Edge Device Access Filtering for Unauthorized UE Core Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized user equipment (UE) can pose a security threat and impact network entities in telecommunications systems by accessing core networks, leading to potential malicious activity and increased network load.

Innovation Solution

An edge device or system associated with the access network identifies and manages communication channels for unauthorized UE, determining presence of malicious activity and controlling access to prevent unauthorized access to core network entities, thereby improving network security and capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If unauthorized UE is allowed to access core network, then communication service can be provided, but network security is compromised and malicious activity increases

Engineering Contradiction:
Improveaccess service availabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

An edge device is introduced as an intermediary between unauthorized UE and core network entities. The edge device receives requests from unauthorized UE, determines available communication channels, and provides access information without allowing direct core network access. This mediator enables service provision while maintaining security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network access function is segmented into edge-level handling and core network functions. Unauthorized UE access management is separated from core network authentication and service provision. The edge device handles channel determination and access control, while core network entities remain protected from direct unauthorized access attempts.

Inventive Principle:
Principle #1Segmentation

2Reliability

If unauthorized UE access attempts are blocked at core network, then security is maintained, but network capacity is reduced and downstream entities are impacted

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security filtering and access channel determination are performed preliminarily at the edge device before requests reach core network entities. The edge device identifies unauthorized UE, determines available communication channels, and provides access information in advance, preventing unnecessary core network entity involvement and preserving network capacity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security filtering function is extracted from core network entities and placed at the edge device. Unauthorized UE management, including channel determination and access control, is separated from core network authentication and service provision functions. This extraction protects downstream entities from security-related processing load.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If edge device manages unauthorized UE access, then network security is improved and capacity preserved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidedge device functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The edge device performs multiple functions including receiving requests from unauthorized UE, determining available communication channels, providing access information, and detecting malicious activity. By consolidating these diverse functions in a single edge device rather than distributing them across multiple core network entities, the solution achieves improved security and capacity while managing complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250280354A1Access filtering for unauthoirized devices by an edge device
Publication Date: 2025.09.04 T MOBILE US INC
  • US20250280354A1 patent drawing
  • US20250280354A1 patent drawing
  • US20250280354A1 patent drawing

AI summary

Techniques for managing a communication session for an unauthorized user equipment (UE) are described herein. A telecommunications system can implement an edge computing device to determine a communication channel that enables an unauthorized UE to communicate with an emergency service provider and/or receive instructions to receive one or more services. The edge computing device can determine that the UE is not associated with a mobile network operator or is otherwise untraceable, and configure a first communication channel between the UE and emergency service provider or a second communication channel for exchanging data over an access network independent of using a core network of the telecommunications system.