DNS Security in 5G Edge Roaming via IPUPS Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G edge computing scenarios with home-routed roaming, DNS messages sent during edge application server selection bypass the Inter PLMN User Plane Security (IPUPS) functionality, raising security concerns as they traverse the PLMN border without being subject to security checks.

Innovation Solution

Implementing a network security function, such as IPUPS, to ensure that DNS messages are subjected to security checks and forwarded through the IPUPS functionality, either by establishing a dedicated tunnel or reusing existing IPUPS functionality on the user plane tunnel between the visited and home networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DNS messages are sent directly between V-EASDF and H-DNS during edge application server selection, then the edge computing service can be established efficiently, but the security of DNS messages is compromised as they bypass IPUPS functionality

Engineering Contradiction:
Improveedge computing service establishment efficiencyVSAvoidDNS message security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a dedicated tunnel (N9 interface with GTP-U protocol) as an intermediary between V-EASDF and H-DNS. This tunnel is controlled by IPUPS functionality, which acts as a mediator to enforce security checks on DNS messages while allowing them to reach their destination. The tunnel endpoint functions (TEFs) at V-EASDF and H-DNS communicate through this secured intermediary path rather than direct connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPUPS functionality is deployed on all user data paths, then network security is enhanced, but the complexity of the system increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies IPUPS functionality selectively rather than universally. Specifically, the dedicated tunnel for DNS messages is established only when edge computing services are being selected, and only between specific network elements (V-EASDF and H-DNS). This localized application of security functionality reduces overall system complexity while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent establishes the dedicated tunnel and activates IPUPS functionality in advance during the PDU session establishment phase, before actual DNS message exchange begins. The SMF configures the tunnel endpoints and security parameters beforehand, so that when DNS messages need to be sent during EAS selection, the secure path is already in place and ready to use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240163671A1V-easdf and ipups
Publication Date: 2024.05.16 NOKIA SOLUTIONS & NETWORKS OY
  • US20240163671A1 patent drawing
  • US20240163671A1 patent drawing
  • US20240163671A1 patent drawing

AI summary

A method, for use in a network control element, is provide, the method comprising: allocating a network security function between a visited network and a home network of a user equipment, and controlling domain name system related signalling between an edge computing related network element in the visited network and a network element in the home network such that the domain name system related signalling is subjected to the network security function.