A mobile network security system
Abstract
A security system for a mobile network (1) that has a gateway (3) for receiving messages from outside the network and a network element (10) that stores mobile terminal position information, characterized in that the system of Security (2) is adapted to: monitor in real time query requests that enter the network through the gateway (3), monitor in real time messages that enter the network through the gateway and their correspondence with said query requests; decide under such supervision if messages are likely to be unsolicited; and where the system also includes a data memory (5) and a timer (6), the system is adapted to store in the data memory information regarding query requests received from the gateway, and to decide what is a message is likely to be unsolicited if a corresponding prior query request has not been received within a pre-established period of time.

Term
Term ended
Projected expiry passed 18 January 2026, 0.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
21 claims: 6 independent, 15 dependent
- 1ES 2 322 396 T3 REIVINDICACIONES 1. Un sistema de seguridad para una red móvil (1) que tiene una puerta de enlace (3) para recibir mensajes de fuera de la red y un elemento de red (10) que guarda información de posición de terminal móvil, caracterizado porque el sistema de seguridad (2) está adaptado para:supervisar en tiempo real peticiones de consulta que entran en la red a través de la puerta de enlace (3), supervisar en tiempo real mensajes que entran en la red a través de la puerta de enlace y su correspondencia con dichas peticiones de consulta;decidir según dicha supervisión si es probable que los mensajes sean no solicitados;y donde el sistema incluye además una memoria de datos (5) y un temporizador (6), el sistema está adaptado para almacenar en la memoria de datos información con relación a peticiones de consulta recibidas de la puerta de enlace, y para decidir que es probable que un mensaje sea no solicitado si una petición de consulta anterior correspondiente no se ha recibido dentro de un período de tiempo preestablecido.
- 2Un sistema según la reivindicación 1, donde el sistema está adaptado para determinar que una petición de consulta corresponde a un mensaje si tiene la misma dirección de terminación.
- 3Un sistema según cualquier reivindicación precedente, donde el sistema está adaptado para supervisar una dirección fuente de una petición de consulta y una dirección fuente de un mensaje correspondiente, y decide que es probable que el mensaje sea no solicitado si su dirección fuente es diferente de la de la petición de consulta correspondiente.
- 4Un sistema según cualquier reivindicación precedente, donde el sistema está adaptado para almacenar la información de petición de consulta en la memoria de datos (5) solamente durante un período de tiempo preestablecido, y determinar, cuando a la recepción de un mensaje se busca en la memoria de datos si se ha recibido una petición de consulta anterior correspondiente dentro de dicho período de tiempo preestablecido, si se guarda en la memoria de datos información con relación a dicha petición de consulta.
- 5Un sistema según cualquier reivindicación precedente, donde el sistema está adaptado para activar el temporizador a la recepción de una petición de consulta.
- 6Un sistema según la reivindicación 5, donde el temporizador está configurado para funcionar desde el tiempo de recepción T 0 hasta un límite de tiempo preestablecido T preset _ end .
- 7Un sistema según cualquier reivindicación precedente, donde el sistema está adaptado para establecer el límite de tiempo del temporizador T preset _ end para una categoría de petición de consulta.
- 8Un sistema según cualquier reivindicación precedente, donde el sistema está adaptado para bloquear mensajes que probablemente son no solicitados.
- 9Un sistema según cualquier reivindicación precedente, donde el sistema es configurable para enviar un reconocimiento positivo o negativo según la supervisión.
- 10Un sistema según cualquier reivindicación precedente, donde el sistema está adaptado para marcar como sospechosa y mantener para investigación adicional una dirección fuente de una petición de consulta correspondiente a un mensaje que probablemente es no solicitado.
- 11Un método implementado por un sistema de seguridad (4) para supervisar mensajes en una red móvil que tiene una puerta de enlace (3) para recibir mensajes de fuera de la red y un elemento de red (10) que guarda información de posición de terminal móvil, caracterizado porque el método incluye los pasos del sistema de seguridad:supervisar en tiempo real peticiones de consulta que entran en la red a través de la puerta de enlace (3);supervisar en tiempo real mensajes que entran en la red a través de la puerta de enlace (3) y su correspondencia con dichas peticiones de consulta;decidir según dicha supervisión si es probable que los mensajes sean no solicitados;y donde el sistema (4) guarda en una memoria de datos (5) información con relación a peticiones de consulta recibidas de la puerta de enlace (3), y decide que es probable que un mensaje sea no solicitado si una petición de consulta anterior correspondiente no se ha recibido dentro de un período de tiempo preestablecido. ES 2 322 396 T3
- 12Un método según la reivindicación 11, donde el sistema determina que una petición de consulta corresponde a un mensaje si tienen la misma dirección de terminación.
- 13Un método según las reivindicaciones 11 o 12, donde el sistema supervisa una dirección fuente de una petición de consulta y una dirección fuente de un mensaje correspondiente, y decide que es probable que el mensaje sea no solicitado si su dirección fuente es diferente de la de la petición de consulta correspondiente.
- 14Un método según cualquiera de las reivindicaciones 11 a 13, donde el sistema guarda la información de petición de consulta en la memoria de datos solamente durante un período de tiempo preestablecido, y determina, cuando se busca en la memoria de datos a la recepción de un mensaje si una petición de consulta anterior correspondiente ha sido recibida dentro de dicho período de tiempo preestablecido, si en la memoria de datos se guarda información con relación a tal petición de consulta.
- 15Un método según cualquiera de las reivindicaciones 11 a 14, donde el sistema activa un temporizador (6) a la recepción de una petición de consulta.
- 16Un método según la reivindicación 15, donde el temporizador funciona desde el tiempo de recepción T 0 a un límite de tiempo preestablecido T preset _ end .
- 17Un método según cualquiera de las reivindicaciones 11 a 16, donde el límite de tiempo T preset _ end se establece para una categoría de petición de consulta.
- 18Un método según cualquiera de las reivindicaciones 11 a 17, donde el sistema bloquea mensajes que probablemente son no solicitados.
- 19Un método según cualquiera de las reivindicaciones 11 a 18, incluyendo el paso adicional de enviar un reconocimiento positivo o negativo según la supervisión.
- 20Un método según cualquiera de las reivindicaciones 11 a 19, donde el sistema (4) marca como sospechosa y mantiene para investigación adicional una dirección fuente de una petición de consulta correspondiente a un mensaje que probablemente es no solicitado.
- 21Un medio legible por ordenador incluyendo código de software para realizar un método de cualquiera de las reivindicaciones 11 a 20 cuando se ejecuta en un procesador de datos digitales.
Independent claims21
51 paragraphs in 4 sections, as filed
ES 2 322 396 T3
DESCRIPTION
Security system for mobile networks.
Field of the invention
The present invention relates to a security system for mobile networks and a method of providing increased security in mobile networks.
Explanation of the prior art
As with email, unsolicited messages or spam messages are a problem in the mobile network environment. The content of these messages is generally intended to encourage the recipient to use some uploaded services. Such messages are a source of irritation to the user and are often misleading.
Like junk email, junk messages are a growing source of annoyance for mobile users. The content of these messages is generally intended to encourage the recipient to use some fee-based services, such as calling a specific fee-based 0800 number. This phenomenon is irritating to the non-fooled receiver, and it is also deceptive when the end user who has fallen for the trap eventually blames the operator. By using fictitious source addresses in their messages, spamming parties keep their identity hidden from operators.
US2003 / 0083078 describes a routing node with a message discrimination module.
US6101393 describes a system for the selective acceptance of short messages.
The invention solves the problem of unsolicited messages in mobile networks, in particular to bring more flexibility to the techniques used by the spamming parties.
Summary of the invention
According to the invention, a security system as set forth in claim 1 is provided.
The invention also provides a method as set forth in claim 11 implemented by a security system.
In one embodiment, the system blocks messages that are likely unsolicited.
In another embodiment, the system monitors a source address of an inquiry request and a source address of a corresponding message, and decides that the message is likely to be unsolicited if its source address is different from that of the corresponding inquiry request.
In one embodiment, the system saves inquiry requests only for a preset period of time, and determines whether a request received within said preset period of time is saved in data memory when data memory is searched upon receipt. of a message.
In another embodiment, the system determines that a query request corresponds to a message if they have the same source address.
In another embodiment, the system activates the timer upon receipt of said request.
In another embodiment, the timer is configured to run from the reception time T<sub>0</sub> up to a preset time limit T<sub>preset</sub>_<sub>end</sub>.
In another embodiment, the system facilitates setting the time limit of the timer T<sub>preset</sub>_<sub>end</sub> for a query request category.
Detailed description of the invention
Brief description of the drawings
The invention will be more clearly understood from the following description of some of its embodiments, given by way of example only with reference to the accompanying drawings in which:
Figure 1 is a block diagram illustrating the components of a system of the invention.
Figure 2 is a flow chart illustrating the flow of data through the system of Figure 1.
ES 2 322 396 T3
And Figures 3 to 6 are message transfer diagrams illustrating the operation of the system in more detail.
Description of the achievements
With reference to Figure 1 a mobile network 1 includes a security system 2 connected to an international mobile network gateway 3. The mobile network 1 includes an HLR (home position register) 10 and a plurality of mobile user devices 12. The positions of the devices 12 served by an operator are maintained in the HLR 10. For each mobile terminated service requested from the network, a query request or send routing information (SRI) is required to the HLR 10 to obtain location information in order to successfully provide the service, eg a post message.
The security system 2 has a processor 4 programmed to monitor incoming SRI requests R1, R2 ... Rn and incoming messages M1, M2 ... Mn. The routing configuration within the mobile network 1 is such that all potentially suspicious messages are directed through the security system 2 where they can be analyzed. Incoming SRI requests include source information. Incoming messages M1, M2 ... Mn are associated with a previous SRI request. The security system 2 also includes a local data memory 5 and a time clock 6. The received SRI requests are monitored, the associated source information is copied to the local data memory 5 and an associated clock counter is started. timer 6.
Some typical characteristics of spam or unsolicited messages are as follows:
- The HLR is queried per SRI request once by MSISDN, independent of possible immediate downstream MT services, to find where an end-user mobile terminal M1 may typically reside.
- The position information retrieved from the HLR query, in response to a query request / SRI request, is subsequently used in the subsequent time period T to present unsolicited messages destined for the end user.
- Traffic enters a network through the international gateway and goes directly to the receiving mobile terminal M1 without going through any local service center (and thus bypasses local network filters).
- A fictitious source address is used in messages (to avoid tracing the message to the originating party).
- As a result of the fictitious source address in the message, the acknowledgment related to the message will never reach the true originator. In contrast to regular trusted MT services, the outcome of individual message deliveries is irrelevant to the originator as long as a significant percentage of deliveries are successful. The latter criterion is expected to be met due to the above SRI request revealing the typical positions of the desired mobile stations M1, M2, ... Mn.
System 1 and the method of the invention operate by preventing the passage of messages with the characteristics indicated above. The method of operation involves monitoring SRI requests and incoming messages. As noted above, the position information retrieved from the HLR query, in response to a query request / SRI request, is then used in the subsequent time period T to present unsolicited messages destined for the end user. The timer clock 6 is thus preset to operate from the time of receipt of a request SRI T<sub>0</sub> up to a preset time limit T<sub>preset</sub>_<sub>end</sub>. The timer value can be implemented based on parameters, such as the position of the SRI source.
With reference to figure 2, the method performed by the security system 4 includes the following steps:
1. When an SRI request enters network 1 through international gateway 3:
The petition is passed,
A timer is started at 6 clock,
Relevant source information is copied to local data memory 5, including the originating address and the terminating mobile station address (MSISDN),
If the timer expires without a subsequent message, the associated source information from the SRI request is removed from local memory or kept internally for tracking purposes.
2. A message that enters the network is monitored and analyzed and acted upon depending on the result of the analysis.
ES 2 322 396 T3
If no previous SRI request was observed within the time limits set by the timer, the message is not passed and an acknowledgment is generated. Since the source address in the message itself is likely to be fictitious, it is expected that the acknowledgment will not return to the true originator and therefore the choice between a positive or negative acknowledgment is an implementation dependent choice of the operator. The system associates a message with an inquiry request based on the terminating mobile station identification (MSISDN).
If a previous SRI request was observed within the previous time limit, it is subjected to another test in which the source information of the message is compared with the source information of the previous position request. If the two source addresses are not identical, then the message is not passed. Again, depending on environments chosen by the operator, a positive or negative acknowledgment can be returned. The source address of the above SRI request can be marked suspicious and kept for further investigation when it is the true source of these unsolicited messages.
If the two source addresses match, the message is passed for delivery and the timer is reset.
Figures 3-6 illustrate the operating dynamics of the system in more detail. The "@" component refers to an external entity / message source, the "G" component is the gateway through which the message / SRI enters the local network, the "I" component is the system of In the invention, the component "H" is the local HLR that contains the positions of all the mobile devices in the network, and finally the mobile pictogram refers to the mobile devices themselves.
The (internal) architecture of the security system includes a proxy that is capable of viewing the relevant details of a pass-through message / SRI request and a data memory to hold relevant data related to (recent) SRI requests so that these details can be compared to later messages.
In the event that an SRI enters, at least the following information is stored: source address of the originator of the SRI, identification of the mobile for which the query is planned, and the current time. As soon as a message itself is received, the address of the recipient of that message is used to query the memory. If a record (or more) of a previous SRI is found, the source address of that SRI is compared with that of the message itself. If no previous SRI is found (Figure 6), if no matching source address is found (Figure 5), or if the time between the SRI and the message itself is greater than some configurable value (Figure 4), the message does not happens. Otherwise, the message is delivered normally (figure 3).
The system of the invention allows real-time monitoring and control of unsolicited messages arriving on a mobile network. This method prevents mobile users from receiving untraceable messages with fictitious source addresses from an international source by monitoring and controlling international traffic as described above.
The method of the invention serves to prevent unsolicited messages from passing through mobile networks. It has the advantage of ensuring traceability and that end users are not disturbed by these messages.
The invention is not limited to the described embodiments, but can be varied in construction and detail.
Contents4
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
14 members in 10 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 20050644531P | United States of America | – | |
| 64453105 | United States of America | P | |
| 64453105 | United States of America | P | |
| 644531P06700722 | – | – | – |
| US20050644531P | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO2006077563A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1839417A1 | European Patent Office (EPO) | A1 | |
| IL184515A0 | Israel | A0 | |
| US2008092225A1 | United States of America | A1 | |
| EP1839417B1 | European Patent Office (EPO) | B1 | |
| AT423420T | Austria | T | |
| ATE423420T1 | Austria | T1 | |
| DE602006005225D1 | Germany | D1 | |
| PT1839417E | Portugal | E | |
| ES2322396T3This record | Spain | T3 | |
| BRPI0606597A2 | Brazil | A2 | |
| PL1839417T3 | Poland | T3 | |
| IL184515A | Israel | A | |
| US8196202B2 | United States of America | B2 |
Numbers
- Publication
- 2322396
- Publication, DOCDB
- 2322396
- Publication, EPODOC
- ES2322396T
- Application
- 6700722
- Application, DOCDB
- 06700722
- Application, EPODOC
- ES20060700722T
Titles2
- Spanish
- SISTEMA DE SEGURIDAD PARA REDES MOVILES.
- English
- SECURITY SYSTEM FOR MOBILE NETWORKS.
Classification
- CPC, 5
- H04L63/0236
- H04W4/12
- H04W4/16
- H04L51/212
- H04L51/58
- IPC, 1
- H04L12 58