Access Network Device Identifier Matching for Terminal Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Terminal devices with simple functions and poor security are vulnerable to attacks, leading to potential denial-of-service (DoS) scenarios where attackers control multiple devices to overload servers, causing service disruptions.
Innovation Solution
An access network device performs matching between identifiers such as GUTI, S-TMSI, and hash values to identify and restrict access of terminal devices exhibiting abnormal behavior, using a security function network element to determine and indicate abnormal behavior, and releasing connections to reduce load and prevent attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If terminal devices with simple functions are used, then device complexity is reduced and ease of operation is improved, but security protection deteriorates making devices vulnerable to attacks
Solution Approach 1:
The patent introduces an access network device as an intermediary between terminal devices and the core network. This intermediary monitors terminal behavior, identifies abnormal patterns (such as botnet activity), and restricts access before attacks reach the core network, thereby protecting the system without requiring complex security features in the terminal devices themselves
Solution Approach 2:
The access network device performs preliminary security checks and behavior analysis on terminal devices before they can initiate attacks. By identifying and restricting abnormal behavior in advance (such as detecting botnet-controlled devices), the system prevents attacks before they occur, maintaining security without adding complexity to terminal devices
2Reliability
If access control measures are implemented to restrict abnormal terminal devices, then network security is improved, but access control complexity increases
Solution Approach 1:
The access network device serves as a mediator that handles complex security analysis and access control decisions. It monitors terminal behavior, communicates with the core network to obtain device information, and makes access decisions based on abnormal behavior detection, thereby centralizing security functions without increasing complexity at other network levels
Solution Approach 2:
The system implements feedback mechanisms where the access network device continuously monitors terminal behavior, compares it against normal patterns, and adjusts access decisions based on detected anomalies. The core network provides feedback about terminal device information, enabling dynamic access control based on real-time behavior analysis rather than static complex rules
3Measurement precision
If multiple identifiers are matched to identify abnormal devices, then identification accuracy is improved, but processing time increases
Solution Approach 1:
The access network device performs partial matching by focusing on key identifiers and abnormal behavior patterns rather than analyzing all possible device attributes. It identifies suspicious terminals based on critical security-relevant information and abnormal behavior indicators, achieving sufficient identification accuracy without exhaustive processing of all device parameters
Solution Approach 2:
The system performs preliminary filtering by obtaining basic terminal device information from the core network before detailed behavior analysis. This preliminary action allows the access network device to quickly identify potentially suspicious devices using readily available information, reducing the need for time-consuming deep analysis of all device identifiers
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This application provides a method for restricting access of a terminal device, and an apparatus. The method includes: receiving, by an access network device, a first identifier that is from a terminal device, where the first identifier is used to identify the terminal device; and if the first identifier matches a second identifier, restricting, by the access network device, access of the terminal device, where the second identifier is used to identify a terminal device having abnormal behavior. Based on the solution, the access network device pre-records the second identifier of the terminal device having the abnormal behavior. When there is a terminal device sending the first identifier to the access network device to request to establish a connection or request to resume a connection, the access network device first determines, based on the first identifier, whether the first identifier matches the second identifier recorded by the access network device. If the first identifier matches the second identifier, it indicates that the terminal device corresponding to the first identifier is the terminal device having the abnormal behavior. Therefore, the access network device restricts access of the terminal device, so as to effectively control an attack from the terminal device.