Method and apparatus for generating charging data in a wireless communication network
An identity validation entity validates identities in wireless communication systems, ensuring valid identities are included in charging data, thereby improving analysis and preventing erroneous charging.
Patent Information
- Application Number
- PCT/EP2025/058109
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-25
- Filing Date
- 2025-03-25
- Publication Date
- 2025-10-02
AI Technical Summary
Existing wireless communication systems lack a mechanism to ensure the validity of identities included in charging data records (CDRs), leading to the inclusion of anonymized or spoofed identities that hinder effective analysis and result in erroneous charging.
Implement an identity validation entity (IVE) to validate identities before inclusion in charging data, replacing invalid identities with placeholder data.
Reduces the presence of anonymized or spoofed identities in CDRs, enhancing the accuracy of analysis and preventing erroneous charging.
Smart Images

Figure EP2025058109_02102025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR GENERATING CHARGING DATA IN A WIRELESS COMMUNICATION NETWORKFIELD OF TECHNOLOGY
[0001] The present disclosure relates to generating charging data in a wireless communication system.BACKGROUND
[0002] The present disclosure relates to the generation of charging data for call detail records (CDRs) in a wireless communication system. CDRs are generated by mobile network operators when a subscriber initiates or receives a network event, such as, for example, a call, short message service (SMS) message, or mobile data. CDRs are generated for both for billing and record keeping purposes and are generated for both regular and emergency calls and sessions. CDRs typically include charging data associated the network event to be used for billing purposes. The charging data typically include one or more identities associated with the subscriber and / or the device associated with the network event.
[0003] Developments in the generation of charging data are desirable.SUMMARY
[0004] According to one aspect of an embodiment, the present disclosure provides a method performed by a validation entity, the method including receiving a request to validate an identity associated with charging data, determining whether the identity is valid or invalid, transmitting a response to the request, the response based on the determining, wherein the response includes the identity when the identity is valid, or the response includes a modified identity when the identity is invalid.
[0005] In an example, the modified identity comprises placeholder data.
[0006] In an example, all digits of the placeholder data are a same character.
[0007] In an example, the modified identity further comprises the identity that is separated from the placeholder data by at least one non-numeric character.
[0008] In an example, the identity comprises an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G-GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), or a user identifier.
[0009] In an example, determining whether the identity is valid or invalid includes determining that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the requested.
[0010] In an example, determining that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the requested comprises at least one of determining that a number of digits of the identity does not match to a number of digits indicated in the identity information associated with the identity expected to be associated with the request, wherein the identity includes an international mobile subscriber identity (IMSI) that includes a mobile country code (MCC), a mobile network code (MNC), and a mobile subscriber identification number (MSIN), performing at least one of determining that the MCC does not match one of one or more valid country codes, determining that the MNC does not match one of one or more valid network codes, or determining that the MSIN matches one of one or more invalid subscriber identities, or wherein the identity includes an international mobile equipment identity (IMEI) that includes a type allocation code (TAC) and a serial number (SNR), determining that the TAC does not match one of one or more valid type allocation codes, or determining that the SNR does not match one of one or more valid serial numbers, or both determining that the TAC does not match one of one or more valid type allocation codes and determining that the SNR does not match one of one or more valid serial numbers.
[0011] In an example, determining whether the identity is valid or invalid comprises performing pattern matching on at least a portion of the identity to determine whether the identity is valid or invalid.
[0012] In an example, performing pattern matching comprises determining the identity is invalid based on determining that the identity includes, at least one of a first number of consecutive digits that have the same value is equal to or greater than a first threshold number, a second number of consecutive digits that sequentially increase or decrease in value by same amount is equal to or greater than a second threshold number, or a third number digits that differ from corresponding digits of a previous identity is less than or equal to a third threshold number.
[0013] In an example, the validation entity also implements a charging function, receiving the request to validate the identity associated with charging data comprises receiving a request for charging data associated with the identity, the method further includes generating,based on the determining, charging data associated with the identity, wherein the charging data includes the identity when the identity is valid, the charging data includes the modified identity when the identity is invalid, and the response includes the charging data that was generated.
[0014] According to another aspect of an embodiment, the present disclosure provides an apparatus that includes at least one processor, at least one memory storing instructions for a validation entity, wherein when the instructions are executed by the at least one processor, cause the apparatus to receive a request to validate an identity associated with charging data, determine whether the identity is valid or invalid, transmit a response to the request, the response based on the determining, wherein the response includes the identity when the identity is valid, or the response includes a modified identity when the identity is invalid.
[0015] In an example, the modified identity comprises placeholder data.
[0016] In an example, all digits of the placeholder data are a same character.
[0017] In an example, the modified identity further comprises the identity that is separated from the placeholder data by at least one non-numeric character.
[0018] In an example, the identity comprises an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G-GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), or a user identifier.
[0019] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to determine whether the identity is valid or invalid include instructions that, when executed by the at least one processor, cause the apparatus to determine that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the request.
[0020] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to determine that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the request include instructions that, when executed by the at least one processor, cause the apparatus to perform at least one of determine that a number of digits of the identity does not match to a number of digits indicated in the identity information associated with the identity expected to be associated with the request, when the identityincludes an international mobile subscriber identity (IMSI) that includes a mobile country code (MCC), a mobile network code (MNC), and a mobile subscriber identification number (MSIN) determine that the MCC does not match one of one or more valid country codes, determine that the MNC does not match one of one or more valid network codes, or determine that the MSIN matches one of one or more invalid subscriber identities, or when the identity includes an international mobile equipment identity (IMEI) that includes a type allocation code (TAC) and a serial number (SNR), determine that the TAC does not match one of one or more valid type allocation codes, or determine that the SNR does not match one of one or more valid serial numbers, or both determine that the TAC does not match one of one or more valid type allocation codes and determine that the SNR does not match one of one or more valid serial numbers.
[0021] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to determine whether the identity is valid or invalid include instructions that, when executed by the at least one processor, cause the apparatus to perform pattern matching on at least a portion of the identity to determine whether the identity is valid or invalid.
[0022] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to perform pattern matching include instructions that, when executed by the at least one processor, cause the apparatus to determine the identity is invalid based on determining that the identity includes, at least one of a first number of consecutive digits that have the same value is equal to or greater than a first threshold number, a second number of consecutive digits that sequentially increase or decrease in value by same amount is equal to or greater than a second threshold number, or a third number digits that differ from corresponding digits of a previous identity is less than or equal to a third threshold number.
[0023] In an example, the instruction for the validation entity also comprise instructions for a charging function, the instructions that, when executed by the at least one processor, cause the apparatus to receive the request to validate the identity associated with charging data include instructions that, when executed by the at least one processor, cause the apparatus to receive a request for charging data associated with the identity, the instructions further include instructions that, when executed by the at least one processor, cause the apparatus to generate, based on the determining, charging data associated with the identity, wherein the charging data includes the identity when the identity is valid, the charging data includes the modified identity when the identity is invalid, and the response includes the charging datathat was generated.
[0024] According to another aspect of an embodiment, the present disclosure provides a computer-readable medium storing instructions of a validation entity, wherein when the instructions are executed by at least one processor of an apparatus, cause the apparatus to receive a request to validate an identity associated with charging data, determine whether the identity is valid or invalid, transmit a response to the request, the response based on the determining, wherein the response includes the identity when the identity is valid, or the response includes a modified identity when the identity is invalid.
[0025] In an example, the modified identity comprises placeholder data.
[0026] In an example, all digits of the placeholder data are a same character.
[0027] In an example, the modified identity further comprises the identity that is separated from the placeholder data by at least one non-numeric character.
[0028] In an example, the identity comprises an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G-GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), or a user identifier.
[0029] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to determine whether the identity is valid or invalid include instructions that, when executed by the at least one processor, cause the apparatus to determine that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the request.
[0030] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to determine that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the request include instructions that, when executed by the at least one processor, cause the apparatus to perform at least one of determine that a number of digits of the identity does not match to a number of digits indicated in the identity information associated with the identity expected to be associated with the request, when the identity includes an international mobile subscriber identity (IMSI) that includes a mobile country code (MCC), a mobile network code (MNC), and a mobile subscriber identification number (MSIN) determine that the MCC does not match one of one or more valid country codes,determine that the MNC does not match one of one or more valid network codes, or determine that the MSIN matches one of one or more invalid subscriber identities, or when the identity includes an international mobile equipment identity (IMEI) that includes a type allocation code (TAC) and a serial number (SNR), determine that the TAC does not match one of one or more valid type allocation codes, or determine that the SNR does not match one of one or more valid serial numbers, or both determine that the TAC does not match one of one or more valid type allocation codes and determine that the SNR does not match one of one or more valid serial numbers.
[0031] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to determine whether the identity is valid or invalid include instructions that, when executed by the at least one processor, cause the apparatus to perform pattern matching on at least a portion of the identity to determine whether the identity is valid or invalid.
[0032] In an example, the instructions that, when executed by the at least one processor, cause the apparatus to perform pattern matching include instructions that, when executed by the at least one processor, cause the apparatus to determine the identity is invalid based on determining that the identity includes, at least one of a first number of consecutive digits that have the same value is equal to or greater than a first threshold number, a second number of consecutive digits that sequentially increase or decrease in value by same amount is equal to or greater than a second threshold number, or a third number digits that differ from corresponding digits of a previous identity is less than or equal to a third threshold number.
[0033] In an example, the instruction for the validation entity also comprise instructions for a charging function, the instructions that, when executed by the at least one processor, cause the apparatus to receive the request to validate the identity associated with charging data include instructions that, when executed by the at least one processor, cause the apparatus to receive a request for charging data associated with the identity, the instructions further include instructions that, when executed by the at least one processor, cause the apparatus to generate, based on the determining, charging data associated with the identity, wherein the charging data includes the identity when the identity is valid, the charging data includes the modified identity when the identity is invalid, and the response includes the charging data that was generated.
[0034] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Embodiments of the present disclosure will now be described, by way of example only, with reference to the attached figures.
[0036] FIG. l is a schematic diagram showing a communication network in accordance with an aspect of an embodiment.
[0037] FIG. 2 is a flowchart showing a method in accordance with examples.
[0038] FIG. 3 is a flowchart showing a method in accordance with an example embodiment.
[0039] FIG. 4 and FIG. 5 are diagrams showing operations in a procedure in accordance with embodiments.
[0040] FIG. 6 is a schematic diagram showing components of one or more of the example embodiments.DETAILED DESCRIPTION
[0041] For simplicity and clarity of illustration, reference numerals may be repeated among the figures to indicate corresponding or analogous elements. Numerous details are set forth to provide an understanding of the examples described herein. The examples may be practiced without these details. In other instances, well-known methods, procedures, and components are not described in detail to avoid obscuring the examples described. The description is not to be considered as limited to the scope of the examples described herein.
[0042] The present disclosure relates to verifying the identities that are included in generated charging data in a wireless communication system such that, when an identifier is determined to be invalid, a modified identifier, such as placeholder data, is included in the charging data where the identifier would otherwise. Embodiments of the present disclosure may result in fewer anonymized or spoofed identities being included in the charging data, which may reduce the presence of anonymized or spoofed identifiers being included in call data records (CDRs).
[0043] Government agencies may request bulk CDRs to check for illegal telecom setups such as, for example, detecting numbers that belong to the grey market. Additionally, law enforcement agencies may request information by area or any other means during criminalinvestigations such as, for example, cases related to telecom fraud activities. For these purposes, telecom service providers maintain data lakes of raw CDRs.
[0044] The content and format of a CDR generated for 5G data connectivity - PDU session charging is set out in Section 6.1.3 of V18.0 3GPP TS 32.255. Table 6.1.3.2.1 ofV18.0 3GPP TS 32.255 includes the PDU Session charging CHF record data, referred to herein as “charging data”, the contents of a CDR. The PDU Session charging CHF record data is defined in Section 5.4 of V18.0 3GPP TS 32.240 to include a “Subscriber Identifier” field that contains the subscription permanent identifier (SUPI), i.e., the IMSI of the subscriber or the device, and in case of emergency sessions if SUPI is absent, then the permanent equipment identifier (PEI) of the device i.e., IMEI of the device, should be included.
[0045] For this reason, raw CDRs contain “subscriber identifiers”, which are referred to in the present disclosure as an “identity” or “identities”. Examples of identities that may be included in raw CDRs include an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G- GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), a cell identifier (cell ID), a mobile country code (MCC), a mobile network code (MNC), and a user identifier that is allocated to a user of a user equipment (UE) such as a username or an email address.
[0046] Anonymized or spoofed identities are identities that contain invalid identity data, often generated randomly, in order to mask the true identity of a subscriber or device that is utilized to access to a communication network. For example, when attackers launch distributed denial of service (DDoS) attacks on network systems, they may use anonymized or spoofed identities such as, for example, a series of randomly generated numbers in place of a valid identity. In these cases, the anonymized or spoofed identities are included in the charging data that is included CDRs that are generated in association with network events.
[0047] CDRs that contain invalid identity data in the form of an anonymized or spoofed identity may prevent or inhibit standard CDR analysis tools that look for subscriber identities from analyzing the CDRs in an effective or efficient manner. For example, CDRs that include erroneous or nonsensical caller ID may inhibit use of well-established CDR analysis techniques based on caller ID. Further, the presence of invalid and / or randomized identity data in an identity field of a CDR makes the task of CDR analysis more tedious because of the uncertainty regarding whether the identities present in the CDR are real (i.e., valid) oranonymized / spoofed (i.e., invalid). Additionally, the use of an anonymized or spoofed identity in a CDR may result in erroneous charging by the billing domain.
[0048] In the present disclosure, references to an invalid identity refer to data or values contained in an identity field, such as an identity field in a request for charging data as described below, that to do not correspond to valid identity data or values, and references to a valid identity refers to data or values contained in an identity field, such as an identity field in a request for charging data, that contains data or values that correspond to valid identity data or values.
[0049] Reference is first made to FIG. 1, which shows a schematic representation of a communication network 100 that a user equipment (UE) 102 has access to in order to communicate with application servers (AS) 103 hosting third party application functions (not shown) via data network 104. The communication network 100 comprises radio access network entities 106 (e.g., a NG-RAN) and a core network 108 (e.g., a 5G core network (5GC)) that operate based on the 5th generation radio access technology described in the 3rdGeneration Partnership Project (3 GPP) standard for new radio.
[0050] The radio access network (RAN) entities 106 comprise one or more radio access network (RAN) nodes (otherwise referred to as base stations), such as a gNodeB (gNB). A radio access network node comprises a central unit (e.g., gNB-CU) and one or more distributed units (e.g., one or more gNB-DUs) linked to the central unit (e.g., gNB-CU) by a Fl interface.
[0051] The core network 108 has a service-based architecture and comprises a plurality of network functions, including, inter alia, an access and mobility function (AMF) 112, a trusted application function (AF) 114, an authentication server function (AUSF) 116, a network exposure function (NEF) 118, a network repository function (NRF) 120, a network slicing selection function (NSSF) 122, a policy control function (PCF) 124, a session management function (SMF) 126, a user plane function (UPF) 128, and a united data repository (UDM) 130. Other network functions of the core network 108 are not illustrated but would be understood by a person skilled in the art. The functionalities of the network functions of the core network are known to a person skilled in the art and hence are not described in detail.
[0052] The network functions of the core network 108 also include a charging function (CHF) 110 that is responsible for the charging operations at the core network 108 and interfaces with a billing domain 112, such as a billing system or systems utilized for billing. The CHF 110 generates charging data that includes an identity associated with the UE 102 ora subscriber associated with the UE 102. The charging data generated by the CHF 110 is included in the CDRs that are associated with network events of the UE 102.
[0053] In addition to the conventional network functions referred to above, the example core network 108 also includes an identity validation entity (IVE) 134 that may be utilized to validate an identity, such as a subscriber identity prior to be included in charging data generated by the CHF 110. As described in more detail below, in the event that the IVE 134 determines that an identity is invalid, placeholder data is inserted into charging data in place of the identity.
[0054] Although the example core network 108 shown in FIG. 1 shows the CHF 110 and the IVE 134 as separate functions or entities, in other examples, the IVE 134, and the associated functionality of the IVE 134 disclosed herein, may be included in the CHF 110, or in any other network function of the core network 108.
[0055] The IVE 134, or the network function, such as the CHF 110, that incorporates the IVE 134, may be implemented by a combination of hardware processing circuit and software and / or firmware comprising machine-readable instructions that are executable by the hardware processing circuit, or software comprising machine-readable instructions that are executable by a hardware processing circuit of an apparatus. A hardware processing circuit includes at least one processor comprising machine-readable instructions that are executable by the hardware processing circuit and at least one memory storing the machine-readable instructions. A processor includes any or some combination of an accelerator, microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphic processing unit, a tensor processing unit. Memory includes any or some combination of volatile or non-volatile memory (e.g., a flash memory, cache, a random-access memory (RAM), and / or a read-only memory (ROM)). The memory stores the machine-executable instructions of the software and / or firmware for execution by the at least one processor of the hardware processing circuit. The machine-executable instructions are executable by the hardware processing circuit to perform the actions or operations of the methods of the IVE and / or the network function that incorporates the IVE, such as the CHF, described herein.
[0056] Each network function (NF) of the core network 108 provides one or more services to other network functions of the core network via Application Programming Interfaces (APIs). Each NF can also register itself and the services it supports (e.g., the services it offers other network functions) to the NRF 120 of the core network 108. The NRF 120 is used by anynetwork function to discover other network functions (or instances of NFs) and the services the other NFs support (e.g., services the other NFs provide). Any NF is operable to consume (e.g., use) the services provided and exposed by another NF. A NF that consumes a service of another network function is generally referred to as a network function service consumer. A network function that provides and exposes one or more of its services is referred to as a network function service producer.
[0057] Typically, the AMF of a core network, such as the AMF 112 of the example core network 108 described previously, will cause a CHF of the core network, such as CHF 110 of the example core network 108 described previously, to generate charging data for a session by sending a request to the CHF. The request sent by the AMF may be, for example, a Nchf ConvergedCharging request that is generated in accordance with Table 6.2.1-1 of VI 8.0 3GPP TS 32.290. The charging data request message sent to the CHF typically includes an identity in an identity field of the request. The identity may be, for example, a IMSI and / or a IMEI associated with the subscriber of the session. The identities may be included in Nchf ConvergedCharging request in accordance with Table 6.1.1.2.1 of VI 8.0 3GPP TS 32.256.
[0058] Although an AMF, such as the AMF 112 of the example core network 108 described previously, may be configured to authenticate and authorize a UE, utilizing the procedure set out in Section 10.2.1.3 of V18.0 3GPP TS 33.501, prior to the establishment of a PDU session, in some examples, a PDU session may be established without authenticating and authorizing the UE associated with the PDU session. For example, Section 10.2.2.2 of V18.0 3GPP TS 33.501 describes unauthenticated emergency PDU sessions in which network policy may be configured to allow an emergency PDU session even if authentication of the UE fails to ensure, for example, that valid emergency calls are not denied. Attackers may exploit this by using an invalid identity to make emergency calls when launching a DDoS attack on an emergency service network. In other examples, the AMF 112 may be configured to not authenticate and authorize an identity, even when establishing a non-emergency PDU session, to avoid delays in the establishing PDU sessions that result from the authentication process, which slows down the entire network. In such circumstances in which invalid identities may be used to establish PDU sessions, these invalid identities are included in the resulting CDRs.
[0059] Conventionally, there is no mechanism to ensure that the identity that is included in generated charging data is valid. Rather, the identity that is provided to the CHF with thecharging data request message is included in the generated charging data, which charging data is included in the CDR. In this way, invalid identities are included in generated CDRs, which leads to the issues described.
[0060] In embodiments of the present disclosure, an IVE, such as the IVE 134 of the example core network 108 described previously, may validate an identity that is associated with a charging data request received at a CHF, such as CHF 110 of the example core network 108 described previously, from an AMF, such as the AMF 112 of the example core network 108 described previously. The I'VE may be a separate network function, similar to the I'VE 134 of the example core network 108, or the functionality of the I'VE described herein may be incorporated into another network function such as, for example, a CHF, such as the CHF 110 of the example core network 108.
[0061] FIG. 2 is a flowchart showing a method or process in accordance with one example. The method or process is performed by an I'VE, such as the I'VE 134 or the CHF 110 of the example core network 108 described previously, or network function that incorporates the functionality of an I'VE, such as a CHF.
[0062] At 202, a request associated with an identity is received. In examples in which the I'VE that performs the identity validation is separate from the CHF, the request may be an identity validation request that is received at the I'VE from a CHF or other network function. For example, a CHF may send an identity validation request to the I'VE in response to receiving a charging data request from the AMF, e.g., a Nchf_ConvergedCharging request. The identity validation request may be, for example, a Nchf_ConvergedCharging_Identity Validation request, which may be as follows:
[0063] In other examples in which the functionality of the I'VE described herein is incorporated into a CHF, for example, then the request received at 202 may be the chargingdata request received from the AMF, e.g., a Nchf_ConvergedCharging request.
[0064] The request received at 202 includes an identity that is associated with the charging data that is to be generated. The identity may be a “subscriber identifier”, as described previously, that is associated with the subscriber and / or device, such as a UE 102 described previously. In some examples, the identity may be, for example, one or more of an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G-GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), a cell identifier (cell ID), a mobile country code (MCC), a mobile network code (MNC), and a user identifier that is allocated to a user of a user equipment (UE) such as a username or an email address.
[0065] At 204, a determination of whether the identity is valid or invalid is performed. The determination at 204 may be performed using any suitable method, and may include determining whether the data or values included in an identity field of the request received at 202 correspond to valid identity data or values.
[0066] For example, the determination at 204 may include comparing the data or values included in an identity field of the request to authorized and / or unauthorized identities. The authorized and unauthorized identities may be maintained by, and received at the IVE from, for example, a network service provider.
[0067] Alternatively or additionally, the determination at 204 may include determining whether the identity data or values included in an identity field of the request match identity information that identifies an entity expected to be associated with the request. For example, the determination may be a determination whether a format of the identity data or values included in an identity field of the request match an expected format that a valid identity is expected to have.
[0068] For example, the format and content of an IMSI is defined in Section 2.2 of VI 8.0 3GPP TS 23.003, and the format and content of a IMEI is defined in Section 6 of 3GPP VI 8.0 TS 23.003, which format and content may provide the identity information that identifies an identity expected to be associated with the request that the identity is compared to at 204.
[0069] In an example, the number of digits that the identity includes may be compared to an expected number of digits such as, for example, a number of digits that an IMSI is defined tohave when the identity is purportedly an IMSI or the number of digits that an IMEI is defined to have when the identity is purportedly an IMEI. If the number of digits of the identity does not match the expected number of digits, then the identity may be determined at 204 to be invalid.
[0070] Alternatively or additionally, if the identity purportedly includes an IMSI, which is defined to include a mobile country code (MCC), a mobile network code (MNC), and a mobile subscriber identification number (MSIN), the portion of the identity that corresponds to the MCC may be compared to a list of valid country codes, and if the portion of the identifier corresponding to the MCC does not match any of the valid country codes, the identifier may be determined at 204 to be invalid.
[0071] Alternatively or additionally, the portion of the identity that corresponds to the MNC may be compared to valid network codes, and if the portion of the identifier corresponding to the MNC does not match any of the valid network codes, the identifier may be determined at 204 to be invalid. Alternatively or additionally, the portion of the identity that corresponds to the MSIN may be compared to, for example, authorized subscriber identities and / or invalid subscriber identities, such as blacklisted or greylisted identities, that may be maintained and provided by, for example, a network service provider, a network operator, or another third party. If the identity matches one of the authorized subscriber identities then the identity may be determined to be valid at 204, and if the identity matches one of the blacklisted or greylisted identities then the identity may be determined to be invalid at 204.
[0072] Alternatively or additionally, if the identity purportedly includes an IMEI, which is defined to include a type allocation code (TAC) which indicates the device manufacturer and a serial number (SNR) of the device, the portion of the identity that corresponds to the TAC may be compared to valid type allocation codes, and if the portion of the identity that corresponds to the TAC does not match any of the valid type allocation codes then the identity may be determined to be invalid at 204. Alternatively or additionally, the portion of the identity that corresponds to the SNR may be compared to valid serial numbers, such as for example valid serial numbers corresponding to the type allocation value included in the portion of the identity corresponding to the TAC. If the portion of the identity corresponding to the SNR does not match any of the valid serial numbers then the identity may be determined invalid at 204.
[0073] In the above examples, the identity information that identifies an identity expected to be associated with the request, such as, for example, the expected number of digits, validcountry and network codes, authorized, blacklisted, and greylisted identities, valid typed allocation codes and valid serial numbers, may be received by the IVE, or the CHF that incorporates the functionality of the IVE, from an operational administration and management (0AM) node associated with the core network that includes the IVE or CHF.
[0074] Alternatively or additionally to utilizing the identity information that identifies an identity expected to be associated with the request, the determination at 204 may include performing pattern matching on at least a portion of the identity. Pattern matching may include any suitable method of determining whether any portion of the identity data or values included in the identity field includes patterns that would tend to indicate that the identity is invalid.
[0075] In one example, such pattern matching may include determining whether the identity includes at least a threshold number of digits having sequentially increasing or decreasing values, e.g., 012345679 or 987654321, and so in some examples. The pattern matching may determine whether the digits of the identity that sequentially increase or decrease by the same value, such as, by one (1), or two (2), or three (3), and so forth, is equal to or greater than a threshold number. The threshold number of digits may be, for example, a threshold number of consecutive digits. For example, if five (5) or more consecutive digits of the identity sequentially increase or decrease in value by the same amount, e.g., by one or two, then it may be determined that the identity is invalid at 204. Although, in the described example, the threshold number of digits is five (5) consecutive digits, in other examples any threshold number of digits, consecutive or not, that tends to indicate that an identity is invalid may be utilized.
[0076] Alternatively or additionally, the pattern matching may include determining whether the identity includes a number of digits that have the same value, e.g., 1111111111, or 2222222222 that is greater than or equal to a threshold number. The threshold number of digits may be, for example, a threshold number of consecutive digits. If the identity includes a threshold number of consecutive digits, for example five (5), that have the same value, the identity may be determined to be invalid at 204. Although, in the described example, the threshold number of digits is five (5) consecutive digits, in other examples any threshold number of digits, consecutive or not, that tends to indicate that an identity is invalid may be utilized.
[0077] Tools that used to generate invalid identities may increate only the last few digits from a previously used identity, e.g., 9876543210, 9876543211, 9876543212, and so forth.Therefore, alternatively or additionally the pattern matching may include determining a number of digits of at least a portion the identity that differ from corresponding digits of a different previous identity is equal to or less than a threshold number. The threshold number may be a threshold number of consecutive digits. The previous identities may be previous identities maintained by a network service provider, and may be provided to the IVE, or the CHF that incorporates the functionality of the IVE, from an 0AM node associated with the core network that includes the IVE, or the CHF. In an example, if five (5) or fewer digits of a portion of the identity, for example the MSIN of an IMSI or the SNR of an IMEI, differ from corresponding digits of a previous identity, then the identity may be determined to invalid at 204.
[0078] In some examples, if the identity cannot be determined to be invalid conclusively by, for example, not having the expected formatting, based on whether values or data of the identity match expected data, or based on pattern matching, then the identity may be presumed valid.
[0079] If the identity is determined to be valid at 204, i.e., “VALID” in FIG. 2, then the process moves to 206 and a response to the request is transmitted that includes the identity. In this case, because the identity is determined, or presumed, to be valid, then the identity is included in the response.
[0080] In examples in which the IVE is separate from the CHF, the response that includes the identity that is transmitted at 206 may be transmitted to the CHF in response to the request received from the CHF at 202. In an example in which the request received at 202 is a Nchf ConvergedCharging ldentity Validation request, the response may be a Nchf_ConvergedCharging_Identity Validation response.
[0081] In example in which the functionality of the IVE is performed by the CHF, the response transmitted at 206 may be a charging data response sent from the CHF to the AMF. For example, in response to a Nchf ConvergedCharging request from the AMF, the response transmitted at 206 may be a Nchf_ConvergedCharging response.
[0082] If the determination at 204 is that the identity is invalid, i.e., “INVALID” in FIG. 2, then the process moves to 208 and a response to the request is transmitted that includes a modified identifier. The modified identifier may be included in an identity field in the response. The modified identifier may include placeholder data, which is included in the identity field of the response where the identifier would otherwise be included. The placeholder data may be any set of data that indicates that the identity associated with theresponse is invalid. For example, the placeholder may be any set of predetermined data, or character(s), such as alphanumeric and / or non-alphanumeric characters. In one example, the placeholder data may be the same character repeated for all digits in the field for the identity. For example, the placeholder data may include all digits having the same number, e.g., 0000000000, or 1111111111, or 2222222222, and so forth. In one example, the placeholder data may have a predetermined sequence of characters for the digits in the field for the identity. For example, the placeholder data may include sequence of digits having the predetermined sequence, e.g., 0101010101, or 1212121212, or 12312321232, and so forth. Any suitable character(s) may be utilized for the digits of the placeholder data to indicate that the data is invalid.
[0083] In some examples, the placeholder data may also include the original identity that was determined to be invalid in parentheses. For example, if the identity determined to be invalid was 0123456789, then the placeholder data that is included in, for example, an identifier field of the response transmitted at 208 may be placeholder data comprising all zeros followed by the invalid identity in parentheses, e.g., 0000000000(0123456789). In other examples, the order of the identity and the placeholder data may be reversed, or any other character other than parentheses may be used to indicate the invalid identity. The retained invalid identity in the response, while still indicating that the identity is determined to be invalid, may be useful to track invalid identities in CDRs.
[0084] Referring now to FIG. 3, a flowchart showing one particular example of a method or process for determining whether an identity is valid or invalid at 204 is provided. The method or process is performed by an IVE, such as the IVE 134 or the CHF 110 of the example core network 108 described previously, or network function that incorporates the functionality of an I'VE, such as a CHF.
[0085] At 302, a determination is made whether the identity is invalid based on whether the identity matches identity information that identifies an identity expected to be associated with the request.
[0086] As described previously, any identity information that identifies an identity expected to be associated with the request, i.e., identity information that a valid identity would be expected to have, may be, for example, compared to the identity that is received to make the determination at 302. For example, as previously described, the identity may be determined to be invalid if, for example, the number of digits of the identity is different from the number of digits that a valid identity is expected to have, and / or the MCC and / or MNC of the identitydo not match any valid country codes or network codes, and / or if the MSIN of the identity matches an invalid subscriber identification number, or the TAC or the SNR of the identity do not match any valid manufacturer TACs or any valid SNRs for the TAC.
[0087] As described previously, identity information that identifies an identity expected to be associated with the request that may be utilized for the determination at 302 may be received at the IVE, or CHF, from an 0 AM node of an operator of the core network that includes the IVE, or the CHF.
[0088] If the determination at 302 is that the identity is invalid based on the comparison, i.e., “YES”, the process moves to 304 and the identity is determined to be invalid.
[0089] If the determination at 302 is that the identity cannot be determined to be invalid, i.e., “NO”, then process continues to 306 and a determination of whether a pattern in at least a portion of the identity is indicative of invalidity is made.
[0090] Because sophisticated users may generate an invalid identity that includes identity information that identifies an identity expected to be associated with a request, such as having an expected number of digits, having an MCC and / or MNC that match valid country codes and network codes, by including an MSIN that is not a known invalid MSIN, e.g., an MSIN included in a blacklisted or greylisted identity, by having a TAC and / or SNR that match valid type allocation codes and serial numbers, the determination at 302 may not be conclusive and further analysis may be necessary to be confident that the identity is valid.
[0091] The determination at 306 may include performing pattern matching of at least a portion of the identity. The pattern matching performed at 306 may be performed in any suitable way to detect whether the identity includes any pattern that would tend to indicate that the identity if invalid. For example, the pattern matching may be performed according to any of the examples of pattern matching described previously with reference to 204. For example, at least a portion of the identity may be determined at 306 to include a pattern indicative of invalidity when the identity includes at least a threshold number of digits that sequentially increase or decrease in value, e.g., 012345679 or 987654321, and / or the identity includes at least a threshold number of digits that have the same value, and / or the identity includes fewer than a threshold number of digits that differ from corresponding digits of a previous identity, such as, for example, a last few digits, e.g., an identity is 9876543210 and a previous identity is 9876543211.
[0092] As described previously, the previous identities that may be utilized for pattern matching at 306 may be received at the IVE, or CHF, from an 0AM node of an operator ofthe core network that includes the IVE, or the CHF.
[0093] If the determination at 306 is that at least a portion of the identity data or values included in an identity field of the request includes a pattern that is indicative in invalidity, i.e., “YES”, then the process moves to 304 and the identity is determined to be invalid. If the determination at 306 is that the identity data or values included in the identity field of the request does not include a pattern that is indicative in invalidity, i.e., “NO”, then the process moves to 308 and the identity is determined to be, or presumed to be, valid.
[0094] Referring to FIG. 4, operations of a procedure in accordance with an example embodiment are shown in which an identity is validated by an IVE 134 prior to charging data being generated by a CHF 110.
[0095] In the operation shown, the AMF 112 initiates generating charging data with subscriber identities by sending a charging data request at 402. As disclosed previously, subscriber identities may be any suitable identity. For example, the identity included in the request may be an IMSI or an IMEI associated with a subscriber. The charging data request sent at 402 may be, for example, a conventional request for charging data as described previously.
[0096] At 404, the AMF 112 sends a charging data request (e.g., a Nchf_ConvergedCharging request) to the CHF 110 that includes the subscriber identity. At 406, the CHF 110 sends an identity validation request (e.g., a Nchf ConvergedCharging ldentity Validation request) to the IVE 134 that includes the subscriber identity.
[0097] At 408, the IVE 134 validates the identity or identities included in the identity validation request. As described previously, the validation performed at 408 may be performing utilizing information received at the IVE 134 from an 0AM node (not shown) associated with the core network. At 410, the IVE 134 sends an identity validation response (e.g., a Nchf ConvergedCharging ldentity Validation response) to the CHF 110. If the validation performed at 408 determines that the identity or identities are valid, then the response sent at 410 includes the identity or identities, and if the validation performed at 408 determines that the identity or identities are invalid, then the response sent at 410 includes placeholder data in place of the identity. At 412, the CHF 110 generates charging data based on the validation response. The charging data generated at 412 includes the identity when the identity is valid according to the identity validation response received at 410, and includes a modified identity when the identity is invalid according to the identity validation response received at 410. The generating the charging data at 412 may comprise generating a CDRthat includes the charging data. At 414, the generated charging data is transmitted by the CHF 110 to the AMF 112 in a charging data response (e.g., a Nchf_ConvergedCharging response). The charging data transmitted at 414 may be included in a CDR in examples in which the CDR is generated at 412.
[0098] Referring to FIG. 5, operations of a procedure in accordance with an example embodiment are shown in which an identity is validated by an IVE 134 prior to charging data being generated by a CHF 110 in response to the establishment of a protocol data unit (PDU) session for a UE 102.
[0099] At 502, the UE 102 messages the AMF 112 with a PDU session establishment request. Although the AMF 112 may validate and authenticate an identity prior to establishing a PDU session, utilizing the procedure set out in VI 8.0 3GPP TS 23.003, in some examples, the PDU session may be established without validating an identity associated with the PDU session. For example, in case of emergency PDU sessions, the network may be configured not to authenticate and authorize the identity associated with the PDU session such that even if the authentication and authorization fails, the emergency sessions are still allowed to ensure, for example, that a valid emergency call is not denied. Attackers may exploit this by using an invalid identity to make emergency calls when launching a DDoS attack on an emergency service network. In other examples, the AMF 112 may be configured to not authenticate and authorize an identity, even when establishing a non-emergency PDU session, to avoid delays in the establishing PDU sessions that result from the authentication process, which slows down the entire network. For these reasons, invalid identities may be used to establish PDU sessions, and it may be desirable to validate the identities to reduce the number of invalid identities that are included in CDRs.
[0100] At 504, the AMF 112 sends the SMF 126 a session management (SM) request with PDU session establishment request. At 508, the SMF 126 sends a SM request with PDU session establishment response to the AFM 112.
[0101] Operations 510, 512, 514, 516, 518, and 520 are substantially similar to the previously described operations at 404, 406, 408, 410, 412, and 414, respectively, and therefore are not described here to avoid repetition.
[0102] Referring to FIG. 6, a schematic diagram illustrating various physical and logical components of an exemplary apparatus 600 for an IVE or CHF in accordance with an embodiment is shown. Although an example embodiment of the apparatus 600 is shown and discussed below, other embodiments may be used to implement examples disclosed herein,which may include components different from those shown. Although FIG. 6 shows a single instance of each component of the apparatus 600, there may be multiple instances of each component shown.
[0103] The apparatus 600 includes one or more processors 602, such as a central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), a field- programmable gate array (FPGA), a dedicated logic circuitry, a graphics processing unit (GPU), a tensor processing unit, a neural processing unit, a dedicated artificial intelligence processing unit, a hardware accelerator, or any other suitable hardware processing circuitry, or combinations thereof. The one or more processors 602 may collectively be referred to as a processor 602.
[0104] The apparatus 600 also includes one or more memories 604 (collectively referred to as "memory 604"), which may include a volatile or non-volatile memory (e.g., a flash memory, a random-access memory (RAM), and / or a read-only memory (ROM)). The non- transitory memory 604 may store instructions for execution by the processor 602. In some embodiments, instructions 606 of an IVE and / or CHF, such as the IVE 134 and CHF 110 of the example core network 108, may be stored in the memory 604, and the instructions 606 may be executed by the processor 602 to perform the actions or operations of the methods or processes described herein. In examples in which the functionality of the I'VE is incorporated into the CHF, such functionality may be incorporated as a software module in the form of instructions 606 stored in the memory 604 that are executable by the processor 602 to perform the functions of the I'VE described herein.
[0105] The apparatus 600 may also include one or more network interfaces 608 for connecting to a network, such as a data network, or other apparatuses of the core network or the access networks described herein.
[0106] The apparatus 600 may optionally include a user input 610 for receiving input from a user of the apparatus 600 and a display 612.
[0107] In some examples, the apparatus 600 may also include one or more electronic storage units (not shown), such as a solid state drive, a hard disk drive, a magnetic disk drive and / or an optical disk drive. In some examples, one or more datasets and / or modules may be provided by an external memory (e.g., an external drive in wired or wireless communication with the apparatus 100) or may be provided by a transitory or non-transitory computer- readable medium. Examples of non-transitory computer readable media include a RAM, a ROM, an erasable programmable ROM (EPROM), an electrically erasable programmableROM (EEPROM), a flash memory, a CD-ROM, or other portable memory storage. The storage units and / or external memory may be used in conjunction with memory 604 to implement data storage, retrieval, and caching functions of the apparatus 600.
[0108] The components of the apparatus 600 may communicate with each other via a bus. In some embodiments, the apparatus 600 may be a processing system implementing functionality of the IVE and / or CHF described herein. In some embodiments, the apparatus 600 may be distributed computing system and may include multiple computing devices in communication with each other over a data network, as well as optionally one or more additional components. The various operations described herein may be performed by different computing devices of a distributed computing system in some embodiments. In some embodiments, the apparatus 600 a cloud computing system or may be a virtual machine provided by a cloud computing system.
[0109] Embodiments of the present invention including functions, processes, and operations, may be implemented in software, hardware, application logic or a combination of software, hardware and application logic. The software, application logic and / or hardware may reside on memory, or any computer media. In an example embodiment, the application logic, software or an instruction set is maintained on any one of various conventional computer- readable media. In the context of this application, a “memory” or “computer-readable medium” may be any non-transitory media or means that contains, stores, communicates, propagates or transports the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer.
[0110] Reference to, where relevant, “computer-readable medium”, “computer program product”, “tangibly embodied computer program” etc., or a “processor” or “processing circuitry” etc. should be understood to encompass not only computers having differing architectures such as single / multi-processor architectures and sequencers / parallel architectures, but also specialized circuits such as field programmable gate arrays FPGA, application specify circuits ASIC, signal processing devices / apparatus and other devices / apparatus. References to computer program, instructions, code etc. should be understood to express software for a programmable processor firmware such as the programmable content of a hardware device / apparatus as instructions for a processor or configured or configuration settings for a fixed function device / apparatus, gate array, programmable logic device / apparatus, etc.[OHl] As used in the present disclosure, the term “circuitry”, for example in the hardwareprocessing circuitry that may be used to implement the IVE or the CHF in accordance with certain embodiments of the present disclosure, may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (iii) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in the present disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0112] The present disclosure provides methods and apparatuses for validating identities prior to including the identities into CDRs and if an identity is determined to be invalid, including placeholder data in place of the identity in the CDR.
[0113] The functions, processes, and operations described herein may be performed in a different order, or may be performed concurrently with each other, or a combination thereof. Furthermore, one or more of the functions, processes, and operations may be optional or may be combined. It will be appreciated that the flow diagrams shown in FIG. 2 and FIG. 3 and the procedures illustrated in FIG. 4 and FIG. 5 are examples only. Various operations and processes depicted therein may be omitted, may be reordered, may be combined, or a combination of reordered and combined.
[0114] Advantageously, validating identities that are included in charging data and CDRs may reduce the occurrence of invalid or false data that is included in CDRs, which may better facilitate analyzing and / or searching through CDRs. Improving the searchability and analyzability of CDRs results in an improvement in the overall functioning of computer systems that are utilized for searching and / or analyzing CDRs and solves a technical problemof how to make CDR more accurate and reliable, and more easily searchable.
[0115] The scope of the claims should not be limited by the preferred embodiments set forth in the examples but should be given the broadest interpretation consistent with the description as a whole.
Claims
CLAIMS1. A method performed by a validation entity, the method comprising: receiving a request to validate an identity associated with charging data; determining whether the identity is valid or invalid; transmitting a response to the request, the response based on the determining, wherein: the response includes the identity when the identity is valid, or the response includes a modified identity when the identity is invalid.
2. The method of claim 1, wherein the modified identity comprises placeholder data.
3. The method of claim 2, wherein all digits of the placeholder data are a same character.
4. The method of claim 2, wherein the modified identity further comprises the identity that is separated from the placeholder data by at least one non-numeric character.
5. The method according to claim 1, wherein the identity comprises: an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G-GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), or a user identifier.
6. The method according to claim 1, wherein determining whether the identity is valid or invalid comprises: determining that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the requested.
7. The method according to claim 6, wherein determining that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the requested comprises at least one of: determining that a number of digits of the identity does not match to a number of digits indicated in the identity information associated with the identity expected to be associated with the request; wherein the identity includes an international mobile subscriber identity (IMSI) that includes a mobile country code (MCC), a mobile network code (MNC), and a mobile subscriber identification number (MSIN), performing at least one of: determining that the MCC does not match one of one or more valid country codes; determining that the MNC does not match one of one or more valid network codes; or determining that the MSIN matches one of one or more invalid subscriber identities; or wherein the identity includes an international mobile equipment identity (IMEI) that includes a type allocation code (TAC) and a serial number (SNR), determining that the TAC does not match one of one or more valid type allocation codes, or determining that the SNR does not match one of one or more valid serial numbers, or both determining that the TAC does not match one of one or more valid type allocation codes and determining that the SNR does not match one of one or more valid serial numbers.
8. The method according to claim 1, wherein determining whether the identity is valid or invalid comprises performing pattern matching on at least a portion of the identity to determine whether the identity is valid or invalid.
9. The method according to claim 8, wherein performing pattern matching comprises determining the identity is invalid based on determining that the identity includes, at least one of:a first number of consecutive digits that have the same value is equal to or greater than a first threshold number; a second number of consecutive digits that sequentially increase or decrease in value by same amount is equal to or greater than a second threshold number; or a third number digits that differ from corresponding digits of a previous identity is less than or equal to a third threshold number.
10. The method according to claim 1 : wherein the validation entity also implements a charging function; wherein receiving the request to validate the identity associated with charging data comprises receiving a request for charging data associated with the identity; wherein the method further comprises generating, based on the determining, charging data associated with the identity, wherein: the charging data includes the identity when the identity is valid, the charging data includes the modified identity when the identity is invalid; and wherein the response includes the charging data that was generated.
11. An apparatus comprising: at least one processor; at least one memory storing instructions for a validation entity, wherein when the instructions are executed by the at least one processor, cause the apparatus to: receive a request to validate an identity associated with charging data; determine whether the identity is valid or invalid; transmit a response to the request, the response based on the determining, wherein: the response includes the identity when the identity is valid, or the response includes a modified identity when the identity is invalid.
12. The apparatus of claim 11, wherein the modified identity comprises placeholder data.
13. The apparatus of claim 12, wherein all digits of the placeholder data are a same character.
14. The apparatus of claim 12, wherein the modified identity further comprises the identity that is separated from the placeholder data by at least one non-numeric character.
15. The apparatus according to claim 11, wherein the identity comprises: an international mobile subscriber identity (IMSI), an international mobile equipment identity (IMEI), a subscription permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a 5G globally unique temporary identifier (5G-GUTI), a permanent equipment identifier (PEI), a generic public subscription identifier (GPSI), a mobile station international subscriber directory (MSISDN), or a user identifier.
16. The apparatus according to claim 11, wherein the instructions that, when executed by the at least one processor, cause the apparatus to determine whether the identity is valid or invalid comprise instructions that, when executed by the at least one processor, cause the apparatus to: determine that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the request.
17. The apparatus according to claim 16, wherein the instructions that, when executed by the at least one processor, cause the apparatus to determine that the identity is invalid based on whether at least a portion of the identity matches identity information that identifies an identity expected to be associated with the request comprise instructions that, when executed by the at least one processor, cause the apparatus to perform at least one of: determine that a number of digits of the identity does not match to a number of digits indicated in the identity information associated with the identity expected to be associated with the request; when the identity includes an international mobile subscriber identity (IMSI) that includes a mobile country code (MCC), a mobile network code (MNC), and a mobile subscriber identification number (MSIN):determine that the MCC does not match one of one or more valid country codes; determine that the MNC does not match one of one or more valid network codes; or determine that the MSIN matches one of one or more invalid subscriber identities; or when the identity includes an international mobile equipment identity (IMEI) that includes a type allocation code (TAC) and a serial number (SNR), determine that the TAC does not match one of one or more valid type allocation codes, or determine that the SNR does not match one of one or more valid serial numbers, or both determine that the TAC does not match one of one or more valid type allocation codes and determine that the SNR does not match one of one or more valid serial numbers.
18. The apparatus according to claim 11, wherein the instructions that, when executed by the at least one processor, cause the apparatus to determine whether the identity is valid or invalid comprise instructions that, when executed by the at least one processor, cause the apparatus to perform pattern matching on at least a portion of the identity to determine whether the identity is valid or invalid.
19. The apparatus according to claim 18, wherein the instructions that, when executed by the at least one processor, cause the apparatus to perform pattern matching comprise instructions that, when executed by the at least one processor, cause the apparatus to determine the identity is invalid based on determining that the identity includes, at least one of: a first number of consecutive digits that have the same value is equal to or greater than a first threshold number; a second number of consecutive digits that sequentially increase or decrease in value by same amount is equal to or greater than a second threshold number; or a third number digits that differ from corresponding digits of a previous identity is less than or equal to a third threshold number.
20. The apparatus according to claim 11 : wherein the instruction for the validation entity also comprise instructions for a charging function; wherein the instructions that, when executed by the at least one processor, cause the apparatus to receive the request to validate the identity associated with charging data comprise instructions that, when executed by the at least one processor, cause the apparatus to receive a request for charging data associated with the identity; wherein the instructions further comprise instructions that, when executed by the at least one processor, cause the apparatus to generate, based on the determining, charging data associated with the identity, wherein: the charging data includes the identity when the identity is valid, the charging data includes the modified identity when the identity is invalid; and wherein the response includes the charging data that was generated.
21. A computer-readable medium storing instructions of a validation entity, wherein when the instructions are executed by at least one processor of an apparatus, cause the apparatus to perform the method of any one of claims 1-10.
Citation Information
Patent Citations
Service data transmission charging method, terminal and computer storage medium
EP3291587B1
Validating international mobile equipment identity (IMEI) in mobile networks
US20190223016A1