IP Library › Granted Patent US 12,726,825
Granted Patent B2
US 12,726,825 · App. 18/602,851 · Granted Sep 1, 2026

Automated suspect device filtering on equipment identity registers

Inventors: Anil Kumar Mariyani (Ashburn, VA); Anjj Sharma (Broadlands, VA); Chris Jensen (Snoqualmie, WA); Tupalli Shruthisagar (Aldie, VA); Rajil Malhotra (Olathe, KS)
Assignee: T-MOBILE INNOVATIONS LLC
H04W12/37H04L63/0876H04W8/02H04W12/009H04W12/122H04W12/66H04W12/71H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,825
App. No.
18/602,851
Filed
Mar 12, 2024
Granted
Sep 1, 2026
Kind
B2
Examiner
ZHU, ZHIMEI
Art Unit
2495
USPC
726/4
Abstract

Embodiments of the present disclosure are directed to systems and methods for improving wireless network services by carrying out various procedures to identify and filter suspect user devices. A network function may monitor a plurality of network service requests from a particular user device and determine, based on the plurality of network services requests, that the requesting user device is engaged in suspicious activity. Upon such a determination, the network function may initiate one or more enforcement actions by communicating an instruction to an equipment identity register to add the requesting user device to a suspect device list stored on a unified data repository.

Claims (43)

1 . A method for suspect device filtering in a wireless communication network, the method comprising:

communicating, by an access network, a plurality of connection failure messages to a user device in response to receiving a plurality of requests for a network service from the user device, wherein the user device is associated with a permanent device identifier;

determining, by a first network function of a core network, and based at least in part on the plurality of connection failure messages communicated to the user device during a first predetermined time, that the user device is suspect, wherein the first network function is associated with the provision of the requested network service;

adding the user device to a suspect device list maintained on the first network function based on the determination that the user device is suspect;

receiving, at the radio access network, a subsequent request for the network service from the user device;

communicating the subsequent request for the network service from the radio access network to the first network function;

determining by the first network function, based on a query of a locally stored second suspect device list, that the user device is blacklisted;

communicating an access denial for the network service from the first network function to the user device, via the radio access network; and

ignoring subsequent requests from the user device for the network service after the access denial is communicated,

wherein determining that the user device is suspect comprises the network function determining that a number of the plurality of connection failure messages communicated to the user device within a predetermined time period exceeds a predetermined threshold, and

wherein the suspect device list is a first-level suspect device list that limits access to one or more network services for the user device, and wherein the method further comprises, in response to receiving one or more additional requests from the user device after the user device is added to the first-level suspect device list, adding the user device to a higher-level suspect device list that prevents the user device from accessing the one or more network services.

2 . The method of claim 1 , wherein the predetermined threshold is a modifiably configurable parameter.

3 . The method of claim 2 , wherein the predetermined time period is a modifiably configurable parameter.

4 . The method of claim 1 , wherein the permanent device identifier comprises an international mobile station equipment identity (IMEI).

5 . The method of claim 1 , wherein the network function comprises an access mobility function, call session control function, or internet protocol multimedia system media gateway.

6 . The method of claim 1 , wherein determining that the user device is suspect further comprises the network function determining that a greater than threshold amount of temporary identity failures have occurred within a predetermined time period.

7 . The method of claim 1 , wherein the access denial is communicated to the user device without a subsequent query to the second network function.

8 . A method for suspect device filtering in a wireless communication network, the method comprising:

determining that a triggering event has occurred in a geographic area, the triggering event comprising a threshold high utilization of one or more radio access network nodes in the geographic area;

subsequent to said determination, receiving, at a radio access network, a plurality of requests for a network service from a user device, wherein the user device is associated with a permanent device identifier;

communicating the plurality of requests for the network service to a network function, wherein the network function is associated with the provision of the requested network service;

determining, by the network function, and based at least in part on the receipt of the plurality of requests for the network service from the user device during a first predetermined time period and that the user device is located in the geographic area, that the user device is suspect;

adding the user device to a suspect device list, wherein the suspect device list is stored on a data repository; and

ignoring subsequent requests from the user device for the network service after the access denial is communicated.

9 . A method for suspect device filtering in a wireless communication network, the method comprising:

receiving, at a networked computer processing component, a plurality of requests for a network service from a device attempting to access one or more internet resources, wherein the device is associated with a permanent device identifier, and wherein the networked computer processing component is associated with a provider of internet service;

determining, by the networked computer processing component, and based at least in part on the receipt of the plurality of requests from the device during a first predetermined time period, that the device is suspect;

adding the device to a locally stored suspect device list maintained on the networked computer processing component;

receiving a subsequent request from the device at the networked computer processing component;

determining, based on a query of the locally stored suspect device list, that the device is blacklisted;

communicating an access denial from the networked computer processing component to the device; and

ignoring subsequent requests from the user device for the network service after the access denial is communicated,

wherein determining that the device is suspect comprises the networked computer processing component determining that a number of the plurality of requests that have been received by the networked computer processing component within a predetermined time period exceed a predetermined threshold,

wherein the locally stored suspect device list is a first-level suspect device list that limits access to one or more network services for the device, and wherein the method further comprises, in response to receiving one or more additional requests from the device after the device is added to the first-level suspect device list, adding the device to a higher-level suspect device list that prevents the device from accessing the one or more network services list, adding the device to a higher-level suspect device list that prevents the device from accessing the one or more network services.

10 . The method of claim 9 , wherein the predetermined threshold is a modifiably configurable parameter.

11 . The method of claim 10 , wherein the predetermined time period is a modifiably configurable parameter.

12 . The method of claim 9 , wherein the permanent device identifier comprises an international mobile station equipment identity (IMEI).

13 . The method of claim 9 , wherein the networked computer processing component comprises an access mobility function, call session control function, or internet protocol multimedia system media gateway.

14 . The method of claim 9 , wherein determining that the user device is suspect further comprises the networked computer processing component determining that a greater than threshold amount of temporary identity failures have occurred within a predetermined time period.

15 . The method of claim 9 , further comprising communicating, based on the determination that the user device is suspect, an indication from the networked computer processing component to a second network function of the core network that causes the user device to be added to a second suspect device list maintained on the second network function, the second network function being one or more of a unified data repository and an equipment identity register, wherein the second network function is remote from the first network function.

16 . The method of claim 15 , further comprising associating the user device with the suspect device list in response to an acknowledgement from the second network function.

17 . The method of claim 16 , wherein the access denial is communicated to the user device without a subsequent query to the second network function.

18 . The method of claim 9 , wherein the method further comprises determining that a triggering event has occurred in a geographic area, the triggering event comprising one or more of a threshold high utilization of one or more radio access network nodes, a threshold high decrease in traffic capacity of one or more radio access network nodes, or a threshold large degradation of one or more key performance areas associated with providing wireless telecommunication service to the geographic area.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2024
From: MARIYANI, ANIL KUMAR; SHARMA, ANUJ; JENSEN, CHRIS; SHRUTHISAGAR, TUPALLI; MALHOTRA, RAJIL
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 066809/0989 →
Continuity (2)
Continuation 17394217 · Aug 4, 2021
Related Publication 20240224045A1 · Jul 4, 2024
References Cited (39)
US 7570941B2 · Mahajan · 2009 [cited by applicant]
US 9094839B2 · Shaikh et al. · 2015 [cited by applicant]
US 9380630B2 · Youtz · 2016 [cited by examiner]
US 10749867B1 · Litani · 2020 [cited by examiner]
US 10951461B2 · Ganu et al. · 2021 [cited by applicant]
US 20070077912A1 · Mahajan · 2007 [cited by applicant]
US 20120014332A1 · Smith · 2012 [cited by examiner]
US 20120028606A1 · Bobotek · 2012 [cited by examiner]
US 20140179263A1 · Collins · 2014 [cited by examiner]
US 20160029246A1 · Mishra et al. · 2016 [cited by applicant]
US 20160099963A1 · Mahaffey et al. · 2016 [cited by applicant]
US 20170006522A1 · Nishimura et al. · 2017 [cited by applicant]
US 20180007534A1 · Thakolsri et al. · 2018 [cited by applicant]
US 20180034814A1 · Tachikawa · 2018 [cited by applicant]
US 20190297083A1 · Li et al. · 2019 [cited by applicant]
US 20200187048A1 · Mishra · 2020 [cited by examiner]
US 20210144555A1 · Kim · 2021 [cited by examiner]
US 20210203575A1 · Hanetz et al. · 2021 [cited by applicant]
US 20210273783A1 · Park · 2021 [cited by applicant]
US 20210367888A1 · Ramamurthi · 2021 [cited by applicant]
US 20220006756A1 · Ramaswamy et al. · 2022 [cited by applicant]
US 20220345914A1 · Kim et al. · 2022 [cited by applicant]
US 20230164590A1 · Yamine · 2023 [cited by examiner]
CN 105636049A · 2016 [cited by examiner]
CN 101540758A · 2023 [cited by examiner]
EP 2334011A1 · 2011 [cited by examiner]
EP 2334011B1 · 2013 [cited by applicant]
JP 2020005102A · 2020 [cited by applicant]
KR 1020100072973A · 2010 [cited by applicant]
KR 1020210050978A · 2021 [cited by applicant]
WO WO2014105995A1 · 2014 [cited by examiner]
WO 2017092823A1 · 2017 [cited by applicant]
“Max authentication failures”, Jun. 11, 2012, obtained online from <https://community.arubanetworks.com/discussion/max-authentication-failures>, retrieved on May 31, 2025. (Year: 2012). [cited by examiner]
Dzmitry Reshytnik, “Prevent Bad Signals From Harming Network Availability”, obtained online from <https://www.paloaltonetworks.com/blog/2018/02/sp-prevent-bad-signals-harming-network-availability/#:~:text=With%20these%2… [cited by examiner]
Broadforward BV, Equipment Identity Register (EIR), https://www.broadforward.com/equipment-identity-register-eir/, Mar. 1, 2021, Amersfoort, Netherlands, 4 pages. [cited by applicant]
Nicole Singh, “What is the 5G Access and MobilityManagement Function (AMF)?”, Jan. 5, 2023, obtained online from <https://techcommunity.microsoft.com/t5/azure-for-operators-blog/what-is-the-5g-access-and-mobility-manage… [cited by applicant]
Robocall Strike Force Report, Oct. 26, 2016, obtained from <https://transition.fcc.gov/cgb/Robocall-Strike-Force-Final-Report.pdf>, retrieved on Oct. 20, 2023 (Year: 2016). [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/394,219, mailed on Jul. 30, 2024, 11 pages. [cited by applicant]
Final Office Action received for U.S. Appl. No. 17/394,219, mailed on Mar. 27, 2024, 21 pages. [cited by applicant]