PEI Verification for Blocking Spoofed UE Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication networks lack verification of Physical Entity Identifiers (PEI) during subsequent data session establishment requests, allowing attackers to spoof subscriber identities and gain unauthorized access, leading to potential data theft and service disruptions.
Innovation Solution
Implementing a PEI verification process for subsequent data session establishment requests by comparing the PEI of suspect UEs with the initially stored PEI of authorized UEs, and rejecting requests if they do not match, with notifications to the Equipment Identity Register (EIR) for further security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PEI verification is performed only during initial authentication, then authentication process is simple and fast, but subsequent data session establishment requests can be spoofed by attackers
Solution Approach 1:
The patent applies preliminary action by performing PEI verification in advance during initial authentication and storing the verified PEI information in the network storage device. This pre-verification ensures that when subsequent data session establishment requests are made, the network already has the trusted PEI reference to compare against, preventing spoofing without requiring repeated complex verification processes.
Solution Approach 2:
The patent implements feedback by comparing the PEI from subsequent data session requests with the previously stored and verified PEI from initial authentication. This feedback mechanism allows the network to detect mismatches indicating spoofing attempts and reject unauthorized requests, thereby maintaining security while using a relatively simple verification process.
2Reliability
If PEI verification is performed for all requests, then unauthorized access is prevented, but network processing time and resources increase
Solution Approach 1:
The patent performs PEI verification as a preliminary action during initial authentication, establishing a trusted reference PEI in advance. This allows subsequent data session establishment requests to be processed more quickly by only comparing against the pre-verified PEI rather than performing full authentication procedures again, thus preventing unauthorized access while minimizing processing time overhead.
3Ease of operation
If the network trusts authenticated UEs without rechecking PEI, then ease of operation is maintained, but security vulnerabilities allow data theft and service disruption
Solution Approach 1:
The patent introduces a feedback mechanism where the network compares the PEI from data session requests with the previously verified PEI stored during initial authentication. This feedback loop detects spoofing attempts and rejects unauthorized requests, maintaining ease of operation for legitimate UEs while preventing security vulnerabilities from being exploited.
Data Source
AI summary
Embodiments of the present disclosure are directed to systems and methods for preventing unauthorized access of a communications network. For example, the network may store a Physical Entity Identifier (PEI) and subscriber identity of authorized user equipment (UE) during attachment to the network and compare it to PEIs included in subsequent service requests from suspect UEs that are spoofing subscriber identities of the authorized UEs. For example, if the compared PEIs are different, the service request is rejected. In this way, the subsequent service requests can be verified as coming from authorized UEs, thereby preventing unauthorized access to the network.


