Proxy NF Header Insertion for Inter-PLMN SBI Message Screening
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G telecommunications networks, inter-PLMN messages often lack the necessary 3gpp-Sbi-Originating-Network-Id header, leading to inadequate screening by the receiving network, which can result in either allowing attack traffic or blocking legitimate traffic due to insufficient network identification.
Innovation Solution
A proxy NF, such as an SEPP or SCP, determines the originating network identifier using DNS queries or database records, creates a mapping between dynamically assigned SBI message identifiers and network identifiers, and adds the 3gpp-Sbi-Originating-Network-Id header to inter-PLMN SBI request messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If inter-PLMN messages are transmitted without 3gpp-Sbi-Originating-Network-Id headers, then message transmission simplicity is maintained, but network security and message screening capability deteriorate
Solution Approach 1:
The patent applies preliminary action by having the originating SEPP add the 3gpp-Sbi-Originating-Network-Id header to messages before they leave the home PLMN. This proactive insertion of security information ensures that the target SEPP receives messages with proper identification, enabling effective security screening without requiring complex retroactive solutions at the receiving end.
Solution Approach 2:
The patent uses the 3gpp-Sbi-Originating-Network-Id header as an intermediary element that carries critical security information between the originating and target SEPPs. This header acts as a mediator that enables the target network to screen messages properly by providing the necessary originating network identification without requiring direct trust relationships or complex verification protocols between networks.
2Reliability
If the 3gpp-Sbi-Originating-Network-Id header is added to all inter-PLMN messages, then network security and message screening capability are improved, but message processing complexity increases
Solution Approach 1:
The patent applies self-service by implementing automated mechanisms at the originating SEPP that automatically determine the home PLMN identity and insert the appropriate 3gpp-Sbi-Originating-Network-Id header into outgoing messages. This automation eliminates the need for manual configuration or complex processing at intermediate nodes, reducing overall system complexity while maintaining security.
3Measurement precision
If the originating SEPP determines the home PLMN identity using DNS or database lookups, then accurate network identification is achieved, but message processing time increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing and maintaining mappings between SEPP identifiers and home PLMN identities in DNS records or local databases. This preparation work is done in advance, allowing the originating SEPP to quickly resolve network identification information when messages need to be sent, minimizing the time added to the message processing path while ensuring accurate identification.
Data Source
AI summary
A method for detecting and processing egress inter-PLMN SBI request messages without 3gpp-Sbi-Originating-Network-Id headers includes receiving, by a proxy NF serving a plurality of PLMNs, an egress inter-PLMN SBI request message without an 3gpp-Sbi-Originating-Network-Id header. The method further includes determining an originating network identifier from the message, from DNS, or from a database record. The method further includes adding a 3gpp-Originating-Network-Id header to the message, populating the header with the originating network identifier, and forwarding the message to or towards a target PLMN.


