Detection of malicious closed access group (CAG) cells
By pre-configuring core network functions with CAG IDs and equipping user equipment to identify and block malicious CAG cells, the detection and prevention of unauthorized access in next-generation networks are enhanced, improving security in Non-Public Networks.
Patent Information
- Application Number
- PCT/EP2025/068765
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-04
- Filing Date
- 2025-07-02
- Publication Date
- 2026-02-12
AI Technical Summary
Next-generation networks face challenges in detecting and preventing unauthorized or malicious Closed Access Group (CAG) cells, which can compromise security and privacy in Non-Public Networks (NPNs).
Implementing a mechanism where a core network function, such as the AMF, is pre-configured with CAG IDs supported by CAG cells, allowing it to verify and reject access from user equipment (UE) to malicious CAG cells by comparing received CAG IDs with allowed IDs, and UE is equipped to process broadcast messages to identify and prohibit access to such cells.
Effectively detects and prevents access to unauthorized CAG cells, enhancing security in 5G and beyond networks by ensuring only authorized users can access CAG cells.
Smart Images

Figure 00000041_0000 
Figure 00000041_0001 
Figure 00000042_0000
Abstract
Description
[0001] DETECTION OF MALICIOUS CLOSED ACCESS GROUP (CAG) CELLS
[0002] Technical Field
[0003] This disclosure is related to the field of communication systems and, in particular, to next generation networks.
[0004] Background
[0005] Next generation networks, such as Fifth Generation (5G) and beyond (e.g., Sixth Generation (6G)), denote the next major phase of mobile telecommunications standards beyond Fourth Generation (4G) standards. In comparison to 4G networks, next generation networks may be enhanced in terms of radio access and network architecture to deliver faster data rates and more reliability. With mobile networks widely used across the country and the world, communications may be intercepted or suffer from other kinds of attacks. To ensure security and privacy, the 3rd Generation Partnership Project (3GPP) has set forth security mechanisms for mobile networks, and the security procedures performed within the mobile networks. Due to the importance of security in 5G systems and beyond, it is desirable to continue to develop improved security mechanisms.
[0006] Next-generation networks allow for Non-Public Networks (NPNs) that are intended for non-public (or private) use. NPNs offer benefits, such as enhanced control where an owner of the NPN has more control over security, data privacy, traffic prioritization, network management, etc., optimized coverage, reduced latency, etc. In general, an NPN may comprise a Standalone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN). An SNPN operates independently without relying on network functions provided by a Public Land Mobile Network (PLMN) or mobile network operator. A PNI- NPN interacts with a public network but maintains specific access controls. For access control, a Closed Access Group (CAG) is a concept introduced within NPNs to identify a group of subscribers permitted to access specific cells. An access node of the NPN forms a cell referred to herein as a CAG cell. In 5G, a CAG cell is sometimes referred to as a 5G New Radio (NR) femtocell provided by a 5G NR femto access point. The CAG cell broadcasts one or more CAG identifiers (IDs) that are used for network selection or reselection, access control, etc. Only authorized users (i.e., subscribers belonging to the CAG) are able to access a CAG cell broadcasting the CAG IDs, which prevents unauthorized access. As NPNs and CAGs are being implemented in 5G and beyond, it remains an issue to provide robust security or protection mechanisms.
[0007] Summary
[0008] Described herein are mechanisms to detect unauthorized or malicious CAG cells and / or to perform access control with regard to unauthorized or malicious CAG cells. As an overview, a Network Function (NF) of the core network is pre-configured with the CAG ID(s) supported by a CAG cell (e.g., a 5G NR femtocell), such as when a new CAG cell is deployed. Other NFs of the core network may access the pre-configured data regarding CAG cells to detect any unauthorized or malicious CAG cells, and protect User Equipment (UE) from accessing a malicious CAG cell. For example, malicious CAG cell detection may be performed when a UE is attempting to register with a network using a CAG cell, when a network is handing over a UE to a target CAG cell, when a UE is establishing a service request to the network for sending Uplink (UL) data through a CAG cell, etc. One technical benefit is unauthorized or malicious CAG cells can be effectively detected and access to the malicious CAG cells can be controlled or prevented to improve security in 5G networks and beyond.
[0009] In an embodiment (also referred to as an aspect), an apparatus comprises a first network function of a core network (e.g., an AMF), comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the first network function at least to perform: receiving a request message regarding access of user equipment to a closed access group cell, acquiring pre-configured information regarding the closed access group cell from a second network function of the core network that indicates least one closed access group identifier supported by the closed access group cell, performing verification of the closed access group cell by comparing the least one closed access group identifier supported by the closed access group cell to at least one allowed closed access group identifier for the user equipment, detecting the closed access group cell as a malicious cell when the least one closed access group identifier supported by the closed access group cell does not match the at least one allowed closed access group identifier for the user equipment, and rejecting the access by the user equipment to the closed access group cell when the closed access group cell is detected as a malicious cell. In an embodiment, an apparatus comprises a first network function of a core network (e.g., an AMF), comprising means for receiving a request message regarding access of user equipment to a closed access group cell, means for acquiring pre-configured information regarding the closed access group cell from a second network function of the core network that indicates least one closed access group identifier supported by the closed access group cell, means for performing verification of the closed access group cell by comparing the least one closed access group identifier supported by the closed access group cell to at least one allowed closed access group identifier for the user equipment, means for detecting the closed access group cell as a malicious cell when the least one closed access group identifier supported by the closed access group cell does not match the at least one allowed closed access group identifier for the user equipment, and means for rejecting the access by the user equipment to the closed access group cell when the closed access group cell is detected as a malicious cell.
[0010] In an embodiment, user equipment is communicatively coupled to a core network, and comprises at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the user equipment at least to perform: receiving a broadcast message from a closed access group cell, processing the broadcast message to identify at least one closed access group identifier broadcast by the closed access group cell, sending a non-access stratum request message toward a network function of the core network indicating the closed access group cell, receiving a non-access stratum response message from the network function indicating the closed access group cell comprises a malicious cell, and prohibiting access through the closed access group cell when the closed access group cell comprises a malicious cell.
[0011] In an embodiment, user equipment is communicatively coupled to a core network, and comprises means for receiving a broadcast message from a closed access group cell, means for processing the broadcast message to identify at least one closed access group identifier broadcast by the closed access group cell, means for sending a non-access stratum request message toward a network function of the core network indicating the closed access group cell, means for receiving a non-access stratum response message from the network function indicating the closed access group cell comprises a malicious cell, and means for prohibiting access through the closed access group cell when the closed access group cell comprises a malicious cell. In an embodiment, an apparatus comprises a first network function of a core network (e.g., a UDM / UDR) pre-configured with closed access group information for a closed access group cell. The first network function comprises at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the first network function at least to perform: receiving a request message from a second network function of the core network requesting the closed access group information for the closed access group cell, processing the request message to extract a cell identifier provided by the closed access group cell, determining the pre-configured closed access group information associated with the cell identifier of the closed access group cell, and sending a response message to the second network function with the closed access group information.
[0012] In an embodiment, an apparatus comprises a first network function of a core network (e.g., a UDM / UDR) pre-configured with closed access group information for a closed access group cell. The first network function comprises means for receiving a request message from a second network function of the core network requesting the closed access group information for the closed access group cell, means for processing the request message to extract a cell identifier provided by the closed access group cell, means for determining the pre-configured closed access group information associated with the cell identifier of the closed access group cell, and means for sending a response message to the second network function with the closed access group information.
[0013] Other embodiments may include computer readable media, other systems or apparatus, or other methods or means as described below. Also, one or more embodiments as described above may be combinable as described herein.
[0014] The above summary provides a basic understanding of some aspects of the specification. This summary is not an extensive overview of the specification. It is intended to neither identify key or critical elements of the specification nor delineate any scope of the particular embodiments of the specification, or any scope of the claims. Its sole purpose is to present some concepts of the specification in a simplified form as a prelude to the more detailed description that is presented later. Description of the Drawings
[0015] Some embodiments of the invention are now described, by way of example only, and with reference to the accompanying drawings. The same reference number represents the same element or the same type of element on all drawings.
[0016] FIG. 1 illustrates a high-level architecture of a 5G system.
[0017] FIG. 2 illustrates a non-roaming architecture of a 5G system.
[0018] FIG. 3 illustrates an NG-RAN architecture.
[0019] FIG. 4 illustrates security mechanisms within a 5G system.
[0020] FIG. 5 illustrates another architecture of a 5G system in an illustrative embodiment.
[0021] FIG. 6 is a block diagram of network elements / functions for providing security management in an illustrative embodiment.
[0022] FIG. 7 is a block diagram of user equipment (UE) in an illustrative embodiment.
[0023] FIG. 8A illustrates a network architecture in an illustrative embodiment.
[0024] FIG. 8B is a block diagram illustrating CAG information provisioned in a core network in an illustrative embodiment.
[0025] FIG. 9 is a flow chart illustrating a method of detecting of a malicious CAG cell in a core network in an illustrative embodiment.
[0026] FIG. 10 is a flow chart illustrating a method of performing access control within a UE regarding a malicious CAG cell in an illustrative embodiment.
[0027] FIG. 11 is a flow chart illustrating a method of handling pre-configured CAG information in a core network in an illustrative embodiment.
[0028] FIG. 12 is a message diagram illustrating detection of a malicious CAG cell during a UE registration procedure in an illustrative embodiment.
[0029] FIGS. 13-14 are flow charts illustrating methods of detecting of a malicious CAG cell during a UE registration procedure in an illustrative embodiment.
[0030] FIG. 15 illustrates an enhanced UL NAS transport message in an illustrative embodiment.
[0031] FIG. 16 illustrates an enhanced global RAN node identifier in an illustrative embodiment.
[0032] FIG. 17 illustrates an enhanced cause Information Element (IE) in an illustrative embodiment.
[0033] FIG. 18 is a message diagram illustrating detection of a malicious CAG cell during a
[0034] UE handover procedure in an illustrative embodiment. FIGS. 19, 20, and 21A-21B are flow charts illustrating methods of detecting of a malicious CAG cell during a UE handover procedure in an illustrative embodiment.
[0035] FIG. 22 illustrates an enhanced handover required message in an illustrative embodiment.
[0036] FIG. 23 illustrates an enhanced “Target ID” IE in an illustrative embodiment.
[0037] FIG. 24 illustrates an enhanced handover preparation failure message in an illustrative embodiment.
[0038] FIG. 25 illustrates an enhanced “Cause” IE in an illustrative embodiment.
[0039] FIG. 26 is a message diagram illustrating detection of a malicious CAG cell during a service request procedure in an illustrative embodiment.
[0040] FIGS. 27-28 are flow charts illustrating methods of detecting of a malicious CAG cell during a service request procedure in an illustrative embodiment.
[0041] FIG. 29 is a message diagram illustrating detection of a malicious CAG cell at a UE in an illustrative embodiment.
[0042] FIG. 30 is a flow chart illustrating a method of detecting of a malicious CAG cell at a UE in an illustrative embodiment.
[0043] Description of Embodiments
[0044] The figures and the following description illustrate specific exemplary embodiments. It will thus be appreciated that those skilled in the art will be able to devise various arrangements that, although not explicitly described or shown herein, embody the principles of the embodiments and are included within the scope of the embodiments. Furthermore, any examples described herein are intended to aid in understanding the principles of the embodiments, and are to be construed as being without limitation to such specifically recited examples and conditions. As a result, the inventive concept(s) is not limited to the specific embodiments or examples described below, but by the claims and their equivalents.
[0045] FIG. 1 illustrates a high-level architecture of a 5G system 100. A 5G system (5GS) 100 is a communication system (e.g., a 3GPP system) comprising a 5G Access Network ((R)AN) 102 (also referred to generally herein as a RAN) and a 5G core network (5GC) 104 (also referred to generally as a core network) that communicate with 5G User Equipment (UE) 106. The RAN 102 and 5GC 104 together may be referred to as a 5G network 101, a 5G mobile network, a 5G communication network, a next generation network, etc. Although the term “5G” is used herein as an example, any next generation or future generation networks beyond 4G are considered, such as 6G. Thus, a “mobile network” and the concepts described herein apply to 5G and beyond.
[0046] RAN 102 provides radio or wireless connectivity to a UE 106, and connects the UE 106 to the 5GC 104. RAN 102 may comprise a Next Generation Radio Access Network (NG-RAN), a non-3GPP access network, and / or another type of RAN connecting to 5GC 104. RAN 102 may support Evolved-UMTS Terrestrial Radio Access Network (E- UTRAN) access (e.g., through an eNodeB (eNB), gNodeB (gNB), and / or ng-eNodeB (ng- eNB)), Wireless Local Area Network (WLAN) access, satellite radio access, new Radio Access Technologies (RAT), etc. A 5G access network may also support fixed access. 5GC 104 interconnects RAN 102 with a data network (DN) 108. 5GC 104 is comprised of Network Functions (NF) 110, which may be implemented either as a network element on dedicated hardware, as a software instance running on dedicated hardware, as a virtualized function instantiated on an appropriate platform (e.g., a cloud infrastructure), etc. Data network 108 may be an operator external public or private data network, or an intra-operator data network (e.g., for IP Multimedia Subsystem (IMS) services). A UE 106 (also referred to as a mobile terminal) includes a 5G capable device configured to register with 5GC 104 to access services. UE 106 may include an end user device, such as a mobile phone (e.g., smartphone), a tablet, a computer with a mobile broadband adapter, etc. UE 106 may be enabled for voice services, data services, Machine-to-Machine (M2M) or Machine Type Communications (MTC) services, and / or other services.
[0047] FIG. 2 illustrates a non-roaming architecture 200 of a 5G system 100. The architecture 200 in FIG. 2 is a service-based representation, as is further described in 3GPP TS 23.501 (Release 19), which is incorporated by reference as if fully included herein. Architecture 200 is comprised of Network Functions (NF) for a 5GC 104, and the NFs for the control plane (CP) are separated from the user plane (UP). The control plane of the 5GC 104 includes an Authentication Server Function (AUSF) 210, an Access and Mobility Management Function (AMF) 212, a Session Management Function (SMF) 214, a Policy Control Function (PCF) 216, a Unified Data Management (UDM) 218, a Network Slice Selection Function (NSSF) 220, and an Application Function (AF) 222. The control plane of the 5GC 104 further includes a Network Exposure Function (NEF) 224, a NF Repository Function (NRF) 226, a Service Communication Proxy (SCP) 228, a Network Slice Admission Control Function (NSACF) 230, a Network Slice-specific and SNPN Authentication and Authorization Function (NSSAAF) 232, and an Edge Application Server Discovery Function (EASDF) 234. The user plane of the 5GC 104 includes one or more User Plane Functions (UPF) 240 that communicate with data network 108. A UE 106 is able to access the control plane and the user plane of the 5GC 104 through RAN 102.
[0048] FIG. 3 illustrates an NG-RAN architecture 300. An NG-RAN 302 is an example of a RAN 102 as described above, and comprises a plurality of RAN nodes 304 (also referred to as NG-RAN nodes). A RAN node 304 may be a gNB 306 configured to provide new- radio user plane and control plane protocol terminations towards a UE 106, or an ng-eNB 308 configured to provide E-UTRA user plane and control plane protocol terminations towards a UE 106. The gNBs 306 and ng-eNBs 308 are interconnected with each other by means of the Xn interface. The gNBs 306 and ng-eNBs 308 are also connected by means of the NG interfaces to the 5GC 104, more specifically to the AMF 212 by means of the NG-C interface and to the UPF 240 by means of the NG-U interface.
[0049] There are a large number of subscribers that are able to access services from a carrier or home / mobile network operator that implements a mobile network comprising a 5G system 100, such as in FIGS. 1-2. Communications between the users or subscribers (i.e., through a UE) and the mobile network are protected by security mechanisms, such as the ones standardized by the 3GPP. Subscribers and the carrier expect security guarantees from the security mechanisms.
[0050] FIG. 4 illustrates security mechanisms 400 within a 5G system 100. One of the security mechanisms 400 is primary authentication and key agreement between the network (e.g., AMF 212 / UDM 218) and the UE 106. Other security mechanisms 400 are used to protect signaling between the network and the UE 106. For example, a security mechanism 400 is used to protect Non-Access Stratum (NAS) signaling between the AMF 212 and the UE 106. Other security mechanisms 400 are used to protect Access Stratum (AS) communications between a RAN node 304 (e.g., gNB 306) and the UE 106, such as Radio Resource Control (RRC) signaling between a gNB 306 and the UE 106, and User Plane (UP) traffic (also referred to as UP data) between the gNB 306 and the UE 106. Within the network, a security mechanism 400 may be used to protect IP connectivity between the gNB 306 and the 5GC 104 (e.g., AMF 212 / UPF 240), such as Internet Protocol Security (IPSec). Yet another security mechanism 400 is used for roaming and interconnect security, such as to protect control plane signaling between a Security Edge Protection Proxy (SEPP) 410 and another network 401 (e.g., a visited 5G network), and / or to protect user plane data between the UPF 240 and the other network 401. There may be additional security mechanisms 400 defined or used, which are not discussed for the sake of brevity.
[0051] FIG. 5 illustrates another architecture of a 5G system 100 in an illustrative embodiment. In this embodiment, the RAN 102 may include a radio network subsystem 502 that includes base stations 504 (e.g., gNBs 306 and / or ng-eNBs 308) that form macrocells 506 (which may also be referred to as “normal” or “regular” PLMN cells). The RAN 102 may also include a small cell subsystem 510 (also referred to generally as a Home gNB (HgNB) subsystem). The small cell subsystem 510 includes one or more small cell access nodes 512. A small cell access node 512 is a low-powered cellular radio access node that operates in a spectrum having a range less than a macrocell 506, such as a range of about ten meters to a kilometer (or a few kilometers), to form a small cell 514. A small cell access node 512 may be used, such as in a home or small business for example, to bridge a cellular connectivity gap, enabling the use of 5G by providing coverage in places where distance or physical limitations make it difficult to maintain a consistent and reliable cellular connection, and / or to provide a PNI-NPN. This advantageously allows service providers to extend service coverage indoors or at a cell edge, especially where access would otherwise be limited or unavailable, or to provide enhanced control where an owner of an NPN has more control over security, data privacy, traffic prioritization, network management, etc., optimized coverage, reduced latency, etc. One example of a small cell 514 is a 5G NR femtocell 516 (also referred to as 5G NR femto), and one example of a small cell access node 512 is a 5G NR femto access point 518 (also referred to as a femto device, a femto base station, HgNB, etc.).
[0052] One or more of the small cells 514 may comprise a CAG cell 520. In 5G, a CAG identifies a group of subscribers who are permitted / allowed to access one or more CAG cells 520 associated with one or more CAG ID(s) 522. A CAG cell 520 is a cell broadcasting one or multiple CAG IDs 522. The CAG concept may be used to apply access control in PNI-NPNs, for example, to prevent UEs 106, which are not allowed to access the NPN via the associated cell(s), from automatically selecting and / or accessing the associated CAG cell(s) 520. As described in 3GPP TS 23.501, PNI-NPNs are NPNs made available via PLMNs, such as by means of dedicated Data Network Names (DNNs) or by one (or more) network slice instances allocated for the NPN. Thus, a UE 106 may access a PNI- NPN, such as when roaming. An issue in a 5GS 100, for example, is detection of unauthorized or malicious CAG cells and / or to perform access control with regard to unauthorized or malicious CAG cells. CAG membership of a UE 106 is configured in the user subscription data and on the UE 106. When a UE 106 is roaming outside of its home network (e.g., Home PLMN (HPLMN) that represents an operator network or carrier network through which a subscriber (e.g., UE 106) has a subscription for services), access control should be performed in the visited network (e.g., Visited PLMN (VPLMN)) based on CAG IDs 522 configured in the VPLMN. To use CAG, a UE 106, which supports CAG as indicated as part of the UE 5G Mobility Management (5GMM) Core Network Capability, may be pre-configured or (re)configured with the following CAG information included in the subscription as part of the Mobility Restrictions: an allowed CAG list 524 (i.e., a list of CAG identifiers 522 the UE 106 is allowed to access), each entry of the allowed CAG list 524 may be associated with time validity information containing one or more time periods, and optionally, a CAG- only indication whether the UE 106 is only allowed to access the 5GS 100 via CAG cells 520. A UE 106 (which supports CAG) may be configured or re-configured with the CAG information during a registration procedure of the UE 106 or during a UE configuration update procedure. A CAG cell 520 (e.g., through a 5G NR femto access point 518) broadcasts one or more CAG IDs 522, which may be received by a UE 106 in the vicinity of the CAG cell 520. When performing a cell (re-) sei ection procedure, for example, the UE 106 compares the CAG ID(s) 522 broadcast by the CAG cell 520 with its allowed CAG list 524. When a CAG ID(s) 522 broadcast by the CAG cell 520 matches the allowed CAG list 524, the UE 106 is allowed access to the CAG cell 520.
[0053] CAG cells 520, such as in a PNI-NPN, may be untrusted devices from the perspective of a core network 104, as virtually anyone is able to procure an access point and implement a CAG cell 520. A malicious CAG cell, for example, may broadcast an unauthorized or manipulated CAG ID 522. The following embodiments provide enhanced mechanisms, procedures, processes, etc., for detecting malicious CAG cells and protecting UEs 106 from accessing malicious CAG cells that broadcast manipulated CAG IDs 522. In general, the enhanced procedures may be implemented or supported by one or more network functions (e.g., NF 110) of a core network 104 and / or a UE 106.
[0054] FIG. 6 is a block diagram of network elements / functions for providing security management in an illustrative embodiment. More particularly, system 600 of FIG. 6 comprises a UE 106, a RAN node 304, and a plurality of network elements / functions 110 (i.e., a first network element / function 110-1 and a second network element / function 110-N). It is to be appreciated that UE 106, RAN node 304, and the network elements / functions 110 are configured to interact to provide security management (also referred to as protection management). Examples of network elements / functions 110 may include, but are not limited to, an AMF 212, a UDM 218 or Unified Data Repository (UDR), etc. Examples of RAN nodes 304 are gNBs 306, ng-eNBs 308, CAG cells 520 (e.g., HgNB, 5GNR femto access point 518, etc.), etc.
[0055] Network element / function 110-1 comprises a processor 622-1 coupled to a memory 626-1 and interface circuitry 620-1. The processor 622-1 of network element / function 110- 1 includes a security management processing module 624-1 that may be implemented at least in part in the form of software executed by the processor 622-1. The security management processing module 624-1 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 626-1 includes a security management storage module 628-1 that stores data generated or otherwise used during security management operations.
[0056] Network element / function 110-N comprises a processor 622-N coupled to a memory 626-N and interface circuitry 620-N. The processor 622-N of network element / function 110-N includes a security management processing module 624-N that may be implemented at least in part in the form of software executed by the processor 622-N. The security management processing module 624-N performs security management described in conjunction with subsequent figures and otherwise herein. The memory 626-N includes a security management storage module 628-N that stores data generated or otherwise used during security management operations.
[0057] The processors 622-1 and 622-N of the respective network elements / functions 110-1 and 110-N may comprise, for example, microprocessors, application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), digital signal processors (DSPs) or other types of processing devices or integrated circuits, as well as portions or combinations of such elements. Such integrated circuit devices, as well as portions or combinations thereof, are examples of “circuitry” as that term is used herein. A wide variety of other arrangements of hardware and associated software or firmware may be used in implementing the illustrative embodiments.
[0058] The memories 626-1 and 626-N of the respective network elements / functions 110-1 and 110-N may be used to store one or more software programs that are executed by the respective processors 622-1 and 622-N to implement at least a portion of the functionality described herein. For example, security management operations and other functionality as described in conjunction with subsequent figures and otherwise herein may be implemented in a straightforward manner using software code executed by processors 622-1 and 622-N.
[0059] A given one of the memories 626-1 and 626-N may therefore be viewed as an example of what is more generally referred to herein as a computer program product or still more generally as a processor-readable storage medium that has executable program code embodied therein. Other examples of processor-readable storage media may include disks or other types of magnetic or optical media, in any combination. Illustrative embodiments can include articles of manufacture comprising such computer program products or other processor-readable storage media.
[0060] The memories 626-1 and 626-N may more particularly comprise, for example, an electronic random-access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memories such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM) or ferroelectric RAM (FRAM). The term “memory” as used herein is intended to be broadly construed, and may additionally or alternatively encompass, for example, a read-only memory (ROM), a disk-based memory, or other type of storage device, as well as portions or combinations of such devices.
[0061] Interface circuitry 620-1 and 620-N of the respective network elements / functions 110-1 and 110-N illustratively comprise transceivers or other communication hardware or firmware, Application Programming Interfaces (APIs), etc., that allows the associated system elements to communicate with one another in the manner described herein.
[0062] Network element / function 110-1 is configured for communication with network element / function 110-N, and vice-versa, via their respective interface circuitry 620-1 and 620-N. This communication involves network element / function 110-1 sending data to the network element / function 110-N, and the network element / function 110-N sending data to the network element / function 110-1. However, in alternative embodiments, other network elements may be operatively coupled between the network elements / functions 110-1 and 110-N. The term “data” as used herein is intended to be construed broadly, so as to encompass any type of information that may be sent between network elements / functions (as well as between UE 106 and a core network 104) including, but not limited to, messages, identifiers, keys, indicators, user data, control data, etc. RAN node 304 comprises a processor 612 coupled to a memory 616 and interface circuitry 610. The processor 612 of RAN node 304 includes a security management processing module 614 that may be implemented at least in part in the form of software executed by the processor 612. The security management processing module 614 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 616 includes a security management storage module 618 that stores data generated or otherwise used during security management operations. RAN node 304 is configured for communication with UE 106 and one or more network element / functions 110-N via interface circuitry 610. For example, interface circuitry 610 may be configured for radio communication over an air interface to communicate with a UE 106, and may be configured for backhaul communication with one or more network element / functions 110-N of the core network 104.
[0063] It is to be appreciated that the particular arrangement of components shown in FIG. 6 is an example, and numerous alternative configurations may be used in other embodiments. For example, any given network element / function can be configured to incorporate additional or alternative components and to support other communication protocols.
[0064] Other system elements may each also be configured to include components such as a processor, memory, and network interface. These elements need not be implemented on separate stand-alone processing platforms, but could instead, for example, represent different functional portions of a single common processing platform.
[0065] FIG. 7 is a block diagram of a UE 106 in an illustrative embodiment. From a functional standpoint, the UE 106 is composed of at least two parts: Mobile Equipment (ME) 700 and a Universal Subscriber Identity Module (USIM) 760. ME 700 comprises a radio interface component 702, one or more processors 704, a memory 706, and a user interface component 708. The UE 106 may also comprise a battery 710. Radio interface component 702 is a hardware component or means that represents the local radio resources of the UE 106, such as a Radio Frequency (RF) unit 720 (e.g., one or more radio transceivers) and one or more antennas 722. Radio interface component 702 may be configured for 5G New Radio (NR), Long Term Evolution (LTE), WiFi, Bluetooth, etc. Processor 704 represents the internal circuitry, logic, hardware, means, etc., that provides the functions of the UE 106. Processor 704 may be configured to execute instructions 740 for software that are loaded into memory 706. Processor 704 may execute an Operating System (OS) 734 for the UE 106 that manages hardware and software resources, and one or more application clients 735 for an application. Processor 704 may also execute a security controller 736, which comprises a component or means for performing security mechanisms within the UE 106 (i.e., within the ME 700), such as integrity protection mechanisms and / or encryption mechanisms. User interface component 708 is a hardware component for interacting with an end user. For example, user interface component 708 may comprise a display 750, screen, touch screen, and / or the like (e.g., a Liquid Crystal Display (LCD), a Light Emitting Diode (LED) display, etc.). User interface component 708 may include a keyboard or keypad, a tracking device (e.g., a trackball or trackpad), a speaker, a microphone, etc.
[0066] USIM 760 is an integrated circuit that provides security and integrity functions for the UE 106. USIM 760 includes or is provisioned with a subscription profile associated with a subscription of a subscriber. A subscription profile may include a variety of information, such as subscription credentials (e.g., Subscription Permanent Identifier (SUPI)) used to uniquely identify a subscription and to mutually authenticate the UE 106 and a network.
[0067] The UE 106 may comprise various other components not specifically illustrated in FIG. 7.
[0068] FIGS. 8A-8B and 9-11 illustrate enhanced security / protection mechanisms regarding CAG cells 520 in an illustrative embodiment. For the enhanced security / protection mechanisms, the core network 104 is able to detect malicious CAG cells and protect a UE 106 from accessing a malicious CAG cell.
[0069] FIG. 8A illustrates a network architecture 800 in an illustrative embodiment. The network architecture 800 includes a RAN 102 that connects a UE 106 to a core network 104. The RAN 102 includes a CAG cell 520 of a PNI-NPN 802 that supports one or more CAG IDs 522. The core network 104 includes an AMF 212 and a CAG information NF 804. The CAG information NF 804 is pre-configured with CAG information for the CAG cell 520 (e.g., a 5G NR femtocell 516), such as when a new CAG cell is deployed. In an embodiment, the CAG information NF 804 may comprise a UDM 218 or a UDR 806.
[0070] FIG. 8B is a block diagram illustrating CAG information 810 provisioned in the core network 104 in an illustrative embodiment. A (mobile) network operator 820 pre- configures or pre-provisions the CAG information NF 804 with CAG information 810 for one or more CAG cells 520. For example, an operations and management (0AM) server 822 or the like of the network operator 820 may pre-configure the CAG information NF 804 with the CAG information 810 of a CAG cell 520, such as when the CAG cell 520 is deployed. The CAG information 810 for a CAG cell 520 indicates CAG ID(s) 522 supported by that CAG cell 520. The CAG information 810, for example, may comprise identifier (ID) mappings 812. Each ID mapping 812 maps a cell ID 814 for a CAG cell 520 to one or more CAG IDs 522 supported by that CAG cell 520. In the example shown in FIG. 8B, the ID mapping 812 maps the cell ID 814 of “120” to the supported CAG IDs 522 of “66, 21, 40”, the ID mapping 812 maps the cell ID 814 of “1” to the supported CAG IDs 522 of “1, 2, 3”, etc. One technical benefit is the CAG information 810 is pre-configured in the core network 104 (i.e., the HPLMN of a UE 106), which is more secure. If, for example, the CAG information 810 were received from a CAG cell 520 itself, the CAG IDs 522 provided by the CAG cell 520 may be spoofed. By having the network operator 820 pre-configure the CAG information 810 in the core network 104, spoofing of the CAG IDs 522 may be prevented.
[0071] FIG. 9 is a flow chart illustrating a method 900 of detecting of a malicious CAG cell in a core network 104 in an illustrative embodiment. FIG. 10 is a flow chart illustrating a method 1000 of performing access control within a UE 106 regarding a malicious CAG cell in an illustrative embodiment. FIG. 11 is a flow chart illustrating a method 1100 of handling pre-configured CAG information 810 in a core network 104 in an illustrative embodiment. The steps of the flow charts described herein are not all inclusive and may include other steps not shown, and the steps may be performed in an alternative order.
[0072] One assumption is that a UE 106 comes into range of a CAG cell 520, as illustrated in FIG. 8 A. In FIG. 10, the UE 106 receives a broadcast message from the CAG cell 520 (step 1002), and processes the broadcast message to extract or identify one or more CAG IDs 522 provided or broadcast by the CAG cell 520 (step 1004). The UE 106 may perform verification of the CAG cell 520 in response to the broadcast message (optional step 1006). For example, the UE 106 may compare the CAG ID(s) 522 received from the CAG cell 520 with the allowed CAG list 524 (optional step 1008). When the CAG ID(s) 522 received from the CAG cell 520 does not match the allowed CAG list 524 (i.e., the CAG ID(s) 522 is not included in the allowed CAG list 524) and verification fails, the UE 106 may remove the CAG cell 520 from cell selection criteria 826 (optional step 1010), and may perform a fresh cell search to avoid connection with this CAG cell 520. The UE 106 may also process past CAG information regarding prior interactions of the UE 106 with one or more CAG cells 520 as part of the verification (optional step 1012), which is described in more detail below. When the CAG ID(s) 522 received from the CAG cell 520 matches the allowed CAG list 524 (i.e., the CAG ID(s) 522 is included in the allowed CAG list 524) and / or the CAG cell 520 is valid based on the past CAG information, verification is successful and the CAG cell 520 is verified at the UE 106 (optional step 1014).
[0073] The UE 106, such as when verification of a CAG cell 520 is successful, initiates a NAS procedure (e.g., a registration procedure, a service request procedure, etc.), such as described in 3GPP TS 23.502 (Release 19), which is incorporated by reference as if fully included herein. For the NAS procedure, the UE 106 sends a NAS request message toward the AMF 212 regarding access of the UE 106 to the CAG cell 520 (step 1016). The NAS request message may comprise a register request message, a service request message, etc. It is noted that the term “request” message is meant to indicate a general request-response model and not a particular name of a message.
[0074] In FIG. 9, AMF 212 receives a request message regarding access of the UE 106 to a CAG cell 520 (step 902). The request message may comprise a NAS request message sent by the UE 106 as described in FIG. 10, or may comprise another type of request message regarding access of the UE 106 to a CAG cell 520, such as a handover request from a RAN node 304 for a handover procedure. In response to the request message, AMF 212 acquires CAG information 810 regarding the CAG cell 520 from the CAG information NF 804 (e.g., UDM 218 / UDR 806) of the core network 104 (step 904). For example, AMF 212 may send a CAG information request message to the CAG information NF 804 of the core network requesting CAG information 810 for the CAG cell 520 (optional step 906), and receive the CAG information 810 from the CAG information NF 804 in a CAG information response message (optional step 908). As described above, the CAG information 810 may comprise a (pre-configured) ID mapping 812 of a cell ID 814 of the CAG cell 520 to one or more CAG IDs 522 supported by the CAG cell 520. AMF 212 then performs verification of the CAG cell 520 based on the CAG information 810 pre-configured in the core network 104 (step 910). For example, AMF 212 compares the CAG ID(s) 522 supported by the CAG cell 520 as indicated by the CAG information 810, with the allowed CAG ID(s) 522 for the UE 106 (step 912). When the CAG ID(s) 522 supported by the CAG cell 520 matches the allowed CAG ID(s) 522 of the UE 106 and verification is successful, AMF 212 approves access of the UE 106 to the CAG cell 520 (step 914). When the CAG ID(s) 522 supported by the CAG cell 520 does not match the allowed CAG ID(s) 522 of the UE 106 and verification fails, AMF 212 detects the CAG cell 520 as a malicious CAG cell (step 916). AMF 212 rejects access by the UE 106 to the CAG cell 520 detected as malicious (step 918). AMF 212 may send a response message to the UE 106 or a RAN node 304 indicating the CAG cell 520 as a malicious CAG cell (optional step 920). One technical benefit is unauthorized or malicious CAG cells can be effectively detected and access to the malicious CAG cells can be controlled or prevented to improve security in 5G networks and beyond.
[0075] In FIG. 10, for example, the UE 106 may receive a NAS response message from AMF 212 indicating the CAG cell 520 as a malicious CAG cell (step 1018). When the CAG cell 520 is indicated as malicious by AMF 212, the UE 106 prohibits access through the CAG cell 520 (step 1020). For example, the UE 106 may terminate or halt any system procedures toward the CAG cell 520, such as a registration procedure, a service request procedure, etc. The UE 106 may remove the CAG cell 520 from cell selection criteria 826 (optional step 1022). One technical benefit is the UE 106 is protected from accessing malicious CAG cells.
[0076] In FIG. 11, the CAG information NF 804 (e.g., UDM 218 / UDR 806) is preconfigured with CAG information 810 for CAG cells 520 (step 1102), such as when the CAG cells 520 are initially deployed in a PNI-NPN 802. As described above, a network operator 820 may pre-configure the CAG information NF 804 with CAG information 810 for one or more CAG cells 520. The CAG information 810 for a CAG cell 520 may include an ID mapping 812 that maps a cell ID 814 for a CAG cell 520 to CAG ID(s) 522 supported by that CAG cell 520. The CAG information NF 804 receives a CAG information request message from an NF 110 of the core network 104 (e.g., AMF 212) requesting CAG information for one or more CAG cells 520 (step 1104). The CAG information request may include a cell ID 814 for one or more CAG cells 520. The CAG information NF 804 processes the CAG information request message to extract or identify the cell ID 814 provided by or associated with the CAG cell 520 (step 1106). The CAG information NF 804 determines or identifies the (pre-configured) CAG information 810 associated with the cell ID 814 of the CAG cell 520 (step 1108). More particularly, the CAG information NF 804 determines the CAG ID(s) 522 associated with the cell ID 814 of the CAG cell 520 based on the pre-configured ID mapping 812. The CAG information NF 804 sends a CAG information response message to the requesting NF 110 (e.g., AMF 212) with the CAG information 810 (step 1110). Thus, the CAG information 810 provided to the requesting NF 110 indicates the CAG ID(s) 522 associated with the cell ID 814 of the CAG cell 520. One technical benefit is the CAG information NF 804 is able to provide a trusted mapping of CAG ID(s) 522 with a cell ID 814 to the requesting NF 110 to assist the requesting NF 110 in identifying potentially-malicious CAG cells.
[0077] The following provides certain embodiments describing enhanced security / protection mechanisms. The processes, systems, and methods described in the following embodiments may be incorporated in embodiments described above as desired.
[0078] Embodiment 1
[0079] In this embodiment, detection of a malicious CAG cell is performed during a UE registration procedure. In general, a UE 106 needs to register with the network to get authorized to receive services, to enable mobility tracking, and to enable reachability. The registration procedure is described in 3GPP TS 23.502 (Release 19), which is incorporated by reference as if fully included herein, such as in section 4.2.2.2.
[0080] FIG. 12 is a message diagram illustrating detection of a malicious CAG cell during a UE registration procedure in an illustrative embodiment. FIGS. 13-14 are flow charts illustrating methods of detecting of a malicious CAG cell during a UE registration procedure in an illustrative embodiment.
[0081] In FIG. 12, a CAG information NF 804 is illustrated as a UDM / UDR that is preconfigured with CAG information 810 (e.g., ID mappings 812), such as for the CAG cell 520, as described above. UE 106 is configured or provisioned with an allowed CAG list 524 (e.g., allowed CAG ID List = 1, 2, 3), which is a list of CAG IDs 522 the UE 106 is allowed to access. The allowed CAG list 524 is stored in UE’s non-volatile memory. During commissioning or deployment of the CAG cell 520 (e.g., while bringing it up for the first time), the supported CAG ID(s) 522 for the CAG cell 520 is configured in the CAG information 810 stored in UDM / UDR. In this example, the CAG cell 520 supports a CAG ID 522 of “4”. When the UE 106 comes into range of the CAG cell 520, the UE 106 may receive communications from the CAG cell 520 in the form of broadcast messages. Although the CAG cell 520 supports a CAG ID 522 of “4”, the CAG cell 520 broadcasts (e.g., in a System Information Block 1 (SIB1) broadcast message) an unauthorized, manipulated, or wrong CAG ID 522 of “1”.
[0082] FIG. 13 is a flow chart illustrating a method 1300 performed in a UE 106 in an illustrative embodiment. UE 106 receives the broadcast message 1201 from the CAG cell 520 (step 1302), and processes the broadcast message 1201 (i.e., the SIB1) to extract or identify one or more CAG IDs 522 provided / broadcast by the CAG cell 520 (step 1304).
[0083] The UE 106 performs verification of the CAG cell 520 in response to the broadcast message 1201 (step 1306). For example, the UE 106 compares the CAG ID(s) 522 received from the CAG cell 520 with the allowed CAG list 524 (step 1308). When the CAG ID(s) 522 received from the CAG cell 520 does not match the allowed CAG list 524 (i.e., the CAG ID(s) 522 is not included in the allowed CAG list 524) and verification fails, the UE 106 may remove the CAG cell 520 from cell selection criteria 826 (step 1310), and may perform a fresh cell search to avoid connection with this CAG cell 520. The UE 106 may also process past CAG information regarding prior interactions of the UE 106 with one or more CAG cells 520 as part of the verification (optional step 1312), which is described in more detail below. When the CAG ID(s) 522 received from the CAG cell 520 matches the allowed CAG list 524 (i.e., the CAG ID(s) 522 is included in the allowed CAG list 524) and / or the CAG cell 520 is valid based on the past CAG information, verification is successful and the CAG cell 520 is verified at the UE 106 (step 1314).
[0084] In the example of FIG. 12, the CAG ID(s) 522 received from the CAG cell 520 (i.e., CAG ID = “1”) is in the allowed CAG list 524 for the UE 106, so the UE 106 will verify the CAG cell 520. When verification of a CAG cell 520 is successful, the UE 106 initiates a (NAS) registration procedure (step 1316). As part of the registration procedure, UE 106 sends NAS message in the form of a registration request message 1202 toward the AMF 212 (step 1318) through the CAG cell 520. The UE 106 includes the CAG ID(s) 522 provided / broadcast by the CAG cell 520 in the registration request message 1202.
[0085] In response to the registration request message 1202 from the UE 106, the CAG cell 520 sends an Uplink (UL) NAS transport message 1203 to the AMF 212 (see FIG. 12). The CAG cell 520 includes its cell ID 814 and a NAS Packet Data Unit (NAS-PDU) in the UL NAS transport message 1203 to the AMF 212. The NAS-PDU contains the registration request message 1202 from the UE 106.
[0086] FIG. 14 is a flow chart illustrating a method 1400 performed in the AMF 212 in an illustrative embodiment. AMF 212 receives the UL NAS transport message 1203 from the CAG cell 520 regarding access of the UE 106 to the CAG cell 520 (step 1402). AMF 212 processes the UL NAS transport message 1203 to extract or identify the cell ID 814 provided by the CAG cell 520 and the CAG ID(s) 522 provided by the UE 106 in the registration request message 1202 (step 1404). In response to the UL NAS transport message 1203, AMF 212 acquires CAG information 810 regarding the CAG cell 520 from UDM / UDR of the core network 104. To do so, AMF 212 sends a CAG information request message 1204 (e.g., Nudm_5gFemtoNRGet request message) to the UDM 218 to retrieve the CAG ID(s) 522 supported by the CAG cell 520 (step 1406). AMF 212 includes the cell ID 814 provided by the CAG cell 520 in the CAG information request message 1204 to the UDM 218.
[0087] As illustrated in FIG. 11, UDM 218 receives the CAG information request message
[0088] 1204 from the AMF 212 (step 1104). UDM 218 (or UDR 806) processes the CAG information request message 1204 to extract or identify the cell ID 814 of the CAG cell 520 (step 1106). UDM 218 (or UDR 806) determines the CAG ID(s) 522 associated with the cell ID 814 of the CAG cell 520 based on the pre-configured ID mapping 812 (step 1108). UDM 218 then sends a CAG information response message 1205 (e.g., Nudm_5GFemtoNRGet response message) to the AMF 212 (step 1110). UDM 218 includes the CAG ID(s) 522 associated with the cell ID 814 of the CAG cell 520 in the CAG information response message 1205. One technical benefit is the UDM / UDR is able to provide a trusted mapping of CAG ID(s) 522 with a cell ID 814 to the AMF 212 to assist the AMF 212 in identifying potentially-malicious CAG cells.
[0089] In FIG. 14, AMF 212 receives the CAG information response message 1205 from the UDM 218 (step 1408). AMF 212 processes the CAG information response message
[0090] 1205 to extract or identify the CAG ID(s) 522 supported by the CAG cell 520 (step 1410). AMF 212 compares the CAG ID(s) 522 supported by the CAG cell 520 (and received from the UDM / UDR) with the CAG ID 522 provided by the UE 106 in the registration request message 1202 (step 1412). When the CAG IDs 522 match and the comparison is successful (i.e., CAG ID 522 received in registration request message 1202 is equal to the supported CAG ID(s) 522 of the CAG cell 520), AMF 212 may proceed with the registration procedure in a conventional manner (step 1414). When the CAG IDs 522 do not match and the comparison is unsuccessful (i.e., CAG ID 522 received in registration request message 1202 is not equal to the supported CAG ID(s) 522 of the CAG cell 520), AMF 212 detects the CAG cell 520 as an unauthorized or malicious CAG cell 1210 (step 1416). AMF 212 sends a registration reject message 1206 to the UE 106 (step 1418). AMF 212 may set a cause value in the registration reject message 1206 to a value indicating that the CAG cell 520 is unauthorized or malicious. However, any suitable error message may be used. One technical benefit is the AMF 212 is able to verify the CAG ID(s) of a CAG cell 520 during registration of a UE 106 to prevent registration with a malicious CAG cell 1210. In FIG. 13, the UE 106 receives the registration reject message 1206 from the AMF 212 (step 1320), and terminates or halts the registration procedure with the malicious CAG cell 1210 (step 1322). Thus, instead of re-attempting registration through the malicious CAG cell 1210 in response to the registration reject message 1206, the UE 106 terminates the registration procedure. In an embodiment, the UE 106 may remove the malicious CAG cell 1210 from cell selection criteria 826 (optional step 1324). One technical benefit is the UE 106 will not perform registration with the malicious CAG cell 1210. When the UE 106 receives a registration complete message from the AMF 212 (instead of a registration reject), the UE 106 may proceed with the registration procedure in a conventional manner.
[0091] In order to convey certain information as described herein, enhancements may be made to messages used as part of the registration procedure. FIG. 15 illustrates an enhanced UL NAS transport message 1203 in an illustrative embodiment. A UL NAS transport message is described in 3GPP TS 38.413 (Release 19), which is incorporated by reference as if fully included herein, such as in section 9.2.5.3. The enhanced UL NAS transport message 1203 as described herein may be a revision or extension to the UL NAS transport message presently set forth or standardized, such as by the 3 GPP. The enhanced UL NAS transport message 1203 may include the following attributes or Information Elements (IES) as described in the standards: “Message Type”, “AMF UE NGAP ID”, “RAN UE NGAP ID”, “NAS-PDU”, “User Location Information”, “W-AGF Identity Information”, “TNGF Identity Information”, and “TWIF Identity Information”. The “NAS-PDU” IE 1502 includes the registration request message 1202 provided by the UE 106. In an embodiment, the enhanced UL NAS transport message 1203 may further include a CAG cell ID IE 1504 specified or defined to indicate a cell ID 814 of a CAG cell 520, which may be labeled “HgNB ID” although other labels are considered herein. One technical benefit is the core network 104 is able to receive a cell ID 814 from CAG cells 520, such as in a UL NAS transport message.
[0092] FIG. 16 illustrates an enhanced global RAN node ID 1600 in an illustrative embodiment. A global RAN node ID is described in 3GPP TS 38.413, such as in section 9.3.1.5, and is used to globally identify an NG-RAN node. The enhanced global RAN node ID 1600 as described herein may be a revision or extension to the global RAN node ID presently set forth or standardized, such as by the 3GPP. The enhanced global RAN node ID 1600 may include the following attributes or IEs as described in the standards: “Global gNB ID”, “Global ng-eNB ID”, “Global N3IWF ID”, “Global TNGF ID”, “Global TWIF ID”, and “Global W-AGF ID”. In an embodiment, the enhanced global RAN node ID 1600 may further include a global CAG cell ID IE 1602 specified for a cell ID 814 of a CAG cell 520, which may be labeled “Global HgNB ID” although other labels are considered herein. One technical benefit is the core network 104 is able to receive a cell ID 814 from CAG cells 520, such as in a UL NAS transport message.
[0093] FIG. 17 illustrates an enhanced cause IE 1700 in an illustrative embodiment. A cause IE is described in 3GPP TS 24.501 (Release 19), which is incorporated by reference as if fully included herein, such as in section 9.11.3.2, and is used to indicate the reason why a 5GMM request from a UE 106 is rejected by the network. The enhanced cause IE 1700 as described herein may be a revision or extension to the cause IE presently set forth or standardized, such as by the 3GPP. In an embodiment, the enhanced cause IE 1700 may include a cause value 1702 (yet to be defined) to indicate an unauthorized or malicious CAG cell 1210. One technical benefit is the AMF 212, for example, may specify a cause value 1702 in a registration reject message 1206 to a UE 106 to indicate that a CAG cell 520 is an unauthorized or malicious CAG cell 1210.
[0094] Embodiment 2
[0095] In this embodiment, detection of a malicious CAG cell is performed during a UE handover (HO) procedure. The handover procedure in 5G is used to hand over a UE 106 from a source RAN node to a target RAN node, such as using the Xn or N2 reference points. Handover may be triggered, for example, due to new radio conditions, load balancing, due to a specific service, etc. The handover procedure is described in 3GPP TS 23.502, such as in section 4.9.
[0096] FIG. 18 is a message diagram illustrating detection of a malicious CAG cell during a UE handover procedure in an illustrative embodiment. FIGS. 19, 20, and 21A-21B are flow charts illustrating methods of detecting of a malicious CAG cell during a UE handover procedure in an illustrative embodiment.
[0097] In FIG. 18, a CAG information NF 804 is illustrated as a UDM / UDR that is preconfigured with CAG information 810 (e.g., ID mappings 812), such as for a target CAG cell 520, as described above. UE 106 is configured or provisioned with an allowed CAG list 524 (e.g., allowed CAG ID List = 1, 2, 3), which is a list of CAG IDs 522 the UE 106 is allowed to access. The allowed CAG list 524 is stored in UE’s non-volatile memory. During commissioning or deployment of the target CAG cell 520 (e.g., while bringing it up for the first time), the supported CAG ID(s) 522 for the target CAG cell 520 is configured in the CAG information 810 stored in UDM / UDR. In this example, the target CAG cell 520 supports a CAG ID 522 of “4”.
[0098] In this example, the UE 106 is attached to a source RAN node 304 other than the target CAG cell 520, which acts as a serving cell for the UE 106. The source RAN node 304 may comprise a gNB 306 (i.e., a source gNB 306), an ng-eNB 308 (i.e., a source ng- eNB), another CAG cell 520 (e.g., a source HgNB), etc. When the UE 106 comes into range of the target CAG cell 520, the UE 106 may receive communications from the target CAG cell 520 in the form of broadcast messages. Although the target CAG cell 520 supports a CAG ID 522 of “4”, the target CAG cell 520 broadcasts (e.g., in a SIB1 broadcast message) an unauthorized, manipulated, or wrong CAG ID 522 of “1”.
[0099] FIG. 19 is a flow chart illustrating a method 1900 performed in a UE 106 in an illustrative embodiment. UE 106 receives the broadcast message 1801 from the target CAG cell 520 (step 1902), and processes the broadcast message 1801 (i.e., the SIB1) to extract or identify one or more CAG IDs 522 provided by the target CAG cell 520 (step 1904). The UE 106 performs verification of the target CAG cell 520 in response to the broadcast message 1801 (step 1906). For example, the UE 106 compares the CAG ID(s) 522 received from the target CAG cell 520 with the allowed CAG list 524 (step 1908). When the CAG ID(s) 522 received from the target CAG cell 520 does not match the allowed CAG list 524 (i.e., the CAG ID(s) 522 is not included in the allowed CAG list 524) and verification fails, the UE 106 may remove the target CAG cell 520 from cell selection criteria 826 (step 1910), and may perform a fresh cell search to avoid connection with this target CAG cell 520. The UE 106 may also process past CAG information regarding prior interactions of the UE 106 with one or more CAG cells 520 as part of the verification (optional step 1912), which is described in more detail below. When the CAG ID(s) 522 received from the target CAG cell 520 matches the allowed CAG list 524 (i.e., the CAG ID(s) 522 is included in the allowed CAG list 524) and / or the target CAG cell 520 is valid based on the past CAG information, verification is successful and the target CAG cell 520 is verified at the UE 106 (step 1914).
[0100] In the example of FIG. 18, the CAG ID(s) 522 received from the target CAG cell 520 (i.e., CAG ID = “1”) is in the allowed CAG list 524 for the UE 106, so the UE 106 will verify the target CAG cell 520. When verification is successful, the UE 106 sends a measurement report 1802 to the source RAN node 304 (step 1916). A 5G UE, for example, is enabled to perform measurements of signals (e.g., downlink (DL) signals) received from neighboring RAN nodes, such as SS-RSRP (Synchronization Signal -Reference Signal Received Power), NR-RSSI (NR carrier Received Signal Strength Indicator), SS-RSRQ (Secondary synchronization Signal Reference Signal Received Quality), SS-SINR (SS signal -to-noise and interference ratio), etc. The UE 106 generates the measurement report
[0101] 1802 based on the measurements, and sends the measurement report 1802 to the source RAN node 304.
[0102] FIG. 20 is a flow chart illustrating a method 2000 performed in source RAN node 304 in an illustrative embodiment. The source RAN node 304 receives the measurement report 1802 from the UE 106 (step 2002). It is assumed that based on the measurement report 1802 from the UE 106, the target CAG cell 520 is a target for handover regarding the UE 106. The source RAN node 304 initiates a handover procedure regarding handover of the UE 106 to the target CAG cell 520 (step 2004). As part of the handover procedure, the source RAN node 304 sends a handover required message 1803 to AMF 212 (step 2006). The source RAN node 304 includes the cell ID 814 of the target CAG cell 520 in the handover required message 1803 to the AMF 212.
[0103] FIG. 21 A is a flow chart illustrating a method 2100 performed in the AMF 212 in an illustrative embodiment. AMF 212 receives the handover required message 1803 from the source RAN node 304 (step 2102). AMF 212 processes the handover required message
[0104] 1803 to extract or identify the cell ID 814 of the target CAG cell 520 (step 2104). In response to the handover required message 1803, AMF 212 acquires CAG information 810 regarding the target CAG cell 520 from UDM / UDR of the core network 104. To do so, AMF 212 sends a CAG information request message 1804 (e.g., Nudm_5gFemtoNRGet request message) to the UDM 218 to retrieve the CAG ID(s) 522 supported by the target CAG cell 520 (step 2106). AMF 212 includes the cell ID 814 of the target CAG cell 520 in the CAG information request message 1804 to the UDM 218.
[0105] As illustrated in FIG. 11, UDM 218 receives the CAG information request message
[0106] 1804 from the AMF 212 (step 1104). UDM 218 (or UDR 806) processes the CAG information request message 1804 to extract or identify the cell ID 814 of the target CAG cell 520 (step 1106). UDM 218 (or UDR 806) determines the CAG ID(s) 522 associated with the cell ID 814 of the target CAG cell 520 based on the pre-configured ID mapping 812 (step 1108). UDM 218 then sends a CAG information response message 1805 (e.g., Nudm_5GFemtoNRGet response message) to the AMF 212 (step 1110). UDM 218 includes the CAG ID(s) 522 associated with the cell ID 814 of the target CAG cell 520 in the CAG information response message 1805. One technical benefit is the UDM / UDR is able to provide a trusted mapping of CAG ID(s) 522 with a cell ID 814 to the AMF 212 to assist the AMF 212 in identifying potentially-malicious CAG cells.
[0107] In FIG. 21 A, AMF 212 receives the CAG information response message 1805 from the UDM 218 (step 2108). AMF 212 processes the CAG information response message 1805 to extract or identify the CAG ID(s) 522 supported by the target CAG cell 520 (step 2110). AMF 212 identifies the allowed CAG list 524 (e.g., allowed CAG ID List = 1, 2, 3) of the UE 106 (step 2112), which is a list of CAG IDs 522 the UE 106 is allowed to access. For example, AMF 212 may access a Mobility Restriction List (MRL) 1808 for the UE 106 to identify the allowed CAG list 524 (optional step 2113). AMF 212 compares the CAG ID(s) 522 supported by the target CAG cell 520 (and received from the UDM / UDR) with the CAG ID(s) 522 in the allowed CAG list 524 for the UE 106 (step 2114). When the CAG IDs 522 match and the comparison is successful (i.e., CAG ID(s) 522 in the allowed CAG list 524 is equal to the supported CAG ID(s) 522 of the target CAG cell 520), AMF 212 may proceed with the handover procedure in a conventional manner (step 2116). When the CAG IDs 522 do not match and the comparison is unsuccessful (i.e., CAG ID(s) 522 in the allowed CAG list 524 is not equal to the supported CAG ID(s) 522 of the target CAG cell 520), AMF 212 detects the target CAG cell 520 as an unauthorized or malicious CAG cell 1210 (step 2118). AMF 212 sends a handover preparation failure message 1806 to the source RAN node 304 (step 2120). AMF 212 may set a cause value in the handover preparation failure message 1806 to a value indicating that the target CAG cell 520 is unauthorized or malicious. However, any suitable error message may be used. One technical benefit is the AMF 212 is able to verify the CAG ID(s) 522 of a target CAG cell 520 to prevent handover of a UE 106 to a malicious CAG cell 1210.
[0108] In FIG. 20, the source RAN node 304 receives the handover preparation failure message 1806 from AMF 212 (step 2008), and terminates or halts the handover procedure with the target CAG cell 520 (i.e., a malicious CAG cell 1210) in response to the handover preparation failure message 1806 (step 2010). The source RAN node 304 may also exclude the target CAG cell 520 (detected as malicious) from future handover decisions (optional step 2012). One technical benefit is the source RAN node 304 will not perform handover of the UE 106 to a malicious CAG cell 1210. When the source RAN node 304 receives a handover command message from the AMF 212 (instead of a handover preparation failure), the source RAN node 304 may proceed with the handover procedure in a conventional manner.
[0109] FIG. 2 IB illustrates additional steps / details that may be performed within the AMF 212. In some examples, the source RAN node 304 may comprise a CAG cell 520 (i.e., a source CAG cell). In step 2104, AMF 212 may process the handover required message 1803 to extract or identify the cell ID 814 of the source CAG cell 520 (i.e., in addition to the target CAG cell 520). When AMF 212 sends the CAG information request message 1804 (e.g., Nudm_5gFemtoNRGet request message) to the UDM 218, the CAG information request message 1804 may be sent to further retrieve the CAG ID(s) 522 supported by the source CAG cell 520 (step 2106). For example, AMF 212 may include the cell ID 814 of the source CAG cell 520 in the CAG information request message 1804 to the UDM 218. Alternatively, AMF 212 may send a separate request message to the UDM 218 to retrieve the CAG ID(s) 522 supported by the source CAG cell 520.
[0110] Upon receipt of the CAG information response message 1805 from the UDM 218 (step 2108), AMF 212 may process the CAG information response message 1805 to further extract or identify the CAG ID(s) 522 supported by the source CAG cell 520 (step 2110). AMF 212 may compare the CAG ID(s) 522 supported by the source CAG cell 520 (and received from the UDM / UDR) with the CAG ID(s) 522 in the allowed CAG list 524 for the UE 106 (step 2122). When the CAG IDs 522 match and the comparison is successful (i.e., CAG ID(s) 522 in the allowed CAG list 524 is equal to the supported CAG ID(s) 522 of the source CAG cell 520), AMF 212 may proceed with the handover procedure in a conventional manner (step 2116). When the CAG IDs 522 do not match and the comparison is unsuccessful (i.e., CAG ID(s) 522 in the allowed CAG list 524 is not equal to the supported CAG ID(s) 522 of the source CAG cell 520), AMF 212 may detect the source CAG cell 520 as an unauthorized or malicious CAG cell 1210 (step 2124). AMF 212 may maintain information about this detected malicious CAG cell locally, and use it for future optimizations as well as statistical and security analytics purposes. One technical benefit is the AMF 212 is able to verify the CAG ID(s) 522 of a source CAG cell 520 to identify the presence of a malicious CAG cell 1210.
[0111] In order to convey certain information, certain enhancements may be made to messages used as part of the handover procedure. FIG. 22 illustrates an enhanced handover required message 1803 in an illustrative embodiment. A handover required message is described in 3GPP TS 38.413, in section 9.2.3.1. The enhanced handover required message 1803 as described herein may be a revision or extension to the handover required message presently set forth or standardized, such as by the 3 GPP. The enhanced handover required message 1803 may include the following attributes or Information Elements (IES) as described in the standards: “Message Type”, “AMF UE NGAP ID”, “RAN UE NGAP ID”, “Handover Type”, “Cause”, “Target ID”, “Direct Forwarding Path Availability”, etc. The “Target ID” IE 2202 identifies the target for handover.
[0112] FIG. 23 illustrates an enhanced “Target ID” IE 2202 in an illustrative embodiment. The “Target ID” IE 2202 is described in 3GPP TS 38.413, in section 9.3.1.25. The enhanced “Target ID” IE 2202 as described herein may be a revision or extension to the “Target ID” IE presently set forth or standardized, such as by the 3GPP. The enhanced “Target ID” IE 2202 may additionally include attributes or Information Elements (IEs) specified or defined to indicate a cell ID 814 of a CAG cell 520, which is shown in FIG. 23 as a CAG cell ID IE 2302. For example, the CAG cell ID IE 2302 may indicate the PLMN identity for the CAG cell 520, and the identifier of the CAG cell (shown as Home gNB ID in FIG. 23). One technical benefit is the enhanced handover required message 1803 may be populated with the cell ID 814 of the target CAG cell 520 for handover.
[0113] FIG. 24 illustrates an enhanced handover preparation failure message 1806 in an illustrative embodiment. A handover preparation failure message is described in 3GPP TS 38.413, in section 9.2.3.3. The enhanced handover preparation failure message 1806 as described herein may be a revision or extension to the handover preparation failure message presently set forth or standardized, such as by the 3 GPP. The enhanced handover preparation failure message 1806 may include the following attributes or Information Elements (IEs) as described in the standards: “Message Type”, “AMF UE NGAP ID”, “RAN UE NGAP ID”, “Cause”, “Criticality Diagnostics”, and “Target to Source Failure Transparent Container”. The “Cause” IE 2402 indicates the reason for a particular event for Next Generation Application Protocol (NGAP), which serves as the essential language for communication between the core network and the RAN in 5G.
[0114] FIG. 25 illustrates an enhanced “Cause” IE 2402 in an illustrative embodiment. The “Cause” IE 2402 is described in 3GPP TS 38.413, in section 9.3.1.2. The enhanced “Cause” IE 2402 as described herein may be a revision or extension to the “Cause” IE presently set forth or standardized, such as by the 3GPP. The enhanced “Cause” IE 2402 may additionally include a malicious CAG cell IEs 2502 specified or defined to indicate an unauthorized or malicious CAG cell 1210, which is shown in FIG. 25 as “Malicious Femto device / unauthorized Femto device”. One technical benefit is the enhanced handover preparation failure message 1806 may indicate a handover failure due to handover to an unauthorized or malicious CAG cell 1210.
[0115] Embodiment 3
[0116] In this embodiment, detection of a malicious CAG cell is performed during a service request procedure. The service request procedure in 5G is used when a UE 106 wants to establish a connection to the AMF 212. The service request procedure is described in 3GPP TS 23.502, such as in section 4.2.3.2. FIG. 26 is a message diagram illustrating detection of a malicious CAG cell during a service request procedure in an illustrative embodiment. FIGS. 27-28 are flow charts illustrating methods of detecting of a malicious CAG cell during a service request procedure in an illustrative embodiment.
[0117] In FIG. 26, a CAG information NF 804 is illustrated as a UDM / UDR that is preconfigured with CAG information 810 (e.g., ID mappings 812), such as for the CAG cell 520, as described above. UE 106 is configured or provisioned with an allowed CAG list 524 (e.g., allowed CAG ID List = 1, 2, 3), which is a list of CAG IDs 522 the UE 106 is allowed to access. The allowed CAG list 524 is stored in UE’s non-volatile memory. During commissioning or deployment of the CAG cell 520 (e.g., while bringing it up for the first time), the supported CAG ID(s) 522 for the CAG cell 520 is configured in the CAG information 810 stored in UDM / UDR. In this example, the CAG cell 520 supports a CAG ID 522 of “4”. When the UE 106 comes into range of the CAG cell 520, the UE 106 may receive communications from the CAG cell 520 in the form of broadcast messages. Although the CAG cell 520 supports a CAG ID 522 of “4”, the CAG cell 520 broadcasts (e.g., in a SIB1 broadcast message) an unauthorized, manipulated, or wrong CAG ID 522 of it ”
[0118] FIG. 27 is a flow chart illustrating a method 2700 performed in a UE 106 in an illustrative embodiment. The UE 106 receives the broadcast message 2601 from the CAG cell 520 (step 2702), and processes the broadcast message 2601 (i.e., the SIB1) to extract or identify one or more CAG IDs 522 provided by the CAG cell 520 (step 2704). The UE 106 performs verification of the CAG cell 520 in response to the broadcast message 2601 (step 2706). For example, the UE 106 compares the CAG ID(s) 522 received from the CAG cell 520 with the allowed CAG list 524 (step 2708). When the CAG ID(s) 522 received from the CAG cell 520 does not match the allowed CAG list 524 (i.e., the CAG ID(s) 522 is not included in the allowed CAG list 524) and verification fails, the UE 106 may remove the CAG cell 520 from cell selection criteria 826 (step 2710), and may perform a fresh cell search to avoid connection with this CAG cell 520. The UE 106 may also process past CAG information regarding prior interactions of the UE 106 with one or more CAG cells 520 as part of the verification (optional step 2712), which is described in more detail below. When the CAG ID(s) 522 received from the CAG cell 520 matches the allowed CAG list 524 (i.e., the CAG ID(s) 522 is included in the allowed CAG list 524) and / or the CAG cell 520 is valid based on the past CAG information, verification is successful and the CAG cell 520 is verified at the UE 106 (step 2714).
[0119] In this example, the CAG ID(s) 522 received from the CAG cell 520 (i.e., CAG ID = “1”) is in the allowed CAG list 524 for the UE 106, so the UE 106 will verify the CAG cell 520. When verification of a CAG cell 520 is successful, the UE 106 initiates a (NAS) service request procedure (step 2716). As part of the service request procedure, UE 106 sends NAS message in the form of a service request message 2602 to the CAG cell 520 (step 2718). The UE 106 includes the CAG ID(s) 522 provided / broadcast by the CAG cell 520 in the service request message 2602.
[0120] In response to the service request message 2602 from the UE 106, the CAG cell 520 sends a UL NAS transport message 2603 to the AMF 212 (see FIG. 26). The CAG cell 520 includes its cell ID 814 and a NAS-PDU in the UL NAS transport message 2603 to the AMF 212. The NAS-PDU contains the service request message 2602 from the UE 106.
[0121] FIG. 28 is a flow chart illustrating a method 2800 performed in the AMF 212 in an illustrative embodiment. AMF 212 receives the UL NAS transport message 2603 from the CAG cell 520 (step 2802). AMF 212 processes the UL NAS transport message 2603 to extract or identify the cell ID 814 provided by the CAG cell 520 (step 2804). AMF 212 sends a CAG information request message 2604 (e.g., Nudm_5gFemtoNRGet request message) to the UDM 218 to retrieve the CAG ID(s) 522 supported by the CAG cell 520 (step 2806). AMF 212 includes the cell ID 814 provided by the CAG cell 520 in the CAG information request message 2604 to the UDM 218.
[0122] As illustrated in FIG. 11, UDM 218 receives the CAG information request message 2604 from the AMF 212 (step 1104). UDM 218 (or UDR 806) processes the CAG information request message 2604 to extract or identify the cell ID 814 of the CAG cell 520 (step 1106). UDM 218 (or UDR 806) determines the CAG ID(s) 522 associated with the cell ID 814 of the CAG cell 520 based on the pre-configured ID mapping 812 (step 1108). UDM 218 then sends a CAG information response message 2605 (e.g., Nudm_5GFemtoNRGet response message) to the AMF 212 (step 1110). UDM 218 includes the CAG ID(s) 522 associated with the cell ID 814 of the CAG cell 520 in the CAG information response message 2605. One technical benefit is the UDM / UDR is able to provide a trusted mapping of CAG ID(s) 522 with a cell ID 814 to the AMF 212 to assist the AMF 212 in identifying potentially-malicious CAG cells.
[0123] In FIG. 28, AMF 212 receives the CAG information response message 2605 from the UDM 218 (step 2808). AMF 212 processes the CAG information response message 2605 to extract or identify the CAG ID(s) 522 supported by the CAG cell 520 (step 2810). AMF 212 identifies the allowed CAG list 524 (e.g., allowed CAG ID List = 1, 2, 3) of the UE 106 (step 2812), which is a list of CAG IDs 522 the UE 106 is allowed to access. For example, AMF 212 may access a MRL 1808 for the UE 106 to identify the allowed CAG list 524 (optional step 2813). AMF 212 compares the CAG ID(s) 522 supported by the CAG cell 520 (and received from the UDM / UDR) with the CAG ID(s) 522 in the allowed CAG list 524 for the UE 106 (step 2814). When the CAG IDs 522 match and the comparison is successful (i.e., CAG ID(s) 522 in the allowed CAG list 524 is equal to the supported CAG ID(s) 522 of the CAG cell 520), AMF 212 may proceed with the service request procedure in a conventional manner (step 2816). When the CAG IDs 522 do not match and the comparison is unsuccessful (i.e., CAG ID(s) 522 in the allowed CAG list 524 is not equal to the supported CAG ID(s) 522 of the CAG cell 520), AMF 212 detects the CAG cell 520 as an unauthorized or malicious CAG cell 1210 (step 2818). AMF 212 sends a service reject message 2606 to the UE 106 (step 2820). AMF 212 may set a cause value in the service reject message 2606 to a value indicating that the CAG cell 520 is unauthorized or malicious. However, any suitable error message may be used. One technical benefit is the AMF 212 is able to verify the CAG ID(s) of a CAG cell to prevent access of the UE 106 to a malicious CAG cell 1210.
[0124] In FIG. 27, the UE 106 receives the service reject message 2606 from the AMF 212 (step 2720), and terminates or halts the service request procedure with the malicious CAG cell 1210 (step 2722). In an embodiment, the UE 106 may remove the malicious CAG cell 1210 from cell selection criteria 826 (optional step 2724). One technical benefit is the UE 106 will not access the malicious CAG cell 1210 through the service request procedure. When the UE 106 receives a service accept message from the AMF 212 (instead of a service reject), the UE 106 may proceed with the service request procedure in a conventional manner.
[0125] Embodiment 4
[0126] In this embodiment, detection of a malicious CAG cell is performed by verification within the UE 106. FIG. 29 is a message diagram illustrating detection of a malicious CAG cell at a UE 106 in an illustrative embodiment. FIG. 30 is a flow chart illustrating a method 3000 of detecting of a malicious CAG cell at a UE 106 in an illustrative embodiment.
[0127] In FIG. 29, UE 106 is configured or provisioned with an allowed CAG list 524 (e.g., allowed CAG ID List = 1, 2, 3), which is a list of CAG IDs 522 the UE 106 is allowed to access. The allowed CAG list 524 is stored in UE’s non-volatile memory. In FIG. 30, UE 106 also stores, generates, or maintains past CAG information 2910 (step 3002), which may be stored in UE memory. The past CAG information 2910 includes information regarding prior interactions of the UE 106 with one or more CAG cells 520 (e.g., 5G NR femtocells 516). In an embodiment, the past CAG information 2910 may include a whitelist 2912 of verified CAG cells 520 previously accessed by the UE 106. For example, when a registration, handover, or service request procedure is successful via a CAG cell 520, the UE 106 may add that CAG cell 520 to the whitelist 2912 as a verified CAG cell 520. The UE 106 may also add a mapping of the cell ID 814 for the verified CAG cell 520 to the CAG ID(s) 522 supported by the verified CAG cell 520. Thus, the UE 106 may store mappings for ^-previously successful registrations, handovers, service request procedures, etc., such as in the whitelist 2912. In an embodiment, the past CAG information 2910 may include a blacklist 2914 of malicious CAG cells 1210. For example, when a registration, handover, or service request procedures is unsuccessful via a CAG cell 520 with a cause value indicating a malicious CAG cell 1210, the UE 106 may add that malicious CAG cell 1210 to the blacklist 2914. The UE 106 may also add a mapping of the cell ID 814 for the malicious CAG cell 1210 to the CAG ID(s) 522 supported by the malicious CAG cell 1210. Considering that the UE 106 may have limited storage space, past CAG information 2910 may be refreshed regularly based on memory management in implementation. Also, in some implementations, the past CAG information 2910 may be used to derive statistics and / or use local Artificial Intelligence (Al) within the UE 106 to detect any anomalies with respect to CAG IDs 522 received from CAG cells 520. In the example in FIG. 29, the CAG cell 520 supports a CAG ID 522 of “4”. When the UE 106 comes into range of the CAG cell 520, the UE 106 may receive communications from the CAG cell 520 in the form of broadcast messages. Although the CAG cell 520 supports a CAG ID 522 of “4”, the CAG cell 520 broadcasts (e.g., in a SIB1 broadcast message) an unauthorized, manipulated, or wrong CAG ID 522 of “1”.
[0128] In FIG. 30, the UE 106 receives the broadcast message 2901 from the CAG cell 520 (step 1002), and processes the broadcast message 2901 (i.e., the SIB1) to extract or identify one or more CAG IDs 522 provided by the CAG cell 520 (step 1004). The UE 106 may perform verification of the CAG cell 520 in response to the broadcast message 2901 (step 1006). As described above, the UE 106 may compare the CAG ID(s) 522 received from the CAG cell 520 with the allowed CAG list 524 (step 1008). When the CAG ID(s) 522 received from the CAG cell 520 does not match the allowed CAG list 524 (i.e., the CAG ID(s) 522 is not included in the allowed CAG list 524) and verification fails, the UE 106 may remove the CAG cell 520 from cell selection criteria 826 (step 1010), and may perform a fresh cell search to avoid connection with this CAG cell 520.
[0129] The UE 106 also processes the past CAG information 2910 as part of the verification (step 1012). To do so, the UE 106 may also compare the CAG ID(s) 522 received from the CAG cell 520 with past CAG information 2910 regarding prior interactions of the UE 106 with one or more CAG cells 520 (step 3004). For example, the UE 106 may determine whether the CAG cell 520 is recorded in the whitelist 2912 as a verified CAG cell, recorded in the blacklist 2914 as a malicious CAG cell 1210, etc. When the CAG ID(s) 522 received from the CAG cell 520 does not match / satisfy the past CAG information 2910 and verification fails, the UE 106 may remove the CAG cell 520 from cell selection criteria 826 (step 1010). When the CAG ID(s) 522 received from the CAG cell 520 matches / satisfies the past CAG information 2910, verification is successful and the CAG cell 520 is verified at the UE 106 (step 1014). When verification of a CAG cell 520 is successful, the UE 106 initiates a NAS procedure (step 3006), such as a registration procedure, a service request procedure, etc. Subsequent steps may be performed as per any of the previous embodiments where the network checks the validity of CAG ID 522 published by the CAG cell 520. One technical benefit is the UE 106 is able to verify a CAG cell 520 locally based on historical data.
[0130] Any of the various elements or modules shown in the figures or described herein may be implemented as hardware, software, firmware, or some combination of these. For example, an element may be implemented as dedicated hardware. Dedicated hardware elements may be referred to as “processors”, “controllers”, or some similar terminology. When provided by a processor, the functions may be provided by a single dedicated processor, by a single shared processor, or by a plurality of individual processors, some of which may be shared. Moreover, explicit use of the term “processor” or “controller” should not be construed to refer exclusively to hardware capable of executing software, and may implicitly include, without limitation, digital signal processor (DSP) hardware, a network processor, application specific integrated circuit (ASIC) or other circuitry, field programmable gate array (FPGA), read only memory (ROM) for storing software, random access memory (RAM), non-volatile storage, logic, or some other physical hardware component or module.
[0131] Also, an element may be implemented as instructions executable by a processor or a computer to perform the functions of the element. Some examples of instructions are software, program code, and firmware. The instructions are operational when executed by the processor to direct the processor to perform the functions of the element. The instructions may be stored on storage devices that are readable by the processor. Some examples of the storage devices are digital or solid-state memories, magnetic storage media such as a magnetic disks and magnetic tapes, hard drives, or optically readable digital data storage media.
[0132] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0133] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry);
[0134] (b) combinations of hardware circuits and software, such as (as applicable):
[0135] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware; and
[0136] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); and
[0137] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0138] Although specific embodiments were described herein, the scope of the disclosure is not limited to those specific embodiments. The scope of the disclosure is defined by the following claims and any equivalents thereof.
Claims
35Claims:
1. An apparatus comprising: a first network function of a core network, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the first network function at least to perform: receiving a request message regarding access of user equipment to a closed access group cell; acquiring pre-configured information regarding the closed access group cell from a second network function of the core network that indicates least one closed access group identifier supported by the closed access group cell; performing verification of the closed access group cell by comparing the least one closed access group identifier supported by the closed access group cell to at least one allowed closed access group identifier for the user equipment; detecting the closed access group cell as a malicious cell when the least one closed access group identifier supported by the closed access group cell does not match the at least one allowed closed access group identifier for the user equipment; and rejecting the access by the user equipment to the closed access group cell when the closed access group cell is detected as a malicious cell.
2. The apparatus of claim 1, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the first network function at least to perform: in rejecting the access by the user equipment: sending a response message to the user equipment or a radio access network node serving the user equipment, indicating that the closed access group cell is detected as a malicious cell.
3. The apparatus of claim 1, wherein: the first network function comprises an access and mobility management function of the core network.
364. The apparatus of claim 1, wherein: the second network function comprises at least one of a unified data management or a unified data repository of the core network.
5. The apparatus of claim 1, wherein: the request message comprises an uplink non-access stratum transport message comprising a registration request message for the user equipment.
6. The apparatus of claim 5, wherein: the uplink non-access stratum transport message comprises a cell identifier information element defined to indicate a cell identifier for the closed access group cell.
7. The apparatus of claim 5, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the first network function at least to perform: in rejecting the access by the user equipment: sending a registration reject message toward the user equipment indicating that the closed access group cell comprises a malicious cell.
8. The apparatus of claim 7, wherein: the registration reject message comprises a cause value defined to indicate that the closed access group cell comprises a malicious cell.
9. The apparatus of claim 1, wherein: the closed access group cell comprises a target closed access group cell for handover of the user equipment; and the request message comprises a handover message regarding handover of the user equipment from a source radio access network node to the target closed access group cell.
10. The apparatus of claim 9, wherein: the handover message comprises an information element defined to indicate a cell identifier for the target closed access group cell.
11. The apparatus of claim 9, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the first network function at least to perform: in rejecting the access by the user equipment: sending a handover preparation failure message to the source radio access network node indicating that the closed access group cell comprises a malicious cell.
12. The apparatus of claim 11, wherein: the handover preparation failure message comprises a cause information element defined to indicate that the closed access group cell comprises a malicious cell.
13. The apparatus of claim 9, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the first network function at least to perform: when the source radio access network node comprises a source closed access group cell: acquiring the pre-configured information regarding the source closed access group cell from the second network function of the core network that indicates at least one closed access group identifier supported by the source closed access group cell; and comparing the least one closed access group identifier supported by the source closed access group cell to the at least one allowed closed access group identifier for the user equipment.
14. The apparatus of claim 1, wherein: the request message comprises an uplink non-access stratum transport message comprising a service request message for the user equipment.
15. The apparatus of claim 1, wherein: the closed access group cell comprises a 5G new radio femtocell.
16. An apparatus comprising:user equipment communicatively coupled to a core network, the user equipment comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the user equipment at least to perform: receiving a broadcast message from a closed access group cell; processing the broadcast message to identify at least one closed access group identifier broadcast by the closed access group cell; sending a non-access stratum request message toward a network function of the core network indicating the closed access group cell; receiving a non-access stratum response message from the network function indicating the closed access group cell comprises a malicious cell; and prohibiting access through the closed access group cell when the closed access group cell comprises a malicious cell.
17. The apparatus of claim 16, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the user equipment at least to perform: removing the closed access group cell from cell selection criteria when the closed access group cell comprises a malicious cell.
18. The apparatus of claim 16, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the user equipment at least to perform: sending a registration request message toward the network function indicating the closed access group cell; and receiving a registration reject message from the network function indicating the closed access group cell comprises a malicious cell.3919. The apparatus of claim 18, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the user equipment at least to perform: terminating a registration procedure toward the closed access group cell when the registration reject message indicates the closed access group cell comprises a malicious cell.
20. The apparatus of claim 16, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the user equipment at least to perform: sending a service request message toward the network function indicating the closed access group cell; and receiving a service reject message from the network function indicating the closed access group cell comprises a malicious cell.
21. The apparatus of claim 20, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the user equipment at least to perform: terminating a service request procedure toward the closed access group cell when the service reject message indicates the closed access group cell comprises a malicious cell.
22. The apparatus of claim 16, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the user equipment at least to perform: storing past information regarding prior interactions of the user equipment with one or more closed access group cells; and comparing the at least one closed access group identifier broadcast by the closed access group cell to the past information.
23. The apparatus of claim 22, wherein: the past information comprises a whitelist of verified closed access group cells previously accessed by the user equipment.
24. The apparatus of claim 22, wherein:40 the past information comprises a blacklist of one or more malicious closed access group cells.
Citation Information
Patent Citations
Method and apparatus for managing CAG related procedure in wireless communication network
US20230156566A1
Method and apparatus for mitigating man in the middle attack in wireless network
US20230413057A1
False cell detection in a wireless communication network
WO2023072435A1