Mac address based validation for network element protection
By validating MAC addresses during the Fl setup procedure using predefined symmetric keys and a database of known addresses, the method strengthens network security and reliability against unauthorized access and cyber-attacks in 3GPP networks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- RAKUTEN SYMPHONY INC
- Filing Date
- 2024-11-27
- Publication Date
- 2026-06-04
AI Technical Summary
Existing 3GPP networks lack robust security measures to prevent unauthorized access and mitigate risks of network congestion and cyber-attacks during the Fl setup procedure, which is crucial for ensuring the integrity and reliability of network elements like gNodeB and gNB-CU.
Incorporating MAC address validation in the Fl setup request message, using predefined symmetric keys for encryption and decryption, and maintaining a database of known MAC addresses at the gNB-CU to authenticate network elements, thereby allowing or rejecting setup requests based on recognized MAC addresses.
Enhances network security by preventing unauthorized access, mitigating network congestion, and protecting against cyber-attacks, while ensuring reliable and efficient communication between gong-DU and gNB-CU.
Smart Images

Figure US2024057590_04062026_PF_FP_ABST
Abstract
Description
Attorney Docket No.: 6487-327PCTMAC ADDRESS BASED VALIDATION FOR NETWORK ELEMENT PROTECTION FIELD
[0001] The present disclosure relates to mac address based validation for network element protection.BACKGROUND
[0002] The 3rd Generation Partnership Project (3GPP) is a protocol for telecommunications, which provides standardization and interoperability between mobile networks having different architectures, for example 5G networks. Within these networks, Media Access Control (MAC) addresses are utilized to uniquely identify network elements, which facilitates communication within a network.
[0003] Network element components, also referred to as nodes, include Radio Units (gang- RU) and Distributed Units (gong-DU), these being integral components to, for example, 5G architecture. The gang-RU functions relate to radio transmission and reception, while the gong- DU functions relate to lower-layer processing of radio signals, to ensure efficient, flexible, and reliable deployment of mobile networks.
[0004] An Fl setup process is a procedure which establishes a logical connection between the gang-DU and the Central Unit (gNB-CU). The connection involves exchanging setup messages to ensure proper interoperability and configuration between the network elements.SUMMARY
[0005] A method of connecting via Fl setup procedure to a network, including receiving of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”). The method of connecting via Fl setup procedure to a network including extracting and decrypting a Media AccessControl (“MAC”) address from the Fl setup request message using a predefined symmetricAttorney Docket No.: 6487-327PCT key. The method of connecting via F 1 setup procedure to a network including storing the MAC address at the gNB-CU for validation purposes. The method of connecting via Fl setup procedure to a network including validating the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown. The method of connecting via Fl setup procedure to a network including sending of an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining that the MAC address is known.
[0006] A non-transitory computer-readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations including receiving of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”). The non-transitory computer-readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations including extracting and decrypting a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key. The non- transitory computer-readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations including storing the MAC address at the gNB-CU for validation purposes. The non-transitory computer- readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations including validating the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown. The non-transitory computer-readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations including sending of an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining the MAC address is known.Attorney Docket No.: 6487-327PCT
[0007] A Fl setup system, configured to receive a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”). The Fl setup system, configured to extract and decrypt a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key. The Fl setup system, configured to store the MAC address at the gNB-CU for validation purposes. The Fl setup system, configured to validate the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown. The Fl setup system, configured to send an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining the MAC address is known.BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Features, aspects, and advantages of certain exemplary embodiments of the disclosure will be described below with reference to the accompanying drawings, in which like reference numerals denote like elements, and wherein:
[0009] Fig. lA-Fig. 1C is a diagram of an example Fl setup request / response, an Fl setup request / response with MAC address, and an Fl setup request / response without MAC address, respectively, in accordance with some embodiments.
[0010] Fig. 2 is an example of a high-level functional block diagram of a processor-based system, in accordance with some embodiments.
[0011] Fig. 3 is a diagram of a system for a Fl setup procedure, in accordance with some embodiments.DETAILED DESCRIPTION
[0012] The following detailed description of example embodiments refers to the accompanying drawings. The foregoing disclosure provides illustration and description but is not intended to be exhaustive or to limit the implementations to the precise form disclosed.Attorney Docket No.: 6487-327PCTModifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations. Further, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). Additionally, in the flowcharts and descriptions of operations provided below, it is understood that one or more operations may be omitted, one or more operations may be added, one or more operations may be performed simultaneously (at least in part), and the order of one or more operations may be switched, as long as these modifications may not affect the resulting scope of the invention.
[0013] It will be apparent that systems and / or methods, described herein, may be implemented in different forms of hardware, software, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the implementations. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code. It is understood that software and hardware may be designed to implement the systems and / or methods based on the description herein.
[0014] Even though particular combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of possible implementations. In fact, many of these features may be combined in ways not specifically recited in the claims and / or disclosed in the specification. Although each dependent claim listed below may directly depend on only one claim, the disclosure of possible implementations includes each dependent claim in combination with every other claim in the claim set.
[0015] No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items and may be used interchangeably with “one or more.” Where onlyAttorney Docket No.: 6487-327PCT one item is intended, the term “one” or similar language is used. Also, as used herein, the terms “has,” “have,” “having,” “include,” “including,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Furthermore, expressions such as “at least one of [A] and [B]”, “[A] and / or [B]”, or “at least one of [A] or [B]” are to be understood as including only A, only B, or both A and B. The foregoing disclosure provides illustration and description but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations.
[0016] The present disclosure relates to a method / system to enhance the security and reliability of the Fl setup procedure in telecommunication networks, for example, 3GPP networks, by incorporating a MAC address as an attribute in the Fl setup request message. The gong-DU or gang-RU includes an encrypted MAC address in the request, which the gNB-CU decrypts and validates against a database of known MAC addresses. The nodes of distributed units and radio units are also known as gNodeB, gNB, generalized Node B, or Next-Gen Node B. If the MAC address is recognized, the setup proceeds. In at least one embodiment of the present disclosure, if the MAC address is not recognized, the setup does not proceed, and the request is able to be logged and stored as a secure file in a database in a storage / memory 304 / 420 for security auditing, quarantining, and compliance.
[0017] The gong-Distributed Unit (“DU”) is a component in the 5G base station architecture, responsible for the lower layers of the radio interface protocol stack, e.g., the RLC (Radio Link Control), MAC (Medium Access Control), and parts of the PHY (Physical) layer. The gong- DU is also responsible for functions such as scheduling, which dynamically allocates radio resources to different UEs based on respective requirements and network conditions, managing time and frequency resources to optimize throughput and mitigate latency and lag. The gong-Attorney Docket No.: 6487-327PCTDU manages HARQ (Hybrid Automatic Repeat Request), a mechanism which ensures reliable data transmission by combining error detection and correction, enhancing the robustness of the communication link. Additionally, the gong-DU supports advanced antenna technologies like beamforming and MIMO (Multiple Input Multiple Output), which improve signal quality and network capacity by directing signals towards users and utilizing multiple antennas for transmission and reception. The gong-DU handles real-time processing tasks such as link adaptation, power control, and interference management, ensuring optimal performance in varying radio conditions. The gong-DU is able to be deployed closer to cell sites to reduce latency. The gong-DU communicates with the gNB-CU (Central Unit) over the Fl interface, allowing for the separation of control and user plane functions, which provides greater flexibility and scalability in the network.
[0018] The gang-Radio Unit (“RU”) is a component of the 5G base station and focuses on the radio frequency (RF) functions. The gang-RU is responsible for RF transmission and reception, conversion of digital signals from the gong-DU into RF signals for transmission over the air and vice versa, involving modulation, up conversion, amplification, and filtering of the signals. The gang-RU is directly connected to the antennas, ensuring minimal signal loss and high-quality transmission, and supports various antenna configurations, including massive MIMO, which enhances network capacity and coverage. The gang-RU also performs RF processing tasks such as digital pre-distortion (DPD) to linearize power amplifiers, reducing signal distortion and improving efficiency, and beamforming, which focuses the RF energy in specific directions to enhance signal strength and reduce interference. By handling these RF functions, the gang-RU is able to maintain the quality and efficiency of the radio link, with its proximity to the antennas minimizing signal degradation and contributing to the overall performance and reliability of the 5G network.
[0019] This method / system of the present disclosure helps to prevent unauthorized devicesAttorney Docket No.: 6487-327PCT from accessing the network, mitigates risks of network congestion, and protects against malicious cyber- attacks. The method / system of the present disclosure also includes mechanisms for logging, secure communication, and retry limitations to prevent denial-of- service attacks.
[0020] Fig. lA-Fig. 1C is a diagram of an example Fl setup request / response, an Fl setup request / response with MAC address, and an Fl setup request / response without MAC address, respectively, in accordance with some embodiments.
[0021] The Fl setup process, or F1AP, provides a procedure to transfer application-level data, as shown in the example code as seen in Fig. 2, for proper Fl interfacing between the gong- DU and gNB-CU. While a Transport Network Layer (“TNL”) association is active, the Fl setup process 100 is the first procedure to be initiated. In at least one embodiment of the present disclosure, the Fl setup process 100 utilizes signaling related with non-user equipment (“UE”). During the Fl setup process 100, received application-level configuration data is substituted for existing data in the two nodes. In at least one embodiment of the disclosure, during the Fl setup process 100, all connected signaling connections in the two nodes, i.e., gong-DU / rang- RU and gNB-CU, is erased or reset, and re-initializes any contexts related to the Fl AP UE.
[0022] The present disclosure relates to a Fl connection request procedure 104 in the Fl setup process 100, which adds a MAC address 112 as an attribute to help assure the validity and integrity of the network element(s) in order to overcome network congestion by rejecting requests from unauthorized network hosts.
[0023] In the present disclosure, the gNB-CU 106 is not receiving any information about the request originator's, the gong-DU 102, MAC address to identify or track the valid network element(s) in the Fl connection request / message 104. In at least one embodiment of the present disclosure, an Information Element (“IE”) is added to the Fl connection request / message 104. In at least one embodiment of the present disclosure, the IE includes information on the MACAttorney Docket No.: 6487-327PCT address / MAC addresses of the lower layer network element(s). In at least one embodiment, the gNB-CLJ 106 is able to store the MAC address in a database in a memory 304 / 420 for validation purposes throughout the Fl setup process 100 for a connection request in a future instance. In at least one embodiment of the present disclosure the MAC addresses / MAC addresses able to be stored in the database in the memory 304 / 420 include a database for authorized MAC addresses which complete the Fl setup process 100B, and database for unauthorized MAC addresses unable to complete the Fl setup process 100C.
[0024] Thus, in at least one embodiment of the present disclosure, in a new Fl connection request / message 104 is received in a future instance, the gNB-CU 106 is able to cross-validate the Fl connection request message 104 against the MAC address stored in the memory 304 / 420. In at least one embodiment of the present disclosure, based on the MAC address 112 being known, the Fl setup process 100 is able to be completed. In at least one embodiment of the present disclosure, based on the MAC address 112 being unknown, the Fl setup process 100 is not continue, and the Fl connection request / message 104 is able to be logged and stored in a database in accordance with the above embodiments. In at least one embodiment of the present disclosure, along with the Fl connection request / message 104 being discarded, a cause code is provided indicating why the particular Fl connection request / message 104 is being discarded.
[0025] Based on the Fl setup process 100, the MAC address-based validation is able to increase network element integrity and authenticity. In at least one embodiment of the present disclosure, predefined symmetric keys for encrypting and decrypting data are utilized to encrypt the MAC address as a further safeguard to prevent malicious denial-of-service / distributed denial-of-service (“DOS / DDoS”) attacks or man-in-the-middle (“MITM”) attacks from overwhelming network resources by rouge network elements. In at least one embodiment of the present disclosure, the predefined symmetric keys include the following algorithms:Attorney Docket No.: 6487-327PCTAdvanced Encryption Standard (AES) which uses 128-bit, 192-bit, and 256-bit key encryption, Data Encryption Standard (DES) which uses 56-bit key encryption, Triple DES (3DES) which apples the aforementioned DES algorithm in three layers to each block of data, ChaCha20, and Blowfish having a variable length key of 32 bits to 448 bits.
[0026] In at least one embodiment of the present disclosure, an IE is able to pass the encrypted MAC address as an attribute in the Fl setup request.
[0027] The exchange of application-level data for the gong-DU and gNB-CU to properly interact on the Fl interface to provide encryption of a MAC address occurs during the Fl setup process 100. By comparing the initial Fl connection request / message 104 with the stored or learned MAC addresses in the MAC address database 304 / 420, gNB-CU will first determine whether the Fl connection request / message 104 originates from a new or existing network element. In at least one embodiment of the present disclosure, the connection proceeds if the Fl connection request / message 112 / 114 originates from a recognized network element. Both the gong-DU 102 and gNB-CU 106 ends are able to employ a pre-defined symmetric key for encryption and decryption purposes as disclosed above.
[0028] In at least one embodiment of the present disclosure, if the MAC address in the Fl connection request / message 116 / 118 (See Fig. 1C) is not able to be validated at the gNB-CU side during the Fl setup process 100, the setup is logged, stored, or discarded as aforementioned. Further, in at least one embodiment of the present disclosure, an Fl setup failure with the relevant cause value is generated and logged and / or stored. In at least one embodiment of the present disclosure, the relevant cause value is able to be triggered as an alert to notify a user. In at least one embodiment of the present disclosure, if a request from the same MAC address is received within a predetermined waiting time period after the initial rejection, the Fl connection request / message is automatically rejected again. The predetermined waiting time period, which is able to be 10-20 milliseconds, permits the system to update in the eventAttorney Docket No.: 6487-327PCTFl setup process should have been completed, but was rejected for another reason, for example, network traffic due to a higher layer network element’s Fl connection request / message being prioritized over a lower layer network element’s Fl connection request / message. The autoreject mechanism may also assist to reduce the risk of connection requests flooding the network and interrupting service, or preventing further connections to authorized devices. Additionally, the gong-DU 102 waits a predetermined waiting time period before retrying the Fl setup process towards the same gNB-CU 106 if the “Fl setup failure message’’ includes the “Time to Wait Information Element” “(IE”).
[0029] By delivering the designated information to the gNB-CU in an Fl connection request / message 104, the gong-DU 102 initiates the Fl setup process 100. The relevant data is included in an Fl connection response / message 108, which is sent by the gNB-CU in response. In at least one embodiment of the present disclosure, the gNB-CU is able to utilize the gong-DU Name IE as a human-readable name of the gong-DU if present in the Fl connection request / message 104. In at least one embodiment of the present disclosure, the gNB-CU is able to consider if a gong-DU Served Cells List IE is present in the Fl connection request / message 104.
[0030] Fig. 2 is a high-level functional block diagram of a processor-based system, in accordance with some embodiments.
[0031] In some embodiments, system 200 is a general-purpose computing device including a hardware processing circuitry 202 and a non-transitory, computer-readable storage medium 204. Storage medium 204, amongst other things, is encoded with, i.e., stores, computer instructions 206, i.e., a set of executable instructions such as an Al recommended auto-assurance policy manager. Execution of instructions 206 by hardware processing circuitry 202 represents (at least in part) a tool which implements a portion or all the methods, such as methods 100 and 200, described herein inAttorney Docket No.: 6487-327PCT accordance with one or more embodiments (hereinafter, the noted processes and / or methods).
[0032] Hardware processing circuitry 202 is electrically coupled to a computer- readable storage medium 204 via a bus 208. Hardware processing circuitry 202 is further electrically coupled to an I / O interface 210 by bus 208. A network interface 212 is further electrically connected to processing circuitry 202 via bus 208. Network interface 212 is connected to a network 214, so that processing circuitry 202 and computer-readable storage medium 204 connect to external elements via network 214. Processing circuitry 202 is configured to execute computer instructions 206 encoded in computer-readable storage medium 204 in order to cause system 200 to be usable for performing the noted processes and / or methods, such as methods 100 and 200, of FIGS. 1 and 2. In one or more embodiments, processing circuitry 202 is a central processing unit (CPU), a multi-processor, a distributed processing system, an application specific integrated circuit (ASIC), and / or a suitable processing unit.
[0033] In one or more embodiments, computer-readable storage medium 204 is an electronic, magnetic, optical, electromagnetic, infrared, and / or a semiconductor system (or apparatus or device). For example, computer-readable storage medium 204 includes a semiconductor or solid-state memory, a magnetic tape, a removable computer diskette, a random-access memory (RAM), a read-memory (ROM), a rigid magnetic disk, and / or an optical disk. In one or more embodiments using optical disks, computer-readable storage medium 204 includes a compact disk-read memory (CD- ROM), a compact disk-read / write (CD-R / W), and / or a digital video disc (DVD).
[0034] In one or more embodiments, storage medium 204 stores computer instructions 206 configured to cause system 200 to be usable for performing a portion or the noted processes and / or methods. In one or more embodiments, storage medium 204 furtherAttorney Docket No.: 6487-327PCT stores information, such as an Al recommended auto-assurance policy engine which facilitates performing the noted processes and / or methods.
[0035] System 200 includes I / O interface 210. I / O interface 210 is coupled to external circuitry. In one or more embodiments, I / O interface 210 includes a keyboard, keypad, mouse, trackball, trackpad, touchscreen, cursor direction keys and / or other suitable I / O interfaces are within the contemplated scope of the disclosure for communicating information and commands to processing circuitry 202.
[0036] System 200 further includes network interface 312 coupled to processing circuitry 202. Network interface 212 allows system 200 to communicate with network 214, to which one or more other computer systems are connected. Network interface 212 includes wireless network interfaces such as BLUETOOTH, WIFI, WIMAX, GPRS, or WCDMA; or wired network interfaces such as ETHERNET, USB, or IEEE- 864. In one or more embodiments, noted processes and / or methods, are implemented in two or more system 200.
[0037] System 200 is configured to receive information through I / O interface 210. The information received through I / O interface 310 includes one or more of instructions, data, and / or other parameters for processing by processing circuitry 202. The information is transferred to processing circuitry 202 via bus 208. System 200 is configured to receive information related to a UI, such as UI 218, through I / O interface 210. The information is stored in computer-readable medium 204 as user interface (UI) 208.
[0038] In some embodiments, the noted processes and / or methods are implemented as a standalone software application for execution by processing circuity. In some embodiments, the noted processes and / or methods are implemented as a software application that is a part of an additional software application. In some embodiments,Attorney Docket No.: 6487-327PCT the noted processes and / or methods is implemented as a plug-in to a software application.
[0039] In some embodiments, the processes are realized as functions of a program stored in a non-transitory computer readable recording medium. Examples of a non- transitory computer-readable recording medium include, but are not limited to, external / removable and / or internal / built-in storage or memory unit, e.g., one or more of an optical disk, such as a DVD, a magnetic disk, such as a hard disk, a semiconductor memory, such as a ROM, a RAM, a memory card, and the like.
[0040] Fig. 3 illustrates an exemplary embodiment of a device 300. As shown in FIG. 3, the device 300 may include a processor 310, a memory 320, a storage component 330, an input component 340, an output component 350, a communication interface 360, and a bus 370.
[0041] The processor 310, as used herein, means any type of computational circuit that may comprise hardware elements and software elements. The processor 310 may be embodied as a multi-core processor, a single core processor, or a combination of one or more multi-core processors and one or more single core processors, a distributed processing system, or the like. The processor 310 may be a Central Processing Unit (CPU) a graphics processing unit (GPU), an accelerated processing unit (APU), an application-specific integrated circuit (ASIC), or another type of processing component.
[0042] Memory 320 includes a random-access memory (RAM), a read only memory (ROM), and / or another type of dynamic or static storage device (e.g., a flash memory, a magnetic memory, and / or an optical memory) that stores information and / or instructions for use by processor 310. The memory 320 comprises machine-readable instructions which are executable by the processor 310. These machine-readable instructions when executed by the processor 310 causes the processor 310 to perform method steps of an exemplary embodiment described herein.Attorney Docket No.: 6487-327PCT
[0043] Storage component 330 stores information and / or software related to the operation and use of the device 300. For example, storage component 330 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optic disk, and / or a solid-state disk), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cartridge, a magnetic tape, and / or another type of non-transitory computer-readable medium, along with a corresponding drive.
[0044] Input component 340 is configured to receive information, such as via user input. For example, the input component 340 may include, but not be limited to, a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, and / or a microphone. Additionally, or alternatively, the input component 340 may include a sensor for sensing information (e.g., a global positioning system (GPS), an accelerometer, a gyroscope, and / or an actuator).
[0045] Output component 350 is configured to provide output information from the device 300. For example, the output component 350 may be, but not limited to, a display, a speaker, and / or one or more light-emitting diodes (LEDs).
[0046] Communication interface 360 is an interface that provides a communication connection to other devices. The connection by the communication interface 360 can be a wired connection, a wireless connection, or a combination of wired and wireless connections, and can be a direct connection or an indirect connection via a communication network that exists between other devices. In other words, the standard of the communication interface 360 is not limited.
[0047] The bus 370 acts as an interconnect between the processor 310, the memory 320, the storage component 330, the input component 340, the output component 350, and the communication interface 360 of the device 300.
[0048] The number and arrangement of components shown in Figure3 are provided as an example. In practice, device 300 may include additional components, fewer components, different components, or differently arranged components than those shown in Figure 3.Attorney Docket No.: 6487-327PCTAdditionally, or alternatively, a set of components (e.g., one or more components) of device 300 may perform one or more functions described as being performed by another set of components of device 300.
[0049] Supplemental Note 1
[0050] A method of connecting via Fl setup procedure to a network, including receiving of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”). The method of connecting via Fl setup procedure to a network including extracting and decrypting a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key. The method of connecting via Fl setup procedure to a network including storing the MAC address at the gNB-CU for validation purposes. The method of connecting via Fl setup procedure to a network including validating the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown. The method of connecting via Fl setup procedure to a network including sending of an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining that the MAC address is known.
[0051] Supplemental Note 2
[0052] The method of connecting via Fl setup procedure to a network according to Supplemental Note 1 , further including adding the MAC address of a network element to an Fl setup request message.
[0053] Supplemental Note 3
[0054] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1 or 2, further including encrypting the MAC address using a predefined symmetric key before adding the MAC address to the Fl setup request message.
[0055] Supplemental Note 4
[0056] The method of connecting via Fl setup procedure to a network according toAttorney Docket No.: 6487-327PCTSupplemental Notes 1-3, further including discarding the Fl setup request in response to determining that the MAC address is unknown.
[0057] Supplemental Note 5
[0058] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1-4, further including sending an Fl setup failure message with a cause code in response to determining that the MAC address is unknown.
[0059] Supplemental Note 6
[0060] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1-5, wherein the network element is a gong-Distributed Unit (“DU”).
[0061] Supplemental Note 7
[0062] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1-6, wherein the network element is a gang-Radio Unit (“RU”).
[0063] Supplemental Note 8
[0064] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1-7, further including storing the MAC address at the gNB-CU for future validation, and updating the database of known MAC addresses with the new MAC address in response to the Fl setup procedure being successful.
[0065] Supplemental Note 9
[0066] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1-8, further including waiting for a predefined predetermined time period before retrying the Fl setup procedure in response to the Fl setup failure message having a Time to Wait Information Element (“IE”), and logging the time and reason for the Fl setup failure for future analysis.
[0067] Supplemental Note 10
[0068] The method of connecting via Fl setup procedure to a network according toAttorney Docket No.: 6487-327PCTSupplemental Notes 1-9, further including comparing the MAC address with a database of known MAC addresses stored at the gNB-CU, and generating an alert in response to determining the MAC address is not found in the database of known MAC addresses.
[0069] Supplemental Note 11
[0070] The method of connecting via Fl setup procedure to a network according to Supplemental Notes 1-10, further including displaying the alert which further indicates a cause value of an Fl setup failure message.
[0071] Supplemental Note 12
[0072] A non-transitory computer-readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations, including receiving of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”). The method of connecting via Fl setup procedure to a network including extracting and decrypting a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key. The method of connecting via Fl setup procedure to a network including storing the MAC address at the gNB-CU for validation purposes. The method of connecting via Fl setup procedure to a network including validating the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown. The method of connecting via Fl setup procedure to a network including sending of an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining that the MAC address is known.
[0073] Supplemental Note 13
[0074] The non-transitory computer-readable media including computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations according to Supplemental Note 12, including adding the MAC address of a network element to an Fl setup request message, and encrypting the MAC address using a predefinedAttorney Docket No.: 6487-327PCT symmetric key before adding the MAC address to the Fl setup request message.
[0075] Supplemental Note 14
[0076] The non-transitory computer-readable media according to Supplemental Notes 12 or 13 computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations according to Supplemental Notes 12 or 13, including discarding the Fl setup request in response to determining that the MAC address is unknown.
[0077] Supplemental Note 15
[0078] A Fl setup system, configured to receive of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”). The Fl setup system, configured to extract and decrypt a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key. The Fl setup system, configured to store the MAC address at the gNB-CU for validation purposes. The Fl setup system, configured to validate the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown. The Fl setup system, configured to send an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining that the MAC address is known.
[0079] Supplemental Note 16
[0080] The Fl setup system according to Supplemental Note 15, configured to add the MAC address of a network element to an Fl setup request message.
[0081] Supplemental Note 17
[0082] The Fl setup system according to Supplemental Notes 15 or 16, configured to discard the Fl setup request in response to determining that the MAC address is unknown.
[0083] Supplemental Note 18
[0084] The Fl setup system according to Supplemental Notes 15-17, further configured to encrypt the MAC address using a predefined symmetric key before adding the MAC address to the Fl setup request message.Attorney Docket No.: 6487-327PCT
[0085] Supplemental Note 19
[0086] The F 1 setup system according to Supplemental Notes 15-18, further configured to send an Fl setup failure message with a cause code in response to determining that the MAC address is unknown.
[0087] Supplemental Note 20
[0088] The non-transitory computer-readable media according to Supplemental Notes 12 or 13 computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations according to Supplemental Notes 12-14, including sending an Fl setup failure message with a cause code in response to determining that the MAC address is unknown.
[0089] The foregoing outlines features of several embodiments so that those skilled in the art may better understand the aspects of the present disclosure. Those skilled in the art should appreciate that they may readily use the present disclosure as a basis for designing or modifying other processes and structures for carrying out the same purposes and / or achieving the same advantages of the embodiments introduced herein. Those skilled in the art should also realize that such equivalent constructions do not depart from the spirit and scope of the present disclosure, and that they may make various changes, substitutions, and alterations herein without departing from the spirit and scope of the present disclosure.
Claims
Attorney Docket No.: 6487-327PCTCLAIMSWhat is claimed is:
1. A method of connecting via Fl setup procedure to a network, comprising: receiving of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”); extracting and decrypting a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key; storing the MAC address at the gNB-CU for validation purposes; validating the MAC address against stored MAC addresses to determine whether the MAC address is known; and sending an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining that the MAC address is known.
2. The method of claim 1, further comprising adding the MAC address of a network element to an Fl setup request message.
3. The method of claim 1, further comprising encrypting the MAC address using a predefined symmetric key before adding the MAC address to the Fl setup request message.
4. The method of claim 1, further comprising discarding the Fl setup request in response to determining that the MAC address is unknown.
5. The method of claim 1, further comprising sending an Fl setup failure message with a cause code in response to determining that the MAC address is unknown.
6. The method of claim 2, wherein the network element is a gong-Distributed Unit (“DU”).
7. The method of claim 2, wherein the network element is a gang-Radio Unit (“RU”).
8. The method of claim 1, further comprising: storing the MAC address at the gNB-CU for future validation; andAttorney Docket No.: 6487-327PCT updating the database of known MAC addresses with the new MAC address in response to the Fl setup procedure being successful.
9. The method of claim 1, further comprising: waiting for a predetermined time period before retrying the Fl setup procedure in response to the Fl setup failure message having a Time to Wait Information Element (“IE”); and logging the time and reason for the Fl setup failure for future analysis.
10. The method of claim 1, further comprising: comparing the MAC address with a database of known MAC addresses stored at the gNB-CU; and generating an alert in response to determining the MAC address is not found in the database of known MAC addresses.
11. The method of claim 10, further comprising: displaying the alert which further indicates a cause value of an Fl setup failure message.
12. A non-transitory computer-readable media comprising computer-readable instructions stored thereon, which in response to being executed causes a Fl setup system to perform operations comprising: receiving of a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”); extracting and decrypting a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key; storing the MAC address at the gNB-CU for validation purposes; validating the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown; and sending of an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining the MAC address is known.
13. The non-transitory computer-readable media according to claim 12, further comprising: adding the MAC address of a network element to an Fl setup request message; andAttorney Docket No.: 6487-327PCT encrypting the MAC address using a predefined symmetric key before adding the MAC address to the Fl setup request message.
14. The non-transitory computer-readable media according to claim 12, further comprising: discarding the Fl setup request in response to determining that the MAC address is unknown.
15. A Fl setup system, configured to: receive a Fl setup request message at a gNB (“Node”)-Central Unit (“CU”); extract and decrypt a Media Access Control (“MAC”) address from the Fl setup request message using a predefined symmetric key; store the MAC address at the gNB-CU for validation purposes; validate the MAC address against stored MAC addresses to determine whether the MAC address is known or unknown; and send an Fl setup response message by the gNB-CU allowing the Fl setup procedure to proceed in response to determining the MAC address is known.
16. The Fl setup system according to claim 15, further configured to add the MAC address of a network element to an Fl setup request message.
17. The Fl setup system according to claim 15, further configured to discard the Fl setup request in response to determining that the MAC address is unknown.
18. The Fl setup system according to claim 15, further configured to encrypt the MAC address using a predefined symmetric key before adding the MAC address to the Fl setup request message.
19. The Fl setup system according to claim 15, further configured to send an Fl setup failure message with a cause code in response to determining that the MAC address is unknown.Attorney Docket No.: 6487-327PCT20. The non-transitory computer-readable media according to claim 12, further comprising sending an Fl setup failure message with a cause code in response to determining that the MAC address is unknown.