Gateway Node IP Reassignment Control for Over-Billing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems, particularly 3GPP networks, are vulnerable to over-billing attacks where hackers deceive the system into assigning IP addresses to malicious servers, leading to unintended charges for unsuspecting users, as existing stateful firewalls cannot detect or block such attacks without additional proprietary hardware.

Innovation Solution

Implementing a method where the gateway node detects deactivation of data transportation connections and sends 'Destination Unreachable' messages to the firewall, deleting state information and preventing reassignment of IP addresses for a predefined period, thereby blocking malicious traffic and preventing over-billing attacks without requiring additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stateful firewalls are used to control data transportation, then data security is improved, but the system cannot detect over-billing attacks without additional proprietary hardware

Engineering Contradiction:
Improvedata securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway node performs multiple functions: it controls data transportation like a traditional firewall, detects over-billing attacks by monitoring PDP context deactivation, sends ICMP messages to the firewall, and prevents IP address reassignment. This eliminates the need for separate proprietary hardware while maintaining comprehensive security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway node autonomously detects when a user deactivates their PDP context and automatically triggers the appropriate security response by sending ICMP messages to the firewall and preventing IP reassignment. This self-service mechanism eliminates the need for external monitoring hardware or complex additional systems.

Inventive Principle:
Principle #25Self-service

2Productivity

If IP addresses are reassigned quickly to new users, then network efficiency is improved, but over-billing attacks can occur with existing state information

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidover-billing attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The gateway node prevents IP address reassignment to new users before the firewall has a chance to process old state information. By implementing a predefined period during which IP addresses cannot be reassigned after PDP context deactivation, the system proactively prevents over-billing attacks before they can affect network efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway node receives feedback from the firewall about state information and uses this feedback to control IP address reassignment. When the firewall indicates that state information needs to be deleted, the gateway waits for this feedback before allowing IP reassignment, creating a feedback loop that prevents attacks while maintaining efficiency.

Inventive Principle:
Principle #23Feedback

3Reliability

If state information is retained in the firewall, then data transportation control is maintained, but malicious traffic can be unintentionally allowed

Engineering Contradiction:
Improvedata transportation controlVSAvoidmalicious traffic
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The gateway node extracts and removes state information from the firewall by sending ICMP messages that trigger the firewall to delete old state entries. This extraction mechanism eliminates harmful state information while preserving the firewall's ability to control legitimate data transportation, separating the harmful element from the useful function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway node acts as an intermediary between the user and the firewall, managing state information deletion and IP address reassignment. This intermediary role allows the system to maintain data transportation control while preventing malicious traffic by coordinating between the gateway and firewall functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7620808B2Security of a communication system
Publication Date: 2009.11.17 NOKIA TECHNOLOGIES OY
  • US7620808B2 patent drawing
  • US7620808B2 patent drawing
  • US7620808B2 patent drawing

AI summary

Communications systems and methods for controlling transportation of data. The methods commonly include entering state information associated with a data transportation connection in a state information record maintained in a data processing entity. The data transportation connection is normally established between user equipment and a node, commonly via a gateway node, and the data processing entity is typically configured to control transportation of data based on the state information table. The methods also usually include, detecting that the data transportation connection is deactivated for the user equipment, sending information from the gateway node that the user equipment cannot be reached, and, in response to the information, deleting the state information from the state information record. The systems generally allow for implementation of the methods.