Distributed NAD Functions for Abnormal UE Detection in vRAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The virtualized Radio Access Network (vRAN) architecture in cellular communication systems lacks effective methods to detect abnormal User Equipment (UE) behavior, particularly malicious activities, due to unclear segregation of network functions and vulnerabilities that may go undetected.
Innovation Solution
Implementing a Network Anomaly Detection (NAD) function in each vRAN that collaborates with others to generate a global model of UE behavior using machine learning models, such as K-means clustering, to predict abnormal behavior by exchanging partial models and utilizing temporary identifiers to track UE mobility across vRANs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a traditional base station architecture is used, then processing software can be deployed at each base station level, but the architecture is not scalable and security updates must be pushed to all eNBs in different physical locations
Solution Approach 1:
The patent segments the base station functionality into distributed RAN nodes and a centralized security management entity. Each RAN node operates semi-autonomously with local detection capabilities, while the security entity coordinates global security policies and model distribution, enabling scalable deployment without requiring updates to every individual base station
Solution Approach 2:
The patent introduces a new architectural dimension by adding a centralized security management layer that operates above the distributed RAN nodes. This layered approach allows security updates and model improvements to be propagated vertically through the architecture rather than requiring horizontal updates across all base stations, enhancing scalability
2Measurement precision
If a centralized security detection system is implemented, then a global view of UE behavior can be achieved, but the detection load and processing requirements increase significantly
Solution Approach 1:
The patent merges detection capabilities at multiple levels: local RAN nodes perform initial anomaly detection using lightweight models, while the centralized security entity aggregates results and maintains global behavior models. This hierarchical merging allows the system to achieve global detection accuracy without concentrating all processing load in one location
Solution Approach 2:
The patent implements partial detection action at distributed RAN nodes using simplified models, reserving full detection capabilities for the centralized entity. This partial action approach allows local nodes to handle routine monitoring with reduced processing load while maintaining the option for comprehensive analysis when needed
3Adaptability or versatility
If machine learning models are trained on local data only, then detection can be performed locally, but the system cannot detect unknown vulnerabilities or abnormal behaviors that occur across different RANs
Solution Approach 1:
The patent implements feedback loops where detection results, UE behavior patterns, and model performance metrics from distributed RAN nodes are continuously fed back to the centralized security entity. This feedback mechanism enables the system to learn from cross-RAN patterns, detect emerging threats, and propagate improved detection strategies back to local nodes, enhancing detection coverage without losing local information
Data Source
AI summary
Systems and methods for detecting abnormal User Equipment (UE) behavior in a cellular communications system are disclosed. In some embodiments, a method of operation of a first Network Anomaly Detection (NAD) function associated with a first Radio Access Network (RAN) in a cellular communications system comprises, during a period of time, obtaining information regarding UEs served by the first RAN, detecting that a particular UE has moved from the first RAN to a second RAN, and sending at least some of the information regarding the particular UE to a second NAD function associated with the second RAN. The method further comprises producing a trained partial model of UE behavior for the first RAN, sending corresponding information to the second NAD function, receiving information regarding a trained partial model of UE behavior for the second RAN, generating a trained global model, and performing a prediction of abnormal UE behavior based thereon.


