Selective Inter-PLMN Security Handshake Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G telecommunications networks, the lack of inter-PLMN security handshake validation mechanisms exposes networks to security risks, such as hackers registering fake PLMN data, which can lead to eavesdropping on communications intended for other PLMNs.

Innovation Solution

A method for selective inter-PLMN security handshake validation, where a Security Edge Protection Proxy (SEPP) performs a lookup in its trust relationship database to determine if an incoming security handshake request originates from a trusted SEPP. If not, the SEPP conducts a security handshake validation procedure and, if the request fails, performs a network protective operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If inter-PLMN security handshake validation is performed for all handshake requests, then security against fake PLMN registration is improved, but operational burden on network operators increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating the validation approach based on the trust relationship status of the requesting SEPP. Trusted SEPPs receive expedited processing with validation performed only on PLMN ID format, while untrusted SEPPs undergo comprehensive validation including PLMN ID format, existence in validation database, and authorization verification. This localized quality adjustment resolves the contradiction by applying rigorous validation only where security risks exist, rather than uniformly to all requests.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by pre-configuring the SEPP with an inter-PLMN security handshake validation database containing authorized PLMN IDs and corresponding SEPP identifiers before operation. This preliminary setup enables the SEPP to quickly determine whether incoming handshake requests are from trusted or untrusted sources, allowing it to apply appropriate validation levels without increasing operational burden during actual handshake operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security handshake validation is performed, then security against eavesdropping is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the security validation process into distinct stages: initial trust relationship verification using the pre-configured database, followed by conditional PLMN ID validation. This segmentation allows the system to quickly filter out untrusted SEPPs through database lookup, and only perform time-consuming comprehensive validation on requests from untrusted sources, thereby reducing overall processing time while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by adjusting the depth of validation based on the trust relationship status. Trusted SEPPs undergo minimal validation (PLMN ID format checking only), while untrusted SEPPs undergo comprehensive validation including database verification and authorization checks. This localized approach resolves the contradiction by applying rigorous validation only where necessary, minimizing processing time for the majority of trusted connections.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If no security handshake validation is performed, then operational burden is reduced, but network security is compromised

Engineering Contradiction:
Improveoperational burdenVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring the SEPP with an inter-PLMN security handshake validation database containing authorized PLMN IDs and corresponding SEPP identifiers before operation. This preliminary setup enables the SEPP to quickly determine whether incoming handshake requests are from trusted or untrusted sources, allowing it to apply appropriate validation levels without increasing operational burden during actual handshake operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies self-service by implementing automated validation logic within the SEPP that performs trust relationship verification, PLMN ID validation, and authorization checks without requiring manual intervention from network operators. The system automatically queries the pre-configured validation database and applies appropriate validation levels, reducing operational burden while maintaining security through automated enforcement of validation policies.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12206649B2Methods, systems, and computer readable media for selective inter-public land mobile network (PLMN) security handshake validation
Publication Date: 2025.01.21 ORACLE INT CORP
  • US12206649B2 patent drawing
  • US12206649B2 patent drawing
  • US12206649B2 patent drawing

AI summary

A method for selective inter-PLMN security handshake validation includes receiving, at a SEPP, a first inter-PLMN security handshake request message. The method further includes performing, by the SEPP and in an SEPP trust relationship database, a lookup to determine whether the first inter-PLMN security handshake request message originates from a trusted SEPP. The method further includes determining that the first inter-PLMN security handshake request message does not originate from a trusted SEPP, and, in response, performing, by the SEPP, an inter-PLMN security handshake validation procedure on the first inter-PLMN security handshake request message. The method further includes determining that the first inter-PLMN security handshake request message fails the inter-PLMN security handshake validation procedure, and, in response, performing a network protective operation.