Roaming Hub Header Validation for Secure Inter-PLMN Interconnect
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of intermediate proxies in secure interconnect scenarios for 5G networks can cause issues with verifying the authenticity of PLMN identifiers, leading to unauthorized access and inefficient message forwarding between networks without direct roaming agreements.
Innovation Solution
Implementing a roaming hub that adds and modifies custom HTTP headers in messages to indicate validated PLMN identifiers and roaming hub identifiers, ensuring integrity protection and enabling secure interconnect between networks with no direct roaming agreements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If intermediate proxies are implemented between SEPPs for roaming scenarios, then message forwarding capability is improved, but security verification of PLMN identifiers deteriorates
Solution Approach 1:
The patent introduces a roaming hub as an intermediary entity between SEPPs that performs both message forwarding and security verification functions. The roaming hub adds custom HTTP headers containing PLMN identifier information and validates these identifiers, thereby maintaining security while enabling message forwarding through intermediate proxies.
Solution Approach 2:
The roaming hub performs preliminary security verification by validating PLMN identifiers and adding integrity-protected custom headers to messages before forwarding them. This preliminary action ensures that security verification is completed upfront, preventing security deterioration while enabling subsequent message forwarding.
2Reliability
If custom HTTP headers are added to messages for PLMN validation, then security and tracking are improved, but message processing complexity increases
Solution Approach 1:
The patent applies local quality by adding specific custom HTTP headers only where needed in the message structure, rather than fundamentally changing the entire message format. This allows PLMN validation and tracking functionality to be added with minimal impact on overall message processing complexity.
Solution Approach 2:
The roaming hub modifies message parameters by adding custom HTTP headers with specific PLMN identifier information. This parameter change approach enables enhanced security and tracking capabilities while maintaining compatibility with existing message processing systems that can handle additional header parameters.
3Reliability
If integrity protection is applied to custom headers, then message authenticity is improved, but processing overhead increases
Solution Approach 1:
The roaming hub applies integrity protection to custom headers in advance before message forwarding. This preliminary action ensures that authenticity verification is completed upfront, reducing the need for repeated verification processing and thereby minimizing overall processing overhead despite the initial integrity protection step.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Systems, methods, and software for inter-PLMN communications. In one embodiment, a roaming hub receives a message from a sending entity across an N32 interface, and determines whether the message includes an HTTP custom header that indicates a PLMN that is validated. When the message as received does not include the HTTP custom header, the roaming hub adds the HTTP custom header to the message that indicates the PLMN of the sending entity, integrity protects the HTTP custom header, and forwards the message toward a receiving entity.