Proxy NF Screening of SBI Requests Using NF Discovery Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G networks are vulnerable to security attacks through fake service-based interface (SBI) request messages at the interface between visited public land mobile networks (VPLMN) and home PLMN (HPLMN) or between mobile network operator (MNO) and mobile virtual network operator (MVNO) networks, leading to denial of service and unauthorized access to subscriber information.

Innovation Solution

Implementing a proxy NF, such as a security edge protection proxy (SEPP) or service communication proxy (SCP), to link NF discovery results with subsequent messages, creating records in an NF-discovery-linked security database, and screening SBI request messages based on these records to authenticate and authorize consumer NFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NF discovery service operation is implemented to enable consumer NFs to obtain information about producer NFs, then service discovery capability is improved, but network security is worsened due to vulnerability to fake SBI request messages

Engineering Contradiction:
Improveservice discovery capabilityVSAvoidnetwork security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy NF as an intermediary component between consumer NFs and producer NFs. The proxy NF intercepts and screens SBI request messages, validating them against recorded NF discovery results before forwarding to producer NFs. This intermediary mechanism maintains service discovery functionality while blocking fake messages that would otherwise compromise network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary recording of authentic NF discovery results in a database before actual service requests occur. By pre-storing verified consumer-NF-identifying parameters and producer-NF-identifying parameters from legitimate NF discovery operations, the system establishes a baseline for later validation, enabling rapid authentication and rejection of fraudulent requests.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If screening of SBI request messages is implemented at proxy NF to block fake messages, then network security is improved, but message processing time is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates simplified copies of essential authentication data by storing only critical identifying parameters (consumer NF identifiers and producer NF identifiers) from NF discovery results in a database. This copying approach enables rapid lookup and validation of SBI request messages without requiring complex verification procedures, thus maintaining security while minimizing processing time overhead.

Inventive Principle:
Principle #26Copying

3Measurement precision

If records of consumer NF and producer NF identifying parameters are created and stored, then authentication accuracy is improved, but database complexity is worsened

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddatabase structure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential identifying parameters (consumer NF identifiers and producer NF identifiers) from complete NF discovery results and stores them in a simplified database structure. By taking out only the critical authentication elements rather than storing entire NF profiles, the system achieves accurate authentication while maintaining database simplicity and ease of management.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12470592B2Methods, systems, and computer readable media for mitigating network security attacks by linking network function (NF) discovery results with subsequent messages at proxy NF
Publication Date: 2025.11.11 ORACLE INT CORP
  • US12470592B2 patent drawing
  • US12470592B2 patent drawing
  • US12470592B2 patent drawing

AI summary

A method for mitigating network security attacks by linking NF discovery results to subsequent messages includes receiving, at a proxy NF, NF discovery messages. The method further includes reading, by the proxy NF, producer NF and consumer-NF-identifying parameters from the NF discovery messages. The method further includes creating, by the proxy NF, records in an NF-discovery-linked security database maintained by the proxy NF, wherein the records include the consumer NF and producer-NF-identifying parameters read from the NF discovery messages. The method further includes receiving, by the proxy NF, a service-based interface (SBI) request message. The method further includes screening, by the proxy NF and using the records in the NF-discovery-linked security database, the SBI request message. The method further includes performing, by the proxy NF, a network security action for the SBI request message based on results of the screening.