Edge Proxy for Secure 5G Core Network Function Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The service-based architecture of 5G core networks faces challenges in protecting communication between network functions (NFs) while maintaining network operator flexibility and inter-network or inter-slice security, especially when NFs are in different public land mobile networks (PLMNs) or network slices.

Innovation Solution

The implementation of network equipment that acts as a proxy to establish secure connections between NFs, allowing for selective forwarding and interception of communication, including the use of edge proxies to ensure security and load balancing across different PLMNs or network slices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct secure communication is established between NFs in different PLMNs or network slices, then communication security is improved, but network operator flexibility and ability to intercept/monitor communication deteriorates

Engineering Contradiction:
Improvecommunication securityVSAvoidnetwork operator flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an edge proxy as an intermediary component that terminates secure connections from NFs in different PLMNs or network slices. The edge proxy acts as a mediator that receives encrypted traffic, decrypts it using intercepted keys, inspects the content, and forwards it to the destination NF. This intermediary architecture maintains security while enabling operator-controlled inspection and interception capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication path is segmented into multiple hops: NF → Edge Proxy → NF. Instead of direct peer-to-peer communication, the edge proxy creates an intermediate segment that allows operators to insert security inspection points. This segmentation enables both secure communication and operator flexibility to monitor and control traffic between different PLMNs or slices.

Inventive Principle:
Principle #1Segmentation

2Productivity

If direct communication is established between NFs, then communication efficiency is improved, but ability to perform load balancing and security inspection deteriorates

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidload balancing capability
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The edge proxy serves as a mediator that NFs can connect to for service discovery and communication. The proxy maintains a registry of available NFs and can direct traffic to appropriate destinations, enabling load balancing without requiring changes to the NFs themselves. The proxy absorbs the complexity of service management while maintaining efficient communication paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The edge proxy performs multiple functions: it acts as a security gateway for intercepting and inspecting traffic, serves as a service discovery mechanism for NFs to find each other, and provides load balancing by distributing traffic across multiple instances. This multi-functional approach consolidates several capabilities into a single component, improving overall system efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11641376B2Protection of traffic between network functions
Publication Date: 2023.05.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11641376B2 patent drawing
  • US11641376B2 patent drawing
  • US11641376B2 patent drawing

AI summary

Methods and network equipment in a core network for intercepting protected communication between core network (CN) network functions (NFs). A method performed by network equipment in a core network may include establishing a first connection with a first NF for which the network equipment serves as a proxy and establishing, on behalf of the first NF, a second connection that is towards a second NF and that is secure. The method may also include selectively forwarding communication between the first and second NFs over the first and second connections, including transmitting and/or receiving the communication on behalf of the first NF over the second connection. The method may further include intercepting the communication that the network equipment selectively forwards between the first and second NFs.