GGSN Binding Update Detection for Roaming Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing General Packet Radio Service (GPRS) network faces challenges in routing internet packets efficiently when a mobile node roams to a foreign network, leading to potential theft of service due to unauthorized destination addresses, as the current systems lack effective mechanisms to differentiate between legitimate and unauthorized addresses during route optimization.

Innovation Solution

The proposed solution involves a gateway support node (GGSN) that detects binding updates to identify the care-of-address of a mobile node and uses a Service Based Local Policy to ensure only authorized internet packets are routed, by examining both the hop-by-hop and destination address fields in the IP header, thereby preventing unauthorized access to network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the GGSN routes internet packets based on the source address in the IP header, then packets can be efficiently routed to the correspondent node, but the GGSN cannot handle packets from mobile nodes that have roamed to foreign networks and changed their source address to a care-of-address

Engineering Contradiction:
Improvepacket routing efficiencyVSAvoidability to handle roaming mobile nodes
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a binding update mechanism as an intermediary process. When a mobile node roams to a foreign network and changes its source address to a care-of-address, it sends a binding update message to the GGSN. This binding update acts as a mediator that informs the GGSN of the address change, allowing the GGSN to maintain efficient routing by updating its forwarding information base with the new care-of-address associated with the mobile node's home address.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the GGSN allows packets with any destination address to pass through, then network connectivity is maintained, but unauthorized destination addresses can be used for theft of service

Engineering Contradiction:
Improvenetwork connectivityVSAvoidtheft of service attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing authorization rules before packets are routed. The GGSN maintains a binding update database that pre-records the relationship between mobile node home addresses and their care-of-addresses. Before routing a packet, the GGSN performs a preliminary check to verify that the destination address in the packet matches an authorized care-of-address in the database. This preliminary verification prevents theft of service attacks while maintaining legitimate network connectivity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the GGSN implements strict address verification to prevent theft of service, then network security is improved, but legitimate packets from roaming mobile nodes may be blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidlegitimate packet delivery
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements feedback through the binding update mechanism. When a mobile node roams and changes its address, it provides feedback to the GGSN by sending a binding update message. The GGSN uses this feedback to update its forwarding information base and binding update database. This feedback loop ensures that the GGSN has accurate, up-to-date information about the mobile node's current care-of-address, allowing it to securely route legitimate packets while blocking unauthorized ones. The feedback mechanism resolves the contradiction by providing the GGSN with the knowledge needed to distinguish between legitimate and unauthorized packets.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7860037B2Telecommunications system and method for communicating internet packets between an external packet data communications network and a packet radio network
Publication Date: 2010.12.28 3G LICENSING SA
  • US7860037B2 patent drawing
  • US7860037B2 patent drawing
  • US7860037B2 patent drawing

AI summary

A telecommunications system for communicating internet packets between a correspondent node and a mobile node. The system comprises a packet radio network providing packet data bearers for communicating internet packets with nodes. Each of the bearers is defined with respect to a source address of the internet packets, the packet radio network including a gateway support node (GGSN) to provide an interface between the external network and the packet radio network. The GGSN detects whether an internet packet is for providing a binding update to the correspondent node of a first source address of the mobile node to a care-of-address of the mobile node. If the internet packet is a binding update, the GGSN allows egress of internet packets sent from the correspondent node. By allowing egress of packets from the correspondent node having this care-of-address as the destination address, a measure of security is provided.