Network Authentication Counter for Mobile Traffic Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile terminals are vulnerable to viruses that can lead to abnormal behavior, such as uncontrollable SMS transmission and resource consumption, causing financial and operational issues in radiocommunication networks, necessitating rapid detection and mitigation of such anomalies.

Innovation Solution

A method that collaborates with the radiocommunication network's location register to monitor and detect traffic anomalies, using authentication counters and alert messages to identify and address abnormal behavior, including the possibility of virus infections, allowing for quick reactive measures to minimize adverse effects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile terminals implement complex operating systems with increased functionality, then the versatility and capability of the terminal improve, but the vulnerability to virus infections and malicious attacks increases

Engineering Contradiction:
Improveterminal functionalityVSAvoidvirus vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary detection system consisting of network elements (GGSN, SGSN, HLR) that monitor authentication traffic between the mobile terminal and the network. This intermediary system detects abnormal authentication patterns caused by viruses without requiring changes to the terminal's operating system, thus maintaining terminal versatility while mitigating virus threats through network-side monitoring

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the network monitors traffic from each mobile terminal to detect anomalies, then the detection precision improves, but the complexity of the network system increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidnetwork system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the anomaly detection functionality into existing network elements (GGSN, SGSN, HLR) that are already part of the radiocommunication network infrastructure. By combining detection tasks with existing network functions rather than adding separate dedicated detection systems, the patent achieves precise monitoring of authentication traffic while minimizing additional system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network elements (particularly the HLR and authentication mechanisms) perform multiple functions: they authenticate legitimate users, manage subscriber data, and simultaneously detect abnormal authentication patterns caused by viruses. This multi-functionality allows precise anomaly detection without requiring dedicated single-purpose detection devices, thus reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If the network rapidly detects and responds to abnormal behavior, then the loss of time is reduced, but the need for automated monitoring and response systems increases device complexity

Engineering Contradiction:
Improvedetection response timeVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where network elements continuously monitor authentication requests and automatically compare them against established thresholds. When abnormal patterns are detected (e.g., excessive authentication failures or unusual traffic patterns), the system automatically generates alerts and can trigger blocking actions. This automated feedback loop enables rapid detection and response without requiring complex manual monitoring systems

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The detection system leverages the existing self-service nature of authentication protocols. The network elements automatically perform detection, analysis, and response actions without external intervention. The system serves itself by using its own authentication infrastructure to detect anomalies and automatically initiate corrective measures, reducing the need for complex external monitoring apparatus

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2134115B1Detection of abnormal behavior of traffic transmitted from a mobile terminal in a radiocommunication network
Publication Date: 2019.01.16 ALCATEL LUCENT SA
  • EP2134115B1 patent drawingFigure 1
  • EP2134115B1 patent drawingFigure 2

AI summary

The method involves incrementing an authentication count (CA) assigned to a mobile terminal (TM), over a predetermined time interval, by an evaluation module (ME) of a warning device (DA) when security data (DS) are transmitted to an entity of a radiocommunication network (RR) e.g. Global System for Mobile communicationsnetwork, for authenticating the terminal. The authentication count is compared with a predefined threshold (SP) so as to detect an anomaly of traffic transmitted by the mobile terminal if the count exceeds the threshold. An independent claim is also included for a device communicating with a location register of a radiocommunication network for detecting an anomaly of traffic transmitted from a mobile terminal in the radiocommunication network.