Virtualizing Gateway SIM Whitelisting in LTE Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current LTE networks face challenges in identifying user identities and providing per-user based functionality due to secured NAS signaling between UE and MME, making it difficult to implement features like whitelisting and blacklisting, especially when transitioning from 3G to LTE technologies.

Innovation Solution

A virtualizing gateway (VG) is introduced to derive user identities, such as IMSI, and apply rules like whitelisting or blacklisting by acting as an S1 proxy, virtualizing UE connections from the MME and presenting itself as an MME to UEs, allowing for intelligent network access control without requiring changes to the EPC or standard eNodeBs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secured NAS signaling is used between UE and MME for authentication, then security is improved, but the ability to identify user identities and apply per-user access control rules deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser identity identification
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a gateway node as an intermediary between the UE and the core network. This gateway can derive user identities (IMSI) from temporary identifiers (GUTI, S-TMSI) contained in NAS messages before they reach the MME, enabling access control filtering while preserving the security of NAS signaling. The gateway acts as a mediator that extracts identification information without compromising authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary derivation of user identities from NAS messages at the gateway before the messages reach the authentication entities. By pre-extracting IMSI information from GUTI/S-TMSI in incoming NAS messages, the system enables access control decisions to be made in advance, allowing whitelisting/blacklisting functionality without interfering with the actual authentication process.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If a virtualizing gateway is introduced to derive user identities and apply access control, then access control capability is improved, but network complexity increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidnetwork architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway node performs multiple functions: it acts as a standard network gateway for message routing, derives user identities from temporary identifiers, applies access control filtering based on whitelists/blacklists, and virtualizes UE connections to multiple core networks. By consolidating these diverse functions into a single multi-functional node, the patent reduces overall network complexity compared to adding separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtualizing gateway serves as an intermediary that virtualizes UE connections to multiple core networks (EPCs). This single intermediary node handles connection management, identity derivation, and access control for multiple operators, replacing what would otherwise require multiple separate gateway nodes, thereby simplifying the network architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If SIM whitelisting and blacklisting are implemented at the gateway, then network access security is improved, but signaling processing complexity increases

Engineering Contradiction:
Improvenetwork access securityVSAvoidsignaling processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway performs preliminary derivation of IMSI from GUTI/S-TMSI and preliminary filtering based on whitelists and blacklists before NAS messages reach the MME. By making access control decisions in advance based on derived identities, the system prevents unauthorized signaling processing, thereby reducing overall signaling processing complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway extracts user identity information (IMSI) from the temporary identifiers (GUTI, S-TMSI) contained in NAS messages. By extracting and utilizing this identification information at the gateway level, the system enables filtering and access control decisions without requiring changes to the core authentication processing, thereby managing signaling processing complexity effectively.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If the gateway acts as an S1 proxy virtualizing UE connections, then network flexibility and multi-operator support are improved, but device complexity increases

Engineering Contradiction:
Improvemulti-operator core network supportVSAvoidgateway functionality
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway is designed as a universal node that simultaneously supports connections to multiple operator core networks (EPCs), performs identity derivation, applies access control, and virtualizes UE connections. By consolidating these multiple functions into a single multi-functional gateway, the patent achieves high network flexibility and multi-operator support without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway acts as an intermediary that virtualizes UE connections to multiple core networks, allowing a single UE to be connected to multiple operators through one gateway node. This intermediary approach simplifies the architecture compared to having separate gateway nodes for each operator, thereby improving adaptability while managing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20220030502A1SIM Whitelisting and Multi-Operator Core Networks
Publication Date: 2022.01.27 PARALLEL WIRELESS INC
  • US20220030502A1 patent drawing
  • US20220030502A1 patent drawing
  • US20220030502A1 patent drawing

AI summary

A method may be disclosed in accordance with some embodiments, comprising: receiving, at a virtualizing gateway, a first service request from a first user equipment (UE) via a first eNodeB; creating, at the virtualizing gateway, an association from each of a plurality of UE identifiers to a desired core network; applying, at the virtualizing gateway, a first filter using a first UE identifier of the first UE, based on the association; forwarding, at the virtualizing gateway, based on the applied first filter, the first service request from the first UE to the first core network; receiving, at the virtualizing gateway, via a second base station, a second service request from a second user equipment (UE); applying, at the virtualizing gateway, a second filter using a second UE identifier of the second UE, based on the association; and forwarding, at the virtualizing gateway, based on the applied second filter, the second service request from the second UE to the second core network.