DNS Security in 5G Edge Roaming via IPUPS Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G edge computing scenarios with home-routed roaming, DNS messages sent during edge application server selection bypass the Inter PLMN User Plane Security (IPUPS) functionality, raising security concerns as they traverse the PLMN border without being subject to security checks.
Innovation Solution
Implementing a network security function, such as IPUPS, to ensure that DNS messages are subjected to security checks and forwarded through the IPUPS functionality, either by establishing a dedicated tunnel or reusing existing IPUPS functionality on the user plane tunnel between the visited and home networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If DNS messages are sent directly between V-EASDF and H-DNS during edge application server selection, then the edge computing service can be established efficiently, but the security of DNS messages is compromised as they bypass IPUPS functionality
Solution Approach 1:
The patent introduces a dedicated tunnel (N9 interface with GTP-U protocol) as an intermediary between V-EASDF and H-DNS. This tunnel is controlled by IPUPS functionality, which acts as a mediator to enforce security checks on DNS messages while allowing them to reach their destination. The tunnel endpoint functions (TEFs) at V-EASDF and H-DNS communicate through this secured intermediary path rather than direct connectivity.
2Reliability
If IPUPS functionality is deployed on all user data paths, then network security is enhanced, but the complexity of the system increases
Solution Approach 1:
The patent applies IPUPS functionality selectively rather than universally. Specifically, the dedicated tunnel for DNS messages is established only when edge computing services are being selected, and only between specific network elements (V-EASDF and H-DNS). This localized application of security functionality reduces overall system complexity while maintaining security where needed.
Solution Approach 2:
The patent establishes the dedicated tunnel and activates IPUPS functionality in advance during the PDU session establishment phase, before actual DNS message exchange begins. The SMF configures the tunnel endpoints and security parameters beforehand, so that when DNS messages need to be sent during EAS selection, the secure path is already in place and ready to use.
Data Source
AI summary
A method, for use in a network control element, is provide, the method comprising: allocating a network security function between a visited network and a home network of a user equipment, and controlling domain name system related signalling between an edge computing related network element in the visited network and a network element in the home network such that the domain name system related signalling is subjected to the network security function.


