Split SEPP Architecture for 5G PLMN Interconnection Resilience
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication networks face challenges in secure interconnection between Public Land Mobile Networks (PLMNs), particularly in scaling and localizing security edge protection proxies (SEPPs) for control plane and user plane traffic, which affects resiliency and efficiency in 5G core networks.
Innovation Solution
The solution involves splitting the functionalities of SEPPs into control plane SEPPs (SEPP-cp) and user plane SEPPs (SEPP-up), allowing independent scaling and localization, with SEPP-cp handling security negotiations over a control plane interface and SEPP-up handling message forwarding over a forwarding interface, enabling separate traffic management and redundancy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SEPP functionalities are combined for both control plane and user plane traffic, then security policy negotiation is simplified, but resiliency and scalability are reduced due to coupled failure modes
Solution Approach 1:
The SEPP functionality is segmented into separate control plane SEPP (SEPP-cp) and user plane SEPP (SEPP-up) components. SEPP-cp handles security policy negotiation and control plane traffic, while SEPP-up handles user plane traffic forwarding. This segmentation allows independent failure modes, so a loss or overload of one SEPP type does not affect the other, thereby improving interconnection resiliency while maintaining manageable architectural complexity through clear functional separation.
2Adaptability or versatility
If SEPP instances are deployed centrally, then security management is simplified, but localization and load distribution capabilities are reduced
Solution Approach 1:
By separating control plane and user plane SEPP functionalities, the system enables flexible deployment strategies. Control plane SEPPs can be deployed centrally for simplified security management, while user plane SEPPs can be distributed locally to enhance localization capabilities and load distribution. This segmentation allows each component to be optimized for its specific deployment scenario without increasing overall system complexity.
3Reliability
If a single SEPP handles both control plane and user plane traffic, then resource utilization is maximized, but failure impact is amplified across both traffic types
Solution Approach 1:
The patent segments SEPP functionalities into distinct control plane and user plane instances, enabling failure isolation. When a SEPP instance experiences loss or overload, the segmentation ensures that only the corresponding traffic type (control plane or user plane) is affected, while the other continues to operate normally. This approach improves reliability through failure isolation while minimizing the quantity of SEPP instances needed, as each instance is specialized for a specific function.
4Productivity
If security policies are renegotiated during dynamic instantiation, then security assurance is maintained, but signaling overhead and delay increase
Solution Approach 1:
Security policies are negotiated and established in advance during the initial SEPP-cp setup phase. When SEPP instances are dynamically instantiated or scaled, the pre-negotiated security policies can be reused, eliminating the need for repeated security negotiations. This preliminary action approach maintains security assurance while significantly improving dynamic instantiation efficiency by reducing signaling overhead and delay.
Data Source
AI summary
According to an example aspect of the present disclosure, there is provided an apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus to perform at least one of: transmit to a second security edge protection proxy (SEPP) of a second public land mobile network (PLMN), in a control plane signaling procedure, addressing information of a first SEPP of a first PLMN, to be used by the second SEPP for forwarding messages from the second PLMN to the first PLMN and receive from the second SEPP of the second PLMN, in the control plane signaling procedure, addressing information of the second SEPP of the second PLMN, to be used by the first SEPP for forwarding messages from the first PLMN to the second PLMN.


