N32 PRINS Roaming Security Without HTTP CONNECT Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing PRINS protocol for N32 interconnect security in 5G roaming requires roaming intermediaries (RIs) to support HTTP CONNECT, which introduces business and security risks by allowing unauthorized access and loss of visibility and control over transmitted data, and impedes the operation of RIs due to confidentiality protection.
Innovation Solution
The proposed solution involves establishing a transport layer security (TLS) connection using HTTPS as a uniform resource identifier (URI) and employing Javascript Object Notation (JSON) Web Signature (JWS) tokens for secure negotiation and key exchange between network nodes, allowing authorized RIs to modify signaling messages while ensuring end-to-end security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HTTP CONNECT is used to establish TLS tunnel over roaming intermediaries, then end-to-end security is achieved, but security risks and loss of visibility are introduced due to unauthorized access
Solution Approach 1:
The patent extracts the security negotiation process from the HTTP CONNECT tunneling mechanism and places it in a separate, controlled framework. By using SEPPs to manage security capabilities independently and using PRINS for application-layer security, the system eliminates the need for HTTP CONNECT while maintaining end-to-end security and preventing unauthorized access through proper authentication and authorization mechanisms.
Solution Approach 2:
The patent introduces SEPPs (Security Edge Protection Proxies) as intermediary components that mediate between roaming intermediaries and network functions. These SEPPs perform security capability negotiation and enforce access control policies, acting as trusted intermediaries that prevent unauthorized access while enabling secure communication without requiring HTTP CONNECT tunneling.
2Reliability
If HTTP CONNECT is used for TLS tunnel establishment, then security protection is achieved, but operational efficiency of roaming intermediaries is impeded
Solution Approach 1:
The patent extracts the security protection function from the HTTP CONNECT process and implements it through a separate security capability negotiation mechanism using SEPPs and PRINS. This separation allows roaming intermediaries to operate efficiently without being constrained by HTTP CONNECT requirements, while security protection is maintained through application-layer authentication and authorization.
Solution Approach 2:
The patent changes the fundamental parameters of how security is negotiated by moving from HTTP CONNECT-based TLS tunneling to a SEPP-mediated security capability exchange using PRINS. This parameter change enables roaming intermediaries to maintain security protection while improving operational efficiency through more flexible and standardized security negotiation processes.
3Reliability
If end-to-end TLS tunnel is used, then confidentiality is protected, but visibility and control over transmitted data are lost
Solution Approach 1:
The patent segments the security function into multiple components: SEPPs for security capability negotiation, PRINS for application-layer protection, and controlled decryption points at each SEPP. This segmentation allows confidentiality to be maintained during transmission while enabling controlled visibility and data control at designated points in the communication path.
Solution Approach 2:
The patent introduces SEPPs as intermediary components that act as trusted decryption and inspection points. These SEPPs can decrypt data at specific locations in the communication path to provide visibility and control, while maintaining end-to-end confidentiality through proper encryption. The SEPPs serve as mediators that balance security with operational visibility needs.
Data Source
AI summary
Session management for a Fifth Generation (5G) roaming solution using PRotocol for N32 INterconnect Security (PRINS) with roaming intermediaries is described herein. A first network node establishes a transport layer security (TLS) connection with a second network node, wherein the TLS connection is established using hypertext transfer protocol secure (HTTPS) as a uniform resource identifier (URI). The first network node creates a security negotiation request message, including a fully qualified domain name (FQDN) of the second network node. The first network node protects information elements (IEs) in the security negotiation request message with a Javascript Object Notation (JSON) Web Signature (JWS) token, wherein the JWS token uses a digital signature and includes a public key certificate of the first network node. The first network node sends over TLS, to the second network node, an HTTPS request, including the security negotiation request message and the JWS token.


