NWDAF UE Security Risk Detection via AF Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing 5G mobile communication network systems lack effective detection and defense mechanisms for identifying and mitigating risks associated with user equipment (UE), such as malicious behavior or hijacking, which can lead to security issues and significant economic losses.
Innovation Solution
A method and device utilizing a Network Data Analytics Function (NWDAF) entity to acquire and analyze UE behavioral information, sending indications to network functions and the UE to trigger policy updates, parameter adjustments, alarms, or risk defense actions, thereby enhancing management and control within the mobile communication network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the NWDAF entity carries out slice-level network data analysis based on static configuration, then network optimization can be performed, but the NWDAF cannot sense user equipment which currently uses the slices or detect malicious behavior
Solution Approach 1:
The patent segments the detection function by introducing a separate AF entity that specializes in UE behavior analysis, while the NWDAF continues to perform slice-level network data analysis. This segmentation allows each entity to focus on its specific detection task without compromising the other, thereby improving overall network security detection capability without excessive complexity
Solution Approach 2:
The AF entity acts as an intermediary between the NWDAF and the network functions. It receives slice load information from NWDAF, enriches it with UE behavioral data, and provides comprehensive risk assessment to network functions. This intermediary approach enables enhanced UE-level detection while maintaining the existing slice-level analysis architecture
2Reliability
If no UE-level detection mechanism is implemented, then the network system remains simple, but malicious behavior by terminals cannot be detected or defended against
Solution Approach 1:
The AF entity performs self-service by autonomously collecting UE behavioral information from multiple network functions, analyzing this data to assess terminal risk levels, and generating appropriate responses. This self-service capability enables UE-level security detection without requiring complex centralized control, thereby improving terminal security while managing system complexity
Solution Approach 2:
The AF entity is designed with multi-functionality, serving both as a data collector from various network functions and as an analysis engine for UE risk assessment. It can provide services to multiple network functions simultaneously, enabling comprehensive UE-level detection across different network scenarios without proportionally increasing system complexity
3Reliability
If static configuration is used for network data collection, then the system operation is simple, but real-time UE behavior changes and emerging risks cannot be detected
Solution Approach 1:
The patent implements dynamics by enabling the AF entity to continuously collect and analyze UE behavioral information in real-time, adapting to changing user behaviors and emerging security threats. The system dynamically adjusts its detection focus based on observed patterns, allowing accurate detection of real-time UE behavior changes and emerging risks while maintaining manageable operational complexity through automated processes
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are a method and device for managing and controlling a terminal UE. The method is applied to a network data analytics function (NWDAF) entity, and the method comprises: acquiring feature information of a UE; analyzing the feature information, and determining that a security risk exists in the UE; sending a first indication to at least one network function entity in a network, and triggering the at least one network function entity to carry out policy update or parameter adjustment on the UE, wherein the first indication is used for prompting the type of the security risk confronted by the UE, or for indicating a policy or parameter for the security risk of the UE; and/or sending a second indication to the UE, and triggering the UE to raise an alarm and/or carry out risk defense, wherein the second indication is used for prompting the type of the security risk confronted by the UE. The present invention is used for solving the problem of an existing mobile communication network system lacking effective detection and defense on a confronted or potential security risk of a terminal.