HNB Gateway Access Control During Home Node B Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Home Node B (HNB) handover scenarios, the lack of specific authorization information for each HNB connected via an HNB Gateway (HNB GW) to the core network leads to potential security vulnerabilities, allowing unauthorized user equipment (UE) to fraudulently access CSG cells by reporting incorrect CSG IDs or access modes.
Innovation Solution
The method involves the core network acquiring and verifying target HNB information, including CSG IDs and access modes, and sending this information to the HNB GW for further validation against stored access control information, ensuring accurate access control by matching the received information with the HNB GW's stored data to determine authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the core network performs access control based on CSG ID and authorization mode reported by UE, then the handover process can be completed, but security vulnerabilities arise allowing fraudulent access to CSG cells
Solution Approach 1:
The HNB GW performs preliminary access control validation before allowing handover to complete. The gateway verifies the CSG ID and access mode reported by the UE against its stored authorization information for the target HNB, preventing fraudulent access attempts from completing the handover process
Solution Approach 2:
The HNB GW acts as an intermediary between the core network and the HNB during handover. It receives the handover request from the core network, performs additional access control verification using its local authorization database, and only forwards the request to the target HNB if verification succeeds, thus mediating security between the core network and HNB
2Reliability
If the HNB GW stores and verifies access control information for each HNB, then network security is improved, but system complexity increases
Solution Approach 1:
The HNB GW performs multiple functions: it acts as a routing gateway, a security verification server, and an authorization database. By consolidating these functions in a single entity, the system avoids the complexity of distributed verification across multiple network elements while maintaining strong security
3Measurement precision
If the core network has specific authorization information for each HNB, then access control precision is improved, but information storage requirements increase
Solution Approach 1:
The authorization information is segmented and distributed: the core network stores general UE authorization data (White List), while the HNB GW stores specific HNB access control information (CSG ID, access mode). This segmentation allows precise access control without requiring the core network to store all detailed authorization data centrally
Data Source
AI summary
The present invention discloses a method and a system for controlling network access during HNB handover. The method comprises the following steps: a core network acquires target HNB information to determine whether to allow access of User Equipment (UE) and sends the target HNB information to an HNB GW to which the target HNB belongs if the access of the UE is allowed and the target HNB is connected with the core network via the HNB GW, and the HNB GW determines whether to allow the access of the UE according to the received target HNB information. The present invention can prevent the occurrence of illegal accesses and improve the security of network access.


