SEPP Authentication for Cross-Network UE Subscription Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In conventional telecommunications networks, implementing secure edge protection proxy entities and subscription concealed identifiers makes it difficult for user equipment to connect to a core network using a network identity associated with another network, especially in roaming situations, due to security and authentication challenges.
Innovation Solution
A method involving a user equipment subscription with subscriber permanent identifier information related to a first network and subscription identifier information comprising a second network, using secure edge protection proxy entities to forward messages via a bidirectional channel for authentication and deconcealment, allowing communication services despite using 'wrong' network identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure edge protection proxy entities and subscription concealed identifiers are implemented, then security and authentication are improved, but the ability of user equipment to connect to a core network using a network identity associated with another network deteriorates
Solution Approach 1:
The patent introduces a bidirectional channel between secure edge protection proxy entities that acts as an intermediary to forward messages. This channel enables the visited network to communicate with the home network's secure edge protection proxy entity, allowing authentication and message forwarding while maintaining security. The intermediary resolves the contradiction by enabling cross-network communication without compromising security mechanisms.
Solution Approach 2:
The patent segments the authentication and communication process into distinct components: the user equipment uses subscription concealed identifiers for initial access, while the bidirectional channel between secure edge protection proxy entities handles the actual authentication and message forwarding. This segmentation allows different parts of the system to use different identification mechanisms, resolving the conflict between security requirements and network adaptability.
2Reliability
If subscription concealed identifiers are used, then security is improved, but message routing and network identification become more difficult
Solution Approach 1:
The bidirectional channel between secure edge protection proxy entities serves as an intermediary that handles the complexity of routing messages with concealed identifiers. The visited network's secure edge protection proxy entity forwards messages through this channel to the home network's proxy entity, which then deconceals the identifier and routes the message appropriately. This intermediary approach maintains security while simplifying the routing process.
Solution Approach 2:
The patent establishes bidirectional channels between secure edge protection proxy entities in advance, before actual message routing is needed. This preliminary setup includes pre-configured routing information and authentication credentials, allowing the system to handle subscription concealed identifiers efficiently without real-time complexity. The preliminary action resolves the routing difficulty by preparing the infrastructure beforehand.
Data Source
AI summary
In order to provide the communication services to a user equipment comprising or applying secure edge protection proxy authentication: in a first step, a network function of a visited telecommunications network receives a request related to the user equipment, triggering a message towards a third secure edge protection proxy entity or functionality; and in a second step, the third secure edge protection proxy entity or functionality accesses a first secure edge protection proxy entity or functionality in an authenticated manner such that a message related to a second network identifier information is able to be sent, by the visited telecommunications network, to a network function in a first telecommunications network and accepted by the first telecommunications network.


