SEPP Location Velocity Check for 5G Spoofing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G networks lack an effective mechanism for validating incoming service-based interface (SBI) request messages for user equipment (UE) authentication at the Security Edge Protection Proxy (SEPP), making them vulnerable to spoofing attacks, particularly as existing location and velocity checks are inadequate to ensure the legitimacy of UE authentication requests.
Innovation Solution
Implementing a method at the SEPP to perform location and velocity checks by querying a database network function for previous authentication information, including a previous network identifier and time, to determine if the UE could have traveled to the current network within a valid timeframe, and taking network security actions based on the results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the SEPP performs location and velocity checks by querying database NF for previous authentication information, then network security against spoofing attacks is improved, but device complexity and processing time increase
Solution Approach 1:
The SEPP queries the database NF for previous authentication information (location, timestamp, velocity) before processing the authentication request. This preliminary action enables the SEPP to perform location and velocity checks to detect spoofing attacks, improving network security by validating the legitimacy of incoming requests against historical data stored in the database.
Solution Approach 2:
The database NF acts as an intermediary between the SEPP and the authentication server function. It stores and provides previous authentication information to the SEPP, enabling the SEPP to perform security checks without directly burdening the authentication server function. This intermediary approach resolves the contradiction by distributing the security validation workload.
2Reliability
If the SEPP performs location and velocity checks on incoming authentication requests, then spoofing attack detection is improved, but processing time and loss of time increase
Solution Approach 1:
The SEPP retrieves previous authentication information from the database NF before processing the current authentication request. This preliminary retrieval enables the SEPP to perform location and velocity checks to detect spoofing attacks, improving detection capability while managing processing time by using pre-stored historical data rather than real-time queries during authentication.
Solution Approach 2:
The SEPP uses feedback from the database NF containing previous authentication information (location, timestamp, velocity) to validate incoming requests. By comparing current request data against historical feedback data, the SEPP can detect spoofing attacks through location and velocity checks, improving detection while keeping processing efficient through automated comparison logic.
3Reliability
If the AUSF performs screening of authentication requests, then network security is improved, but the burden on AUSF increases
Solution Approach 1:
The authentication screening function is extracted from the AUSF and relocated to the SEPP. The SEPP now performs location and velocity checks using previous authentication information from the database NF, removing the screening burden from the AUSF. This extraction improves AUSF productivity while maintaining authentication security through the SEPP's validation capabilities.
Solution Approach 2:
The SEPP acts as an intermediary that performs authentication request screening before forwarding requests to the AUSF. By using previous authentication information from the database NF to validate incoming requests, the SEPP filters out potential spoofing attacks, improving network security while reducing the processing burden on the AUSF.
4Measurement precision
If the SEPP queries database NF for previous authentication information, then detection precision of spoofing attacks is improved, but device complexity and processing overhead increase
Solution Approach 1:
The database NF stores previous authentication information (location, timestamp, velocity) in advance, enabling the SEPP to perform precise location and velocity checks when validating authentication requests. This preliminary storage of historical data improves detection precision by providing reference data for comparison, while the automated query and comparison processes manage the complexity overhead.
Solution Approach 2:
The SEPP replaces manual or rule-based spoofing detection with automated location and velocity checks using data from the database NF. This substitution improves detection precision by using objective, data-driven validation (comparing current request data against historical authentication patterns) rather than simple rule-based filtering, while the automated nature of the process manages complexity.
Data Source
AI summary
A method for performing a location and velocity check at an SEPP to protect against a spoofing attack includes receiving an SBI request message relating to authentication of UE. The method further includes querying a database NF to obtain previous authentication information for the UE, the previous authentication information including a previous network identifier and a previous authentication time for the UE. The method further includes receiving a response from the database NF, the response including the previous network identifier and the previous authentication time. The method further includes reading, a current network identifier from the SBI request message, performing, using the current network identifier from the SBI request message, the previous network identifier, the previous authentication time, and a time of receipt by the SEPP of the SBI request message, a location and velocity check for the UE, and performing a network security action for the SBI request message based on results of the location and velocity check.


