SEPP Secure Communication Through IPX Policy Intermediaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SEPP devices in local networks face resource consumption and cost increases due to the need to maintain numerous message modification policies when interconnected with a large number of roaming partner networks through various IPX devices, leading to inefficient resource usage.

Innovation Solution

The SEPP device at the transmitting end obtains a message modification policy from the interconnected IPX device and includes it in an N32 message, allowing the receiving SEPP device to check the message without needing local configuration, thereby reducing the number of policies maintained and conserving resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SEPP devices negotiate message modification policies with SEPP devices in roaming partner networks, then message transmission security is ensured, but the quantity of message modification policies maintained increases significantly, consuming more resources and increasing costs

Engineering Contradiction:
Improvemessage transmission securityVSAvoidquantity of message modification policies maintained
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces IPX devices as intermediaries between SEPP devices. Instead of SEPP devices directly negotiating policies with each other, they negotiate with IPX devices which then enforce the policies. This mediator approach reduces the policy maintenance burden on SEPP devices while ensuring security through the IPX device's policy enforcement capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the message modification policy management function from SEPP devices and relocates it to IPX devices. SEPP devices only need to negotiate policies with their directly connected IPX devices, while the IPX devices handle policy enforcement and modifications. This extraction significantly reduces the quantity of policies that SEPP devices must maintain.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If SEPP devices maintain a large quantity of message modification policies for multiple roaming partner networks, then comprehensive message security coverage is achieved, but resource consumption and device costs increase

Engineering Contradiction:
Improvemessage security coverageVSAvoidresource consumption of SEPP device
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

IPX devices serve as intermediaries that handle policy enforcement and modifications. SEPP devices only maintain policies for their directly connected IPX devices, while IPX devices enforce policies for messages passing through them. This intermediary architecture reduces resource consumption by distributing policy management responsibilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the policy management function into two parts: SEPP devices negotiate policies with their connected IPX devices, and IPX devices enforce policies independently. This segmentation allows each device to maintain only the policies necessary for its direct connections, reducing overall resource consumption while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If SEPP devices negotiate policies with multiple roaming partner SEPP devices through different IPX devices, then network interconnection flexibility is improved, but the quantity of policies to maintain increases

Engineering Contradiction:
Improvenetwork interconnection flexibilityVSAvoidquantity of message modification policies
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

IPX devices act as intermediaries that abstract the complexity of multiple network paths. SEPP devices only need to negotiate policies with their directly connected IPX devices, regardless of how many roaming partner networks or alternative paths exist. The IPX devices handle policy enforcement for all paths, maintaining flexibility without increasing policy complexity for SEPP devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12388792B2Secure communication method, related apparatus, and system
Publication Date: 2025.08.12 HUAWEI TECH CO LTD
  • US12388792B2 patent drawing
  • US12388792B2 patent drawing
  • US12388792B2 patent drawing

AI summary

A secure communication method includes a security edge protection proxy (SEPP) device at a transmitting end that obtains a message modification policy of an Internet Protocol (IP) exchange service (IPX) device interconnected with the SEPP device, and then sends a first N32 message to the IPX device, where the first N32 message carries a first signaling message and the message modification policy. The IPX device sends the received first N32 message to a SEPP device at a receiving end, and the SEPP device at the receiving end checks the first N32 message according to the message modification policy carried in the first N32 message.