Mobility Management Element APN Restriction Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In next-generation mobile communication networks, the Serving Gateway (SGW) may incorrectly determine whether to send a Modify Bearer Request to the Packet Data Network (PDN) gateway, leading to incorrect maximum Access Point Name (APN) restriction values being sent, which can result in security threats to private PDNs due to unauthorized PDN connections.

Innovation Solution

A method where a mobility management element receives APN restriction information from another mobility management element, obtains the maximum APN restriction value, and determines whether to establish a new PDN connection, ensuring accurate APN restriction values are used by the PGW to prevent unauthorized connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the SGW determines whether to send the Modify Bearer Request, then the SGW can control the signaling flow, but the target mobility management element cannot obtain the correct maximum APN restriction value

Engineering Contradiction:
ImproveSGW control over signaling flowVSAvoidmaximum APN restriction value
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The source mobility management element performs preliminary action by determining the maximum APN restriction value before the mobility management procedure and includes it in the context information transfer to the target mobility management element. This ensures the target element has the correct value before needing to make PDN connection decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The source mobility management element acts as an intermediary by receiving the maximum APN restriction value from the PGW and forwarding it to the target mobility management element through context information transfer. This intermediary role ensures the value is transmitted even when the SGW does not send the Modify Bearer Request.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the target mobility management element sends an incorrect maximum APN restriction value to the PGW, then the PDN connection establishment may be simplified, but unauthorized PDN connections are allowed creating security threats

Engineering Contradiction:
ImprovePDN connection establishment speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The maximum APN restriction value is determined in advance by the source mobility management element before the mobility management procedure occurs. This preliminary determination ensures the correct value is available to the target element, enabling both fast PDN connection establishment and proper security enforcement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The target mobility management element uses the received maximum APN restriction value to make informed decisions about PDN connection requests. The element compares the requested APN against the restriction value, providing feedback control that prevents unauthorized connections while allowing legitimate ones.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3404965B1Setting maximum access point name restriction information
Publication Date: 2020.07.08 HUAWEI TECH CO LTD
  • EP3404965B1 patent drawingFigure 1
  • EP3404965B1 patent drawingFigure 2
  • EP3404965B1 patent drawingFigure 3

AI summary

A method, a system, a network element, and a gateway for processing access point name restriction information are disclosed. The method includes: a second mobility management element receives first access point name restriction information from a first mobility management element; the second mobility management element obtains maximum access point name restriction information according to the first access point name restriction information, so that a packet data network gateway determines to or refuses to establish a new packet data network gateway connection. With the present invention, the second mobility management element may receive the access point name restriction information sent by the first mobility management element or pre-stored access point name restriction information sent by a serving gateway, and then obtain the maximum access point name restriction information according to the received access point name restriction information. In this way, the packet data network gateway can determine to or refuse to establish a new packet data network gateway connection, therefore improving the security of private packet data network gateways.