Control Plane Protection via Communication Context Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for wireless communication networks lack flexible protection mechanisms against signaling attacks and anomalies, particularly in the control plane, due to differences in protocols compared to TCP/IP networks, and struggle to maintain network consistency during malicious message handling.

Innovation Solution

A method for protecting control plane functionality in wireless communication networks involves maintaining communication contexts for mobile terminals, determining if received messages conform to protection rules, and handling them according to a set protection policy, allowing for flexible and timely defense against malicious attacks and errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message validation and protection mechanisms are implemented in wireless network control plane, then network security and reliability are improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvecontrol plane securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing protection rules and communication context validation mechanisms before malicious attacks occur. The system pre-defines expected message patterns, protocol states, and communication contexts, allowing it to quickly validate incoming messages against these pre-established criteria rather than analyzing each message from scratch, thus improving security while limiting the increase in processing complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary protection layer between the mobile terminal and the network core. This intermediary mechanism validates messages, checks communication contexts, and filters malicious traffic before it reaches critical network functions. By placing this protective intermediary layer, the system achieves enhanced security without requiring complex modifications throughout the entire network architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If protection rules are enforced for all incoming messages, then network protection against attacks is improved, but message processing time and network latency increase

Engineering Contradiction:
Improveattack protectionVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively enforcing protection rules based on communication context and message type. Rather than applying the same level of validation to all messages, the system adjusts the depth of validation according to the established communication context, allowing legitimate messages to pass through with minimal checking while subjecting suspicious or unauthorized messages to more rigorous validation, thus balancing security with processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

By pre-establishing communication contexts and expected message patterns during normal operation, the system creates a baseline for rapid validation. When messages arrive, they are compared against these pre-defined expectations, allowing most legitimate messages to be processed quickly while only requiring deeper analysis of messages that deviate from the established patterns.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If communication contexts are maintained and validated for each mobile terminal, then message interpretation accuracy is improved, but memory usage and processing overhead increase

Engineering Contradiction:
Improvemessage interpretation accuracyVSAvoidmemory resources
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments communication context information into discrete, manageable units associated with each mobile terminal and communication session. Rather than maintaining a single large context structure, the system divides context data into modular components that can be independently stored, validated, and managed. This segmentation allows for more efficient memory utilization while maintaining the precision needed for accurate message interpretation within each contextual framework.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10219158B2Method and devices for protection of control plane functionality
Publication Date: 2019.02.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10219158B2 patent drawing
  • US10219158B2 patent drawing
  • US10219158B2 patent drawing

AI summary

This disclosure relates to methods and apparatuses for protection of control plane functionality of a network node of a communications network providing wireless communication to a mobile terminal. The network node is configured to support control plane signaling with the mobile terminal. A communication context for the mobile terminal is maintained, wherein the communication context is associated with a control signaling message exchange between the mobile terminal and the network node. One method includes establishing, for a received message, a communication context to which it belongs; determining, in relation to information in the established communication context, the received message to be a message conforming to a protection rule or a message violating a protection rule; and handling the message in accordance with rules of a protection policy. Related network nodes, computer programs, and computer program products are disclosed.