Fraud detection method for mobile telecommunication network
Abstract
[Task] A method for detecting unauthorized use of data related to unsuccessful authentication processing such as access type, authentication retry, and server address in the 3rd generation mobile communication network as a secondary indicator of unauthorized use. I will provide a.
Solution.The data is included in a predetermined type of field of the authentication failure report message sent back from the service network to the home network in the authentication process, stored in the home location register, and transferred to the fraud detection system. The fraud detection system detects fraud by processing this data together with a primary indicator of fraud.
Term
Term ended
Projected expiry passed 21 November 2021, 4.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
8 claims: 5 independent, 3 dependent
- 1【特許請求の範囲】 【請求項1】 移動通信システムにおける不正利用を検出するための方法であって、 a)ネットワーク認証不成功又はユーザ認証不成功によるユーザ認証処理の失敗から2次的不正行為指標を得る過程と、 b)該認証処理において、サービス網(3G MSC/VLR、3G SGSN)からホーム網(HE HLR)に送り返される認証失敗報告メッセージ(MAP AFR_req)に、各指標に対応する特定種の新パラメータとして、該2次的不正利用指標を追加する過程と、 c)更なる処理に備えて該メッセージをホーム位置レジスタ(HLR)に保存する過程を有する不正利用検出方法。
- 2【請求項2】 ユーザの認証の失敗回数が所定の値を超えるとオペレーション/メンテナンスゲートウェイ(OMG)を介して不正利用検出システム(FDS)のエンティティにアラームメッセージを転送する過程を含む請求項1に記載の方法。
- 3【請求項3】 ホーム位置レジスタ(HLR)から前記メッセージを受け、不正利用の検出のために、1次的不正利用の指標と共に不正利用検出システム(FDS)において認証失敗報告メッセージ(AFR_req)を処理する過程を含む請求項1又は2に記載の方法。
- 4【請求項4】 前記2次的不正利用の指標が、認証処理が失敗した通信のアクセス種類を含むことを特徴とする前記各請求項の何れか1項に記載の方法。
- 5【請求項5】 前記アクセス種類が、発呼、非常時発呼、位置更新、付加サービス及び短メッセージ転送を含むことを特徴とする請求項4に記載の方法。
- 6【請求項6】 前記2次的不正利用指標が、認証の失敗が、通常の認証処理において発生したものか、認証の再試行において発生したものかを示す再試行指標を含むことを特徴とする前記各請求項の何れか1項に記載の方法。
- 7【請求項7】 前記2次的不正利用指標が、ビジタ位置レジスタ(VLR)又はサービスGPRSサポートノード(SGSN)のアドレスを含むことを特徴とする前記各請求項の何れか1項に記載の方法。
- 8【請求項8】 前記2次的不正利用指標が、特定の種類の新パラメータではなく、前記認証失敗報告メッセージ(MAP AFR_req)の拡張コンテナフィールドに含まれることを特徴とする前記各請求項の何れか1項に記載の方法。
Independent claims8
150 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention generally relates to the detection of fraudulent use in mobile communication networks. More specifically, the present invention relates to a method for acquiring, storing and processing data for detecting unauthorized use.
【0002】
[Conventional technology]
In the 3rd Generation Partnership Project, the security group responsible for security architecture (hereinafter referred to as 3GPP (SA3)) is Technical Specification Group Services and System Aspects 33.102. A new method called Authentication Failure Report has been introduced into the v3.5.0 (hereinafter referred to as 3G TS 33.102) standard. Furthermore, the standard signal messages and message parameters used in this new method will be referred to as the Mobile Application Part (hereinafter referred to as MAP) published by the 3GPP Technical Specification Group Core Network. ) Published in Standard 29.002 v3.4.0 (hereinafter referred to as 3GPP TS 29.002).
【0003】
Most of the previous generation mobile systems have already adopted an authentication method for confirming that the user who wants to access the mobile communication network is the person himself / herself. In addition, network entities involved in specific mobile communications are often subject to authentication rather than the mobile users themselves. For more information, refer to Technical Standard 03.20 on GSM "Security-Related Network Functions" published by the European Telecommunications Standards Institute (generally and in the description below, referred to as TSETSI GSM 03.20, "Security-related Network Functions"). I want to. These authentication methods are intended to prevent unauthorized access to mobile networks and mobile services by unauthorized users and network entities. Furthermore, the request for authentication of mobile users and network entities is not limited to mobile communication networks centered on Europe such as GSM, but for example, in US mobile communication networks based on intermediate standard 41 (hereinafter referred to as IS-41). Is in demand as well.
【0004】
These previous generation mobile communication system authentication methods are constantly evolving within the technical scope of the third generation (hereinafter abbreviated as 3G) of mobile communication systems as they incorporate new security functions. Today, as an example of a general 3G system, there is the Universal Telecommunication System (hereinafter referred to as UMTS), which has security features, security functions, and security architecture related to subscriber authentication and network entity authentication. , Described in the above technical standard 3G TS 33.102.
【0005】
Apart from the differences in the specific network architectures of these mobile communication systems by generations including different standards in Europe and the United States, in order to deepen the understanding of the broad technical scope of the present invention, the following are described below. The common points will be explained.
【0006】
Common mobile communication networks as shown in Fig. 1 include a home network (N-1000) (hereinafter referred to as HE) and a service network (N-2000) (hereinafter referred to as SN). , It can be understood as consisting of a plurality of mobile terminals, that is, a user device (N-3000) (User Equipment: hereinafter referred to as UE). On the other hand, the view that the mobile communication network as shown in Fig. 1 consists of an access network (N-2200) and a core network (N-0100) consisting of a service network and a home network excluding the network entity of the access network. Is also possible.
【0007】
Furthermore, existing mobile communication systems already include circuit switching (N-2120) (hereinafter referred to as CS) services such as pure telephone communication and packet switching (N-2110) (N-2110) (hereinafter referred to as CS) such as other data transfer services. It has a shared and dedicated network infrastructure that can support any of the services (hereinafter referred to as PS). Packet-switched services were introduced in second-generation mobile communication systems. As a typical example of the conventional technology corresponding to the packet switching service, there is a GSM packet radio system (hereinafter referred to as GPRS).
【0008】
HE (N-1000) refers to a network entity that exclusively handles and supports home subscribers of a specific Public Land Mobile Network (hereinafter referred to as PLMN). For example, the Home Location Register (N-1102) (HLR) is a network entity for storing subscriber data of home subscribers of a PLMN, that is, a part of HE. Another network entity that forms part of the HE is the Authentication Center (AUC), which provides authentication and key data, or triplets in the case of GSM, in UMTS. The case is created and provided as a vector. The authentication data is for confirming that the home subscriber is who he / she is, regardless of where he / she is trying to access the mobile communication network, and the key data encrypts the transferred contents on the wireless path. Is for. Next, the authentication methods by the 2nd and 3rd generations and related processes will be described in more detail.
【0009】
An SN (N-2000) is a network entity or resource that uniformly services roaming mobile subscribers within a PLMN, whether they are home subscribers or visitor subscribers. For example, a mobile service switching center (Mobile Service Switching Center or Mobile Switching Center: hereinafter referred to as MSC) is an interface between a wireless communication network and a fixed communication network. This MSC is a network entity that performs circuit switching (CS) related switching functions and manages the location and routing area where a particular subscriber is roaming, and is therefore part of the SN. For other network entities belonging to the SN, visitor location registers (Visitor Location) Register: Hereafter, it is called VLR). This VLR is a subscriber database that holds subscriber data obtained from the HLR to which the subscriber is subscribed, corresponding to each subscriber currently roaming in the managed area. Conventional GSM or IS-41 compliant mobile communication systems often combine these two entities into a single entity (N-2121) abbreviated as MSC / VLR. Furthermore, the advanced version of this MSC / VLR in the 3rd generation mobile communication system is generally referred to as 3G MSC / VLR. Serving GPRS Support Node (N-2111) (Serving GPRS Support), similar to MSC / VLR managing required subscriber data and performing CS functions. Node: hereinafter referred to as SGSN) executes tasks related to the PS function for the relevant subscribers. SGSN acquires subscriber data obtained from the HLR to which the subscriber is subscribed, corresponding to each subscriber currently roaming in the area managed by the SGSN. The SGSN is also a network entity that handles the switching functions associated with packet switching (PS) and controls the location and routing area where a particular subscriber is roaming, and is therefore part of the SN. Furthermore, the advanced version of this SGSN in the 3G mobile communication system is generally referred to as 3G SGSN. Finally, FIG. 1 shows a typical access network node, namely the UMTS Terrestrial Radio Access Network (N2201) (UMTS Terrestrial Radio Access Network: hereinafter referred to as UTRAN).
【0010】
The authentication process is generally performed on the first wireless contact when a mobile subscriber attempts to access a mobile network. It was selected in accordance with the 3G TS 33.102 standard above, considering the transfer from GSM to UMTS, while maximizing compatibility with current GSM security architectures. This method combines a protocol based on the same request / response as the GSM subscriber authentication method, a key setting protocol, and a one-pass protocol based on a sequence number for network authentication. This method is described below, but see 3G TS 33.102 v 3.5.0, sec 5.1.1 and 6.3.1 for a more detailed description.
【0011】
The GSM Challenge / Response method formally begins with the creation and supply of an authentication triplet (authentication vector in the third generation) from SN VLR / SGSN to HE HLR / AUC. This authentication triplet consists of a random number RAND, an expected response XRES, and an encryption key CK. Each authentication triplet is valid only for one authentication process, although it may be reused in certain situations. is there. Upon receiving the triplet from the HE, the VLR / SGSN will perform GSM subscriber authentication and key verification on the subscriber side. Transfer the received random number RAND to Module: hereinafter referred to as SIM). On the subscriber side, the random number RAND and the subscriber identity key KI stored in advance are multiplied by the algorithms A3 and A8 to obtain the signature response SRES and the encryption key CK. The SRES is transferred from the SIM to the requesting VLR / SGSN and compared to the stored XRES. If the SRES and XRES match, the authentication is successful and the CK held by both the VLR / SGSN and SIM is locally used to encrypt subsequent communication over that wireless path.
【0012】
Figure 2 shows how this request / response authentication method evolved in the UMTS network. In accordance with the 3G TS 33.102 standard, SN VLR / SGSN requests HE HLR / AUC to create and provide an authentication vector consisting of random number RAND, expected user response XRES, encryption key CK, integrity key IK and network authentication token AUTN. (S-200). Upon receiving this, HE HLR / AUC creates (B-090) an ordinal array of n authentication vectors (corresponding to the GSM triplet, hereinafter referred to as AV) in the SN VLR / SGSN and sends it. (S-210). This authentication vector is stored (B-100) in SN VLR / S GSN. In GSM, each authentication vector is a VLR / SGSN and a User Service Identity module. It is effective for one-time authentication and key verification processing with (hereinafter referred to as USIM). Unlike GSM, this vector is non-reusable. In terms of security, this USIM authenticates UMTS subscribers and networks, as well as key verification. USIM can also perform GSM authentication and key verification to allow subscribers to roam freely on GSM radio access networks. To start authentication and key verification, VLR / SGSN selects the next authentication vector from the array (B-110) and sends the parameters RAND and AUTN to the user (S-220). USIM uses RAND to calculate the anonymous key AK (B-120), and after the AK can be calculated, the sequence number SQN (B-130), authentication management field AMF (B-140) and the authentication management field AMF (B-140) from the received AUTN. Check if AUTN can be approved by obtaining the message authentication code MAC (B-150). Next, the XMAC is calculated by RAND, SQN and AMF (B-160), and the XMAC value thus obtained is compared with the previously extracted MAC value (B-170). If the values are different, the user sends a "user authentication refusal" to the VLR / SGSN along with the reason (S-230), and the process ends. As a result, it is considered a network authentication failure. In this case, SN VLR / SGSN reports authentication failure with "network signature incorrect answer" as the reason for failure. Send to HLR (S-240). On the other hand, if the MAC and XMAC match, USIM confirms that the SQN value is within the correct range (B-180). If it determines that the SQN is out of range, USIM sends a "synchronization failure" to the VLR / SGSN (S-250) with the appropriate parameters and terminates the process. If the SQN is within range, USIM determines that the network authentication was successful and obtains the response RES, encryption key CK and integrity key IK by applying various functions corresponding to the combination of authentication parameters. (B-190), send this response RES back to the VLR / SGSN (S-260). VLR / SGSN compares the received RES with XRES (B-200). If RES and XRES match, VLR / SGSN considers the authentication and key verification process to be successful. The keys CK and IK thus established are locally used to encrypt the communication on the wireless path. If XRES and RES are different, SN VLR / SGSN sends an authentication failure report to HLR with "user response incorrect answer" as the reason for failure (S-270). The SN VLR / SGSN can then request the user to retry the identity verification and authentication process.
【0013】
In the above method according to the 3G TS 33.102 standard, mutual authentication between the user and the network is possible by presenting the secret key K exclusively shared by USIM and AUC in the user's HE. Furthermore, both the failure detected by USIM on the user side and the failure detected by SN VLR / SGSN on the network side activate a new process called "authentication failure report".
【0014】
The purpose of this new process is to inform the home network (HE) that the authentication has failed, whether the network authentication fails or the user's authentication fails. However, this method cannot be applied to synchronization failures reported by other means. To summarize, this authentication failure reporting method is for reporting the type of failure (user side or network side) and the international mobile subscriber identity (hereinafter referred to as IMSI) to the HE. is there.
【0015】
Here, another important point in the background of the present invention, that is, unauthorized use of mobile services and mobile communication networks will be described. A very common fraudulent activity on mobile communication networks is buying and selling call rights using additional services, which makes it very difficult for users to manage their activities while roaming on a PLMN other than the home network. There is a cause. Call right buying and selling is a fraudulent act of selling an international call service to the world at a price lower than the market price without paying a call charge to a network operator by using a mobile call right. For example, a mobile subscriber can use an HLR call transfer service, a third-party outgoing service, or the like to carry out fraudulent call right buying and selling. Another example of fraudulent use is fraudulent roaming. In fact, most mobile communication systems allow international roaming, and it is common to acquire a foreigner's call right in a specific country where roaming is possible and commit fraud by buying and selling that call right. It is difficult to detect such fraudulent activities promptly because it takes time for the vendor to report or request. Many examples of such fraudulent use have been confirmed, and means for preventing fraudulent use and detecting specific fraudulent activities are desired. As a countermeasure, the means that have been introduced in connection with the authentication process have been mainly in the form of focusing on the prevention of fraudulent use rather than the detection of fraudulent use.
【0016】
However, on the premise that it is almost impossible to completely prevent fraudulent use, the development of a powerful fraudulent use detection system that can realize early detection of fraudulent activity is in progress. To that end, it is important to discover conditions that enable reliable detection of fraudulent activity. Here, apart from the legal interpretation of fraudulent activity, acts and situations that suggest unauthorized use of mobile network resources, either by themselves or in combination of acts, will be described.
【0017】
To that end, a new network entity, commonly referred to as the Fraud Detection System (FDS), has been introduced into mobile networks. This FDS detects fraudulent use by analyzing a specific index. This index can be categorized by its type and usage. When the indicators are classified by type, the following three classifications can be recognized.
【0018】
Usability index: It can be identified by the conditions related to the usage of the mobile phone. Unauthorized use is often characterized by remarkably frequent use. For example, in order to buy and sell call rights, it is necessary to register a large number of call transfer numbers on a mobile terminal.
【0019】
Mobility index: It can be identified by the conditions related to the mobility of the mobile subscriber. For example, the number of times of location update or handover within a predetermined time.
【0020】
Deductive index: It appears as a result of cheating. For example, the use of conference calls and call forwarding.
【0021】
In addition, the indicators can be classified into the following three types according to the usage pattern.
【0022】
Primary indicator: In principle, it alone indicates fraudulent use. For example, the number of call transfer services requested within a given time.
【0023】
Secondary indicators: In principle, they are useful information by themselves, but they are not enough to be convinced of fraudulent use by themselves. For example, information about a cell site or switch area involved in a call is useful because the buying and selling of call rights to a particular party is concentrated in the area where the purchaser lives.
【0024】
Tertiary indicators: Those that are not useful information on their own, but can, in principle, be used to obtain the information needed to detect fraud. For example, the number of successful handovers within a given time. Since fraudulent call rights trading services require a stable location, low mobility suggests fraudulent activity when accompanied by activities that can be inferred from other indicators. However, even if you are not cheating, there is a possibility that mobility is low, so it is necessary to check other activities before concluding that it is fraudulent.
【0025】
The FDS post-processes these indicators to determine if, or at least suspected, fraudulent activity.
【0026】
These two separate, unrelated aspects described above, namely the processing performed when authentication fails and the detection of fraud, are the background techniques of the present invention, as further shown in this description.
【0027】
[Problems to be Solved by the Invention]
Mentioned the authentication process in 2nd and 3rd generation mobile networks. A new method called "authentication failure report" has been introduced in the 3rd generation mobile communication system such as UMTS, but there is no equivalent in the 2nd generation method such as GSM.
【0028】
However, additional processing is being carried out by specific sellers in order to strengthen and complete the current standards for second-generation mobile communication systems. For example, if an Ericsson MSC / VLR detects an authentication failure, the MSC / VLR records the failure data and fires an alarm. Records of this authentication failure are, for example, date, time, IMSI, Mobile Subscriber ISDN Number (hereinafter referred to as MS ISDN, where ISDN is an abbreviation for integrated services digital network), cell global identifier (cell global identifier). Cell Global Identifier (hereinafter referred to as CGI), and includes data indicating whether or not a MAP message "authentication denied" was sent.
【0029】
These seller-side measures suggest that in a multi-seller, multi-business environment, it is now impossible to collect all fraud-related information regarding the failure of authentication of a single subscriber. Such information is stored in the MSC / VLR of a particular distributor, but other MSC / VLRs record different types of authentication failure data according to other service networks. Given this background, the above measures cannot be the basis of a standard fraud detection system, as they must be the fraud conditions that first analyze the MSC / VLR distributor's identifier. .. The MSC / VLR distributor can then use other authentication failure data for FDS post-processing.
【0030】
As a fraud detection method, there is another form of the two-generation mobile communication method, which has been adopted by the supplier to some extent. Figure 3 shows a general fraud detection architecture in mobile communication networks. Here, FDS (N-1301) analyzes fraudulent use from the call data record (Call Data Record: hereinafter referred to as CDR) created by MSC / VLR (N-2122) or SGSN (N-2112). Extract the necessary indicators for this. This CDR is Billing Gateway (N-2301) Gateway: hereafter referred to as BGW) or other billing intermediary device. As a result, the information received by the FDS is only related to the line settings, and other fraud-related information not related to the establishment of the line does not reach the FDS. Since this information is not related to the already established call line, it is not accompanied by a CDR and is not received by the FDS on current devices. For example, the acquisition of fraud-related information based on authentication failure does not necessarily mean that the FDS receives the CDR in this form. In the case of the above-mentioned call right sale, since it is based on the CDR used in the past, the authentication will fail in the subsequent attempts to start the call right sale. Therefore, it is easy for those skilled in the art to understand that while fraud is prevented, a method of detecting fraud that can detect fraud immediately at the moment when the fraud is about to be started is more useful. Let's do it.
【0031】
On the other hand, apart from the second generation system such as GSM, there is a method for reporting authentication failure of IS-41 (TIA / EIA standard). In this way, the reporting message is either denied access by the IS-41's Authentication Center (AC, but different from GSM's) or standardized for security. Used to determine if other related actions are needed. However, it does not specially deal with acts related to the detection of fraudulent activity.
【0032】
The authentication process in IS-41 is not always done in the same way. The VL R may have Shared Secret Data (hereinafter referred to as SSD) previously transmitted by AC, in which case the authentication data used for the authentication process is obtained from the SSD. On the other hand, VLR may obtain authentication data directly from AC, similar to the method in GSM, and it is possible to use this for authentication processing. In either case, if authentication fails (the response received from the user does not match the response expected by VLR), VLR sends an authentication failure report to AC without making any decisions. The AC then decides whether to deny access or try to authenticate again. In the latter case, AC decides whether to send a new SSD to VLR to create new authentication data in VLR, or to create new authentication data directly in AC and use VLR directly for the new authentication process. To do. By this process, a centralized decision method for managing the network can be realized.
【0033】
At present, there is a new method introduced in UMTS, which realizes the total storage of authentication failure data in the home network (HE) in the above-mentioned "authentication failure report". By such a method, HE can manage the authentication failure of the home subscriber.
【0034】
However, the currently defined authentication failure reporting process does not provide meaningful information from the perspective of detecting fraudulent use in an attempt to develop further activities. In this regard, Fig. 4 shows the authentication failure report specified in the 3G TS 29.002 standard of the conventional mobile communication application protocol by its operation and parameters.
【0035】
A further drawback of current countermeasures related to fraud detection is that the CDR only exists after the line has already been established, and this method does so at the moment the fraudster's device is trying to access the network. It cannot be detected.
【0036】
[Means for solving problems]
An object of the present invention is to provide a method for obtaining useful information for detecting fraudulent use in order to solve the above-mentioned conventional problems.
【0037】
According to the present invention, data related to unsuccessful authentication processing, such as access type, authentication retry and server address, is used for detecting unauthorized use.
【0038】
This method is an improvement over the method of reporting authentication failures in order to provide the home network with more useful information for detecting fraudulent use. a) The process of obtaining a secondary fraud index from the failure of the user authentication process due to unsuccessful network authentication or unsuccessful user authentication, b) In the authentication process, the authentication failure report message (MAP AFR_req) sent back from the service network (3G MSC / VLR, 3G SGSN) to the home network (HE HLR) contains new parameters of a specific type corresponding to each index. The process of adding the secondary abuse index and c) A method having a process of storing the message in a home position register (HLR) for further processing.
【0039】
According to another aspect of the method according to the invention, a vendor-specific fraud detection device that processes data related to this fraud stored on the home network together with a primary fraud indicator to detect fraud. The purpose is to transfer to.
【0040】
BEST MODE FOR CARRYING OUT THE INVENTION
As mentioned above, behind the failure of authentication is very useful information that leads to the detection of fraudulent use. Data related to authentication failure cannot be a primary indicator for detecting fraudulent use because the authentication process itself is a method of preventing fraudulent use. It can be used as the next index. However, UMTS authentication failure report messages are poorly handled for the purpose of fraud detection, and in MAP processing, with IMSI as shown in Fig. 2 (S-240, S-270) and Fig. 4. It only reports the type of failure.
【0041】
On the other hand, MSC / VLR has useful and meaningful information for detecting fraudulent use related to authentication failure. Data effective for detecting such fraudulent use is a secondary index for detecting fraudulent use in the fraudulent use detection system, and is treated as a condition for fraudulent use.
【0042】
According to the present invention, when the authentication process shown in FIG. 2 is executed, the data already recognized by the MSC / VLR is requested to report the authentication failure, which is a MAP message, as shown in FIGS. 6 and 7. It is necessary to supply to HE HLR in the state of being incorporated in MAP AFR_req) (S-280, S-290). Examples of this known data that can be used to detect fraud include: [0043]
-Access type: Identifies whether the authentication process was initiated by a call, an emergency call, a location update, an additional service process, or a short message transfer.
【0044】
-Authentication retry: Indicates whether the failure was due to a normal authentication attempt or an authentication retry. In the latter case, it indicates that the authentication failed before that.
【0045】
-Server address: Indicates the address of the network element that has been authenticated, that is, SN MSC / VLR or SN SGSN. This data is included to provide information that indicates the actual location where the authentication failure occurred.
【0046】
In the present invention, each of these three parameters has its own advantages.
【0047】
The access type parameter is to measure the severity of the failure, for example, the failure due to the call setting is more serious than the failure due to short message forwarding, and the failure due to the position update is more serious than the failure due to the call setting. It can be used. This is based on the fact that, for example, the position update must succeed before the call setting fails.
【0048】
The authentication retry parameter indicates whether the failure was in the first authentication process or in the retry. In traditional networks, authentication retries fail due to a mismatch in the Temporary Mobile Station Identity (TMSI) or an incorrect authentication vector received from the previous MSC / VLR or SGSN server (Temporary Mobile Station Identity: TMSI). This is done in case of (retrying after requesting a new authentication vector from HLR). The failure in this case is more serious because the IMSI (when making a user identity request) and the authentication vector (when making an authentication information transmission) use valid authentication retries.
【0049】
The importance of server addresses from the perspective of detecting fraudulent use is due to the tendency for fraudulent activities such as buying and selling call rights in conventional mobile communication networks to be concentrated in a specific area.
【0050】
This data, along with the other data described below, is considered useful to the Fraud Detection System (FDS) as a secondary indicator and is recognized as a condition of fraud in the FDS. When new fraudulent activity is discovered, new data is raised as an index of fraudulent use, which is also a part of the present invention. As will be readily appreciated by those skilled in the art, the technical scope of the invention is not limited to these three types of newly identified and described data contained in the existing MAP AFR_req. For example, as another embodiment of the present invention, on the premise that more accurate information about the area where the fraudulent activity was performed is required depending on the degree of fraudulent use, the geographical position of the user device obtained from the GPS equipment or the like. Can be added to the MAP AFR_req message. As is obvious to those skilled in the art, it is possible for a MAP AFR_req message to include data existing in the MSC / VLR or SGSN that is effective for fraud detection in the MAP AFR_req message. In this way, this data is submitted to HE HLR, from which it is further transferred to a suitable fraud detection system such as FDS.
【0051】
[Example]
As shown in FIG. 7, according to one embodiment of the present invention, the access type, authentication retry and server address are included in the MAP AFR_req message as new specific parameters. Further, according to a preferred embodiment of the present invention, the server address is represented by parameters such as MSC / VLR address and SGSN address in order to identify the service for which authentication has failed, that is, circuit switching or packet switching.
【0052】
The following new parameters can be included in the 3G TS 29.002 standard message and parameterized MAP message "authenticationFailureReport_req" (authentication failure report request), as shown in Figure 7. -"Authentication Reattempt" of "BOOLEAN" type (boolean expression) -"Access Type" of the new "Access Type" (access type) -"Vlr-Number" (VLR number) of type "[0] ISDN-AddressString" -"Sgsn-Number" (SGSN number) of type "[1] ISDN-AddressString" [0053]
In addition, the above new "Access Type" follows the notation of the ASN.1 standard, and by "ENUMERATED", Call (call) (0), emergency Call (emergency call) (1), locationUpdating (location update) ( It can be defined as 2), supplementary Services (3), shortMessage (4). Reordering the existing designations, as will be readily apparent to those skilled in the art, does not affect the object of the invention in this embodiment.
【0054】
Furthermore, adding new data to the MAP AFR_req process according to the preferred embodiment of the invention in FIG. 7 should be interpreted exemplary and non-limitingly. In that respect, in the second embodiment of the present invention, it is proposed to add this new data to the extended container field.
【0055】
The definition of the MAP AFR_req message allows new parameters to be introduced in the extension container. Any of the data proposed in the present invention can be added to the above expansion container as an index of fraudulent use.
【0056】
This extended container is also a means for inserting possession information into standard messages, so if there is an indicator of abuse, it will result in some private measures.
【0057】
As mentioned above, one of the main objects of the present invention is to enable a trader to collect fraudulent use information related to the failure of the subscriber's authentication. If the method is privately owned, this purpose cannot be achieved because the reception of information depends directly on the VLR / SGSN supplier and thus indirectly on the service provider (subscriber roaming status). .. As a result, the vendor will not be able to obtain all the fraudulent information related to the subscriber's authentication failure. However, although inferior to the most desirable embodiment, this second embodiment also provides a reasonable means for supplying the FDS with the secondary indicators necessary for fraud detection.
【0058】
A further process of the present invention is the process of receiving this new fraud-related data, which can be introduced into the MAP AFR_req process in HE, as shown in FIG.
【0059】
When a MAP AFR_req message is received (S-700), the HLR saves the received data with the date and time of the report (B-500).
【0060】
When the number of failures for a particular subscriber reaches a predetermined threshold (B-150), an alarm is raised in the HLR (B-520). The value of the threshold value for activating this alarm can be set arbitrarily.
【0061】
Next, an "Authentication Failure Alarm" is sent (S-710) to the Operation and Maintenance Gateway (hereinafter referred to as OMG) in the vendor's network. Then, the authentication failure alarm reaches the FDS (S-720) via the gateway.
【0062】
Upon receiving this alarm, the FDS requests the HLR (S-730) to log the authentication failure via the operation / maintenance gateway (S-740). Therefore, the HLR log related to the authentication failure report log is also sent to the operation / maintenance gateway (S-750) and finally transferred to the FDS (S-760). In addition, the FDS can analyze the secondary indicators received according to the appropriate fraudulent conditions (B-530) and make a judgment as to whether or not there is fraudulent use. In addition, this secondary index is used in FDS to detect fraudulent activities such as SIM cloning together with a primary index such as the number of incoming call transfers performed within a specific time.
【0063】
[Effect of the invention]
As is clear from the above description, the present invention indicates unauthorized use of data related to unsuccessful authentication processing such as access type, authentication retry, and server address in the third generation mobile communication network. As an index, it is possible to detect fraudulent use.
[Simple explanation of drawings]
[Figure 1]
FIG. 1 is a block diagram showing a mobile communication system from the viewpoint of subscriber and network authentication.
[Figure 2]
FIG. 2 is a flowchart schematically showing an authentication method conventionally defined in a third-generation mobile communication system such as a UMTS network.
[Fig. 3]
FIG. 3 is a block diagram showing a conventional fraud detection system for detecting telephone-related fraud.
[Fig. 4]
Figure 4 shows the authentication failure report by conventional MAP implementation according to the 3G TS 29.002 Recommendation for UMTS, by its operation and parameters.
[Fig. 5]
FIG. 5 is a block diagram showing the overall configuration of the fraud detection system according to the present invention.
[Fig. 6]
FIG. 6 is a flowchart schematically showing the authentication process in the third generation mobile communication system such as the UMTS network according to the present invention.
[Fig. 7]
FIG. 7 shows the authentication failure report by the new MAP implementation according to the embodiment of the present invention by its operation and parameters.
[Fig. 8]
FIG. 8 is a flow chart schematically showing the transmission of an authentication failure report by MAP implementation, storage of the data in HLR and transfer of the data to the FDS for analysis of fraud, along with the newly proposed data according to the present invention. Is.
[Explanation of symbols]
N-0100 core network N-1000 home network N-1102 Home position register (HLR) N-1300 Contractor side equipment N-1301 Fraud detection device (FDS) N-2000 service network N-2111 3rd Generation Service GPRS Support Node (3G SGSN) N-2121 3rd Generation Mobile Exchange / Visitor Position Register (3G MSC / VLR) N-2300 mediator N-2301 Billing Gateway (BGW)
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR100993660B1 | Cited by | Republic of Korea | Examiner |
| JP2006517376A | Cited by | Japan | Examiner |
| US11367081B2 | Cited by | United States of America | Applicant |
| JP2018129591A | Cited by | Japan | Search report |
| JP2007505542A | Cited by | Japan | Search report |
| US11120456B2 | Cited by | United States of America | Applicant |
| US11094202B2 | Cited by | United States of America | Applicant |
| WO2025098573A1 | Cited by | World Intellectual Property Organization (WIPO) | Applicant |
| JP2018506239A | Cited by | Japan | Search report |
| JP2007529957A | Cited by | Japan | Examiner |
| US11961093B2 | Cited by | United States of America | Applicant |
| US12067885B2 | Cited by | United States of America | Applicant |
| JP2013168035A | Cited by | Japan | Search report |
| US8457313B2 | Cited by | United States of America | Applicant |
| US7266364B2 | Cited by | United States of America | Applicant |
| JP2010161733A | Cited by | Japan | Examiner |
| JP2013168035A | Cited by | Japan | Examiner |
| JP2009199627A | Cited by | Japan | Examiner |
| JP2007529933A | Cited by | Japan | Examiner |
| JP2006517375A | Cited by | Japan | Examiner |
| JP2000165512A | Cites | Japan | Search report |
| JPH0669879A | Cites | Japan | Search report |
| JPH07327271A | Cites | Japan | Search report |
| JPH0898248A | Cites | Japan | Search report |
17 members in 9 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 00204177 | European Patent Office (EPO) | A | |
| 00204177 | European Patent Office (EPO) | A | |
| 002041770 | European Patent Office (EPO) | – | |
| 200000204177 | – | – | – |
| EP20000204177 | – | – | – |
Members17
| Document | Office | Kind | |
|---|---|---|---|
| CA2363667A1 | Canada | A1 | |
| EP1209935A1 | European Patent Office (EPO) | A1 | |
| AU9339401A | Australia | A | |
| WO0243424A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU1699402A | Australia | A | |
| CN1357986A | China | A | |
| JP2002247654AThis record | Japan | A | |
| CN1174576C | China | C | |
| AU782981B2 | Australia | B2 | |
| EP1209935B1 | European Patent Office (EPO) | B1 | |
| AT306799T | Austria | T | |
| ATE306799T1 | Austria | T1 | |
| DE60023155D1 | Germany | D1 | |
| ES2251347T3 | Spain | T3 | |
| DE60023155T2 | Germany | T2 | |
| JP4004275B2 | Japan | B2 | |
| CA2363667C | Canada | C |
30 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Dismissal of procedure [no reply to invitation to correct request for examination]JAPANESE INTERMEDIATE CODE: A072A072 | A072 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 2002-247654
- Publication, DOCDB
- 2002247654
- Publication, EPODOC
- JP2002247654
- Application
- 356390
- Application, DOCDB
- 2001356390
- Application, EPODOC
- JP20010356390
Titles2
- Japanese
- 【発明の名称】移動通信網における不正利用検出方法
- English
- PROBLEM TO BE SOLVED: To detect unauthorized use in a mobile communication network.
Classification
- CPC, 3
- H04W12/06
- H04W12/12
- H04W12/0431
- IPC, 4
- G06F21 31
- G06F21 55
- H04B7 26
- H04W12 06