Interface-Located Firewall for Device-Level Filtering in Scrubbed IP Domains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless networks struggle to effectively identify and filter malicious content or traffic from shared connections with similar network address translation schemes, particularly in multi-actor attacks, lacking device-level and subscriber-level filtering capabilities.
Innovation Solution
Implementing an interface-located firewall between radio resources and the user plane of a mobility network, utilizing packet forwarding control protocol messages to identify malicious devices or subscribers, and activating firewalls to block or allow traffic based on device or subscriber identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network-level filtering is used to detect malicious content, then malicious content can be quarantined or neutralized, but device-level and subscriber-level filtering capabilities are lost due to shared NAT connections
Solution Approach 1:
The patent segments the filtering capability by introducing a correlation mechanism that maps network-level observations to device-level identifiers (IMEI, IMSI, SUPI). The system divides the filtering task into: (1) network-level traffic monitoring, (2) correlation with subscriber/device identities through PFCP messages, and (3) device-level filtering enforcement. This segmentation resolves the contradiction by maintaining network-level detection while adding device-level precision through identity correlation.
Solution Approach 2:
The patent introduces an intermediary correlation mechanism that bridges the gap between network-level filtering and device-level identification. The intermediary system uses PFCP (Packet Forwarding Control Protocol) messages to correlate IP addresses with device identifiers (IMEI, IMSI, SUPI), enabling the translation from shared network addresses to specific device identities. This intermediary resolves the contradiction by providing the missing link between network-level observations and device-level filtering requirements.
2Reliability
If interface-located firewall is activated to monitor traffic, then malicious activity can be identified and blocked, but network complexity increases due to additional monitoring infrastructure
Solution Approach 1:
The patent makes the interface-located firewall multi-functional by combining multiple capabilities into a single system: (1) packet filtering, (2) traffic monitoring, (3) PFCP message correlation, and (4) device identification. This universal firewall resolves the contradiction by consolidating multiple security functions into one infrastructure element, reducing overall system complexity while maintaining comprehensive security monitoring and blocking capabilities.
3Measurement precision
If device-level filtering is implemented to identify specific malicious devices, then precise filtering is achieved, but filtering capability is lost in shared NAT connections where device identifiers are not available
Solution Approach 1:
The patent performs preliminary action by pre-correlating device identifiers (IMEI, IMSI, SUPI) with network addresses through PFCP messages before filtering operations. The system proactively establishes the mapping between device identities and their network representations in advance, so when filtering is needed, the correlation is already available. This preliminary action resolves the contradiction by ensuring device-level filtering capability is prepared beforehand, making it applicable even in shared NAT environments where real-time correlation would be difficult.
Data Source
AI summary
Providing mobility network support for scrubbed IP domains can include obtaining packet forwarding control protocol messages associated with a mobility network, the packet forwarding control protocol messages relating to data communications of user equipment attached to the mobility network via a radio resource, correlating the packet forwarding control protocol messages to subscriber identities or device identities to obtain correlated packet forwarding control protocol messages, determining, based on the correlated packet forwarding control protocol messages, if the user equipment is associated with a malicious subscriber or comprises a malicious device, in response to determining that the user equipment is associated with a malicious subscriber or comprises a malicious device, selecting an interface via which the radio resource connects to a user plane of the mobility network, and triggering activation of an interface-located firewall on the interface to monitor data exchanged via the interface.


