Cross-Network Access Control for Blocking Malicious UE Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G communication systems face vulnerabilities to distributed denial of service (DDoS) attacks when malicious user equipment (UE) repeatedly attempts authentication across non-public networks (NPN) and public land mobile networks (PLMN), overwhelming network resources and compromising security.
Innovation Solution
Implementing a method where network elements in the first network record authentication failures and send prohibition signals to block malicious UE access to the second network, using session management to store and enforce access restrictions, thereby reducing network load and ensuring security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the UE is allowed to access both NPN and PLMN networks with full authentication capabilities, then network accessibility and service continuity are improved, but the network becomes vulnerable to DDoS attacks and authentication failures occur
Solution Approach 1:
The patent applies preliminary action by having the second network (NPN) proactively identify malicious UEs through authentication failure detection and send prohibition information to the first network (PLMN) before these UEs can launch DDoS attacks. The PLMN network element stores this prohibition information and blocks malicious UEs in advance, preventing potential security incidents rather than reacting after attacks occur.
2Reliability
If malicious UE authentication attempts are blocked at the second network, then the second network security is improved, but the first network cannot prevent DDoS attacks originating from its registered UEs
Solution Approach 1:
The patent implements feedback by establishing a security information exchange mechanism between the first and second networks. When the second network detects authentication failures or malicious behavior, it sends prohibition information back to the first network. The first network then uses this feedback to block the malicious UE's access, creating a closed-loop security system where each network's security actions inform and strengthen the other's defenses.
3Duration of action of moving object
If the UE frequently initiates authentication requests to the second network, then service continuity is maintained, but network load increases and DDoS attacks occur
Solution Approach 1:
The patent applies preliminary anti-action by having the first network proactively block UEs that have been identified as malicious by the second network, before these UEs can generate excessive authentication requests and cause DDoS attacks. By storing and enforcing prohibition information from the second network, the first network prevents malicious UEs from consuming network resources through frequent authentication attempts, thus reducing overall network load while maintaining service continuity for legitimate UEs.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of this application provide a method, a device, and a system for enhancing cross-network access security. In a scenario in which UE accesses a second network via a first network, in the embodiments of this application, a security event (for example, an authentication status) of the UE is recorded in the second network and a decision result is determined for a subsequent behavior of the UE. The decision result is notified to the first network, to help the first network perform security processing on the subsequent behavior of the UE for the second network, to implement security collaboration between the first network and the second network. Malicious UE is managed near a source in the first network, so that communication load of the first network and the second network is reduced, and network security of the second network is also ensured.