Virtualizing Gateway SIM Whitelisting for LTE Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing LTE network technologies face challenges in identifying user identities securely and efficiently, particularly in small cell environments, which hinders intelligent functionality on a per-user basis and complicates quarantining of rogue UEs.
Innovation Solution
A virtualizing gateway (VG) is introduced to act as a gateway between eNodeBs and core networks, capable of deriving user identities through IMSI extraction and applying whitelisting or blacklisting filters to authenticate and manage user access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM-based authentication is used in LTE networks, then user identity security is improved, but network complexity increases due to core network involvement
Solution Approach 1:
The patent introduces a virtualizing gateway as an intermediary component between the eNodeB and core network. This gateway extracts IMSI identifiers from UE messages and applies whitelisting/blacklisting filters locally, thereby maintaining security requirements while reducing the need for complex core network authentication procedures. The gateway acts as a mediator that handles identity verification before messages reach the core network.
Solution Approach 2:
The patent implements preliminary filtering actions at the virtualizing gateway by maintaining whitelists and blacklists of IMSI identifiers. Before messages are forwarded to the core network, the gateway pre-authenticates UEs by checking their IMSI against these lists. This preliminary action reduces the authentication burden on the core network and simplifies overall network complexity.
2Reliability
If per-user authentication is implemented, then network security is improved, but signaling load on core network increases
Solution Approach 1:
The virtualizing gateway serves as an intermediary that performs local authentication filtering using IMSI whitelisting and blacklisting. By handling authentication decisions at the gateway level rather than requiring all authentication signaling to reach the core network, the solution maintains per-user security while significantly reducing the signaling load on core network elements.
Solution Approach 2:
The patent extracts the authentication filtering function from the core network and places it at the virtualizing gateway. By taking out this specific authentication function and implementing it locally at the gateway using IMSI-based filters, the system maintains security requirements while reducing the signaling burden on core network elements.
3Reliability
If SIM whitelisting is implemented at gateway level, then rogue UE quarantining is improved, but device complexity at gateway increases
Solution Approach 1:
The virtualizing gateway acts as an intermediary that implements SIM whitelisting and blacklisting functionality. By concentrating the authentication filtering logic at this single gateway point rather than distributing it across multiple network elements, the solution achieves effective rogue UE quarantining while limiting the complexity increase to a single strategic location in the network.
Solution Approach 2:
The virtualizing gateway is designed to perform multiple functions including message forwarding, IMSI extraction, authentication filtering via whitelists/blacklists, and rogue UE identification. By making the gateway multi-functional, the patent consolidates several security and routing functions into a single device, achieving rogue UE quarantining without proportionally increasing overall network complexity.
Data Source
AI summary
A method may be disclosed in accordance with some embodiments, comprising: receiving, at a virtualizing gateway, a first service request from a first user equipment (UE) via a first eNodeB; creating, at the virtualizing gateway, an association from each of a plurality of UE identifiers to a desired core network; applying, at the virtualizing gateway, a first filter using a first UE identifier of the first UE, based on the association; forwarding, at the virtualizing gateway, based on the applied first filter, the first service request from the first UE to the first core network; receiving, at the virtualizing gateway, via a second eNodeB, a second service request from a second user equipment (UE); applying, at the virtualizing gateway, a second filter using a second UE identifier of the second UE, based on the association; and forwarding, at the virtualizing gateway, based on the applied second filter, the second service request from the second UE to the second core network.


