Shared SEPP for MVNO Roaming Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G networks require separate Security Edge Protection Proxies (SEPPs) for routing messages between trusted networks and between trusted and untrusted networks, leading to increased operational costs. There is a need for a mechanism to eliminate the need for multiple SEPPs, especially in networks with Mobile Virtual Network Operators (MVNOs).

Innovation Solution

A shared SEPP is introduced that functions as a single point of ingress and egress between a mobile virtual network operator (MVNO) public land mobile network (PLMN) and a mobile network operator (MNO) PLMN, as well as between the MVNO PLMN and MNO PLMNs and external networks. This shared SEPP maintains a trusted PLMN ID list and applies security measures such as network topology hiding and firewall filtering to route messages appropriately.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate SEPPs are used for routing between trusted networks and between trusted and untrusted networks, then network security is maintained, but operational costs and device complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidSEPP quantity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate SEPP functions into a single shared SEPP that handles both trusted network routing and untrusted network routing. The shared SEPP maintains separate trusted PLMN lists and applies different security policies based on the destination network type, eliminating the need for separate SEPP instances while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared SEPP is designed to perform multiple functions: it routes messages to both trusted PLMNs (using trusted PLMN lists) and untrusted PLMNs (using untrusted PLMN lists), applies topology hiding, and enforces different security policies based on the destination. This multi-functional design allows one SEPP to replace what previously required multiple separate SEPPs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate SEPPs are deployed for different network types, then security policies can be independently enforced, but resource duplication and operational expenses increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidnetwork resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The shared SEPP internally segments security policies by maintaining separate trusted PLMN lists and untrusted PLMN lists. When routing a message, the SEPP determines which list to consult based on the destination PLMN ID, thereby enforcing appropriate security policies without requiring separate physical SEPP instances. This segmentation is achieved through data structure separation rather than physical separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges the resource requirements of multiple SEPPs into a single shared infrastructure. The shared SEPP uses a single message routing engine, single IP address, and shared processing resources while maintaining separate security policy data structures for trusted and untrusted networks, thereby eliminating resource duplication.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If multiple SEPPs are used to handle different routing scenarios, then message routing accuracy is improved, but system complexity and maintenance difficulty increase

Engineering Contradiction:
Improvemessage routing accuracyVSAvoidrouting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The shared SEPP dynamically determines routing behavior based on the destination PLMN ID. It checks whether the destination PLMN is in the trusted PLMN list or untrusted PLMN list and adjusts its routing behavior accordingly - applying topology hiding for untrusted networks while using direct routing for trusted networks. This dynamic adaptation eliminates the need for static, separate SEPP configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The shared SEPP acts as an intermediary that mediates between the message source and different destination network types. It maintains separate trusted and untrusted PLMN lists as reference data structures, and uses these lists to determine the appropriate routing action, thereby achieving accurate routing without requiring separate SEPPs for each network type.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12342159B2Methods, systems, and computer readable media for providing shared security edge protection proxy (SEPP) for roaming aggregators
Publication Date: 2025.06.24 ORACLE INT CORP
  • US12342159B2 patent drawing
  • US12342159B2 patent drawing
  • US12342159B2 patent drawing

AI summary

A method for providing a shared SEPP for roaming aggregators includes, at a shared SEPP that functions as a single point of ingress and egress between an MVNO PLMN and an MNO PLMN and between the MVNO PLMN and MNO PLMNs and external networks, receiving a first service-based interface (SBI) request message from the MVNO PLMN. The method further includes determining, by the shared SEPP, that the first SBI request message is destined for the MNO PLMN, and, in response, routing the first SBI request message to the MNO PLMN. The method further includes receiving a second SBI request message from the MVNO PLMN and determining that the second SBI request message is destined for one of the external networks, and, in response, routing the second SBI request message to the one external network. The shared SEPP may apply security measures for messages transmitted to and from the MNO PLMN and the MVNO PLMN.