Virtualizing Gateway SIM Whitelisting in LTE Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current LTE networks face challenges in identifying user identities and providing per-user based functionality due to secured NAS signaling between UE and MME, making it difficult to implement features like whitelisting and blacklisting, especially when transitioning from 3G to LTE technologies.
Innovation Solution
A virtualizing gateway (VG) is introduced to derive user identities, such as IMSI, and apply rules like whitelisting or blacklisting by acting as an S1 proxy, virtualizing UE connections from the MME and presenting itself as an MME to UEs, allowing for intelligent network access control without requiring changes to the EPC or standard eNodeBs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secured NAS signaling is used between UE and MME for authentication, then security is improved, but the ability to identify user identities and apply per-user access control rules deteriorates
Solution Approach 1:
The patent introduces a gateway node as an intermediary between the UE and the core network. This gateway can derive user identities (IMSI) from temporary identifiers (GUTI, S-TMSI) contained in NAS messages before they reach the MME, enabling access control filtering while preserving the security of NAS signaling. The gateway acts as a mediator that extracts identification information without compromising authentication security.
Solution Approach 2:
The patent implements preliminary derivation of user identities from NAS messages at the gateway before the messages reach the authentication entities. By pre-extracting IMSI information from GUTI/S-TMSI in incoming NAS messages, the system enables access control decisions to be made in advance, allowing whitelisting/blacklisting functionality without interfering with the actual authentication process.
2Adaptability or versatility
If a virtualizing gateway is introduced to derive user identities and apply access control, then access control capability is improved, but network complexity increases
Solution Approach 1:
The gateway node performs multiple functions: it acts as a standard network gateway for message routing, derives user identities from temporary identifiers, applies access control filtering based on whitelists/blacklists, and virtualizes UE connections to multiple core networks. By consolidating these diverse functions into a single multi-functional node, the patent reduces overall network complexity compared to adding separate dedicated components for each function.
Solution Approach 2:
The virtualizing gateway serves as an intermediary that virtualizes UE connections to multiple core networks (EPCs). This single intermediary node handles connection management, identity derivation, and access control for multiple operators, replacing what would otherwise require multiple separate gateway nodes, thereby simplifying the network architecture.
3Reliability
If SIM whitelisting and blacklisting are implemented at the gateway, then network access security is improved, but signaling processing complexity increases
Solution Approach 1:
The gateway performs preliminary derivation of IMSI from GUTI/S-TMSI and preliminary filtering based on whitelists and blacklists before NAS messages reach the MME. By making access control decisions in advance based on derived identities, the system prevents unauthorized signaling processing, thereby reducing overall signaling processing complexity while maintaining security.
Solution Approach 2:
The gateway extracts user identity information (IMSI) from the temporary identifiers (GUTI, S-TMSI) contained in NAS messages. By extracting and utilizing this identification information at the gateway level, the system enables filtering and access control decisions without requiring changes to the core authentication processing, thereby managing signaling processing complexity effectively.
4Adaptability or versatility
If the gateway acts as an S1 proxy virtualizing UE connections, then network flexibility and multi-operator support are improved, but device complexity increases
Solution Approach 1:
The gateway is designed as a universal node that simultaneously supports connections to multiple operator core networks (EPCs), performs identity derivation, applies access control, and virtualizes UE connections. By consolidating these multiple functions into a single multi-functional gateway, the patent achieves high network flexibility and multi-operator support without proportionally increasing device complexity.
Solution Approach 2:
The gateway acts as an intermediary that virtualizes UE connections to multiple core networks, allowing a single UE to be connected to multiple operators through one gateway node. This intermediary approach simplifies the architecture compared to having separate gateway nodes for each operator, thereby improving adaptability while managing device complexity.
Data Source
AI summary
A method may be disclosed in accordance with some embodiments, comprising: receiving, at a virtualizing gateway, a first service request from a first user equipment (UE) via a first eNodeB; creating, at the virtualizing gateway, an association from each of a plurality of UE identifiers to a desired core network; applying, at the virtualizing gateway, a first filter using a first UE identifier of the first UE, based on the association; forwarding, at the virtualizing gateway, based on the applied first filter, the first service request from the first UE to the first core network; receiving, at the virtualizing gateway, via a second base station, a second service request from a second user equipment (UE); applying, at the virtualizing gateway, a second filter using a second UE identifier of the second UE, based on the association; and forwarding, at the virtualizing gateway, based on the applied second filter, the second service request from the second UE to the second core network.


