IP Library › Granted Patent US 12,262,208
Granted Patent B2
US 12,262,208 · App. 18/135,105 · Granted Mar 25, 2025

Methods, systems, and computer readable media for performing location and velocity check at security edge protection proxy (SEPP) to avoid spoofing

Inventors: Ashish Jyoti Sharma (New Delhi, IN); Jay Rajput (Bangalore, IN); John Nirmal Mohan Raj (Bangalore, IN)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04W12/122H04W12/06H04W12/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,262,208
App. No.
18/135,105
Granted
Mar 25, 2025
Kind
B2
Abstract

A method for performing a location and velocity check at an SEPP to protect against a spoofing attack includes receiving an SBI request message relating to authentication of UE. The method further includes querying a database NF to obtain previous authentication information for the UE, the previous authentication information including a previous network identifier and a previous authentication time for the UE. The method further includes receiving a response from the database NF, the response including the previous network identifier and the previous authentication time. The method further includes reading, a current network identifier from the SBI request message, performing, using the current network identifier from the SBI request message, the previous network identifier, the previous authentication time, and a time of receipt by the SEPP of the SBI request message, a location and velocity check for the UE, and performing a network security action for the SBI request message based on results of the location and velocity check.

Claims (34)

1. A method for performing a location and velocity check at a security edge protection proxy (SEPP) to protect against a spoofing attack, the method comprising:

receiving, at an SEPP, a service-based interface (SBI) request message relating to authentication of a user equipment (UE);

querying, by the SEPP, a database network function (NF) to obtain previous authentication information for the UE, the previous authentication information including a previous network identifier and a previous authentication time for the UE;

receiving, at the SEPP, a response from the database NF, the response including the previous network identifier and the previous authentication time;

reading, by the SEPP, a current network identifier from the SBI request message;

performing, by the SEPP and using the current network identifier from the SBI request message, the previous network identifier, the previous authentication time, and a time of receipt by the SEPP of the SBI request message, a location and velocity check for the UE; and

performing a network security action for the SBI request message based on results of the location and velocity check.

2. The method of claim 1 wherein receiving the SBI request message relating to authentication of a UE includes receiving an Nausf_UEauthentication message.

3. The method of claim 1 wherein querying the database NF includes transmitting an authentication information query message to a unified data repository (UDR) using an application programming interface (API) provided by the UDR for previous authentication information queries from the SEPP.

4. The method of claim 1 wherein querying the database NF includes transmitting an authentication information query message to a unified data management function (UDM) using an application programming interface (API) provided by the UDM for previous authentication information queries from the SEPP.

5. The method of claim 4 comprising, at the UDM, receiving the authentication information query message and querying a unified data repository (UDR) for the previous authentication information for the UE.

6. The method of claim 5 comprising, at the UDM, determining that the authentication information query message includes a subscription concealed identifier (SUCI), and, in response, prior to querying the UDR, invoking a subscription identifier de-concealing function (SIDF) to de-conceal the SUCI.

7. The method of claim 1 wherein reading the current network identifier from the SBI request message includes reading a public land mobile network (PLMN) ID from the SBI request message.

8. The method of claim 1 wherein performing the location and velocity check includes determining whether a distance between a previous network identified by the previous network identifier and a current network identified by the current network identifier could have been traveled by the UE in light of a time difference between the previous authentication time and the time of receipt of the SBI request message.

9. The method of claim 8 wherein performing the network security action includes blocking the SBI request message in response to determining that the distance could not have been traveled by the UE.

10. The method of claim 8 wherein performing the network security action includes blocking future messages from a sender of the SBI request message in response to determining that the distance could not have been traveled by the UE.

11. The method of claim 4 wherein the UDM queries a unified data repository (UDR) for the previous authentication information for the UE, the UDR provides the previous authentication information for the UE to the UDM, and the response received by the SEPP is from the UDM.

12. A system for performing a location and velocity check at a security edge protection proxy (SEPP) to protect against a spoofing attack, the system comprising:

an SEPP including at least one processor and a memory;

a user equipment (UE)-authentication-based location and velocity checker implemented by the at least one processor for receiving a service based interface (SBI) request message relating to authentication of a UE, querying a database network function (NF) to obtain previous authentication information for the UE, the previous authentication information including a previous network identifier and a previous authentication time for the UE, the UE-authentication-based location and velocity checker for receiving a response from the database NF, the response including the previous network identifier and the previous authentication time, reading, by the SEPP, a current network identifier from the SBI request message, performing, using the current network identifier from the SBI request message, the previous network identifier, the previous authentication time, and a time of receipt by the SEPP of the SBI request message, a location and velocity check for the UE, and performing a network security action for the SBI request message based on results of the location and velocity check.

13. The system of claim 12 wherein the SBI request message relating to authentication of a UE includes an Nausf_UEauthentication message.

14. The system of claim 12 wherein, in querying the database NF, the UE-authentication-based location and velocity checker is configured to transmit an authentication information query message to a unified data repository (UDR) using an application programming interface (API) provided by the UDR for previous authentication information queries from the SEPP.

15. The system of claim 12 wherein, in querying the database NF, the UE-authentication-based location and velocity checker is configured to transmit an authentication information query message to a unified data management function (UDM) using an application programming interface (API) provided by the UDM for previous authentication information queries from the SEPP.

16. The system of claim 12 wherein the current network identifier includes a public land mobile network (PLMN) ID.

17. The system of claim 12 wherein, in performing the location and velocity check, the UE-authentication-based location and velocity checker is configured to determine whether a distance between a previous network identified by the previous network identifier and a current network identified by the current network identifier could have been traveled by the UE in light of a time difference between the previous authentication time and the time of receipt of the SBI request message.

18. The system of claim 17 wherein the network security action includes blocking the SBI request message in response to determining that the distance could not have been traveled by the UE.

19. The system of claim 17 wherein the network security action includes blocking future messages from a sender of the SBI request message in response to determining that the distance could not have been traveled by the UE.

20. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

receiving, at a security edge protection proxy (SEPP), a service-based interface (SBI) request message relating to authentication of a user equipment (UE);

querying, by the SEPP, a database network function (NF) to obtain previous authentication information for the UE, the previous authentication information including a previous network identifier and a previous authentication time for the UE;

receiving, at the SEPP, a response from the database NF, the response including the previous network identifier and the previous authentication time;

reading, by the SEPP, a current network identifier from the SBI request message;

performing, by the SEPP and using the current network identifier from the SBI request message, the previous network identifier, the previous authentication time, and a time of receipt by the SEPP of the SBI request message, a location and velocity check for the UE; and

performing a network security action for the SBI request message based on results of the location and velocity check.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2023
From: SHARMA, ASHISH JYOTI; RAJPUT, JAY; MOHAN RAJ, JOHN NIRMAL
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 063343/0705 →
Continuity (1)
Related Publication 20240349057A1 · Oct 17, 2024
References Cited (23)
US 10470154B2 · Chellamani et al. · 2019 [cited by applicant]
US 10834045B2 · Mahalank et al. · 2020 [cited by applicant]
US 20060276226A1 · Jiang · 2006 [cited by examiner]
US 20100313024A1 · Weniger · 2010 [cited by examiner]
US 20110014939A1 · Ravishankar · 2011 [cited by examiner]
US 20110170532A1 · Tchepnda · 2011 [cited by examiner]
US 20220070674A1 · Russell · 2022 [cited by applicant]
US 20220159445A1 · Rajavelu · 2022 [cited by applicant]
US 20220201489A1 · Mahalank et al. · 2022 [cited by applicant]
US 20220272541A1 · Rajput · 2022 [cited by examiner]
US 20220369091A1 · Nair et al. · 2022 [cited by applicant]
US 20240349059A1 · Sharma et al. · 2024 [cited by applicant]
Hailu et al., “Hybrid paging and location tracking scheme for inactive 5G UEs”, Jun. 2017, European Conference on Networks and Communications, pp. 1-6 (Year: 2017). [cited by examiner]
Yakhlef et al., “Simulation of Location Management Strategies of Timer, Location Area, and Movement Based Update/Paging for Wireless Networks”, May 2013, The International Conference on Technological Advances in Electri… [cited by examiner]
Commonly-Assigned, co-pending U.S. Appl. No. 18/135,108 for “Methods, Systems, and Computer Readable Media for Performing Location and Velocity Check at Security Edge Protection Proxy (SEPP) Using Service Communication … [cited by applicant]
5G Interconnect Security, GSMA FS-36, Version 2.0, Jun. 3, 2021. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 18) 3GPP TS 33.501 V18.0.0 (Dec. 2022). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Principles and Guidelines for Services Definition; Stage 3 (Release 18) 3GPP TS 29.501 V18.0.0 (Dec. 2022). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 18) 3GPP TS 29.500 V18.0.0 (Dec. 2022). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 18) 3GPP TS 29.510 V18.1.0 (Dec. 2022). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17) 3GPP TS 23.502 V17.7.0 (Dec. 2022). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects for the 5G System (5GS); Stage 2; (Release 17) 3GPP TS 23.501 V17.7.0 (Dec. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 18)” 3GPP TS 33.501 V18.1.0, pp. 1-293 (Mar. 2023). [cited by applicant]
Cited By (1)
US 12,532,181