PEI Verification for Blocking Spoofed UE Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks lack verification of Physical Entity Identifiers (PEI) during subsequent data session establishment requests, allowing attackers to spoof subscriber identities and gain unauthorized access, leading to potential data theft and service disruptions.

Innovation Solution

Implementing a PEI verification process for subsequent data session establishment requests by comparing the PEI of suspect UEs with the initially stored PEI of authorized UEs, and rejecting requests if they do not match, with notifications to the Equipment Identity Register (EIR) for further security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PEI verification is performed only during initial authentication, then authentication process is simple and fast, but subsequent data session establishment requests can be spoofed by attackers

Engineering Contradiction:
Improvesecurity of data session establishmentVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing PEI verification in advance during initial authentication and storing the verified PEI information in the network storage device. This pre-verification ensures that when subsequent data session establishment requests are made, the network already has the trusted PEI reference to compare against, preventing spoofing without requiring repeated complex verification processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by comparing the PEI from subsequent data session requests with the previously stored and verified PEI from initial authentication. This feedback mechanism allows the network to detect mismatches indicating spoofing attempts and reject unauthorized requests, thereby maintaining security while using a relatively simple verification process.

Inventive Principle:
Principle #23Feedback

2Reliability

If PEI verification is performed for all requests, then unauthorized access is prevented, but network processing time and resources increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidrequest processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs PEI verification as a preliminary action during initial authentication, establishing a trusted reference PEI in advance. This allows subsequent data session establishment requests to be processed more quickly by only comparing against the pre-verified PEI rather than performing full authentication procedures again, thus preventing unauthorized access while minimizing processing time overhead.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the network trusts authenticated UEs without rechecking PEI, then ease of operation is maintained, but security vulnerabilities allow data theft and service disruption

Engineering Contradiction:
ImproveUE access simplicityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a feedback mechanism where the network compares the PEI from data session requests with the previously verified PEI stored during initial authentication. This feedback loop detects spoofing attempts and rejects unauthorized requests, maintaining ease of operation for legitimate UEs while preventing security vulnerabilities from being exploited.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260032440A1Unauthorized access prevention in a communications network
Publication Date: 2026.01.29 T MOBILE INNOVATIONS LLC
  • US20260032440A1 patent drawing
  • US20260032440A1 patent drawing
  • US20260032440A1 patent drawing

AI summary

Embodiments of the present disclosure are directed to systems and methods for preventing unauthorized access of a communications network. For example, the network may store a Physical Entity Identifier (PEI) and subscriber identity of authorized user equipment (UE) during attachment to the network and compare it to PEIs included in subsequent service requests from suspect UEs that are spoofing subscriber identities of the authorized UEs. For example, if the compared PEIs are different, the service request is rejected. In this way, the subsequent service requests can be verified as coming from authorized UEs, thereby preventing unauthorized access to the network.