Network Node Validation via IMEI Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communications networks, particularly mobile communications networks, face vulnerabilities due to the lack of validation of mobility management messages and location information, which can lead to fraudulent activities such as revenue fraud and call interceptions, with innocent parties often held responsible for rectifying the damage.
Innovation Solution
A network node validation method that involves obtaining and verifying the international mobile equipment identity (IMEI) from a network node, comparing it with trusted or verified information stored in a validation data store, and taking mitigating actions if the node is deemed invalid, such as discarding or blocking malicious messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network operators use security appliances and firewalls to prevent unauthorized access, then network security is improved, but numerous security issues still exist due to inherent vulnerabilities in protocols and procedures
Solution Approach 1:
The patent applies preliminary action by validating network nodes before they can process mobility management messages. The home network node validates the visited network node using the mobile subscriber's IMEI as a key, obtaining validation information in advance and storing it for future message processing. This prevents fraudulent nodes from gaining unauthorized access before they can execute malicious activities.
Solution Approach 2:
The patent introduces an intermediary validation mechanism where the mobile subscriber's IMEI serves as a trusted mediator between the home network node and the visited network node. The validation information, derived from the IMEI, acts as an intermediary credential that proves the authenticity of the visited network node without requiring direct trust between network nodes, thereby overcoming protocol vulnerabilities.
2Productivity
If network nodes process mobility management messages without validation, then message processing speed is improved, but fraudulent activities such as revenue fraud and call interceptions can occur
Solution Approach 1:
The patent performs validation in advance by obtaining and storing validation information for the mobile subscriber before processing mobility management messages. The home network node retrieves validation information using the IMEI and stores it locally, so that subsequent message processing can proceed quickly with minimal validation overhead, maintaining productivity while preventing fraud.
Solution Approach 2:
The patent applies partial action by performing validation only when mobility management messages are received from visited network nodes, rather than validating all network traffic continuously. The validation is triggered selectively based on message type and source, reducing the overall validation burden while providing sufficient security against fraudulent activities.
3Reliability
If the home network node validates every mobility management message, then security against fraudulent nodes is improved, but network operation complexity increases
Solution Approach 1:
The patent implements partial validation by validating only mobility management messages received from visited network nodes, rather than all network messages. The validation is performed selectively based on message type and source node, reducing the overall validation workload and operational complexity while maintaining security against fraudulent nodes.
Solution Approach 2:
The patent reduces operational complexity by performing validation in advance and storing the results. The home network node obtains validation information using the mobile subscriber's IMEI before processing messages, and stores this validation information for rapid retrieval during message processing, avoiding repeated validation operations.
4Measurement precision
If validation information is stored for each mobile subscriber, then validation accuracy is improved, but data storage requirements increase
Solution Approach 1:
The patent stores validation information in advance for mobile subscribers, preparing the data before it is needed for message processing. By obtaining and storing validation information using the IMEI beforehand, the system ensures accurate validation when messages are received, while the storage is optimized to only keep essential validation data rather than complete subscriber profiles.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and computer readable media for network node validation are disclosed. One method occurs at a first network node. The method includes receiving, from a second network node, a first message associated with a mobile subscriber; sending, by the first network node, a query to the second network node, the query requesting identification information identifying mobile communications equipment of the mobile subscriber; receiving, by the first network node, a response to the query from the second network node, wherein the response includes the identification information; extracting, from the response, the identification information; comparing the identification information extracted from the response and validated identification information identifying the mobile communications equipment of the mobile subscriber; and in response to the identification information matching the validated identification information, recognizing the second network node as being authorized to send the first message and processing the first message.