Shared SEPP for MVNO Roaming Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G networks require separate Security Edge Protection Proxies (SEPPs) for routing messages between trusted networks and between trusted and untrusted networks, leading to increased operational costs. There is a need for a mechanism to eliminate the need for multiple SEPPs, especially in networks with Mobile Virtual Network Operators (MVNOs).
Innovation Solution
A shared SEPP is introduced that functions as a single point of ingress and egress between a mobile virtual network operator (MVNO) public land mobile network (PLMN) and a mobile network operator (MNO) PLMN, as well as between the MVNO PLMN and MNO PLMNs and external networks. This shared SEPP maintains a trusted PLMN ID list and applies security measures such as network topology hiding and firewall filtering to route messages appropriately.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate SEPPs are used for routing between trusted networks and between trusted and untrusted networks, then network security is maintained, but operational costs and device complexity increase
Solution Approach 1:
The patent combines multiple separate SEPP functions into a single shared SEPP that handles both trusted network routing and untrusted network routing. The shared SEPP maintains separate trusted PLMN lists and applies different security policies based on the destination network type, eliminating the need for separate SEPP instances while maintaining security requirements.
Solution Approach 2:
The shared SEPP is designed to perform multiple functions: it routes messages to both trusted PLMNs (using trusted PLMN lists) and untrusted PLMNs (using untrusted PLMN lists), applies topology hiding, and enforces different security policies based on the destination. This multi-functional design allows one SEPP to replace what previously required multiple separate SEPPs.
2Reliability
If separate SEPPs are deployed for different network types, then security policies can be independently enforced, but resource duplication and operational expenses increase
Solution Approach 1:
The shared SEPP internally segments security policies by maintaining separate trusted PLMN lists and untrusted PLMN lists. When routing a message, the SEPP determines which list to consult based on the destination PLMN ID, thereby enforcing appropriate security policies without requiring separate physical SEPP instances. This segmentation is achieved through data structure separation rather than physical separation.
Solution Approach 2:
The patent merges the resource requirements of multiple SEPPs into a single shared infrastructure. The shared SEPP uses a single message routing engine, single IP address, and shared processing resources while maintaining separate security policy data structures for trusted and untrusted networks, thereby eliminating resource duplication.
3Measurement precision
If multiple SEPPs are used to handle different routing scenarios, then message routing accuracy is improved, but system complexity and maintenance difficulty increase
Solution Approach 1:
The shared SEPP dynamically determines routing behavior based on the destination PLMN ID. It checks whether the destination PLMN is in the trusted PLMN list or untrusted PLMN list and adjusts its routing behavior accordingly - applying topology hiding for untrusted networks while using direct routing for trusted networks. This dynamic adaptation eliminates the need for static, separate SEPP configurations.
Solution Approach 2:
The shared SEPP acts as an intermediary that mediates between the message source and different destination network types. It maintains separate trusted and untrusted PLMN lists as reference data structures, and uses these lists to determine the appropriate routing action, thereby achieving accurate routing without requiring separate SEPPs for each network type.
Data Source
AI summary
A method for providing a shared SEPP for roaming aggregators includes, at a shared SEPP that functions as a single point of ingress and egress between an MVNO PLMN and an MNO PLMN and between the MVNO PLMN and MNO PLMNs and external networks, receiving a first service-based interface (SBI) request message from the MVNO PLMN. The method further includes determining, by the shared SEPP, that the first SBI request message is destined for the MNO PLMN, and, in response, routing the first SBI request message to the MNO PLMN. The method further includes receiving a second SBI request message from the MVNO PLMN and determining that the second SBI request message is destined for one of the external networks, and, in response, routing the second SBI request message to the one external network. The shared SEPP may apply security measures for messages transmitted to and from the MNO PLMN and the MVNO PLMN.


