Security Edge Protection Proxy for 5G Inter-Network Access Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of 5G network communication, when a network function consumer (NFc) in one network attempts to access a service from a network function producer (NFp) in a different network, the Network Repository Function (NRF) in the producer's network cannot validate the requester side parameters, leading to a lack of trust and potential unauthorized access.

Innovation Solution

The solution involves the Network Function consumer's (NFc) request being forwarded to a Security Edge Protection Proxy (SEPP) in its own network, which verifies the information and adds it to the access token request. This verified information is then transmitted to the SEPP in the producer's network, where it is further validated, and if authorized, an access token is generated and provided to the NFc, allowing trusted access without needing the NFc's profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NFc requests service from NFp in a different network without profile validation, then inter-network service access is enabled, but security and trust are compromised leading to potential unauthorized access

Engineering Contradiction:
Improveinter-network service accessVSAvoidsecurity and trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The SEPP acts as an intermediary component between NFc and NFp in different networks. It validates the access token request by verifying the requester side parameters (NF type, PLMN ID, SNPN ID, NF set ID, service set ID, vendor ID, domain ID) against configured allowed values, and only forwards authorized requests to the target network, thus maintaining security while enabling inter-network access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of the access token request at the source network's SEPP before the request reaches the target network. By verifying the requester side parameters in advance and configuring allowed values beforehand, the system prevents unauthorized access attempts from reaching NFp, ensuring security is established before the service interaction occurs

Inventive Principle:
Principle #10Preliminary action

2Reliability

If NFc's profile is required for validation, then security is enhanced, but the complexity of inter-network access increases and profile management becomes difficult

Engineering Contradiction:
ImprovesecurityVSAvoidprofile management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the essential validation requirements from the complete NF profile, retaining only the critical requester side parameters (NF type, PLMN ID, SNPN ID, NF set ID, service set ID, vendor ID, domain ID) that are necessary for security validation. This selective extraction maintains security while eliminating the need to manage and transmit complete NF profiles across networks, reducing complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4075722B1Security enhancement on inter-network communication
Publication Date: 2025.03.26 NOKIA TECHNOLOGIES OY
  • EP4075722B1 patent drawingFigure 1
  • EP4075722B1 patent drawingFigure 2
  • EP4075722B1 patent drawingFigure 3

AI summary

Embodiments of the present disclosure relate to methods, apparatuses and computer readable storage media for inter-network communication. A first edge protection proxy in a first network receives a request for an access token from a network repository function in the first network. The access token is to be used by a first network function in the first network to request a service from a second network function in a second network. The first edge protection proxy validates the request based on configurations allowed to access services provided by networks different from the first network. If the validation of the request is successful, the first edge protection proxy transmits the request to a second edge protection proxy in the second network. The transmitted request comprises verified information concerning the first network function.