Location Register Server Security Verification for Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile Communication Networks face security risks due to unauthorized Information Retrieval Requests from outside servers that can impersonate fraudulent Home Location Registers, potentially accessing sensitive subscriber data.
Innovation Solution
A security method that extracts Specification Codes from Information Retrieval Requests and compares them to a Verification List to determine if the Sending Entity is authorized, allowing or prohibiting data transmission, thereby enhancing security without altering existing communication protocols or network structures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing communication protocols and network structures are maintained, then network compatibility and ease of operation are preserved, but security against unauthorized information retrieval requests deteriorates
Solution Approach 1:
The patent applies preliminary action by verifying the Sending Entity's authorization status before processing the information retrieval request. The Location Register Server checks whether the Sending Entity is authorized to receive the requested information about the mobile subscriber, and only then proceeds with data transmission. This prevents unauthorized access attempts from fraudulent HLRs while maintaining compatibility with existing network protocols and structures.
2Reliability
If verification of Sending Entity authenticity is implemented, then security against fraudulent HLRs is improved, but processing time and operational complexity increase
Solution Approach 1:
The verification of the Sending Entity's authorization is performed as a preliminary check before the actual information retrieval processing. By determining early whether the Sending Entity is authorized to receive the requested information, the system avoids wasting processing time on fraudulent requests that would ultimately be rejected, thus minimizing the time loss while maintaining security.
Solution Approach 2:
The system implements feedback by checking the authorization status of the Sending Entity and using this information to determine whether to proceed with data transmission. The verification result directly influences the subsequent action, allowing the system to efficiently reject unauthorized requests without undergoing the full information retrieval process.
3Ease of operation
If all information retrieval requests are processed without verification, then ease of operation is maintained, but vulnerability to fraud increases
Solution Approach 1:
The patent introduces a preliminary verification step that checks whether the Sending Entity is authorized to receive the requested information before processing the request further. This maintains ease of operation for legitimate requests while effectively blocking fraudulent ones, as the verification is seamlessly integrated into the existing request handling flow without requiring complex additional procedures for authorized entities.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The invention is related to Security method for the verification of an Information Retrieval Request (10) which requests a transmission of data (20) from a Location Register Server (LR) to a Sending Entity (30) in a Mobile Communication Network (100), comprising the following steps: - Receive an Information Retrieval Request (10) from the Sending Entity (20), - Extract at least one Specification Code (12) for specifying the Sending Entity (20) and/or a Mobile Subscriber (MS) out of the Information Retrieval Request (10), - Compare the extracted at least one Specification Code (12) to a Verification List (14), - Based on the result of the comparison with the Verification List (14), allow or prohibit the transmission of data (20) requested in the Information Retrieval Request (10).