Dynamic SEPP Discovery via Root Node in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The manual and static configuration of Security Edge Protection Proxies (SEPPs) in wireless networks becomes burdensome for operators due to the exponential growth of wireless networks and the increasing number of operators, lacking a standardized method for dynamic discovery and selection.
Innovation Solution
Implementing a Root SEPP Discovery node managed by the Network Repository Function (NRF) to enable dynamic registration, subscription, and discovery of SEPPs, allowing for the management of SEPPs as Network Functions under the 5G Service-Based Architecture, facilitating connection establishment between SEPPs of different operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual and static configuration of SEPPs is used, then network security protection is provided, but the resource and time burden on operators increases significantly due to exponential network growth
Solution Approach 1:
The patent transforms the static SEPP configuration into a dynamic system where SEPPs automatically register with the NRF, subscribe to discovery services, and establish connections based on real-time network conditions. The NRF maintains a dynamic repository of SEPP information that automatically updates as SEPPs are added or removed from the network, eliminating manual reconfiguration needs.
Solution Approach 2:
SEPPs are designed to autonomously perform configuration tasks by automatically registering themselves with the NRF, publishing their service information, and discovering peer SEPPs through standardized interfaces. This self-service mechanism eliminates the need for operator intervention in SEPP configuration and management.
2Reliability
If manual configuration methods are used for SEPP selection, then security edge protection is achieved, but the time and resources required for SEPP management increase
Solution Approach 1:
SEPPs perform automatic registration and service publication with the NRF in advance, so that when connection establishment is needed, the NRF already has the necessary SEPP information available. This preliminary action eliminates the need for time-consuming manual configuration and discovery during actual connection setup.
Solution Approach 2:
The NRF acts as an intermediary between SEPPs, centralizing the management of SEPP information and providing a standardized discovery mechanism. Instead of SEPPs directly managing peer connections, they query the NRF which returns appropriate SEPP selections based on stored registration data, significantly reducing configuration time.
3Reliability
If static SEPP configuration is implemented, then network security is maintained, but adaptability to network growth and changes is reduced
Solution Approach 1:
The NRF provides a universal service that handles registration, discovery, and selection for all SEPPs in the network through standardized interfaces. This universal mechanism automatically adapts to network growth by accepting registrations from new SEPPs and making them available for discovery without requiring changes to the core system architecture.
Solution Approach 2:
The system implements continuous feedback through the subscription mechanism where SEPPs subscribe to discovery services and receive updates when new SEPPs register or existing ones change status. This feedback loop ensures the network dynamically adapts to changes while maintaining security through consistent application of security policies.
Data Source
AI summary
Systems, methods, and devices that relate to adapting the SEPP as a Network Function (NF) under the 5G SBA are disclosed. In one example aspect, a system for wireless communication includes a first SEPP network function located at an edge of a first network, a first network repository function in communication with the SEPP network function, and a root SEPP discovery node in communication with the first network repository function and a second network repository function of a second network. The second network repository function of the second network is in communication with a second SEPP network function located at an edge of the second network. The root SEPP discovery node is configured to store information of different SEPP network functions that include the first and the second SEPP network functions available in different networks globally or regionally.


