Roaming Hub Header Validation for Secure Inter-PLMN Interconnect

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of intermediate proxies in secure interconnect scenarios for 5G networks can cause issues with verifying the authenticity of PLMN identifiers, leading to unauthorized access and inefficient message forwarding between networks without direct roaming agreements.

Innovation Solution

Implementing a roaming hub that adds and modifies custom HTTP headers in messages to indicate validated PLMN identifiers and roaming hub identifiers, ensuring integrity protection and enabling secure interconnect between networks with no direct roaming agreements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If intermediate proxies are implemented between SEPPs for roaming scenarios, then message forwarding capability is improved, but security verification of PLMN identifiers deteriorates

Engineering Contradiction:
Improvemessage forwarding capabilityVSAvoidsecurity verification of PLMN identifiers
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a roaming hub as an intermediary entity between SEPPs that performs both message forwarding and security verification functions. The roaming hub adds custom HTTP headers containing PLMN identifier information and validates these identifiers, thereby maintaining security while enabling message forwarding through intermediate proxies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The roaming hub performs preliminary security verification by validating PLMN identifiers and adding integrity-protected custom headers to messages before forwarding them. This preliminary action ensures that security verification is completed upfront, preventing security deterioration while enabling subsequent message forwarding.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If custom HTTP headers are added to messages for PLMN validation, then security and tracking are improved, but message processing complexity increases

Engineering Contradiction:
ImprovePLMN validation securityVSAvoidmessage processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by adding specific custom HTTP headers only where needed in the message structure, rather than fundamentally changing the entire message format. This allows PLMN validation and tracking functionality to be added with minimal impact on overall message processing complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The roaming hub modifies message parameters by adding custom HTTP headers with specific PLMN identifier information. This parameter change approach enables enhanced security and tracking capabilities while maintaining compatibility with existing message processing systems that can handle additional header parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If integrity protection is applied to custom headers, then message authenticity is improved, but processing overhead increases

Engineering Contradiction:
Improvemessage authenticityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The roaming hub applies integrity protection to custom headers in advance before message forwarding. This preliminary action ensures that authenticity verification is completed upfront, reducing the need for repeated verification processing and thereby minimizing overall processing overhead despite the initial integrity protection step.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4152691B1Roaming hub for secure interconnect in roaming scenarios
Publication Date: 2025.10.15 NOKIA TECHNOLOGIES OY
  • EP4152691B1 patent drawingFigure 1~2
  • EP4152691B1 patent drawingFigure 3
  • EP4152691B1 patent drawingFigure 4

AI summary

Systems, methods, and software for inter-PLMN communications. In one embodiment, a roaming hub receives a message from a sending entity across an N32 interface, and determines whether the message includes an HTTP custom header that indicates a PLMN that is validated. When the message as received does not include the HTTP custom header, the roaming hub adds the HTTP custom header to the message that indicates the PLMN of the sending entity, integrity protects the HTTP custom header, and forwards the message toward a receiving entity.