NWDAF UE Security Risk Detection via AF Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 5G mobile communication network systems lack effective detection and defense mechanisms for identifying and mitigating risks associated with user equipment (UE), such as malicious behavior or hijacking, which can lead to security issues and significant economic losses.

Innovation Solution

A method and device utilizing a Network Data Analytics Function (NWDAF) entity to acquire and analyze UE behavioral information, sending indications to network functions and the UE to trigger policy updates, parameter adjustments, alarms, or risk defense actions, thereby enhancing management and control within the mobile communication network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the NWDAF entity carries out slice-level network data analysis based on static configuration, then network optimization can be performed, but the NWDAF cannot sense user equipment which currently uses the slices or detect malicious behavior

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the detection function by introducing a separate AF entity that specializes in UE behavior analysis, while the NWDAF continues to perform slice-level network data analysis. This segmentation allows each entity to focus on its specific detection task without compromising the other, thereby improving overall network security detection capability without excessive complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The AF entity acts as an intermediary between the NWDAF and the network functions. It receives slice load information from NWDAF, enriches it with UE behavioral data, and provides comprehensive risk assessment to network functions. This intermediary approach enables enhanced UE-level detection while maintaining the existing slice-level analysis architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If no UE-level detection mechanism is implemented, then the network system remains simple, but malicious behavior by terminals cannot be detected or defended against

Engineering Contradiction:
Improveterminal securityVSAvoiddetection system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The AF entity performs self-service by autonomously collecting UE behavioral information from multiple network functions, analyzing this data to assess terminal risk levels, and generating appropriate responses. This self-service capability enables UE-level security detection without requiring complex centralized control, thereby improving terminal security while managing system complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The AF entity is designed with multi-functionality, serving both as a data collector from various network functions and as an analysis engine for UE risk assessment. It can provide services to multiple network functions simultaneously, enabling comprehensive UE-level detection across different network scenarios without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If static configuration is used for network data collection, then the system operation is simple, but real-time UE behavior changes and emerging risks cannot be detected

Engineering Contradiction:
Improverisk detection accuracyVSAvoiddata collection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by enabling the AF entity to continuously collect and analyze UE behavioral information in real-time, adapting to changing user behaviors and emerging security threats. The system dynamically adjusts its detection focus based on observed patterns, allowing accurate detection of real-time UE behavior changes and emerging risks while maintaining manageable operational complexity through automated processes

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3780538B1Method and device for managing and controlling terminal ue
Publication Date: 2022.11.30 DATANG MOBILE COMM EQUIP CO LTD
  • EP3780538B1 patent drawingFigure 1
  • EP3780538B1 patent drawingFigure 2
  • EP3780538B1 patent drawingFigure 3

AI summary

Disclosed are a method and device for managing and controlling a terminal UE. The method is applied to a network data analytics function (NWDAF) entity, and the method comprises: acquiring feature information of a UE; analyzing the feature information, and determining that a security risk exists in the UE; sending a first indication to at least one network function entity in a network, and triggering the at least one network function entity to carry out policy update or parameter adjustment on the UE, wherein the first indication is used for prompting the type of the security risk confronted by the UE, or for indicating a policy or parameter for the security risk of the UE; and/or sending a second indication to the UE, and triggering the UE to raise an alarm and/or carry out risk defense, wherein the second indication is used for prompting the type of the security risk confronted by the UE. The present invention is used for solving the problem of an existing mobile communication network system lacking effective detection and defense on a confronted or potential security risk of a terminal.