Network Signalling Message Verification in PLMN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network signalling messages in PLMNs lack adequate security, allowing third parties to imitate messages and access subscriber services, with existing solutions either not providing complete protection or requiring all roaming partners to implement additional functionality.

Innovation Solution

A network entity that authenticates received network signalling messages by comparing the message addresses of the routing and instruction parts, using protocols like SCCP and TCAP, and verifying these against database addresses to ensure authenticity, thereby reducing the burden on the home registration entity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network signalling messages are transmitted without authentication, then message processing speed is maintained, but security is compromised allowing third-party imitation

Engineering Contradiction:
Improvemessage securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing authentication checks on message addresses before processing the signalling message content. The verification logic authenticates the routeing part and instruction part addresses in advance, determining message validity before any service processing occurs, thereby preventing imitation attacks without requiring complex post-processing authentication mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication function from the main message processing flow by implementing a separate verification logic module that specifically validates message addresses. This extraction allows authentication to be performed independently on the routeing and instruction parts without complicating the overall message processing architecture, resolving the contradiction between security and complexity

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If TCAP handshake protocol is used for authentication, then message authenticity is ensured, but implementation requires all roaming partners to cooperate and commercial agreements

Engineering Contradiction:
Improvemessage authenticityVSAvoidroaming partner compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies self-service by enabling the home registration entity to independently verify message authenticity using its own stored VLR address information. The verification logic compares the instruction part address against addresses obtained from the HLR database, allowing the system to authenticate messages without requiring roaming partners to implement additional functionality or reach commercial agreements, thus improving compatibility while maintaining security

Inventive Principle:
Principle #25Self-service

3Reliability

If proxy node is introduced to verify VLR address, then spoofing is detected, but system complexity increases and burden on HLR increases

Engineering Contradiction:
Improvespoof detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication function into the existing home registration entity rather than introducing a separate proxy node. The verification logic is integrated within the network entity that already has access to HLR database information, combining address verification with existing message processing functions. This merging reduces system architecture complexity and eliminates the need for additional nodes while maintaining spoof detection capability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the home registration entity multi-functional by enabling it to perform both standard message processing and authentication verification through its verification logic. The same entity that manages subscriber information also authenticates incoming messages by comparing addresses against its database, eliminating the need for dedicated proxy nodes and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If message addresses are verified against database, then authentication accuracy is improved, but processing time increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidmessage processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by performing authentication verification selectively based on message type and source. The verification logic authenticates the routeing part and instruction part addresses, and can determine when verification is necessary versus when messages can be processed with standard procedures. This selective approach maintains high authentication accuracy for critical messages while reducing unnecessary verification overhead for routine communications

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10341861B2Network signalling message verification
Publication Date: 2019.07.02 VODAFONE IP LICENSING LTD
  • US10341861B2 patent drawing

AI summary

A received network signalling messages in a Public Land Mobile Network (PLMN) comprises a routeing part and an instruction part, each of the routeing part and the instruction part comprising a respective message address. These are handled by: authenticating the received network signalling message on the basis of the message address of the routeing part and the message address of the instruction part; and processing the received network signalling message based on the authentication.