MAP Security Gateway Node for Flexible Domain Interconnection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current implementations of MAP application layer security in mobile networks are inflexible and costly, especially when dealing with multiple network nodes, as they require a common physical node for encrypting and decrypting MAP messages, which limits scalability and increases implementation costs.
Innovation Solution
A gateway node is introduced that can connect multiple domains, allowing for the conversion of MAP messages between secured and unsecured forms, enabling flexible and cost-efficient implementation of MAP application layer security by acting as a firewall and managing security levels independently for each domain, with the option to fallback to lower security levels based on trust levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAP application layer security is implemented with a common physical node for encrypting and decrypting messages, then security is provided, but flexibility is reduced and implementation costs increase
Solution Approach 1:
The patent segments the security function from the MAP protocol instance by introducing a separate security node. The MAP protocol instance in the first domain is divided into two functional parts: the protocol processing logic remains in the original node, while the security functions (encryption/decryption) are extracted and placed in a dedicated security node. This segmentation allows the security node to serve multiple MAP protocol instances across different domains, thereby improving flexibility while maintaining security.
Solution Approach 2:
The security node acts as an intermediary between the MAP protocol instance in the first domain and the second domain. It receives secured MAP messages from the first domain, decrypts them, and forwards the unsecured messages to the second domain, and vice versa. This intermediary approach allows security to be implemented without requiring changes to the core MAP protocol logic, enabling flexible deployment across multiple domains and nodes.
2Reliability
If MAP application layer security is implemented in a network with many different network nodes, then security is provided, but implementation costs increase
Solution Approach 1:
The security node is designed with multi-functionality to serve multiple MAP protocol instances across different domains. A single security node can handle security operations for numerous MAP protocol instances, eliminating the need to deploy separate security functionality in each node. This universal approach significantly reduces implementation costs while providing consistent security across the entire network infrastructure.
3Adaptability or versatility
If security levels are configured independently for different domains, then flexibility is improved, but system complexity increases
Solution Approach 1:
The system implements dynamic security level configuration where the security node can independently adjust security parameters for different domains based on trust levels and policy requirements. The security node dynamically selects appropriate security mechanisms (encryption algorithms, key management, etc.) for each domain without requiring changes to the overall system architecture. This dynamic approach provides flexibility while keeping the complexity localized to the security node rather than propagating throughout the entire system.
Data Source
AI summary
According to the present invention a telecommunication network with a first domain (PLMN-A) comprising at least one mobile application part protocol instance is connected to a gateway node (MSEGA) which is adapted to send and receive mobile application part messages and which is connectable to a second domain. The telecommunication network is remarkable in that the gateway node (MSEGA) is adapted to receive a mobile application part message from the first domain, to convert the received mobile application part message obtaining a secured mobile application part message, and to send the obtained message to the second domain. The gateway node (MSEGA) is further adapted to receive a secured mobile application part message from the second domain, to extract an unsecured mobile application part message from the received secured mobile application part message and to send the extracted message to the first domain.


