Fraudulent Network Session Detection Through PLMN Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Impersonation attacks in wireless communication networks, where malicious actors impersonate subscribers' traffic via rogue packet data contexts in foreign networks, leading to unauthorized data session establishment and potential roaming charges, are not effectively mitigated by existing methods like GTP firewalls due to high complexity and signaling delays.

Innovation Solution

The home network leverages Public Land Mobile Network (PLMN) information during subscriber registration to verify the authenticity of incoming data-plane session requests by comparing identifiers, allowing for the rejection of suspicious requests, thereby preventing impersonation attacks with minimal complexity and overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If GTP firewalls are used to prevent impersonation attacks, then network security is improved, but device complexity and signaling delays increase

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification function from complex GTP firewalls and relocates it to the simpler policy control node. By removing unnecessary complex monitoring components and focusing only on essential PLMN identifier comparison, the solution reduces processing complexity while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary verification of PLMN identifiers during the session establishment request processing. By checking the PLMN identifier match before allowing data session setup, the system prevents impersonation attacks early in the process without requiring complex continuous monitoring or deep packet inspection.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If GTP firewalls monitor signaling flows to prevent impersonation, then network security is improved, but signaling delays increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsignaling delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security verification during the session establishment request processing itself, rather than requiring separate post-processing or continuous monitoring phases. The PLMN identifier comparison is integrated into the existing signaling flow at the point of decision, eliminating additional signaling delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent removes the complex continuous monitoring function from GTP firewalls and replaces it with a single point verification in the policy control node. This extraction of the security check to the appropriate processing stage eliminates unnecessary signaling overhead while maintaining effective security monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If PLMN information verification is implemented during registration, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the PLMN verification logic from complex GTP firewall implementations and places it in the policy control node's existing session establishment processing. This relocation leverages existing processing structures rather than adding separate complex verification systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the verification parameter from complex packet inspection to simple PLMN identifier comparison. By focusing on comparing the PLMN identifier in the session establishment request with the registered PLMN information, the system achieves effective security verification with minimal processing complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250261255A1Identification of fraudulent network data sessions
Publication Date: 2025.08.14 T MOBILE US INC
  • US20250261255A1 patent drawing
  • US20250261255A1 patent drawing
  • US20250261255A1 patent drawing

AI summary

Systems, methods, and devices that relate to the improvement of controlling impersonating attacks from foreign networks are disclosed. In one example aspect, a method for wireless communication includes receiving, by a policy control node, a request message from a first network node. The request message comprising a first identifier indicating a first public land mobile network associated with an establishment of a bearer or a session for a terminal device. The method includes transmitting a query to a second network node in the core network to obtain a second identifier of a second public land mobile network associated with a registration of the terminal device. The method also includes accepting or rejecting, by the policy control node, the establishment of the bearer or the session for the terminal based on whether the first identifier matches the second identifier.