Detection and Modem-Level Blocking of Silent MT Calls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems are vulnerable to silent Mobile Terminated (MT) call attacks, which cause excessive resource allocation and de-allocation, leading to network performance degradation, increased power consumption, and difficulty in connecting legitimate calls due to prioritization of malicious MT calls over Mobile Originated (MO) calls.
Innovation Solution
A user equipment (UE) is equipped with a system that detects silent MT call attacks by monitoring the number of MT calls within a time period, determines a subset of non-verified calls using a call verification score, and performs modem-level blocking of identified malicious calling parties to mitigate the attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system blocks all incoming MT calls to prevent malicious attacks, then network security is improved, but legitimate calls cannot be connected
Solution Approach 1:
The patent applies local quality by implementing different treatment policies for different subsets of MT calls. Specifically, verified calls (legitimate) are allowed to connect while non-verified calls (potentially malicious) are blocked. This is achieved by evaluating each incoming MT call against verification criteria such as calling party identity, called party identity, and time of call, thereby applying quality differentiation at the level of individual calls rather than uniformly to all calls.
2Measurement precision
If the system processes and verifies each MT call to differentiate legitimate from malicious calls, then call accuracy is improved, but processing time and power consumption increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing verification rules and criteria for evaluating MT calls before the actual call processing begins. The system pre-configures parameters such as acceptable calling party identities, called party identities, and time windows for call verification. This allows the system to quickly evaluate incoming calls against predetermined criteria without performing complex real-time analysis, thereby reducing processing time while maintaining verification accuracy.
3Adaptability or versatility
If the system allocates resources for each incoming MT call, then call handling capability is improved, but network resource consumption increases during attacks
Solution Approach 1:
The patent applies the taking out principle by extracting and isolating potentially malicious MT calls from the normal call processing flow. The system identifies non-verified calls that match attack patterns and removes them from further processing before they can consume network resources. This extraction occurs at the verification stage, where calls failing to meet verification criteria are immediately blocked, preventing them from proceeding to resource allocation phases such as radio resource management and call setup.
4Productivity
If the system prioritizes MT calls over MO calls as per traditional protocol, then incoming call reception is improved, but outgoing call initiation is degraded during attacks
Solution Approach 1:
The patent applies dynamics by making the call prioritization scheme adaptive rather than static. Under normal conditions, the system maintains traditional MT call prioritization to ensure reliable incoming call reception. However, when an attack is detected (indicated by a high number of non-verified MT calls within a verification time window), the system dynamically adjusts priorities to allow MO calls to proceed without being blocked by malicious MT call attempts. This dynamic adjustment resolves the contradiction by adapting prioritization behavior to current system conditions.
Data Source
AI summary
Systems and techniques are provided for wireless communications. A process can include determining that a quantity of a plurality of Mobile Terminated (MT) calls received within a first time period is greater than a first configured threshold. A process can include determining a subset of non-verified MT calls from the plurality of MT calls based on a call verification score for each respective MT call of the plurality of MT calls received within the first time period. A process can include determining that a quantity of non-verified MT calls included in the subset is greater than a second configured threshold. A process can include performing modem-level blocking based on determining a corresponding calling party identity associated with a non-verified MT call included in the subset.


