Security Edge Protection Proxies for Automated 5G Roaming SLAs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual setup of roaming service level agreements (SLAs) between network operators is cumbersome and inefficient, lacking automation and dynamic enforcement, especially in 5G networks, leading to challenges in resource management and cost inefficiencies.

Innovation Solution

The implementation of Security Edge Protection Proxies (SEPPs) in 5G networks facilitates automated negotiation and enforcement of roaming SLAs using service-based application programming interfaces, enabling dynamic and secure management of SLAs between home and visited networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual setup of roaming service level agreements is used, then network operators can establish SLAs between home and visited networks, but the process is cumbersome and inefficient without automation

Engineering Contradiction:
Improveautomation of SLA negotiationVSAvoidtime for SLA setup
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system enables automated SLA negotiation where the SEPP entities autonomously exchange service level agreement information and parameters without requiring manual intervention. The automation negotiates SLA terms, validates compliance, and enforces agreements between network operators, allowing the system to serve itself in establishing roaming arrangements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The Security Edge Protection Proxy (SEPP) acts as an intermediary entity between home and visited networks, facilitating automated SLA negotiation. The SEPP receives service level agreement information from the home network, validates it against local policies, and enforces the agreed terms, serving as a mediating component that streamlines the interaction between network operators.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual SLA management is used, then network operators can coordinate home and visited networks, but resource management becomes inefficient and costs increase due to over-provisioning

Engineering Contradiction:
Improveresource management efficiencyVSAvoidcost inefficiency
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system implements automated feedback mechanisms where the SEPP continuously monitors service level agreement compliance and resource utilization. The automated enforcement compares actual resource consumption against SLA parameters, providing real-time feedback that enables dynamic resource allocation and prevents over-provisioning, thereby improving resource management efficiency and reducing operational costs.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If automated SLA negotiation is implemented, then the negotiation process is streamlined and secured, but system complexity increases

Engineering Contradiction:
Improvenegotiation process simplicityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The Security Edge Protection Proxy (SEPP) is designed as a multi-functional entity that combines security functions with automated SLA negotiation and enforcement capabilities. By integrating these diverse functions into a single universal component, the system achieves streamlined operation without proportionally increasing complexity, as the SEPP handles multiple tasks including security protection, SLA validation, and automated negotiation within a unified architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3847782B1Automated roaming service level agreements between network operators via security edge protection proxies in a communication system environment
Publication Date: 2025.08.13 NOKIA TECHNOLOGIES OY
  • EP3847782B1 patent drawingFigure 1
  • EP3847782B1 patent drawingFigure 2
  • EP3847782B1 patent drawingFigure 3

AI summary

Techniques for automated management of a service level agreement between a first communication network and a second communication network are provided. For example, one of the communication networks is a visited network while the other is a home network whereby the service level agreement is a roaming agreement. In one example, a message is received at a first communication network from a second communication network, wherein at least a portion of the message relates to the service level agreement between the first communication network and the second communication network. An automated verification of information in the message is performed at the first communication network to determine compliance with the service level agreement. The message receiving step is performed by a security edge protection proxy function of the first communication network and the automated verification performing step is performed by a service level agreement management function of the first communication network.