N32-c Signalling for Inter-PLMN TLS Connection Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP technologies lack a mechanism to correlate N32-f TLS connections with their corresponding N32-c TLS connections, which is essential for enabling renegotiated security policies, terminating connections, and identifying PLMN-specific connections in inter-PLMN communication scenarios.

Innovation Solution

The proposed solution involves an extension to N32-c signalling that includes a TLS extension for Server Name Indication (SNI) to correlate N32-c and N32-f connections. This involves exchanging domain name information over the N32-c interface to set up and manage corresponding N32-f TLS connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain name information is exchanged over N32-c interface to correlate connections, then connection correlation and security policy management are enabled, but signalling complexity and processing overhead increase

Engineering Contradiction:
Improveconnection correlationVSAvoidsignalling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces domain name information as an intermediary element that is exchanged over the existing N32-c signalling interface. This intermediary carries the correlation information needed to link N32-c and N32-f connections without requiring a separate correlation mechanism, thus enabling reliable connection correlation while utilizing existing infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The N32-c interface, originally designed for security capability negotiation, is extended to also carry domain name information for connection correlation. This multi-functional use of the existing interface enables connection correlation without adding separate dedicated signalling paths, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If TLS extension for Server Name Indication is implemented, then connection identification and security policy application are improved, but implementation complexity and processing time increase

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The domain name information is exchanged and correlated during the initial N32-c handshake phase, before actual data transmission over N32-f begins. This preliminary establishment of correlation information allows security policies to be pre-configured and applied without delays during data plane operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TLS extension mechanism allows the communicating entities themselves to perform the correlation and security policy application using the exchanged domain name information, without requiring external correlation services or additional processing intermediaries, thus reducing overall processing time.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12267679B2Inter-PLMN communication
Publication Date: 2025.04.01 NOKIA TECHNOLOGIES OY
  • US12267679B2 patent drawing
  • US12267679B2 patent drawing
  • US12267679B2 patent drawing

AI summary

There is disclosed an apparatus. The apparatus comprises means for performing: initiating establishment of an N32-c transport layer security connection with an entity, the apparatus located in a first public land mobile network and the entity located in a second public land mobile network; sending from the apparatus to the entity on the N32-c transport layer security connection an N32-c handshake signalling message comprising domain name information of the apparatus to be used by the entity for establishing an N32-f transport layer security connection towards the apparatus; receiving a reply from the entity, the reply comprising domain name information of the entity to be used by the apparatus for establishing the N32-f transport layer security connection towards the entity; and using the domain name information received in the reply to establish the N32-f transport layer security connection towards the entity.