Network Signalling Message Verification in PLMN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network signalling messages in PLMNs lack adequate security, allowing third parties to imitate messages and access subscriber services, with existing solutions either not providing complete protection or requiring all roaming partners to implement additional functionality.
Innovation Solution
A network entity that authenticates received network signalling messages by comparing the message addresses of the routing and instruction parts, using protocols like SCCP and TCAP, and verifying these against database addresses to ensure authenticity, thereby reducing the burden on the home registration entity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network signalling messages are transmitted without authentication, then message processing speed is maintained, but security is compromised allowing third-party imitation
Solution Approach 1:
The patent applies preliminary action by performing authentication checks on message addresses before processing the signalling message content. The verification logic authenticates the routeing part and instruction part addresses in advance, determining message validity before any service processing occurs, thereby preventing imitation attacks without requiring complex post-processing authentication mechanisms
Solution Approach 2:
The patent extracts the authentication function from the main message processing flow by implementing a separate verification logic module that specifically validates message addresses. This extraction allows authentication to be performed independently on the routeing and instruction parts without complicating the overall message processing architecture, resolving the contradiction between security and complexity
2Reliability
If TCAP handshake protocol is used for authentication, then message authenticity is ensured, but implementation requires all roaming partners to cooperate and commercial agreements
Solution Approach 1:
The patent applies self-service by enabling the home registration entity to independently verify message authenticity using its own stored VLR address information. The verification logic compares the instruction part address against addresses obtained from the HLR database, allowing the system to authenticate messages without requiring roaming partners to implement additional functionality or reach commercial agreements, thus improving compatibility while maintaining security
3Reliability
If proxy node is introduced to verify VLR address, then spoofing is detected, but system complexity increases and burden on HLR increases
Solution Approach 1:
The patent merges the authentication function into the existing home registration entity rather than introducing a separate proxy node. The verification logic is integrated within the network entity that already has access to HLR database information, combining address verification with existing message processing functions. This merging reduces system architecture complexity and eliminates the need for additional nodes while maintaining spoof detection capability
Solution Approach 2:
The patent makes the home registration entity multi-functional by enabling it to perform both standard message processing and authentication verification through its verification logic. The same entity that manages subscriber information also authenticates incoming messages by comparing addresses against its database, eliminating the need for dedicated proxy nodes and reducing overall system complexity
4Measurement precision
If message addresses are verified against database, then authentication accuracy is improved, but processing time increases
Solution Approach 1:
The patent applies partial action by performing authentication verification selectively based on message type and source. The verification logic authenticates the routeing part and instruction part addresses, and can determine when verification is necessary versus when messages can be processed with standard procedures. This selective approach maintains high authentication accuracy for critical messages while reducing unnecessary verification overhead for routine communications
Data Source
AI summary
A received network signalling messages in a Public Land Mobile Network (PLMN) comprises a routeing part and an instruction part, each of the routeing part and the instruction part comprising a respective message address. These are handled by: authenticating the received network signalling message on the basis of the message address of the routeing part and the message address of the instruction part; and processing the received network signalling message based on the authentication.
