Diameter Edge Agent Time Distance Security for Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security countermeasures in mobile communications networks cannot apply time and distance checks for outbound roaming subscribers, as Diameter edge agents lack knowledge of the last update location timestamp initiated in the home network, limiting their ability to detect suspicious activity when subscribers first roam to a visited network.
Innovation Solution
A method and system where the Diameter edge agent receives an ingress message from a non-home network, sends a routing information request to the home subscriber server to retrieve the most recent attachment timestamp, calculates the transit time, and compares it to a predefined minimum transit time to determine if the message is suspicious, rejecting or alerting on excessive times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a DEA is used to determine transit time using timestamps from update location request messages in visited non-home networks, then transit time calculation is enabled for roaming subscribers between non-home networks, but the DEA cannot apply time and distance security countermeasures when subscribers initially move from home network to visited network due to lack of knowledge about last update location timestamp in home network
Solution Approach 1:
The patent introduces an intermediary mechanism where the DEA queries the HSS for the last update location timestamp when a subscriber first roams from home network to visited network. This intermediary information retrieval step bridges the information gap, allowing the DEA to obtain the missing timestamp data from HSS without intercepting core network signaling, thereby enabling security countermeasures for outbound roaming subscribers.
2Reliability
If the DEA requests last update location timestamp from HSS for every outbound roaming subscriber, then complete timestamp information is obtained for security analysis, but additional signaling messages and processing overhead are introduced
Solution Approach 1:
The patent applies preliminary action by having the DEA query the HSS for the last update location timestamp at the moment a subscriber first roams from home network to visited network. This timely retrieval ensures the timestamp information is captured before the subscriber moves further, enabling immediate security analysis without requiring continuous querying or complex tracking mechanisms.
3Object-affected harmful factors
If time distance security countermeasures are applied to all ingress Diameter messages from non-home networks, then fraudulent activities are detected and prevented, but legitimate roaming communications may be blocked due to false positives
Solution Approach 1:
The patent uses parameter changes by comparing the calculated transit time against dynamically determined thresholds or ranges that account for different scenarios (e.g., different countries, transportation modes, network conditions). This allows the system to adapt the security criteria to specific contexts, reducing false positives while maintaining detection of actual fraud through configurable parameters rather than rigid fixed thresholds.
Data Source
Figure 1
Figure 2
Figure 2
AI summary
A method includes receiving an ingress Diameter message related to a mobile subscriber from a MME located in a non-home network, sending a RIR message containing a mobile subscriber identifier to a HSS in a home network of the mobile subscriber, receiving identification information identifying a MME in the home network that conducted a most recent attachment of the mobile subscriber, utilizing the identification information to send an IDR message containing the mobile subscriber identifier to the identified MME, receiving an IDA message containing attachment timestamp data corresponding to the most recent attachment of the mobile subscriber in the home network, determining a transit time using the UE attachment timestamp data and timestamp information corresponding to the ingress Diameter message, and analyzing the transit time to determine if the ingress Diameter message is to be designated as a suspicious ingress message.