Cross-Network Access Control for Blocking Malicious UE Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G communication systems face vulnerabilities to distributed denial of service (DDoS) attacks when malicious user equipment (UE) repeatedly attempts authentication across non-public networks (NPN) and public land mobile networks (PLMN), overwhelming network resources and compromising security.

Innovation Solution

Implementing a method where network elements in the first network record authentication failures and send prohibition signals to block malicious UE access to the second network, using session management to store and enforce access restrictions, thereby reducing network load and ensuring security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the UE is allowed to access both NPN and PLMN networks with full authentication capabilities, then network accessibility and service continuity are improved, but the network becomes vulnerable to DDoS attacks and authentication failures occur

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the second network (NPN) proactively identify malicious UEs through authentication failure detection and send prohibition information to the first network (PLMN) before these UEs can launch DDoS attacks. The PLMN network element stores this prohibition information and blocks malicious UEs in advance, preventing potential security incidents rather than reacting after attacks occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If malicious UE authentication attempts are blocked at the second network, then the second network security is improved, but the first network cannot prevent DDoS attacks originating from its registered UEs

Engineering Contradiction:
Improvesecond network securityVSAvoidDDoS attack capability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback by establishing a security information exchange mechanism between the first and second networks. When the second network detects authentication failures or malicious behavior, it sends prohibition information back to the first network. The first network then uses this feedback to block the malicious UE's access, creating a closed-loop security system where each network's security actions inform and strengthen the other's defenses.

Inventive Principle:
Principle #23Feedback

3Duration of action of moving object

If the UE frequently initiates authentication requests to the second network, then service continuity is maintained, but network load increases and DDoS attacks occur

Engineering Contradiction:
Improveservice continuityVSAvoidnetwork load
Core Design Contradiction:
Duration of action of moving objectVSLoss of energy

Solution Approach 1:

The patent applies preliminary anti-action by having the first network proactively block UEs that have been identified as malicious by the second network, before these UEs can generate excessive authentication requests and cause DDoS attacks. By storing and enforcing prohibition information from the second network, the first network prevents malicious UEs from consuming network resources through frequent authentication attempts, thus reducing overall network load while maintaining service continuity for legitimate UEs.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3893536B1Method, device, and system for increasing cross-network access security
Publication Date: 2026.03.11 HUAWEI TECH CO LTD
  • EP3893536B1 patent drawingFigure 1
  • EP3893536B1 patent drawingFigure 2
  • EP3893536B1 patent drawingFigure 3

AI summary

Embodiments of this application provide a method, a device, and a system for enhancing cross-network access security. In a scenario in which UE accesses a second network via a first network, in the embodiments of this application, a security event (for example, an authentication status) of the UE is recorded in the second network and a decision result is determined for a subsequent behavior of the UE. The decision result is notified to the first network, to help the first network perform security processing on the subsequent behavior of the UE for the second network, to implement security collaboration between the first network and the second network. Malicious UE is managed near a source in the first network, so that communication load of the first network and the second network is reduced, and network security of the second network is also ensured.