Dynamic Terminal Classification for Mobile Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for controlling terminal access in mobile communications are inflexible and inadequate, particularly in scenarios where terminals are easily compromised and used in DDoS attacks, as they rely on pre-defined access classes in SIM cards and lack sufficient flexibility in terminal classification.

Innovation Solution

A method for determining class information based on terminal function, user, device, and location data, allowing a core network element to assign classes dynamically and control access at a more granular level, reducing the need for extensive control signaling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access control is performed using pre-defined access classes in SIM cards, then terminal classification can be implemented, but flexibility in terminal classification is insufficient

Engineering Contradiction:
Improveflexibility in terminal classificationVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic terminal classification by allowing the core network element to determine class information based on terminal function information, user information, device information, and location information. This enables the classification to adapt to different scenarios and terminal states, resolving the contradiction between flexibility and complexity by making the classification system dynamic rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters used for classification from fixed access classes in SIM cards to multiple dimensions including terminal function information, user information, device information, and location information. This parameter transformation enables more flexible terminal classification while maintaining manageable system complexity through structured information processing.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If access control is performed at SIM card level with pre-written access classes, then terminal classification is achieved, but the classification method is not sufficiently flexible for diverse attack scenarios

Engineering Contradiction:
Improveclassification flexibilityVSAvoidattack control effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the classification criteria into multiple independent dimensions: terminal function information, user information, device information, and location information. This segmentation allows the system to flexibly combine different criteria to address various attack scenarios, improving both classification flexibility and attack control effectiveness by enabling targeted responses to different types of threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic classification that can adapt to different attack scenarios by evaluating multiple information dimensions. The core network element can determine class information dynamically based on the specific situation, enabling the system to respond effectively to diverse attack types while maintaining classification flexibility.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If detailed terminal information is collected and processed for classification, then classification flexibility is improved, but control signaling overhead increases

Engineering Contradiction:
Improveterminal classification flexibilityVSAvoidsignaling overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges the collection and processing of terminal information into the existing network registration and service request procedures. By integrating class information determination into these existing signaling flows, the system achieves flexible terminal classification without adding excessive signaling overhead, as the information is gathered and processed as part of routine network operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12425861B2Method for determining class information and apparatus
Publication Date: 2025.09.23 HUAWEI TECH CO LTD
  • US12425861B2 patent drawing
  • US12425861B2 patent drawing
  • US12425861B2 patent drawing

AI summary

This application provides example methods and apparatuses for determining class information. One example method includes sending, by a security detection function network element, a subscription data collection event to a mobility management network element, where the subscription data collection event includes a collection range and a reporting condition. The security detection function network element can then receive a data collection service response message from the mobility management network element, where the data collection service response message includes first class information and first traffic data corresponding to the first class information, and where the first traffic data meets the reporting condition. The security detection function network element can then determine abnormal class information based on the first traffic data. The security detection function network element can then send the abnormal class information to a policy control network element.