SMF EASDF Report Control for Signaling Storm Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In edge computing scenarios, malicious DNS queries from user equipment (UE) can trigger excessive control plane signaling, leading to signaling storms and denial-of-service (DOS) attacks, which overwhelm the mobile communication system and prevent it from serving normal UE.
Innovation Solution
The Session Management Function (SMF) transmits control information to the Edge Application Server Discovery Function (EASDF) to ban, stop, reduce, or limit the transmission of reports to the SMF, thereby mitigating the impact of malicious DNS queries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the EASDF transmits reports to the SMF according to the reporting rule, then the SMF can obtain DNS query information, but the system is vulnerable to DOS attacks from malicious DNS queries
Solution Approach 1:
The patent applies preliminary anti-action by having the SMF proactively send control information to the EASDF to ban report transmission before a DOS attack can overwhelm the system. This preventive measure blocks malicious signaling storms before they can cause system failure, while still allowing legitimate DNS query processing to continue.
Solution Approach 2:
The control information acts as an intermediary mechanism between the SMF and EASDF. It mediates the report transmission process by providing a control layer that can selectively block malicious reports while allowing legitimate ones to pass through, thus protecting the system from DOS attacks without completely disabling the reporting function.
2Loss of information
If the EASDF transmits multiple reports to the SMF in response to malicious DNS queries, then the SMF receives comprehensive DNS information, but the control plane signaling is overwhelmed
Solution Approach 1:
The patent extracts the harmful element (excessive report transmission) from the system by implementing a ban on report transmission from EASDF to SMF. This extraction removes the problematic signaling traffic that causes system overload, while the essential DNS query processing function remains intact and operational.
Solution Approach 2:
The patent applies partial action by selectively banning report transmission only when control information is received, rather than completely disabling the reporting function. This allows the system to maintain DNS information collection capabilities when needed while preventing excessive signaling during attack conditions.
3Adaptability or versatility
If the EASDF continues to transmit reports during a DOS attack, then the reporting function remains active, but normal UE cannot be served
Solution Approach 1:
The control information serves as an intermediary that regulates report transmission to protect service availability. It mediates between the need to maintain reporting function adaptability and the need to ensure reliable service for normal UE by blocking malicious reports that would otherwise overwhelm the system.
Solution Approach 2:
The patent applies preliminary anti-action by preemptively banning report transmission when control information is received, preventing the system from entering a state where service availability is compromised. This ensures that normal UE can continue to be served by preventing the signaling storm before it disrupts service.
Data Source
AI summary
A report control method includes: transmitting, by a session management function (SMF), control information to an edge application server discovery function (EASDF), the control information being used for banning, stopping, or reducing transmission of a report to the SMF by the EASDF.


