal, the communication network, and even the service using this authentication information, for which the authentication data has been spoofed. According to an example shown in FIG. 1, a terminal 1a has previously registered with and is therefore connected to a network Res1 that forms part of a communication network Res. According to this example, the network Res comprises a parent network Res4 and three access networks Res1, Res2, and Res3 interconnected to the network Res4. A terminal 1b with the same IMSI or SUPI identifier registers with the network Res4 via the network Res2. This new registration of terminal 1b has the effect of terminating the registration of terminal 1a to network Res4 via network Res1. According to another example, networks Res1 and Res2 are the same network. If the authentication data of the USIM is illegally copied, for example from terminal 1a to terminal 1b, terminal 1a will no longer have access to its communication services.
[0007] When this type of spoofing occurs, it is referred to as SIM card cloning.
[0008] This scenario creates a double problem: while the first, non-spoofed terminal cannot continue to access services from the communications network, a second terminal, known as a spoofing terminal, can access services through the communications network and potentially obtain data specific to the first terminal. Thus, during USIM cloning, a user whose USIM has been cloned not only becomes a victim of identity spoofing, but also loses network services on their terminal. Furthermore, they are unaware that their first terminal's registration is no longer valid and therefore incommunicable until they attempt to use their terminal.
[0009] Furthermore, obvious needs for future communication network architectures include the ability for terminals to simultaneously register with the communication network multiple times, particularly using resources of different access networks, including, for example, other operators.
[0010] These new requirements cannot be met by the current operation of the cellular networks mentioned above, as they involve multiple simultaneous registrations with the same permanent identifier (eg, SUPI identifier). Summary of the Invention [Problem to be solved by the invention]
[0011] The present invention aims to provide improvements over the prior art. [Means for solving the problem]
[0012] The present invention relates to a method for registering a terminal in a communication network, the method being executed at a management entity after receiving a registration request message requesting registration of a terminal in said network, the management entity containing at least one previous registration of said terminal in said communication network, said method comprising: - determining a number of active registrations from among the at least one past registration based on at least one response message received in response to the at least one transmitted solicitation message, the response message including at least one data associated with the at least one past registration; - updating at least one registration based on the received registration request message if the determined number of active registrations is less than a maximum number of registrations for the terminal; The aim is to improve this situation by methods including:
[0013] This registration method advantageously ensures that previous registrations of a terminal to the communication network are still valid and further allows multiple simultaneous registrations of the same terminal. The management entity maintains data on the terminal's previous registrations, which may be, for example, the terminal's identifier, the identifier and / or address of the access network device that interacted with the management device in the previous registration. Thus, when the management entity receives a message related to a new registration request, it can check whether the previous registration is still valid, i.e., whether the terminal maintains a connection to the communication network according to the data from the previous registration. This check is advantageously performed, for example, by sending a message to the access device that sent the previous registration request. If a response message, such as an acknowledgment message, is received in response to this request message, the management entity can infer from this that the registration in question is still valid and should be retained as an active, and therefore current, registration of the terminal. This check prior to accepting or rejecting a connection request by updating the registration data related to the terminal makes it possible, in particular, not to reject a new registration when the number of registrations of the terminal appears to have reached the maximum number of acceptable registrations for the terminal. In practice, the management entity registers the maximum number of simultaneous registrations allowed for a terminal and therefore rejects a new registration request if the terminal has already been registered the permitted number of times. However, the step of determining active registrations has the advantage that only active registrations, i.e. registrations that are still valid, are taken into account. Registrations whose data is kept in the management entity but which should not be kept because the terminal is powered off or is no longer connected to the access network that registered for the registration in question, are not taken into account. This registration method makes it possible to allow multiple connections of a terminal, possibly via separate access networks, while at the same time coordinating the allocation of resources allocated to the multiple registrations.Indeed, on the one hand there is a limit to the number of simultaneous connections per terminal, and on the other hand a check that the registration data kept by the management entity is still valid, which allows resources to be released in the access network and in the management entity if the registration is no longer valid, thus making it possible to preserve resources in the communication network.
[0014] According to one aspect of the invention, the registration method further comprises a step of checking that the received registration request message was sent by a terminal corresponding to a terminal for which the management entity includes at least one previous registration.
[0015] A new registration request may be sent by a terminal that has spoofed the identity of another terminal. While according to the prior art the receipt of a new registration message has the effect that the first registration is no longer valid, the registration method according to the invention may advantageously include a check that the received registration request is in fact sent by the same terminal and implements techniques to detect possible identity spoofing and in that case not add the new registration or to isolate a terminal that may have spoofed the identity of a terminal whose data the management entity has from a previous registration.
[0016] According to another aspect of the invention, in the registration method, the check includes comparing a temporary identifier of the terminal received in the registration request message with an identifier contained in at least one previous registration.
[0017] A check that the registration request message is actually sent by the same terminal as the terminal corresponding to the data associated with the previous registration may be performed by comparing identifiers. Thus, a terminal already registered in the communication network receives a GUTI or 5G-GUTI from the management entity when registering for the first time. If the same identifier (e.g., GUTI) is sent by the terminal in the registration request message, the management entity can infer from this that the terminal sending the registration request message is indeed the terminal that the management entity identified for the previous registration. Thus, the sending of such an identifier specific to the previous registration by the terminal makes it possible to enhance the security of the method and therefore of the communication network.
[0018] According to another aspect of the present invention, in the registration method, the received registration request message further includes a maximum number of registrations of the terminal to the communication network.
[0019] The terminal may advantageously include in its registration request message the maximum number of registrations of the terminal to the communications network. This information can be used to allow or not allow new registrations, and thus limit the number of simultaneous registrations for the terminal, in particular depending on the number of previous registrations already stored by the management entity. This information on the number of registrations also makes it possible to avoid unnecessary tests and checks, in particular in certain cases where the terminal does not request multiple registrations.
[0020] According to another aspect of the present invention, in the registration method, at least one previous registration is updated only if the determined number of registrations to be added is less than or equal to the number of registrations received in the registration request message.
[0021] If the terminal sends in the registration request message the number of registrations to the communication network for the terminal, the management entity may advantageously use this number to allow or disallow this registration and, if allowed, update the data associated with the registration. Thus, if the number of active registrations via the access network already reaches the number of registrations indicated in the registration request message, the management entity may not accept this new registration request and therefore not update the registration data as this new registration is not allowed. Thus, this embodiment prompts the terminal with the sent registration message to cancel one of the active registrations if it wishes to register via the same or another access network.
[0022] According to another aspect of the present invention, in a registration method, if the maximum number of registrations in the registration request message is equal to the number of registrations included in the at least one previous registration, the at least one previous registration is updated.
[0023] Information about the maximum number of registrations present in a registration request message can be used by the management entity to ensure that the same terminal that sent the successive registration requests is actually involved. Thus, by storing the maximum number of registrations present in various successive registration request messages sent by a terminal in the data associated with each registration, the management entity can detect whether the same terminal is involved as the terminal that sent a new registration request. Indeed, if the numbers present in the various registration request messages are not always the same, the management entity can infer from this that the same terminal that sent the various registration messages is not involved.
[0024] According to another aspect of the present invention, in a registration method, at least one previous registration is updated only if an identifier of an access network received in a registration message differs from an identifier of an access network included in at least one previous registration.
[0025] The management entity can advantageously store the access network identifiers (e.g. VPLMN network identifiers) with which the terminal has previously registered. The entity can then use this stored information to allow a new registration of a terminal only if the terminal has not yet registered via this access network. According to another embodiment, the management entity can allow a number of registrations to an access network that is greater than one, but within a configurable limit (e.g. 2 or 3). This information about the identifiers of the access networks can be used in combination with the maximum number of simultaneous registrations to enhance the registration method.
[0026] According to another aspect of the invention, the registration method further comprises the step of registering the terminal in a slice of the communication network to which the slice is associated with the terminal that cannot be registered again; and / or - if the determined number of registrations to be added exceeds the maximum number of registrations permitted for said terminal, and / or - if the number of access networks that the terminal wishes to connect to the communications network contained in the registration request message is not identical to the number of access networks contained in a registration message previously sent by the terminal, and / or - if the determined number of registrations to be added is greater than the number of access networks to which the terminal wishes to connect; a. disabling messaging services for the terminal.
[0027] In order to add a new terminal registration to the management entity, several criteria must be met, which may be mandatory or optional depending on the implemented embodiment, and this addition action corresponds to updating at least one data item associated with at least one previous registration. One or more of these criteria may not be met. For example, the terminal may not be identified as the same terminal for which a registration already exists in the management entity, and / or the number of active registrations has already reached the number of registrations allowed by the management entity or the number of access networks present for a new connection request. If one or more of these criteria are not met, the management entity may not add this new registration and / or may register it by assigning it to a network slice associated with or specific to a terminal that cannot register or re-register for normal services, not allowing access to certain services, and / or making this terminal locatable. This makes it possible, for example, to redirect this new registration to customer service and, for example, to detect if this new registration is from a valid terminal or a terminal authorized to access the communication network, and if the previously registered terminal did not have valid registration, for example, because it used a valid terminal identifier.
[0028] The various aspects of the registration method just described can be implemented independently of one another or in combination with one another.
[0029] The invention also relates to a method for connecting a terminal to a communications network, executed in said terminal capable of communicating with a management entity of said communications network, said management entity containing at least one previous registration of said terminal in said communications network, said method comprising the steps of: - sending a registration request message to a management entity requesting registration in a communications network; - receiving at least one request message from a management entity, the request message including data related to at least one previous registration of the terminal in the communication network; - sending at least one acknowledgement message to the management entity in response to at least one received request message; The present invention relates to a method, comprising:
[0030] According to one aspect of the invention, the registration request message includes a maximum number of registrations of the terminal to the communication network.
[0031] The invention also provides a device for registering a terminal in a communications network, implemented in a management entity containing at least one previous registration of the terminal in the communications network after receiving a registration request message requesting registration of the terminal in said communications network, said device comprising: - a transmitter capable of transmitting at least one solicitation message including at least one data associated with at least one previous registration; a receiver capable of receiving at least one response message in response to at least one transmitted request message; - a determination module capable of determining the number of active registrations from among at least one past registration based on at least one received response message; - a module for updating at least one previous registration based on the received registration request message if the determined number of active registrations is less than a maximum number of registrations for the terminal; The present invention relates to a device comprising:
[0032] This device, in all its embodiments, is capable of implementing the registration method just described.
[0033] The invention also relates to a connection device adapted to connect a terminal to a communications network, the connection device being implemented in a terminal or an access entity capable of communicating with a management entity of the communications network, the management entity comprising at least one previous registration of said terminal with said communications network, the connection device comprising: a transmitter, - sending to a management entity a registration request message requesting registration of the terminal in the communications network; - sending at least one response message to at least one received solicitation message to the management entity; a transmitter capable of a receiver capable of receiving at least one request message from a management entity, the request message including at least one data associated with at least one previous registration of the terminal in the communication network; The present invention relates to a connection device comprising:
[0034] According to one aspect of the invention, in the connection device, the registration message sent by the transmitter includes a maximum number of registrations of the terminal to the communication network.
[0035] This connection device, in all its embodiments, is capable of implementing the connection method described above.
[0036] The invention also relates to a system for registering a terminal in a communication network, comprising a management entity comprising a registration device, a terminal and an access entity, wherein the terminal and / or the access comprises a connection device.
[0037] The present invention also relates to a computer program comprising instructions for carrying out the steps of the respective registration and connection methods just described when both of these programs are executed by a processor, and to a recording medium on which the computer program is recorded, which can be read by the registration device and the connection device, respectively.
[0038] The program may use any programming language and may be in the form of source code, object code, or an intermediate code between source code and object code, for example in a partially compiled form, or in any other desired form.
[0039] The above-mentioned information medium may be any entity or device capable of storing a program. For example, the medium may include a storage means such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means.
[0040] Such storage means may be, for example, a hard disk or a flash memory.
[0041] Furthermore, the information medium may be a transmissible medium such as an electrical or optical signal, which may be routed by wireless or other means via electrical or optical cable. The program according to the invention may in particular be downloadable from a network such as the Internet.
[0042] Alternatively, the information carrier may be an integrated circuit in which the program is embedded, the circuit being designed to perform or be used to perform the method in question.
[0043] Other characteristics and advantages of the invention will become more apparent on reading the following description of particular embodiments, given solely as illustrative and non-limiting examples, and on examining the accompanying drawings, in which: [Brief explanation of the drawings]
[0044] [Figure 1] 1 is a simplified diagram of a communication network according to an aspect of the present invention; [Figure 2] 1 is a simplified diagram of a communication network in which a registration method according to an aspect of the present invention is implemented; [Figure 3] 1 shows an overview of a method for registering a terminal and a method for connecting a terminal according to an embodiment of the present invention; [Figure 4] 1 illustrates a device for registering a terminal in a communication network according to an embodiment of the present invention; [Figure 5] 1 shows a device for connecting a terminal to a communication network according to one embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION
[0045] The remainder of this document presents embodiments of the present invention in a communications network. The network may be implemented to route communications data to fixed or mobile terminals, and may be implemented using physical equipment and / or virtualized capabilities. The network may also be used to route and / or process residential or business customer data.
[0046] Reference is first made to Figure 2, which shows a simplified diagram of a communications network in which the registration and connection methods according to one aspect of the present invention may be implemented.
[0047] The network Res in Figure 2 has the same structure as the network Res in Figure 1 described above. Furthermore, in Figure 2, the parent network Res4 includes a UDM entity. This entity, which may be a physical device or a virtualization function, contains, among other things, subscriber profiles and access rights for the network, particularly for the subscriber using terminal 1a. This UDM entity may alternatively be an HLR or HSS entity. Figure 1 also includes access entities in each visited network Res1, Res2, and Res3, which handle mobility events and access requests sent by terminal 1a to network Res4 via the respective networks Res1, Res2, and Res3. These access entities, denoted AMF1, AMF2, and AMF3 for the respective networks Res1, Res2, and Res3, interact with, among other things, the UDM entity to retrieve the user profile of terminal 1a. Furthermore, the AMF access entity may be an MME (Mobility Management Entity) device or any device of an access network that can receive a registration request for registering a terminal and send it to a management entity, such as a UDM entity, directly or via another entity and / or another network. When a terminal 1a connects to a visited network Res1 by sending a registration request to the entity AMF1, this entity AMF1 sends the registration request to the UDM entity, possibly via another entity in network Res1 and / or network Res4, such as an AUSF entity. Upon receiving this registration request for registering the terminal 1a, the UDM entity first determines what registrations it already has in its memory for this same terminal 1a. For this determination, the UDM entity uses, for example, the USIM identifier sent by the terminal 1a via the entity AMF1 in the registration request. If the UDM entity identifies a registration that may still be valid for the terminal 1a, it sends a request message, for example, to an AMF entity to which the terminal previously registered.According to one example, if terminal 1a has previously registered with network Res2 via entity AMF2, the UDM entity sends a request message to entity AMF2, which UDM entity of entity AMF2 stores an address, or more generally, an identifier, in its memory. If entity AMF2 returns an acknowledgement message to the UDM entity, said UDM entity considers this registration active. According to this alternative, entity AMF2, by implementing a connection device, interacts directly with the UDM entity to send a registration request for registering terminal 1a and to respond to request messages received from the UDM entity. According to another example, entity AMF2 can request terminal 1 to determine whether the registration is active, i.e., whether the terminal is connected. In this case, the terminal interacts with the UDM entity via entity AMF2 using its connection device. According to another example, both terminal 1a and entity AMF2 comprise a device for connecting terminal 1a to communication network Res. The UDM entity performs this request action for each registration stored by the UDM entity for terminal 1a. From the received acknowledgment message, the UDM entity can determine the number of active registrations for terminal 1a when it receives a new registration request for terminal 1a. If the number of active registrations has already reached the maximum number allowed, the UDM entity rejects this new registration request to register terminal 1a, limiting the number of simultaneous registrations for the same terminal and thus the use of resources required to maintain these registrations. If this maximum number has not been reached, the UDM entity accepts this new registration and updates the number of registrations associated with terminal 1a, provided that other conditions for accepting this new registration (such as authentication and access rights) are met.
[0048] According to one alternative, the UDM entity can advantageously check that a registration request message received from a terminal via the entity AMF1 of the network Res1 is indeed sent by terminal 1a by checking the identity of terminal 1a. For example, the UDM entity can compare the identifier of terminal 1a received in the registration request with the identifier of terminal 1a contained in previous registrations.
[0049] If the UDM entity does not receive a response to the sent request message, i.e. an acknowledgement message in response to the sent request message, it may advantageously delete the registration corresponding to the sent request message, keep only active registrations among the past registrations, and allow a new registration, for example for terminal 1a, if the number of active registrations including the current registration is less than or equal to a maximum value.
[0050] The registration request may advantageously include the identifier of the entity AMF1 that sent the registration request to register terminal 1a, e.g. the UDM entity may store this information from previous registrations and use it to send a solicitation message if necessary when a new registration request is received for terminal 1a.
[0051] The access entity AMF1 that sends a registration request for registering the terminal 1a can also be used to identify the access network Res1 to which the registration request is sent. The UDM entity can use this information about the access network Res1 to allow a new registration of the terminal 1a only if a previous registration of the terminal 1a in the communication network was not performed via network Res1. The UDM entity can therefore limit the number of registrations of the terminal 1a, but can also allow only some registrations of the terminal 1a in the same access network, or prohibit multiple registrations of the terminal 1a in the same access network. Thus, according to this alternative, the UDM entity may not register the terminal 1a if a previous registration of the terminal 1a has already been performed via network Res1.
[0052] Reference is first made to Figure 3, which provides an overview of a method for registering and connecting terminals according to one embodiment of the present invention.
[0053] The various entities shown in [Figure 2] are also present in [Figure 3] with the same reference numerals.
[0054] In step 100, the terminal 1a, which may without distinction be a smartphone, an interconnection device, for example a box, a local area network to an operator network, an IoT (Internet of Things) device, a tablet, sends a registration message to the access device AMF1 of the access network Res1. The access network Res1 may be an access network of a visited network, for example a VPLMN network, or a mobile network, which offers for example several access networks which differ depending on the technology used (2G, 3G, 4G, 5G, Wi-Fi, xDSL, etc.) or depending on the type of customer or service of the terminal 1a.
[0055] This registration message sent by the terminal 1a can be sent to the entity AMF1 via a device of the network Res1, for example a radio node, and is, according to one example, a registration request message. According to one alternative, the registration message sent in step 100 via the entity AMF1 further includes a maximum number of registrations of the terminal 1a in the communication network. This maximum number can be configured in the terminal 1a, and according to one example, can be configured by the operator to which the terminal subscribes in order to connect to, and thus register in, a communication network such as the network Res4 shown in FIG. 2. According to one example, the registration message further includes a maximum number of access networks with which the terminal can register in the communication network. Thus, the registration message can include information on the maximum number of registrations allowed for the terminal 1a and / or on the number of different access networks with which the terminal can register in a communication network interconnected with various access networks. This information, optionally present in the registration message, can be used by the UDM management entity responsible for the registration of the terminal 1a to detect that the terminal that sent this registration request is not a terminal for which the UDM management entity maintains previous registration data. This may be the case if the terminal 1a does not transmit the same information regarding the maximum number of registrations and / or the number of different access networks allowed in successive registrations. The information regarding the number of registrations and / or the information regarding the number of access networks may advantageously be configured in the UICC card (or SIM card) of the terminal, more particularly in the USIM module of the UICC card. When it is indicated below that the terminal sends or receives messages, it should be understood that it may be the UICC card of the terminal that exchanges messages with other entities (AMF, UDM, etc.). According to one alternative, the terminal 1a transmits in its registration message a temporary identifier, such as a GUTI or 5G-GUTI identifier, obtained in a previous registration, for example in the last of the previous registrations, or obtained in another procedure related to the NAS (Non Access Stratum) protocol.
[0056] In step 101, the entity AMF1 sends a registration message to the UDM management entity, possibly including various optional information in the message received in step 100. Step 101 typically follows a step of authenticating the terminal 1a with the access network, which authentication step is not shown in FIG. 3. Alternatively, the UDM management entity may be an HLR or HSS entity, or any other entity capable of storing registration data related to a terminal. According to one example, the registration message sent in step 101 is a Nudm_UECM_registration message. According to one example, upon receiving the registration message for registering the terminal 1a in step 100, the entity AMF1 allocates a temporary identifier to the terminal 1a in a step not shown in FIG. 3. This temporary identifier may be, for example, a GUTI or 5G-GUTI identifier. The entity AMF1 sends the temporary identifier to the UDM management entity in step 101, either in the same message as the registration message or in a different message. In one alternative, if entity AMF1 has the capability to match the temporary identifier received from terminal 1a in step 100 with temporary identifiers allocated by itself or by other access entities AMF2 and / or AMF3, it may not transmit the temporary identifier received from terminal 1a to the UDM entity but may check the identity of terminal 1a by comparing the temporary identifiers.
[0057] Upon receiving the registration message, the UDM entity identifies the terminal 1a from which the registration request was sent. For this purpose, for example, as an alternative or in addition to using the temporary identifier described above, the UDM entity uses the IMSI information or the SUPI information sent by the AMF1 entity. According to one example, the AMF1 entity obtains the SUPI information related to the terminal 1a from the 5G-GUTI information sent by the terminal 1a, i.e. from the SUCI identifier sent by the terminal 1a, the SUPI identifier being obtainable by the AMF1 entity by requesting another entity, such as an AUSF entity or another AMF. For example, if this is an AMF different from the AMF1 entity, when the terminal 1a identifies itself to this AMF with the 5G-GUTI identifier, the AMF obtains the identifier of the AMF1 entity with the 5G-GUTI identifier and then queries the AMF1 entity to obtain context information including the SUPI identifier from the 5G-GUTI identifier. Based on the identifier of terminal 1a, the UDM entity determines in step 102 whether it already stores a registration for this same terminal, for example by consulting a database local to the UDM entity or external to the UDM entity. If no registration is stored and all other conditions for allowing registration of terminal 1a in the communication network for which the UDM entity manages registrations (such as access rights and valid authentication keys) are met, the UDM entity authorizes the registration of terminal 1a and notifies entity AMF1, which retransmits this acceptance to terminal 1a in a step not shown in Figure 3. If the UDM entity stores registrations for terminal 1a, it determines whether these registrations are still active or indeed valid, i.e., whether the terminal is still connected to the access network for which the registration request was received. In this example, it is considered that the UDM entity maintains two previous registrations for terminal 1a, which were established by entities AMF2 and AMF3 corresponding to access networks Res2 and Res3 shown in Figure 2, respectively.The UDM entity therefore stores the successive registrations of terminal 1a and, for each registration, stores the identifiers of the access networks (Res2, Res3) and / or the identifiers of the entities of the access networks (AMF2, AMF3) so that it can determine whether the stored registrations are still active. The UDM entity can also store temporary identifiers sent by the AMFs (AMF2 and AMF3) that previously sent registration requests to register terminal 1a. The UDM entity can therefore use the temporary identifier sent by terminal 1a and compare it with the stored temporary identifiers, if the temporary identifier is actually sent by terminal 1a. If the temporary identifier sent by the terminal does not correspond to any of the stored temporary identifiers, the UDM entity can infer from this that the terminal sending the registration request is spoofing the identity of terminal 1a and that the registration should not be accepted.
[0058] According to one alternative, the UDM entity may compare the maximum number of registrations received in a registration message via entity AMF1 with the value received in previous registration messages to identify problems with the identity of the terminal and suggest that if these values are different, the same terminal is not involved.
[0059] If the entity AMF1 is able to analyze the temporary identifier sent by terminal 1a, because terminal 1a has previously registered via this same access entity AMF1, or because the entity AMF1 recognizes a temporary identifier sent by another access entity AMF2 and / or AMF3, AMF1 itself can check the identity of terminal 1a. If the identity is valid, the entity AMF1 can therefore decide to send a registration request to the UDM entity. The UDM entity or possibly the entity AMF1 can therefore check the identity of terminal 1a based on the temporary identifier, such as the GUTI or 5G-GUTI identifier, and / or based on a fixed identifier, such as the IMSI or SUPI identifier. If one and / or the other of the identifiers cannot identify the terminal that sent the registration request as terminal 1a, the terminal in question, which may be spoofing the identity of terminal 1a, may be assigned to a network slice reserved for unrecognized terminals and / or the messaging service (SMS) may be disabled for this terminal, making it possible to locate and track this terminal, block the service, or redirect it to an information page. This is done, for example, by inviting the user of the terminal in question to contact the customer service of the operator of the communications network if it turns out that the first terminal that registered via the entities AMF2 and / or AMF3 is not terminal 1a and therefore did not have the legitimacy to register in the previous registration. An optional check can be performed on the identity of terminal 1a, and if this identity is verified, the UDM entity performs the following steps:
[0060] In step 103, the UDM entity sends a request message to the access entities AMF2 and AMF3, respectively. This request message contains the identifiers of the access entities under consideration, i.e., AMF2 and AMF3, and the identifier of the terminal 1a for which the UDM entity requests the entities AMF2 and AMF3. According to one example, the request message corresponds to a NAMF_Communication_N1N2MessageTransfer message.
[0061] According to this example, of the two previous registrations stored by the UDM entity, one previous registration is active, which is considered to be the registration performed via the access entity AMF2.
[0062] In step 103a, entity AMF2 attempts to solicit terminal 1a in order to determine whether the registration of terminal 1a can be considered active. If, according to step 103b, a response is sent by terminal 1a to entity AMF2, the registration of terminal 1a is considered to be active. It should be noted that if terminal 1a is no longer able to receive data sent by entity AMF2, it is said to be inactive with respect to entity AMF2 and therefore cannot respond to solicit messages sent by entity AMF2. Conversely, if the registration is active, the terminal is either in "connected" mode or in "standby" mode and in both cases is reachable from the network and therefore able to respond to solicit messages sent by entity AMF2.
[0063] The entity AMF2, which receives a response from the terminal 1a in step 103b, responds to the request message received in step 103 with an acknowledgement message or a message indicating that the request was successful, which is sent to the UDM entity in step 104b.
[0064] Terminal 1a no longer has an active registration via the access entity AMF3, which entity requested terminal 1a in step 103a, for example, possibly by sending several messages if no response is received from terminal 1a. The entity AMF3 responds to the received request message in step 103 by not responding to the request message received or by indicating to the UDM entity in step 104a that the request has failed, which causes the UDM entity to consider the registration of terminal 1a via the access entity AMF3 as inactive. According to one alternative, the UDM entity can send several request messages to the entity AMF3 in step 103 in the absence of a response, and in particular checks that the lack of receipt of an acknowledgement message is not due to a network problem or some other problem that temporarily prevents the entity AMF3 from receiving the request message. According to another alternative, the entity AMF3 may respond to the received request message by the absence of an acknowledgement message, thereby indicating to the UDM entity that the request message has been correctly received and that the registration of the terminal 1a via the entity AMF3 is not active. According to another example, the entity AMF3 does not request the terminal 1a to determine whether the registration is active. Indeed, the entity AMF3 may keep information about the fact that the terminal 1a is no longer registered; in this case, the entity AMF3 responds to the request message received from the UDM entity in step 103 in step 104a without requesting the terminal 1a. Message 103a is therefore optional. According to this example, the entity AMF3 comprises a device for connecting the terminal 1a and enables it to send registration request messages received from the terminal 1a to the UDM entity, to receive request messages received from the UDM entity and to respond to these request messages.
[0065] Depending on the messages received in steps 104a and 104b and the maximum number of allowed registrations for terminal 1a, the UDM entity registers or does not register the terminal via entity AMF1. According to this example, if the maximum number of registrations for terminal 1a is 2, the UDM entity registers terminal 1a in step 105, while sending an agreement response message to terminal 1a via entity AMF1 in step 106, which entity AMF1 resends this agreement message to terminal 1a in step 107. When terminal 1a receives the message in step 107, terminal 1a is registered and connected to the communication network via access network Res1 in addition to being registered via entity AMF2.
[0066] Furthermore, in step 105, the UDM entity adds a registration via entity AMF1 from among the previous registrations of terminal 1a, possibly by storing various fixed and / or temporary identifiers of terminal 1a and access entity AMF1 as described above. According to one example, the UDM entity can also update the previous registration by deleting the registration of terminal 1a via entity AMF3, since the registration of terminal 1a is determined to be inactive after no acknowledgement message has been received or after the absence of an acknowledgement message has been received. The determination of the number of active registrations by sending one or more request messages to terminal 1a (in particular, if the first message is not received by terminal 1a due to temporary coverage or connectivity problems) can be used by the UDM entity to update the data associated with the previous registrations of the management entity. Indeed, for example, if no acknowledgement message has been received within a period that can be configured in the UDM entity, or if a message indicating that the registration is inactive or that terminal 1a's request has failed is received, the UDM entity can update the registration data by deleting the data associated with the registration corresponding to this lack of reception. This allows, on the one hand, the terminal 1a to possibly register again, and, on the other hand, allows the network to free up resources corresponding to registrations that are deemed inactive.
[0067] It should be noted that, according to one example, the UDM entity may not allow a registration if an active one of the previous registrations has been performed via entity AMF1 or via any AMF entity of the access network Res1 which includes entity AMF1. The information about network Res1 and / or entity AMF1 sent by entity AMF1 in the registration request may for example be used by the UDM entity to prohibit new registrations if the terminal is already registered in this same access network. As an alternative, the UDM entity may allow a certain number of registrations via access entity AMF1 and / or access network Res1 which comprises entity AMF1.
[0068] If the registration request message received in step 101 includes a maximum number of registrations for terminal 1a, the UDM entity can also use this value to allow or disallow registrations. The UDM entity can use this value to determine the maximum number of registrations for terminal 1a, or it can use this value in addition to the maximum value managed by the UDM and / or the maximum number of registrations for a given access network. According to one example, the smaller of the two values represents the maximum value that must not be exceeded. Furthermore, the maximum number of registrations for a given access network can be used to allow or disallow new registrations.
[0069] According to one alternative, if one or more of the conditions indicated above are not met, instead of rejecting registration, the terminal 1a can be located in a particular network slice and / or messaging services (SMS) can be disabled for this terminal.
[0070] Reference is now made to Figure 4, which illustrates a registration device 200 according to one embodiment of the present invention.
[0071] Such a registration device may be implemented in a management entity such as the UDM entity shown in Figures 2 and 3, or an HLR or HSS entity, etc. This registration device may therefore be operated by an operator of a communications network through which communications data related to digital services are routed, and the management entity may be instantiated in physical equipment or in virtualized form.
[0072] For example, the registration device 200 comprises a processing unit 230, which comprises for example a microprocessor μP and is controlled by a computer program 210 stored in a memory 220 and which executes the registration method according to the invention. Upon initialization, the code instructions of the computer program 210 are loaded, for example, into a RAM memory before being executed by the processor of the processing unit 230. Such a registration device 200 may include: - a transmitter capable of transmitting at least one solicitation message Soll containing at least one data associated with at least one previous registration; a receiver 202, a registration request message Enr requesting registration of the terminal in said network, and - at least one reply message Rep for at least one sent request message a receiver 202 capable of receiving a determination module 203 capable of determining the number of active registrations from among at least one past registration based on at least one received acknowledgment message; a module 204 for updating at least one previous registration based on the received registration request message if the determined number of active registrations is less than a maximum number of registrations for the terminal; Equipped with.
[0073] Reference is now made to Figure 5, which illustrates a connection device 300 according to one embodiment of the present invention.
[0074] Such a connectivity device may be implemented in a terminal, such as a mobile terminal (smartphone, IoT device, tablet, airbox) or a fixed terminal (box), or in an access entity of the communication network, such as the AMF entity, in particular, as presented in [Figure 2] and [Figure 3], or in an equivalent equipment of the communication network (e.g. MME). This connectivity device may therefore be operated by an operator of the communication network or instantiated on a terminal by the operator or a client using the terminal. The connectivity device may be instantiated as a physical device or in virtualized form.
[0075] For example, the connection device 300 comprises a processing unit 330, which comprises for example a microprocessor μP and is controlled by a computer program 310 stored in a memory 320 and which executes the connection method according to the invention. During initialization, the code instructions of the computer program 310 are loaded, for example, into a RAM memory before being executed by the processor of the processing unit 330.
[0076] Such a connection device 300 may include: a transmitter, - sending a registration request message Enr to the management entity (UDM) requesting registration of the terminal (1a) in the communications network (Res), - sending at least one response message to at least one received solicitation message to the management entity; a transmitter capable of a receiver capable of receiving from a management entity at least one solicitation message Soll containing at least one data associated with at least one previous registration of the terminal in the communication network; Equipped with. [Explanation of symbols]
[0077] 100 steps 101 Steps 103 Request Message 104b Response Message 105 steps 106 steps 107 steps 200 registered devices 200 devices 201 Transmitter 202 Receiver 203 Decision Module 204 Modules 210 Computer Programs 220 memory 230 processing units 300 connected devices 301 Transmitter 302 Receiver 310 Computer Programs 320 memory 330 Processing Unit
Claims
1. 1. A method for registering a terminal (1 a) in a communications network (Res), the method being executed in a management entity (UDM) after reception (101) of a registration request message requesting registration of said terminal (1 a) in said communications network (Res), said management entity (UDM) maintaining at least one data associated with at least one previous registration of said terminal (1 a) in said communications network (Res), said method comprising: determining (102) a number of active registrations from among the at least one past registration based on at least one response message (104b) received in response to at least one transmitted request message (103), the response message including at least one data associated with the at least one past registration; updating (105) said at least one previous registration based on said received registration request message (101) if said determined number of active registrations is less than a maximum number of registrations for said terminal (1a); A method comprising:
2. 2. The method of claim 1, comprising checking that the received registration request message was sent by a terminal corresponding to a terminal for which the management entity includes the at least one previous registration.
3. 3. The method of claim 2, wherein the checking comprises comparing a temporary identifier of the terminal received in the registration request message with an identifier included in the at least one previous registration.
4. The method of claim 1 , wherein the received registration request message further includes a maximum number of registrations of the terminal to the communication network.
5. 5. The method of claim 4, wherein the at least one previous registration is updated only if the determined number of registrations to be added is less than or equal to the number of registrations received in the registration request message.
6. The method of claim 5 , wherein if the maximum number of registrations in the registration request message is equal to the number of registrations included in the at least one previous registration, the at least one previous registration is updated.
7. 2. The registration method according to claim 1, wherein said at least one previous registration is updated only if an identifier of an access network (Res1, AMF1) received in a registration message differs from an identifier of an access network (AMF2, AMF3, Res2, Res3) included in said at least one previous registration.
8. Registering the terminal (1a) in a slice of the communication network (Res) to which the terminal is not able to register again, and / or if the determined number of registrations to be added exceeds the maximum number of registrations allowed for the terminal; and / or If the number of access networks to which the terminal wishes to connect to the communications network, contained in the registration request message, is not the same as the number of access networks contained in a registration message previously sent by the terminal; and / or If the determined number of entries to be added is greater than the number of access networks to which the terminal wishes to connect.
2. The method of claim 1, further comprising disabling messaging services for the terminal.
9. A method for connecting a terminal to a communications network, executed in said terminal (1 a) capable of communicating with a management entity (UDM) of said communications network (Res), said management entity (UDM) maintaining at least one data associated with at least one previous registration of said terminal in said communications network, said method comprising the following operations executed by said terminal (1 a): The terminal (1a) sends (100) a registration request message to the management entity (UDM) via an access entity (AMF1, AMF2, AMF3) requesting registration of the terminal (1a) in the communication network; receiving (103) by the terminal (1 a) based on receipt by the access entities (AMF1, AMF2, AMF3) from the management entity (UDM) at least one request message sent from the management entity (UDM) via the access entities (AMF1, AMF2, AMF3), the at least one request message including data related to at least one previous registration of the terminal (1 a) to the communication network (Res); The terminal (1a) sends (103b, 104b) to the management entity (UDM) using (or via) the access entities (AMF1, AMF2, AMF3) at least one response message to the at least one received request message; A method comprising:
10. A method for connecting a terminal to a communications network, the method being performed by an access entity (AMF1, AMF2, AMF3) capable of communicating with a management entity (UDM) of said communications network (Res), said management entity (UDM) holding at least one data associated with at least one previous registration of said terminal in said communications network, said method comprising the following operations performed by said access entities (AMF1, AMF2, AMF3), namely: said access entities (AMF1, AMF2, AMF3) sending (101) to said management entity (UDM) a registration request message requesting registration of said terminal (1a) in said communication network (Res); said access entities (AMF1, AMF2, AMF3) receiving (103) from said management entity (UDM) at least one request message containing data related to at least one previous registration of said terminal (1 a) to said communication network (Res); The access entities (AMF1, AMF2, AMF3) send at least one response message to the management entity (UDM) for at least one received request message (104b); A method comprising:
11. 11. The connection method according to claim 9 or 10, wherein said registration request message comprises a maximum number of registrations of said terminal (1a) in said communication network (Res).
12. A device (200) for registering a terminal (1 a) in a communication network (Res), implemented in a management entity (UDM) that maintains at least one data associated with at least one previous registration of said terminal (1 a) in said communication network (Res), said device (200) comprising: a transmitter (201) capable of transmitting at least one solicitation message Soll containing at least one data associated with said at least one previous registration; A receiver (202), a registration request message Enr requesting registration of the terminal in the communications network, and At least one reply message Rep is sent in response to at least one transmitted request message. a receiver (202) capable of receiving a determination module (203) capable of determining the number of active registrations from among the at least one past registration based on at least one received response message; a module (204) for updating the at least one previous registration based on the received registration request message if the determined number of active registrations is less than a maximum number of registrations for the terminal; A device (200) comprising:
13. A connection device (300) adapted to connect a terminal (1 a) to a communications network (Res), the connection device (300) being implemented in an access entity (AMF1, AMF2, AMF3) capable of communicating with a management entity (UDM) of said communications network (Res), said management entity (UDM) holding at least one data associated with at least one previous registration of said terminal (1 a) to said communications network (Res), said connection device (300) comprising: A transmitter (301), sending a registration request message Enr to said management entity (UDM) requesting registration of said terminal (1a) in said communications network (Res); and sending at least one response message (Rep) to the management entity in response to at least one received request message. a transmitter (301) capable of transmitting a signal; a receiver (302) capable of receiving from said management entity (UDM) at least one solicitation message Soll containing at least one data associated with at least one previous registration of said terminal (1a) in said communication network (Res); A connection device (300) comprising:
14. The connection device (300) of claim 13, wherein the registration message sent by the transmitter includes a maximum number of registrations of the terminal to the communication network.
15. A system for registering a terminal (1 a) in a communications network (Res), comprising: A management entity (UDM) comprising a registration device (200) according to claim 12; A terminal (1a) and access entities (AMF1, AMF2, AMF3), wherein the terminal (1a) and / or the access entity (AMF1, AMF2, AMF3) comprises a connection device (300) according to claim 13 or 14, system.
16. A program comprising instructions for carrying out the registration method according to any one of claims 1 to 8 when executed by a processor.
17. A recording medium that can be read by the registration device of claim 12 and that stores the program of claim 16.
Citation Information
Patent Citations
Registration and security enhancements for WTRUs with multiple USIMs
JP2022544374A
Controlling registration in a communication system
US20050124341A1
Detection And Blocking Of Cloned Mobile Devices
US20160150413A1
Method and Apparatus for Managing Dual Registration with Multiple Networks in One or More Radio Communication Systems
US20190098596A1
Registration and security enhancements for a WTRU with multiple usims
WO2021034593A1