IPX Proxy Signaling Security in 5G Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition to 5G mobile telecommunications technology's service-based roaming architecture, utilizing HTTP/2 as a signaling protocol, bypasses IPX providers, making it difficult for them to perform mediation and other services, compromising signaling integrity and confidentiality.

Innovation Solution

Implementing a method where IPX providers act as proxies using HTTPS end-to-end security, allowing them to inspect, modify, or drop signaling messages by establishing secure connections with SEPPs via TLS or PKI-based mutual-authentication, ensuring mediation services can be executed effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If HTTP/2 signaling protocol is used in 5G service-based roaming architecture, then signaling efficiency and modernization are improved, but IPX providers are bypassed and mediation services are compromised

Engineering Contradiction:
Improvesignaling efficiencyVSAvoidmediation service reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces SEPP (Security Edge Protection Proxy) as an intermediary that sits between VPLMN and HPLMN, enabling HTTP/2 signaling while maintaining IPX provider involvement. The SEPP acts as a mediator that can forward signaling messages through IPX providers while ensuring security and integrity, thus resolving the contradiction between modern signaling protocols and traditional mediation services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the signaling path into multiple segments: VPLMN-SEPP, SEPP-IPX Provider, and IPX Provider-HPLMN. This segmentation allows HTTP/2 to be used for signaling efficiency while IPX providers remain involved in mediation services through the intermediate segment, preventing complete bypass of IPX infrastructure.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If IPX providers bypassed by direct VPLMN-HPLMN connection, then connection simplicity is improved, but signaling integrity and confidentiality are compromised

Engineering Contradiction:
Improveconnection simplicityVSAvoidsignaling integrity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The SEPP serves as a trusted intermediary that maintains simplicity of direct connection appearance while ensuring signaling integrity through security functions. The SEPP can authenticate parties, inspect messages, and forward them through IPX providers, thus maintaining both simplicity and integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical IPX routing mechanisms with HTTP/2-based signaling combined with PKI authentication. This substitution maintains connection simplicity while providing enhanced security through cryptographic mechanisms rather than complex routing protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If HTTP/2 protocol is implemented, then protocol modernization and compatibility are improved, but IPX provider proxy role becomes difficult to play

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidIPX provider mediation capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The SEPP acts as an intermediary that bridges HTTP/2 protocol with IPX provider mediation capabilities. It receives HTTP/2 signaling from VPLMN, translates or forwards through IPX providers who can perform mediation, and ensures compatibility with HPLMN protocols, thus maintaining both modernization and mediation capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the signaling system universal by allowing SEPP to handle multiple protocol types and IPX providers to perform multiple functions (mediation, routing, security). This multi-functionality enables HTTP/2 compatibility while preserving IPX provider versatility in mediation services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11438310B2IPX signaling security
Publication Date: 2022.09.06 KONINK KPN NV
  • US11438310B2 patent drawing
  • US11438310B2 patent drawing
  • US11438310B2 patent drawing

AI summary

The present disclosure may be implemented in the form of a method or corresponding apparatus for sending signaling messages through an IPX proxy from a first network element. The at least one example embodiment includes a first network element located on a first mobile network, the first network element configured to establish an initial signaling connection with a second network element on a second mobile network. The first network element may be configured to send a signaling request message to the second network element, receive a signaling response message from the second network element, the received signaling response message including an indication of an IPX proxy selected by the second network element. The first network element may be further configured to establish a signaling connection with the IPX proxy indicated in the received signaling response message, and send a second signaling request message to the IPX proxy for mediation service.