Security Edge Node Callback URI Modification for TLS Handshake

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In inter-mobile network communications, existing technologies face challenges in ensuring secure routing of messages between Public Land Mobile Networks (PLMNs) due to issues with TLS handshakes failing when the domain name in the Request URI does not match the Subject field or Subject Alternative Name in X.509 certificates, particularly in scenarios involving service-producing and service-consuming network entities across different PLMNs.

Innovation Solution

The method involves generating a second callback resource identifier that includes the domain name of a security edge node, allowing for secure communication by modifying the callback URI to include the security edge node's domain name, thereby enabling successful TLS handshakes and secure message routing between PLMNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TLS handshake is performed using original callback URI, then security is maintained, but TLS handshake fails when domain name does not match certificate

Engineering Contradiction:
ImproveTLS handshake success rateVSAvoidcallback URI structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a callback URI modification mechanism that acts as an intermediary between the original callback URI and the TLS handshake process. The modified callback URI includes the security edge node's domain name, which serves as a mediator to enable certificate matching and successful TLS handshake while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent modifies the callback URI parameter by incorporating the security edge node's domain name into the URI structure. This parameter change enables the domain name in the Request URI to match the Subject field or Subject Alternative Name in the X.509 certificate, thereby resolving the TLS handshake failure issue.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If message routing is performed directly between network entities, then routing simplicity is maintained, but security protection is insufficient

Engineering Contradiction:
Improvemessage routing securityVSAvoidrouting structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces security edge nodes as intermediary entities in the message routing path between different PLMNs. These security edge nodes terminate TLS connections and perform security functions, providing enhanced security protection while maintaining a relatively simple overall routing structure through standardized interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the direct communication path between network entities by introducing security edge nodes at the network perimeter. This segmentation separates security functions from application functions, allowing security protection to be enhanced without significantly complicating the overall routing structure through modular architecture.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If domain name in Request URI matches certificate, then TLS handshake succeeds, but routing flexibility is reduced

Engineering Contradiction:
Improverouting adaptabilityVSAvoidcallback URI structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent changes the domain name parameter in the Request URI to match the security edge node's certificate domain name. This parameter change enables TLS handshake success while maintaining routing flexibility through the use of standardized domain name structures that can adapt to different PLMN configurations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12170899B2Secure inter-mobile network communication
Publication Date: 2024.12.17 NOKIA TECHNOLOGIES OY
  • US12170899B2 patent drawing
  • US12170899B2 patent drawing
  • US12170899B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided a method, comprising: receiving a first message from a service-consuming second network entity in a second mobile network for a service-providing first network entity in a first mobile network, the first message comprising a first callback resource identifier, generating a second callback resource identifier on the basis of the first callback resource identifier, wherein the second callback resource identifier comprises a domain name of a security edge node in the first network, and transferring a callback message from the first network entity to the security edge node, the callback message comprising the second callback resource identifier.