Application Function Session Termination for Abusive User Equipment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Abusing or misbehaving user equipment can continue to access and cause unnecessary network data traffic and malicious signaling in mobile telecommunications networks, even after being identified, leading to resource consumption and potential network attacks.

Innovation Solution

A method and device that determine if a user equipment's access pattern is predefined as abusive or misbehaving, triggering a control message to terminate the session and block further access, using a control plane interface between the Application Function and the Packet Core Network, employing Diameter protocol messages to manage session binding and termination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the AF excludes the identified UE from the AF, then the AF is protected from abusive access, but the UE can still access the PCN and cause unnecessary signaling and network data traffic

Engineering Contradiction:
ImproveAF protection from abusive accessVSAvoidunnecessary signaling and network data traffic from PCN
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The harmful access patterns are extracted and blocked at the PCN level by terminating the default bearer, separating the abusive UE's data plane access from the AF's control plane services. This prevents the UE from generating unnecessary signaling and network traffic while maintaining AF protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The PCN acts as an intermediary between the UE and AF, implementing a control mechanism that terminates bearers based on abuse detection. This intermediary function blocks harmful traffic at the network core level, preventing it from reaching the AF while still allowing the AF to exclude the UE from its services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the AF allows the UE to access the PCN, then network resources are utilized, but abusing UEs can continue to cause malicious signaling and consume network resources

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidmalicious signaling and resource consumption
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The system changes the network state parameter by terminating the default bearer when abuse is detected. This parameter change (bearer termination) dynamically adjusts network resource allocation, allowing legitimate UE to utilize network resources while preventing abusing UE from consuming resources through malicious signaling.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements a feedback mechanism where the AF monitors UE behavior, identifies abusive patterns, and triggers bearer termination at the PCN level. This feedback loop enables the network to respond dynamically to UE behavior, maintaining resource utilization for legitimate users while blocking resource consumption by abusing UEs.

Inventive Principle:
Principle #23Feedback

3Reliability

If the AF monitors and identifies abusing UEs, then network security is improved, but additional signaling and processing overhead is introduced

Engineering Contradiction:
Improvenetwork securityVSAvoidsignaling and processing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary monitoring and identification of abusive UE patterns at the AF level before full-scale network-wide blocking is implemented. This preliminary action allows the system to detect security threats early and trigger bearer termination only when necessary, improving network security while minimizing unnecessary signaling and processing overhead for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3269200B1Technique for handling accesses of user equipments
Publication Date: 2022.08.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3269200B1 patent drawingFigure 1
  • EP3269200B1 patent drawingFigure 2
  • EP3269200B1 patent drawingFigure 3

AI summary

A technique for handling an access from a user equipment (110) accessing an application function (150) is provided. As to a method aspect of the technique, the access is received via a packet core network (140) of a mobile telecommunications network (100).The application function (150) determines that the access from the user equipment (110) fulfills a predefined access pattern. The application function (150) triggers sending of a control message to the packet core network (140) in response to the determination. The control message controls the packet core network (140) to terminate a session with the user equipment (110).