AMF Timer Control for Duplicate UE Onboarding Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face challenges in preventing malicious access during user equipment (UE) onboarding, particularly in non-public networks, which can be vulnerable to attacks like distributed denial-of-service (DDoS) due to lack of effective registration management.
Innovation Solution
Implementing a method and apparatus that involve the Access and Mobility Management Function (AMF) and Equipment Identity Register (EIR) entities to store UE information and use timers to manage UE registration requests, rejecting duplicate or potentially malicious registrations by comparing UE identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If registration management is simplified to enable rapid UE onboarding, then onboarding speed and ease of access are improved, but network security and vulnerability to malicious attacks deteriorate
Solution Approach 1:
The system performs preliminary actions by storing UE identification information and starting timers before actual registration completes. This allows the network to proactively identify and block duplicate registration attempts from the same UE within the onboarding window, preventing malicious attacks before they can compromise network security while still allowing legitimate rapid re-onboarding.
Solution Approach 2:
The system implements feedback mechanisms where the AMF checks stored UE information against new registration requests and provides feedback by accepting or rejecting registrations. The timer-based mechanism provides time-bound feedback that maintains security without permanently blocking legitimate UEs that complete onboarding within the expected time window.
2Reliability
If registration requests are strictly verified to prevent malicious access, then network security is improved, but legitimate UE onboarding may be blocked and network accessibility deteriorates
Solution Approach 1:
The system applies dynamic verification where the strictness of registration checks changes based on timing. Within the timer window, strict verification blocks potential malicious duplicates. After the timer expires or upon successful onboarding completion, the system dynamically adapts to allow new registrations, ensuring legitimate UEs are not permanently blocked while maintaining security during the vulnerable onboarding period.
Solution Approach 2:
The system changes the parameter of registration acceptance based on the timer state and UE information matching. When a duplicate UE identifier is detected within the timer window, registration is rejected. When the timer expires or no duplicate is found, registration is accepted, allowing the system to adapt between security and accessibility based on real-time conditions.
3Reliability
If UE information is stored indefinitely to maintain security, then protection against malicious access is improved, but system resource consumption and complexity increase
Solution Approach 1:
The system implements periodic action through timer-based expiration of stored UE information. Instead of indefinite storage, the system stores UE identification information only for a limited time period corresponding to the onboarding window. This periodic cleanup automatically reduces system complexity and resource consumption while maintaining security protection during the critical onboarding period when malicious attacks are most likely.
Data Source
AI summary
A 5th generation (5G) or 6th generation (6G) communication system for supporting a higher data transmission rate is provided. Also, a method performed by an access and mobility management function (AMF) entity is provided. The method includes after performing a deregistration process with respect to user equipment (UE) registration for onboarding of a first UE, storing information about the first UE and starting a timer, while the timer is running, receiving, from a second UE, a UE registration request message for onboarding of the second UE, and based on the stored information, rejecting the UE registration request message, when the first UE and the second UE are the same as each other.


