Topology Hiding Node for Visited Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions fail to effectively hide the internal topology of networks for user equipment consuming visited network services, particularly when location changes or unsolicited notifications occur, compromising network security.
Innovation Solution
A system with a Topology Hiding Node (THN) coordinates communication between Home Public Land Mobile (HPLM) and Visited Public Land Mobile (VPLM) networks, using long term and short term storage with a change list to represent real identities with virtual identities, hiding network topology and managing mobility updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user equipment consumes visited network services and performs location updates, then mobility management is enabled, but the internal topology of the visited network is exposed and compromised
Solution Approach 1:
The patent introduces a Topology Hiding Node (THN) as an intermediary entity between the visited network and the home network. The THN acts as a mediator that receives location update requests from the visited network, processes them, and forwards appropriate requests to the home network. This intermediary layer prevents the home network from directly accessing the internal topology and structure of the visited network, thereby hiding the topology while still enabling mobility management functionality.
2Measurement precision
If real identities of system entities are used in communication, then communication accuracy is maintained, but network security is compromised due to topology exposure
Solution Approach 1:
The patent implements a virtual identity mechanism where the THN creates and manages virtual identities that represent real system entities. Instead of using real identities (such as actual MME identifiers) in communications between the visited and home networks, the THN uses virtual identity placeholders. These virtual identities are copies or representations that maintain the functional accuracy of communication while preventing exposure of the real network topology and entity identities.
3Reliability
If existing topology hiding solutions are applied, then some network topology is protected, but visited network services for user equipment remain vulnerable
Solution Approach 1:
The patent segments the network communication into distinct functional layers: the visited network layer, the topology hiding layer (THN), and the home network layer. Each layer operates independently with specific responsibilities. The THN layer is specifically designed to handle the topology hiding function while allowing the visited network layer to continue providing services to user equipment without modification. This segmentation enables topology protection to be applied selectively without impacting the versatility of visited network services.
Data Source
AI summary
A system for hiding an internal topology of a network having plurality of client and server entities is provided herein. The system comprises a topology hiding node that coordinates communication between systems in two distinct networks: Home Public Land Mobile and Visited Public Land Mobile. The topology hiding node includes long term storage and a short term storage which includes a change list.A real identity of one system entity is represented by at least one virtual identity allocated from a group of at least two virtual identities, when communicating with the other system entities, and the relation between the virtual identities and the real identities of a current communication session is recorded in the change list and stored in short term storage and the relation between the virtual identities and the real identities of a previous communication sessions is stored in the long term storage.


