5G UE Mobility Tracking for Spoofing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network architecture is vulnerable to network spoofing attacks, where attackers can fake a mobile device's location, leading to interception of communications, and existing solutions like firewall appliances are inefficient in detecting such anomalies due to the need for extensive administrative efforts to verify device location across multiple cities.

Innovation Solution

Implementing a method for historical 5G user equipment (UE) mobility tracking and security screening using a network data aggregation node that generates mobility patterns from UE registration data, including location, timestamp, and type allocation code, and using a security edge protection proxy (SEPP) to determine and block anomalous registrations based on these patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall appliances use velocity checks to detect location anomalies, then security detection capability is improved, but administrative complexity increases due to the need to enter distance data for every major city

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex velocity check logic and city distance data management from the firewall appliance and relocates it to a separate network data aggregation node. This node automatically collects and processes mobility data from multiple network functions, eliminating the need for manual administrative entry of distance data while maintaining the security detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a network data aggregation node as an intermediary between the firewall appliance and the various network functions (AMF, SMF, UPF). This intermediary automatically gathers location and timing data from multiple sources, processes it to determine mobility patterns, and provides the information needed for velocity checks without requiring manual configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual velocity checks are implemented across multiple cities, then location verification accuracy is improved, but time consumption increases due to extensive administrative efforts

Engineering Contradiction:
Improvelocation verification accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the network data aggregation node continuously collect and process mobility data from multiple network functions before security verification is needed. Location, timing, and mobility pattern information are pre-computed and stored, allowing rapid verification during security checks without time-consuming manual administrative efforts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by having the network data aggregation node continuously gather mobility data from AMF, SMF, and UPF functions as devices normally operate. This ongoing data collection and processing maintains up-to-date mobility patterns without interrupting normal network operations or requiring periodic manual updates.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If network spoofing detection is enhanced, then security against interception is improved, but system complexity increases due to additional verification mechanisms

Engineering Contradiction:
Improvesecurity against interceptionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the network data aggregation node to perform multiple functions: collecting data from various network functions (AMF, SMF, UPF), processing mobility patterns, performing velocity checks, and providing security verification. This multi-functional approach enhances security against spoofing without requiring separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by enabling the network data aggregation node to automatically collect mobility data from network functions, process it to determine device mobility patterns, and perform velocity checks without manual intervention. The system self-configurest by gathering necessary data from existing network operations and automatically computing verification information.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11751056B2Methods, systems, and computer readable media for 5G user equipment (UE) historical mobility tracking and security screening using mobility patterns
Publication Date: 2023.09.05 ORACLE INT CORP
  • US11751056B2 patent drawing
  • US11751056B2 patent drawing
  • US11751056B2 patent drawing

AI summary

A method for historical 5G user equipment (UE) mobility tracking and security screening includes receiving, at a network data aggregation node including at least one processor, UE registration data from 5G network functions (NFs) as UEs connect to different network locations. The method further includes aggregating, at the network node, registration data for individual UEs from the 5G NFs to produce mobility patterns for the UEs. The method further includes receiving, at the network node and from a 5G NF located in a home network of a UE, a request for a mobility pattern of the UE in response to receiving a message for effecting a new registration for the UE. The method further includes responding to the request by transmitting the mobility pattern to the 5G NF located in the home network of the UE.