SS7 Interface Security via Message Filtering and Address Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The SS7/MAP protocol in mobile networks is vulnerable to attacks, allowing external users to potentially carry out fraud, violate privacy, and pose security risks due to inadequate protection mechanisms, leading to unauthorized access and manipulation of mobile phone subscriber data.

Innovation Solution

A method and system for securing SS7 network access by analyzing and filtering SS7/MAP messages, verifying sender and recipient addresses, checking for legitimate requests, and rejecting or discarding unauthorized or suspicious messages, including determining the home network of a mobile subscriber and verifying the presence of the subscriber in the network, to prevent fraudulent activities and protect the internal SS7 signaling network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If SS7/MAP protocol is used for mobile network signaling, then communication efficiency and network functionality are improved, but vulnerability to attacks and security risks increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidvulnerability to attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security system positioned between external SS7 networks and the mobile network core. This intermediary analyzes incoming SS7/MAP messages, verifies address legitimacy, checks for attack patterns, and filters malicious traffic before it reaches vulnerable network elements like HLR and VLR. This mediator approach allows the system to maintain SS7 protocol functionality while adding a protective layer that blocks fraud and attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security checks on incoming SS7/MAP messages before they are processed by the mobile network. The system pre-validates sender addresses against known mobile network prefixes, pre-identifies potential attack patterns such as bulk location requests or authentication bypass attempts, and pre-rejects suspicious messages. This preliminary action prevents malicious traffic from consuming network resources or compromising security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If address verification and message filtering are implemented, then security against attacks is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvesecurity against attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial verification by focusing security checks on the most critical aspects of SS7/MAP messages. Rather than validating every single parameter, the system performs targeted checks on key fields such as sender address format, message type legitimacy, and obvious attack patterns. This selective approach provides sufficient security protection while minimizing processing overhead and maintaining fast message handling for legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent uses lightweight, disposable security validation rules that can be quickly created, deployed, and discarded. Security filters are implemented as simple pattern-matching rules and address validation lists that require minimal computational resources. These validation mechanisms can be rapidly updated to counter new attack vectors without requiring complex, long-lived security infrastructure, thus reducing processing time while maintaining security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If comprehensive message analysis and filtering are performed, then prevention of fraudulent activities is improved, but device complexity increases

Engineering Contradiction:
Improveprevention of fraudulent activitiesVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security analysis function into distinct modular components: address validation module, message type verification module, attack pattern detection module, and filtering module. Each component handles a specific aspect of security validation independently. This segmentation allows the complex security function to be implemented as separate, manageable modules that can be independently configured, maintained, and updated, reducing overall system complexity while providing comprehensive fraud prevention.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3029973B1Method and a device for securing a signalling system 7-interface
Publication Date: 2020.05.06 GSMK FUR SICHERE MOBILE KOMMUNIKATION MBH
  • EP3029973B1 patent drawingFigure 1
  • EP3029973B1 patent drawingFigure 2
  • EP3029973B1 patent drawingFigure 3~4

AI summary

A method for securing a signaling system No. 7 interface (SS7 interface) of a system through which access to a local mobile network is provided against an external system, comprising one or more of the following analysis steps: a) determining whether an SS7/MAP-MSU (Mobile Application Part Message Signal Unit) is using valid addresses within a multitude of protocol layers in the interconnect between mobile networks; if no valid addresses are found, the SS7/MAP-MSU is rejected; b) determining whether a mobile subscriber in the interconnect between mobile networks is signaled by one mobile network R as being present in that mobile network R, although it is present in another mobile network; if so, a request is rejected;c) Determine whether an SS7/MAP-MSU has been sent en masse to various network elements of a mobile network in the interconnect between mobile networks for the purpose of locating a mobile device; if so, the SS7/MAP-MSU is rejected; d) Determine whether there has been an abusive modification of mobile subscriber data by falsifying a sender address of SS7/MAP-MSUs in the interconnect between mobile networks; if so, the SS7/MAP-MSU is rejected; e) Determine the legitimacy of an external system by checking the sender and receiver global titles of the SS7/MAP-MSU.