Proxy NF Screening of SBI Requests Using NF Discovery Linking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G networks are vulnerable to security attacks through fake service-based interface (SBI) request messages at the interface between visited public land mobile networks (VPLMN) and home PLMN (HPLMN) or between mobile network operator (MNO) and mobile virtual network operator (MVNO) networks, leading to denial of service and unauthorized access to subscriber information.
Innovation Solution
Implementing a proxy NF, such as a security edge protection proxy (SEPP) or service communication proxy (SCP), to link NF discovery results with subsequent messages, creating records in an NF-discovery-linked security database, and screening SBI request messages based on these records to authenticate and authorize consumer NFs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NF discovery service operation is implemented to enable consumer NFs to obtain information about producer NFs, then service discovery capability is improved, but network security is worsened due to vulnerability to fake SBI request messages
Solution Approach 1:
The patent introduces a proxy NF as an intermediary component between consumer NFs and producer NFs. The proxy NF intercepts and screens SBI request messages, validating them against recorded NF discovery results before forwarding to producer NFs. This intermediary mechanism maintains service discovery functionality while blocking fake messages that would otherwise compromise network security.
Solution Approach 2:
The patent implements preliminary recording of authentic NF discovery results in a database before actual service requests occur. By pre-storing verified consumer-NF-identifying parameters and producer-NF-identifying parameters from legitimate NF discovery operations, the system establishes a baseline for later validation, enabling rapid authentication and rejection of fraudulent requests.
2Reliability
If screening of SBI request messages is implemented at proxy NF to block fake messages, then network security is improved, but message processing time is worsened
Solution Approach 1:
The patent creates simplified copies of essential authentication data by storing only critical identifying parameters (consumer NF identifiers and producer NF identifiers) from NF discovery results in a database. This copying approach enables rapid lookup and validation of SBI request messages without requiring complex verification procedures, thus maintaining security while minimizing processing time overhead.
3Measurement precision
If records of consumer NF and producer NF identifying parameters are created and stored, then authentication accuracy is improved, but database complexity is worsened
Solution Approach 1:
The patent extracts only the essential identifying parameters (consumer NF identifiers and producer NF identifiers) from complete NF discovery results and stores them in a simplified database structure. By taking out only the critical authentication elements rather than storing entire NF profiles, the system achieves accurate authentication while maintaining database simplicity and ease of management.
Data Source
AI summary
A method for mitigating network security attacks by linking NF discovery results to subsequent messages includes receiving, at a proxy NF, NF discovery messages. The method further includes reading, by the proxy NF, producer NF and consumer-NF-identifying parameters from the NF discovery messages. The method further includes creating, by the proxy NF, records in an NF-discovery-linked security database maintained by the proxy NF, wherein the records include the consumer NF and producer-NF-identifying parameters read from the NF discovery messages. The method further includes receiving, by the proxy NF, a service-based interface (SBI) request message. The method further includes screening, by the proxy NF and using the records in the NF-discovery-linked security database, the SBI request message. The method further includes performing, by the proxy NF, a network security action for the SBI request message based on results of the screening.


