Dynamic SEPP Discovery via Root Node in 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual and static configuration of Security Edge Protection Proxies (SEPPs) in wireless networks becomes burdensome for operators due to the exponential growth of wireless networks and the increasing number of operators, lacking a standardized method for dynamic discovery and selection.

Innovation Solution

Implementing a Root SEPP Discovery node managed by the Network Repository Function (NRF) to enable dynamic registration, subscription, and discovery of SEPPs, allowing for the management of SEPPs as Network Functions under the 5G Service-Based Architecture, facilitating connection establishment between SEPPs of different operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual and static configuration of SEPPs is used, then network security protection is provided, but the resource and time burden on operators increases significantly due to exponential network growth

Engineering Contradiction:
Improvenetwork security protectionVSAvoidoperator configuration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transforms the static SEPP configuration into a dynamic system where SEPPs automatically register with the NRF, subscribe to discovery services, and establish connections based on real-time network conditions. The NRF maintains a dynamic repository of SEPP information that automatically updates as SEPPs are added or removed from the network, eliminating manual reconfiguration needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

SEPPs are designed to autonomously perform configuration tasks by automatically registering themselves with the NRF, publishing their service information, and discovering peer SEPPs through standardized interfaces. This self-service mechanism eliminates the need for operator intervention in SEPP configuration and management.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration methods are used for SEPP selection, then security edge protection is achieved, but the time and resources required for SEPP management increase

Engineering Contradiction:
Improvesecurity edge protectionVSAvoidSEPP configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

SEPPs perform automatic registration and service publication with the NRF in advance, so that when connection establishment is needed, the NRF already has the necessary SEPP information available. This preliminary action eliminates the need for time-consuming manual configuration and discovery during actual connection setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The NRF acts as an intermediary between SEPPs, centralizing the management of SEPP information and providing a standardized discovery mechanism. Instead of SEPPs directly managing peer connections, they query the NRF which returns appropriate SEPP selections based on stored registration data, significantly reducing configuration time.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If static SEPP configuration is implemented, then network security is maintained, but adaptability to network growth and changes is reduced

Engineering Contradiction:
Improvenetwork securityVSAvoiddynamic network adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The NRF provides a universal service that handles registration, discovery, and selection for all SEPPs in the network through standardized interfaces. This universal mechanism automatically adapts to network growth by accepting registrations from new SEPPs and making them available for discovery without requiring changes to the core system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements continuous feedback through the subscription mechanism where SEPPs subscribe to discovery services and receive updates when new SEPPs register or existing ones change status. This feedback loop ensures the network dynamically adapts to changes while maintaining security through consistent application of security policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240073103A1Dynamic configuration and discovery of security edge protection proxy
Publication Date: 2024.02.29 T MOBILE US INC
  • US20240073103A1 patent drawing
  • US20240073103A1 patent drawing
  • US20240073103A1 patent drawing

AI summary

Systems, methods, and devices that relate to adapting the SEPP as a Network Function (NF) under the 5G SBA are disclosed. In one example aspect, a system for wireless communication includes a first SEPP network function located at an edge of a first network, a first network repository function in communication with the SEPP network function, and a root SEPP discovery node in communication with the first network repository function and a second network repository function of a second network. The second network repository function of the second network is in communication with a second SEPP network function located at an edge of the second network. The root SEPP discovery node is configured to store information of different SEPP network functions that include the first and the second SEPP network functions available in different networks globally or regionally.