IPX Proxy Signaling Security in 5G Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The transition to 5G mobile telecommunications technology's service-based roaming architecture, utilizing HTTP/2 as a signaling protocol, bypasses IPX providers, making it difficult for them to perform mediation and other services, compromising signaling integrity and confidentiality.
Innovation Solution
Implementing a method where IPX providers act as proxies using HTTPS end-to-end security, allowing them to inspect, modify, or drop signaling messages by establishing secure connections with SEPPs via TLS or PKI-based mutual-authentication, ensuring mediation services can be executed effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If HTTP/2 signaling protocol is used in 5G service-based roaming architecture, then signaling efficiency and modernization are improved, but IPX providers are bypassed and mediation services are compromised
Solution Approach 1:
The patent introduces SEPP (Security Edge Protection Proxy) as an intermediary that sits between VPLMN and HPLMN, enabling HTTP/2 signaling while maintaining IPX provider involvement. The SEPP acts as a mediator that can forward signaling messages through IPX providers while ensuring security and integrity, thus resolving the contradiction between modern signaling protocols and traditional mediation services.
Solution Approach 2:
The patent segments the signaling path into multiple segments: VPLMN-SEPP, SEPP-IPX Provider, and IPX Provider-HPLMN. This segmentation allows HTTP/2 to be used for signaling efficiency while IPX providers remain involved in mediation services through the intermediate segment, preventing complete bypass of IPX infrastructure.
2Device complexity
If IPX providers bypassed by direct VPLMN-HPLMN connection, then connection simplicity is improved, but signaling integrity and confidentiality are compromised
Solution Approach 1:
The SEPP serves as a trusted intermediary that maintains simplicity of direct connection appearance while ensuring signaling integrity through security functions. The SEPP can authenticate parties, inspect messages, and forward them through IPX providers, thus maintaining both simplicity and integrity.
Solution Approach 2:
The patent replaces traditional mechanical IPX routing mechanisms with HTTP/2-based signaling combined with PKI authentication. This substitution maintains connection simplicity while providing enhanced security through cryptographic mechanisms rather than complex routing protocols.
3Adaptability or versatility
If HTTP/2 protocol is implemented, then protocol modernization and compatibility are improved, but IPX provider proxy role becomes difficult to play
Solution Approach 1:
The SEPP acts as an intermediary that bridges HTTP/2 protocol with IPX provider mediation capabilities. It receives HTTP/2 signaling from VPLMN, translates or forwards through IPX providers who can perform mediation, and ensures compatibility with HPLMN protocols, thus maintaining both modernization and mediation capabilities.
Solution Approach 2:
The patent makes the signaling system universal by allowing SEPP to handle multiple protocol types and IPX providers to perform multiple functions (mediation, routing, security). This multi-functionality enables HTTP/2 compatibility while preserving IPX provider versatility in mediation services.
Data Source
AI summary
The present disclosure may be implemented in the form of a method or corresponding apparatus for sending signaling messages through an IPX proxy from a first network element. The at least one example embodiment includes a first network element located on a first mobile network, the first network element configured to establish an initial signaling connection with a second network element on a second mobile network. The first network element may be configured to send a signaling request message to the second network element, receive a signaling response message from the second network element, the received signaling response message including an indication of an IPX proxy selected by the second network element. The first network element may be further configured to establish a signaling connection with the IPX proxy indicated in the received signaling response message, and send a second signaling request message to the IPX proxy for mediation service.


