SEPP Registration and Discovery via NRF Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile core infrastructure networks, Security Edge Protection Proxies (SEPP) face challenges in registration and discovery, particularly in roaming scenarios where consumer Network Functions in the visited PLMN cannot discover the SEPP, and route selection policies for connecting to the Home SEPP are lacking, affecting message integrity and encryption processes.

Innovation Solution

Deploying and registering SEPPs on both visited and home networks, enabling them to register with respective repository functions and perform discovery services to select appropriate network function producers based on type, and applying security policies for message integrity and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SEPP is deployed as a non-transparent proxy at network border, then message integrity and encryption are improved, but discoverability by consumer NFs deteriorates

Engineering Contradiction:
Improvemessage integrityVSAvoiddiscoverability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The NRF acts as an intermediary between consumer NFs and SEPP. Consumer NFs query the NRF to obtain SEPP contact information, and the NRF returns the appropriate SEPP details based on the consumer NF's home PLMN. This mediator approach allows SEPP to remain a non-transparent proxy while still being discoverable through the NRF infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SEPP registration is implemented in visited network, then connectivity to home network is improved, but route selection complexity increases

Engineering Contradiction:
ImproveconnectivityVSAvoidroute selection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SEPP in the visited network automatically registers itself with the NRF, providing its own contact information and capabilities. When consumers need to reach the home network, the NRF uses this pre-registered information to automatically select the appropriate route and SEPP instance, eliminating the need for complex manual route selection logic.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If inter-PLMN discovery service is implemented, then network function interoperability is improved, but information exchange complexity increases

Engineering Contradiction:
ImproveinteroperabilityVSAvoidinformation exchange
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The NRF provides a universal discovery service that handles multiple PLMNs and multiple types of network functions through a single interface and standardized data model. Instead of implementing separate discovery mechanisms for each PLMN pair, the NRF universally manages all inter-PLMN discovery requests using the same Nnrf_NFDiscovery service and information structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11050788B2SEPP registration, discovery and inter-PLMN connectivity policies
Publication Date: 2021.06.29 CISCO TECHNOLOGY INC
  • US11050788B2 patent drawing
  • US11050788B2 patent drawing
  • US11050788B2 patent drawing

AI summary

Presented herein is a Security Edge Protection Proxy (SEPP) fully defined as a 5G network function (NF) that registers and is discoverable by consumer NFs. Inter-Public Land Mobile Network (PLMN) roaming connectivity polices enable the SEPP in the visiting PLMN to select the SEPP per producer NF-Type in the home PLMN, and to select a direct route between PLMNs or an indirect route via one or more an Internetwork Packet Exchange (IPX) providers.