5G OCI Scope Validation Against NF Profiles for DoS Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G telecommunications networks, there is a vulnerability to denial of service (DoS) attacks due to the lack of validation of overload control information (OCI) scope, allowing hackers to disrupt network functions by sending false overload control information, which can cause legitimate network functions to cease communications.

Innovation Solution

A method and system for validating OCI scope information by comparing it against network function (NF) profile information obtained using target resource identification, such as through the 3gpp-Sbi-Target-apiRoot header, to ensure the authenticity of the overload control information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If overload control information is transmitted without validation, then network functions can quickly respond to overload conditions, but the network becomes vulnerable to DoS attacks

Engineering Contradiction:
Improveoverload response speedVSAvoidnetwork security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by validating the scope information in overload control information before processing it. The receiving network function checks whether the scope information matches its own identity before acting on the overload control message, preventing unauthorized messages from causing DoS attacks while maintaining fast response to legitimate overload conditions.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If OCI scope information is not validated, then network functions can process overload control messages efficiently, but false information can cause legitimate traffic to be blocked

Engineering Contradiction:
Improveoverload control processing efficiencyVSAvoidfalse overload information
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by having the receiving network function verify the scope information against its own identity before processing the overload control message. This feedback mechanism ensures that only legitimate overload control information is processed, preventing false information from blocking legitimate traffic while maintaining efficient processing of valid messages.

Inventive Principle:
Principle #23Feedback

3Reliability

If validation of OCI scope information is implemented, then network security is improved, but processing time increases

Engineering Contradiction:
ImproveOCI validation securityVSAvoidvalidation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies parameter changes by validating specific parameters (scope information) of the overload control message rather than the entire message structure. This selective validation approach improves security by checking critical identification parameters while minimizing processing time compared to full message validation.

Inventive Principle:
Principle #35Parameter changes

4Device complexity

If no validation mechanism is used, then network functions operate with minimal overhead, but unauthorized nodes can send false overload information

Engineering Contradiction:
Improvenetwork function complexityVSAvoidunauthorized overload control
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by implementing validation only for the scope information field rather than validating the entire overload control message structure. This localized validation approach adds minimal complexity to network functions while effectively preventing unauthorized nodes from sending false overload information.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4399901B1Reducing likelihood of successful dos attacks by validating overload control information
Publication Date: 2025.09.10 ORACLE INT CORP
  • EP4399901B1 patent drawingFigure 1
  • EP4399901B1 patent drawingFigure 2
  • EP4399901B1 patent drawingFigure 3

AI summary

The subject matter described herein includes a method for reducing the likelihood of successful denial of service (DoS) attacks by validating overload control information (OCI) scope information against network function (NF) profile information obtained using target resource identification information. The method includes receiving a service based interface (SB I) request message, obtaining, from the SBI request message, target resource identification information, obtaining NF profile information using the target resource identification information and storing the NF profile information, receiving an SBI response message including overload control information and scope information for the overload control information, using the stored NF profile information to determine whether the scope information for the overload control information is valid, and, in response to determining that the scope information for the overload control information is invalid, rejecting the SBI response message.