SEPP NF Request Filtering for 5G Signaling Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communications networks, the current management of network function (NF) request messages at a security edge protection proxy (SEPP) leads to unnecessary signaling due to delayed decision-making during NF discovery requests, resulting in inefficient cross-network communication.
Innovation Solution
Implementing a method at the SEPP to receive and analyze NF request messages, obtaining target NF type identifiers, requestor NF type identifiers, and network identifiers, and using these to determine whether the message should be blocked or allowed based on an interface configuration database, thereby discarding or forwarding the message accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the SEPP waits for NF discovery response messages to make blocking decisions, then security verification can be performed, but unnecessary signaling and network traffic are generated
Solution Approach 1:
The SEPP performs preliminary blocking decisions based on NF type identifiers and network identifiers extracted from incoming NF request messages before forwarding them to the NRF. This preliminary action prevents unnecessary signaling by blocking disallowed messages at the edge, while still maintaining security verification capabilities
Solution Approach 2:
The patent introduces an intermediary filtering mechanism at the SEPP that examines NF request messages and determines whether to block them based on configured rules. This intermediary layer prevents disallowed messages from traversing the entire network to the NRF, reducing unnecessary signaling while maintaining security
2Loss of energy
If the SEPP blocks NF discovery requests early, then signaling is reduced, but security verification may be insufficient
Solution Approach 1:
The SEPP performs preliminary blocking decisions based on NF type identifiers and network identifiers extracted from incoming NF request messages before forwarding them to the NRF. This preliminary action reduces signaling while maintaining security through pre-configured blocking rules
Solution Approach 2:
The patent changes the decision-making parameters from requiring full NF discovery response verification to using NF type identifiers and network identifiers for preliminary blocking decisions. This parameter change enables early blocking while maintaining adequate security verification
3Reliability
If the SEPP forwards all NF request messages to the NRF, then security verification is maintained, but network efficiency decreases
Solution Approach 1:
The SEPP performs preliminary filtering of NF request messages based on NF type identifiers and network identifiers before forwarding to the NRF. This preliminary action improves network efficiency by blocking disallowed messages at the edge while maintaining security verification for allowed messages
Solution Approach 2:
The patent extracts and uses specific identifiers (NF type identifier, network identifier) from incoming messages to make blocking decisions. This extraction enables efficient filtering without requiring full message processing, improving network efficiency while maintaining security
4Productivity
If the SEPP implements immediate blocking decisions, then network efficiency improves, but decision accuracy may be compromised
Solution Approach 1:
The patent changes the decision parameters from requiring complete message analysis to using specific identifiers (NF type identifier, network identifier) for immediate blocking decisions. This parameter change enables fast decisions with sufficient accuracy based on the extracted identifier information
Data Source
AI summary
Methods, systems, and computer readable media for managing network function (NF) request messages at a security edge protection proxy (SEPP) are disclosed. One method comprises receiving, by a SEPP and from an NF service consumer, an initial NF request message and obtaining a target NF type identifier, a requestor NF type identifier, and a network identifier from the initial NF request message. The method further includes utilizing the target NF type identifier, the requestor NF type identifier, and the network identifier to determine whether the initial NF request message is to be blocked by an associated service based interface at the SEPP and discarding, by the SEPP, the initial NF request message if the initial NF request message is determined to be blocked by the associated service based interface.


