UE User Data Detection With Central-Edge Abnormal Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The high bandwidth and low latency of 5G networks increase the risk of network attacks due to massive UE access and high service availability, necessitating efficient security detection of user data, while existing methods face challenges with heavy traffic and limited network resources.

Innovation Solution

A data filtering mechanism is employed to reduce the amount of data to be detected by identifying abnormal user equipment (UE) behavior through a central detection node, which determines abnormal group features and sends them to edge detection nodes for filtering, using AI engines to analyze and discard non-compliant data packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all user data is detected to ensure network security, then security detection coverage is improved, but detection efficiency deteriorates due to heavy traffic volume

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the detection system into two parts: a central detection node that analyzes signaling data to identify abnormal UE, and edge detection nodes that filter and detect only relevant data. This segmentation allows the system to maintain comprehensive security coverage while improving detection efficiency by distributing the detection workload and focusing resources on suspicious traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary analysis of signaling data at the central detection node to identify abnormal UE and their characteristics before data reaches the edge detection nodes. This preliminary action enables the edge nodes to filter out normal traffic in advance, so only potentially malicious data requires detailed inspection, thereby improving overall detection efficiency without compromising security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If detection resources are increased to handle massive UE access, then detection capability is improved, but network resource consumption worsens

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local quality by deploying detection capabilities at both central and edge nodes with different functions. The central node focuses on signaling analysis and abnormal UE identification, while edge nodes handle data filtering and inspection. This localized specialization allows the network to achieve comprehensive detection capability without uniformly increasing resources across all nodes, thereby reducing overall network resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by having edge detection nodes filter and inspect only the data relevant to identified abnormal UE, rather than analyzing all user data. This partial inspection approach maintains detection capability for malicious traffic while significantly reducing the computational resources required compared to full-data analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If data filtering is performed to reduce detection volume, then detection efficiency is improved, but detection precision may worsen due to selective filtering

Engineering Contradiction:
Improvedetection efficiencyVSAvoiddetection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where the central detection node continuously analyzes signaling data, identifies abnormal UE, and provides updated abnormal group features to edge detection nodes. This feedback loop ensures that filtering criteria are dynamically adjusted based on actual threat patterns, maintaining detection precision while enabling efficient filtering of normal traffic.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent makes the detection system dynamic by continuously updating the abnormal group features based on real-time signaling data analysis. The edge detection nodes use these dynamic features to adapt their filtering criteria, ensuring that filtering remains precise even as attack patterns evolve, thereby maintaining detection precision while preserving efficiency benefits.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12418796B2Method and device for detecting user data of user equipment UE, and storage medium
Publication Date: 2025.09.16 HUAWEI TECH CO LTD
  • US12418796B2 patent drawing
  • US12418796B2 patent drawing
  • US12418796B2 patent drawing

AI summary

This application discloses a method and device for detecting user data of UE, and a storage medium. The central detection node device determines abnormal UE based on core network signaling data, determines an abnormal group feature based on the abnormal UE and sends the abnormal group feature to an edge detection node device. Where the abnormal UE is UE with an abnormal behavior and the abnormal group feature includes an identifier or a user data transmission mode used by the abnormal UE to perform communication.