Topology Hiding Node for Visited Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions fail to effectively hide the internal topology of networks for user equipment consuming visited network services, particularly when location changes or unsolicited notifications occur, compromising network security.

Innovation Solution

A system with a Topology Hiding Node (THN) coordinates communication between Home Public Land Mobile (HPLM) and Visited Public Land Mobile (VPLM) networks, using long term and short term storage with a change list to represent real identities with virtual identities, hiding network topology and managing mobility updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user equipment consumes visited network services and performs location updates, then mobility management is enabled, but the internal topology of the visited network is exposed and compromised

Engineering Contradiction:
Improvemobility management capabilityVSAvoidnetwork topology exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Topology Hiding Node (THN) as an intermediary entity between the visited network and the home network. The THN acts as a mediator that receives location update requests from the visited network, processes them, and forwards appropriate requests to the home network. This intermediary layer prevents the home network from directly accessing the internal topology and structure of the visited network, thereby hiding the topology while still enabling mobility management functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real identities of system entities are used in communication, then communication accuracy is maintained, but network security is compromised due to topology exposure

Engineering Contradiction:
Improvecommunication accuracyVSAvoidnetwork security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements a virtual identity mechanism where the THN creates and manages virtual identities that represent real system entities. Instead of using real identities (such as actual MME identifiers) in communications between the visited and home networks, the THN uses virtual identity placeholders. These virtual identities are copies or representations that maintain the functional accuracy of communication while preventing exposure of the real network topology and entity identities.

Inventive Principle:
Principle #26Copying

3Reliability

If existing topology hiding solutions are applied, then some network topology is protected, but visited network services for user equipment remain vulnerable

Engineering Contradiction:
Improvenetwork topology protectionVSAvoidvisited network service support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network communication into distinct functional layers: the visited network layer, the topology hiding layer (THN), and the home network layer. Each layer operates independently with specific responsibilities. The THN layer is specifically designed to handle the topology hiding function while allowing the visited network layer to continue providing services to user equipment without modification. This segmentation enables topology protection to be applied selectively without impacting the versatility of visited network services.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9554418B1Device for topology hiding of a visited network
Publication Date: 2017.01.24 F5 NETWORKS INC
  • US9554418B1 patent drawing
  • US9554418B1 patent drawing
  • US9554418B1 patent drawing

AI summary

A system for hiding an internal topology of a network having plurality of client and server entities is provided herein. The system comprises a topology hiding node that coordinates communication between systems in two distinct networks: Home Public Land Mobile and Visited Public Land Mobile. The topology hiding node includes long term storage and a short term storage which includes a change list.A real identity of one system entity is represented by at least one virtual identity allocated from a group of at least two virtual identities, when communicating with the other system entities, and the relation between the virtual identities and the real identities of a current communication session is recorded in the change list and stored in short term storage and the relation between the virtual identities and the real identities of a previous communication sessions is stored in the long term storage.