Distributed NAD Functions for Abnormal UE Detection in vRAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The virtualized Radio Access Network (vRAN) architecture in cellular communication systems lacks effective methods to detect abnormal User Equipment (UE) behavior, particularly malicious activities, due to unclear segregation of network functions and vulnerabilities that may go undetected.

Innovation Solution

Implementing a Network Anomaly Detection (NAD) function in each vRAN that collaborates with others to generate a global model of UE behavior using machine learning models, such as K-means clustering, to predict abnormal behavior by exchanging partial models and utilizing temporary identifiers to track UE mobility across vRANs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a traditional base station architecture is used, then processing software can be deployed at each base station level, but the architecture is not scalable and security updates must be pushed to all eNBs in different physical locations

Engineering Contradiction:
ImprovescalabilityVSAvoidsoftware deployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the base station functionality into distributed RAN nodes and a centralized security management entity. Each RAN node operates semi-autonomously with local detection capabilities, while the security entity coordinates global security policies and model distribution, enabling scalable deployment without requiring updates to every individual base station

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new architectural dimension by adding a centralized security management layer that operates above the distributed RAN nodes. This layered approach allows security updates and model improvements to be propagated vertically through the architecture rather than requiring horizontal updates across all base stations, enhancing scalability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If a centralized security detection system is implemented, then a global view of UE behavior can be achieved, but the detection load and processing requirements increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing load
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent merges detection capabilities at multiple levels: local RAN nodes perform initial anomaly detection using lightweight models, while the centralized security entity aggregates results and maintains global behavior models. This hierarchical merging allows the system to achieve global detection accuracy without concentrating all processing load in one location

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements partial detection action at distributed RAN nodes using simplified models, reserving full detection capabilities for the centralized entity. This partial action approach allows local nodes to handle routine monitoring with reduced processing load while maintaining the option for comprehensive analysis when needed

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If machine learning models are trained on local data only, then detection can be performed locally, but the system cannot detect unknown vulnerabilities or abnormal behaviors that occur across different RANs

Engineering Contradiction:
Improvedetection coverageVSAvoidUE behavior information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements feedback loops where detection results, UE behavior patterns, and model performance metrics from distributed RAN nodes are continuously fed back to the centralized security entity. This feedback mechanism enables the system to learn from cross-RAN patterns, detect emerging threats, and propagate improved detection strategies back to local nodes, enhancing detection coverage without losing local information

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12108315B2Systems and methods for detection of abnormal UE behavior
Publication Date: 2024.10.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12108315B2 patent drawing
  • US12108315B2 patent drawing
  • US12108315B2 patent drawing

AI summary

Systems and methods for detecting abnormal User Equipment (UE) behavior in a cellular communications system are disclosed. In some embodiments, a method of operation of a first Network Anomaly Detection (NAD) function associated with a first Radio Access Network (RAN) in a cellular communications system comprises, during a period of time, obtaining information regarding UEs served by the first RAN, detecting that a particular UE has moved from the first RAN to a second RAN, and sending at least some of the information regarding the particular UE to a second NAD function associated with the second RAN. The method further comprises producing a trained partial model of UE behavior for the first RAN, sending corresponding information to the second NAD function, receiving information regarding a trained partial model of UE behavior for the second RAN, generating a trained global model, and performing a prediction of abnormal UE behavior based thereon.