TLS Routing Agent for 5G Core Roaming IPX Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G core roaming, the existing TCP protocol degrades in performance over long distances due to its design for local area networks, leading to inefficiencies in routing HTTP/2-based N32 traffic between SEPPs in IPX networks, which affects the security and efficiency of mobile signaling communications.
Innovation Solution
Implementing a TLS Routing Agent in the IPX network that acts as a HTTP/2 forward proxy, supporting the CONNECT method and enabling end-to-end TLS sessions between consumer-SEPP and producer-SEPP, with message firewall capabilities and a policy routing engine to determine optimal routing paths, thereby maintaining end-to-end security and improving TCP performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TCP protocol is used for routing HTTP/2-based N32 traffic between SEPPs in IPX networks, then end-to-end security is maintained, but performance degrades over long distances
Solution Approach 1:
The patent introduces a TLS Routing Agent as an intermediary component deployed in the IPX network. This agent acts as a mediator between SEPPs, establishing intermediate TLS sessions that bridge long-distance TCP connections. The TLS Routing Agent performs TLS handshakes with both the source and destination SEPPs, creating secure tunnels that maintain end-to-end security while improving performance by breaking the long-distance connection into shorter hops through the intermediary agent.
2Reliability
If TLS sessions are established directly between SEPPs, then security is ensured, but routing control and traffic management are limited
Solution Approach 1:
The TLS Routing Agent serves as a controlled intermediary that maintains security while enabling routing control. The agent receives TLS sessions from source SEPPs and forwards them to destination SEPPs, allowing the network operator to control traffic flow, select optimal paths, and manage connections centrally. This intermediary approach preserves security through TLS encryption while providing enhanced routing flexibility and operational control.
Solution Approach 2:
The patent implements dynamic routing capabilities where the TLS Routing Agent can adaptively select different paths and SEPPs based on network conditions, load balancing requirements, and policy configurations. The system dynamically establishes and terminates TLS sessions as needed, providing flexible traffic management while maintaining security. This dynamic approach allows the network to respond to changing conditions while preserving end-to-end security through TLS.
Data Source
AI summary
A system and method for implementing Transport Layer Security (TLS) Routing Agent in an Internet Protocol Exchange (IPX) network for 5G core roaming. Transmission Control Protocol (TCP) connections are established between the TLS Routing Agent and consumer Security Edge Protection Proxy (cSEPP) and producer Security Edge Protection Proxy (pSEPP). TLS Routing Agent receives HTTP/2 CONNECT request from cSEPP. The TLS Routing Agent routes subsequent TLS handshake and HTTP/2 application messages to producer-SEPP transparently, so that the end-to-end TLS security is maintained. The TLS Routing Agent enables message firewall to protect mobile operator's SEPP. The TLS Routing Agent applies policy routing to route HTTP/2 message intelligently across the IPX network and improves TCP performance by dividing the long Round-Trip-Time between TCP end points into shorter segments.


