Security Edge Protection Proxy for 5G Inter-Network Access Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of 5G network communication, when a network function consumer (NFc) in one network attempts to access a service from a network function producer (NFp) in a different network, the Network Repository Function (NRF) in the producer's network cannot validate the requester side parameters, leading to a lack of trust and potential unauthorized access.
Innovation Solution
The solution involves the Network Function consumer's (NFc) request being forwarded to a Security Edge Protection Proxy (SEPP) in its own network, which verifies the information and adds it to the access token request. This verified information is then transmitted to the SEPP in the producer's network, where it is further validated, and if authorized, an access token is generated and provided to the NFc, allowing trusted access without needing the NFc's profile.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NFc requests service from NFp in a different network without profile validation, then inter-network service access is enabled, but security and trust are compromised leading to potential unauthorized access
Solution Approach 1:
The SEPP acts as an intermediary component between NFc and NFp in different networks. It validates the access token request by verifying the requester side parameters (NF type, PLMN ID, SNPN ID, NF set ID, service set ID, vendor ID, domain ID) against configured allowed values, and only forwards authorized requests to the target network, thus maintaining security while enabling inter-network access
Solution Approach 2:
The system performs preliminary validation of the access token request at the source network's SEPP before the request reaches the target network. By verifying the requester side parameters in advance and configuring allowed values beforehand, the system prevents unauthorized access attempts from reaching NFp, ensuring security is established before the service interaction occurs
2Reliability
If NFc's profile is required for validation, then security is enhanced, but the complexity of inter-network access increases and profile management becomes difficult
Solution Approach 1:
The invention extracts the essential validation requirements from the complete NF profile, retaining only the critical requester side parameters (NF type, PLMN ID, SNPN ID, NF set ID, service set ID, vendor ID, domain ID) that are necessary for security validation. This selective extraction maintains security while eliminating the need to manage and transmit complete NF profiles across networks, reducing complexity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present disclosure relate to methods, apparatuses and computer readable storage media for inter-network communication. A first edge protection proxy in a first network receives a request for an access token from a network repository function in the first network. The access token is to be used by a first network function in the first network to request a service from a second network function in a second network. The first edge protection proxy validates the request based on configurations allowed to access services provided by networks different from the first network. If the validation of the request is successful, the first edge protection proxy transmits the request to a second edge protection proxy in the second network. The transmitted request comprises verified information concerning the first network function.