IP Library Granted Patent US 12,342,159
Granted Patent B2
US 12,342,159 · App. 17/984,287 · Granted Jun 24, 2025

Methods, systems, and computer readable media for providing shared security edge protection proxy (SEPP) for roaming aggregators

Inventors: John Nirmal Mohan Raj (Bangalore, IN); Nikita Satish Nair (Mumbai, IN); Jay Rajput (Bangalore, IN)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04W12/02H04W8/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,342,159
App. No.
17/984,287
Granted
Jun 24, 2025
Kind
B2
Abstract

A method for providing a shared SEPP for roaming aggregators includes, at a shared SEPP that functions as a single point of ingress and egress between an MVNO PLMN and an MNO PLMN and between the MVNO PLMN and MNO PLMNs and external networks, receiving a first service-based interface (SBI) request message from the MVNO PLMN. The method further includes determining, by the shared SEPP, that the first SBI request message is destined for the MNO PLMN, and, in response, routing the first SBI request message to the MNO PLMN. The method further includes receiving a second SBI request message from the MVNO PLMN and determining that the second SBI request message is destined for one of the external networks, and, in response, routing the second SBI request message to the one external network. The shared SEPP may apply security measures for messages transmitted to and from the MNO PLMN and the MVNO PLMN.

Claims (34)

1. A method for providing a shared security edge protection proxy (SEPP) for roaming aggregators, the method comprising:

at a shared SEPP:

operating as a single point of ingress and egress between a mobile virtual network operator (MVNO) public land mobile network (PLMN) and a mobile network operator (MNO) PLMN and between the MVNO PLMN and MNO PLMNs and external networks, wherein operating as the single point of ingress and egress includes, for egress messages from the MVNO PLMN and the MNO PLMN, providing an exclusive egress interface from the MVNO PLMN and the MNO PLMN to the external networks and, for ingress messages from the external networks, providing an exclusive ingress interface to the MVNO PLMN and the MNO PLMN for messages from the external networks;

receiving a first service-based interface (SBI) request message from the MVNO PLMN;

determining, by the shared SEPP, that the first SBI request message is destined for the MNO PLMN, and, in response, routing the first SBI request message to the MNO PLMN;

receiving a second SBI request message from the MVNO PLMN; and

determining, by the shared SEPP, that the second SBI request message is destined for one of the external networks, and, in response, routing the second SBI request message to the one external network.

2. The method of claim 1 comprising, at the shared SEPP, maintaining a trusted PLMN ID list including PLMN IDs of trusted PLMNs of operators of the MVNO PLMN and the MNO PLMN.

3. The method of claim 2 wherein determining that the first SBI request is intended for the MNO network protected by the shared SEPP includes reading a PLMN ID from the first SBI request, performing a lookup for the PLMN ID in the trusted PLMN ID list and locating the PLMN ID in the trusted PLMN ID list.

4. The method of claim 3 wherein reading the PLMN ID from the first SBI request includes reading the PLMN ID from a 3gpp-Sbi-Target-Apiroot header of the first SBI request.

5. The method of claim 2 wherein determining that the second SBI request is intended for the one of the external networks includes reading a PLMN ID from the second SBI request, performing a lookup for the PLMN ID in the trusted PLMN ID list and failing to locate the PLMN ID in the trusted PLMN ID list.

6. The method of claim 5 wherein reading the PLMN ID from the second SBI request includes reading the PLMN ID from a 3gpp-Sbi-Target-Apiroot header of the second SBI request.

7. The method of claim 1 comprising applying a security measure to the first and second SBI request messages.

8. The method of claim 7 wherein the security measure comprises network topology hiding.

9. The method of claim 1 comprising performing firewall filtering for messages transmitted between the MVNO PLMN and the MNO PLMN and between the MVNO PLMN and the MNO PLMNs and the external networks.

10. The method of claim 9 wherein performing the firewall filtering comprises performing Category 1 and Category 2 message filtering.

11. A system for providing a shared security edge protection proxy (SEPP) for roaming aggregators, the system comprising:

a shared SEPP that operates as a single point of ingress and egress between a mobile virtual network operator (MVNO) public land mobile network (PLMN) and a mobile network operator (MNO) PLMN and between the MVNO PLMN and MNO PLMNs and external networks, the shared SEPP Including at least one processor and a memory, wherein operating as the single point of ingress and egress includes, for egress messages from the MVNO PLMN and the MNO PLMN, providing an exclusive egress interface from the MVNO PLMN and the MNO PLMN to the external networks and, for ingress messages from the external networks, providing an exclusive ingress interface to the MVNO PLMN and the MNO PLMN for messages from the external networks; and

an inter-PLMN routing/security manager implemented by the at least one processor for receiving a first service-based interface (SBI) request message from the MVNO PLMN, determining that the first SBI request message is destined for the MNO PLMN, and, in response, routing the first SBI request message to the MNO PLMN, receiving a second SBI request message from the MVNO PLMN, and determining that the second SBI request message is destined for one of the external networks, and, in response, routing the second SBI request message to the one external network.

12. The system of claim 11 wherein the memory includes a trusted PLMN ID list including PLMN IDs of trusted PLMNs of operators of the MVNO PLMN and the MNO PLMN.

13. The system of claim 12 wherein the inter-PLMN routing/security manager is configured to determine that the first SBI request is intended for the MNO network protected by the shared SEPP by reading a PLMN ID from the first SBI request, performing a lookup for the PLMN ID in the trusted PLMN ID list and locating the PLMN ID in the trusted PLMN ID list.

14. The system of claim 13 wherein the inter-PLMN routing/security manager is configured to read the PLMN ID from a 3gpp-Sbi-Target-Apiroot header of the first SBI request.

15. The system of claim 12 wherein the inter-PLMN routing/security manager is configured to determine that the second SBI request is intended for the one of the external networks by reading a PLMN ID from the second SBI request, performing a lookup for the PLMN ID in the trusted PLMN ID list and failing to locate the PLMN ID in the trusted PLMN ID list.

16. The system of claim 15 the inter-PLMN routing/security manager is configured to read the PLMN ID from a 3gpp-Sbi-Target-Apiroot header of the second SBI request.

17. The system of claim 11 wherein the inter-PLMN routing/security manager is configured to apply network topology hiding to the first and second SBI request messages.

18. The system of claim 11 wherein the inter-PLMN routing/security manager is configured to perform firewall filtering for messages transmitted between the MVNO PLMN and the MNO PLMN and between the MVNO PLMN and the MNO PLMNs and the external networks.

19. The system of claim 18 wherein the inter-PLMN routing/security manager is configured to perform Category 1 and Category 2 message filtering.

20. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

at a shared security edge protection proxy (SEPP):

operating as a single point of ingress and egress between a mobile virtual network operator (MVNO) public land mobile network (PLMN) and a mobile network operator (MNO) PLMN and between the MVNO PLMN and MNO PLMNs and external networks, wherein operating as the single point of ingress and egress includes, for egress messages from the MVNO PLMN and the MNO PLMN, providing an exclusive egress interface from the MVNO PLMN and the MNO PLMN to the external networks and, for ingress messages from the external networks, providing an exclusive ingress interface to the MVNO PLMN and the MNO PLMN for messages from the external networks;

receiving a first service-based interface (SBI) request message from the MVNO PLMN;

determining, by the shared SEPP, that the first SBI request message is destined for the MNO PLMN, and, in response, routing the first SBI request message to the MNO PLMN;

receiving a second SBI request message from the MVNO PLMN; and

determining, by the shared SEPP, that the second SBI request message is destined for one of the external networks, and, in response, routing the second SBI request message to the one external network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2022
From: MOHAN RAJ, JOHN NIRMAL; NAIR, NIKITA SATISH; RAJPUT, JAY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061739/0196 →
Continuity (1)
Related Publication 20240163660A1 · May 16, 2024
References Cited (75)
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10594734B1 · Rappard et al. · 2020 [cited by applicant]
US 10601776B1 · Burakovsky et al. · 2020 [cited by applicant]
US 11792163B2 · Bykampadi · 2023 [cited by examiner]
US 11843580B2 · Rajput et al. · 2023 [cited by applicant]
US 20080235507A1 · Ishikawa et al. · 2008 [cited by applicant]
US 20120204251A1 · Kopti · 2012 [cited by applicant]
US 20140245423A1 · Lee · 2014 [cited by applicant]
US 20190230556A1 · Lee · 2019 [cited by applicant]
US 20200162429A1 · Burakovsky et al. · 2020 [cited by applicant]
US 20200162514A1 · Rappard et al. · 2020 [cited by applicant]
US 20200314672A1 · Farooq · 2020 [cited by applicant]
US 20220015023A1 · De-Gregorio-Rodriguez et al. · 2022 [cited by applicant]
US 20220110177A1 · Choksi · 2022 [cited by examiner]
US 20220124162A1 · Zhang · 2022 [cited by applicant]
US 20220360561A1 · Rajput et al. · 2022 [cited by applicant]
US 20230156549A1 · Tsuda · 2023 [cited by examiner]
US 20230269579A1 · Ma · 2023 [cited by examiner]
US 20230319675A1 · Kaur · 2023 [cited by examiner]
US 20230328620A1 · Pinheiro · 2023 [cited by examiner]
US 20240022910A1 · Li · 2024 [cited by examiner]
US 20240057033A1 · Goel · 2024 [cited by applicant]
US 20240073103A1 · Arends et al. · 2024 [cited by applicant]
US 20240080300A1 · Rajput et al. · 2024 [cited by applicant]
US 20240098490A1 · Wu · 2024 [cited by examiner]
US 20240236677A1 · Rajput · 2024 [cited by examiner]
CN 202280032824X · 2025 [cited by applicant]
EP 3886502A1 · 2021 [cited by applicant]
KR 20190088878A · 2019 [cited by applicant]
WO WO2020030275A1 · 2020 [cited by applicant]
WO WO2021047551A1 · 2021 [cited by applicant]
WO WO2022069089A1 · 2022 [cited by applicant]
WO WO2022235372A1 · 2022 [cited by applicant]
WO WO2024050010A1 · 2024 [cited by applicant]
Alcala-Martin et al., “Global Mobile Network Aggregators: Taxonomy, Roaming Performance and Optimization,” ACM, pp. 1-13 (2022). [cited by applicant]
“OAuth 2.0,” Swagger, https://swagger.io/docs/specification/authentication/oauth2/, pp. 1-6 (2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17),” 3GPP TS 29.510, V17.6.0, pp. 1-306 (Jun. 2022). [cited by applicant]
“5G Interconnect Security,” GSMA, Version 2.0, FS.36, pp. 1-61 (Jun. 3, 2021). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Public Land Mobile Network (PLMN) Interconnection; Stage 3 (Release 17)”, 3GPP TS 29.573, V17.2.0, pp. 1-102 (Sep… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; UE Policy Control Service; Stage 3 (Release 17)”, 3GPP TS 29.525, V17.1.0, pp. 1-59 (Dec. 2020). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Unified Data Management Services; Stage 3 (Release 17)”, 3GPP TS 29.503, V17.1.0, pp. 1-381 (Dec. 2020). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Session Management Services; Stage 3 (Release 17)”, 3GPP TS 29.502, V17.0.0, pp. 1-292 (Mar. 2021). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture and Procedures for 5G System (Release 17)”, 3GPP TS 33.501, V17.0.0, pp. 1-253 (Dec. 2020). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Numbering, Addressing and Identification; (Release 17)”, 3GPP TS 23.003, V17.0.0, pp. 1-142 (Dec. 2020). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17)”, 3GPP TS 29.510, V17.0.0, pp. 1-229 (Dec. 2020). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Principles and Guidelines for Services Definition; Stage 3 (Release 17)”, 3GPP TS 29.501, V17.0.0, pp. 1-78 (Dec.… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 17)”, 3GPP TS 29.500, V17.1.0, pp. 1-90 (De… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17)”, 3GPP TS 23.502, V17.0.0, pp. 1-646 (Mar. 2021). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System (5GS); Stage 2 (Release 17)”, 3GPP TS 23.501, V17.0.0, pp. 1-489 (Mar. 2021). [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/308,018 (Jan. 20, 2023). [cited by applicant]
Commonly-Assigned, Co-pending U.S. Appl. No. 17/902,531 for “Methods, Systems, and Computer Readable Media for Automatic Category 1 Message Filtering Rules Configuration by Learning Topology Information from Network Fun… [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration for International Application No. PCT/US2022/023812 (Jul. 22, 2022). [cited by applicant]
“OAuth 2.0,” Swagger, pp. 1-6 (2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 17),” 3GPP TS 23.501, V17.5.0, pp. 1-568 (Jun. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17),” 3GPP TS 23.502, V17.4.0, pp. 1-738 (Mar. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Public Land Mobile Network (PLMN) Interconnection; Stage 3 (Release 17),” 3GPP TS 29.573, V17.4.0, pp. 1-106 (Mar… [cited by applicant]
“5G Interconnect Security,” GSMA, Version 2.0, pp. 1-61 (Jun. 3, 2021). [cited by applicant]
Commonly-Assigned, Co-pending U.S. Appl. No. 17/308,018 for “Methods, Systems, and Computer Readable Media for Platform Firewall Management by Network Function (NF) Repository Function (NRF) or Service Communications Pr… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17),” 3GPP TS 29.510, V17.1.0, pp. 1-243 (Mar. 2021). [cited by applicant]
“Functionality to be Deployed in Different Locations,” Ericsson, https://www.ericsson.com/en/future-technologies/architecture/network-architecture-domains, pp. 1-20 (2021). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Aspects; Study on security aspects of the 5G Service Based Architecture (SBA) (Release 16),” 3GPP TR 33.855, V16.1… [cited by applicant]
Dredge, “The Service Communication Proxy: 5G Caught Up in a Service Mesh,” Metaswitch, pp. 1-10 (Feb. 14, 2020). [cited by applicant]
Girondi, “Efficient Traffic Monitoring in 5G Core Network,” KTH Royal Institute of Technology, pp. 1-118 (2020). [cited by applicant]
“Ultra Cloud Core 5G Policy Control Function, Release 2020.03—Configuration and Administration Guide,” Cisco, https://www.cisco.com/c/en/us/td/docs/wireless/ucc/pcf/2020-03-0/b_ucc-5g-pcf-config-and-admin-guide_2020-03/… [cited by applicant]
Salva-Garcia et al., “5G Nb-IoT: Efficient Network Traffic Filtering for Multitenant IoT Cellular Network,” Security and Communications Networks, vol. 2018, pp. 1-22 (2018). [cited by applicant]
“Making 5G a Reality,” NEC Corporation, pp. 1-32 (2018). [cited by applicant]
International Search Report and Written Opinion for Appl No. PCT/US2023/031707 dated Dec. 14, 2023. [cited by applicant]
Decision to Grant for European Patent Application Serial No. 22723259.2 (Jan. 7, 2025). [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/902,531 (Dec. 17, 2024). [cited by applicant]
3GPP TSG-SA WG2 Meeting #128 Bis S2-187949 (Aug. 24, 2018). [cited by applicant]
Office Action for Chinese Patent Application Serial No. 202280032824.X (Sep. 1, 2024). [cited by applicant]
Intent to Grant for European Patent Application Serial No. 22723259.2 (Aug. 26, 2024). [cited by applicant]
Notice of Publication for European Patent Application Serial No. 22723259.2 (Feb. 14, 2024). [cited by applicant]
Notice of Allowance and Fee(s) Due for U.S. Appl. No. 17/308,018 (Aug. 2, 2023). [cited by applicant]
Notification to Grant for Chinese Patent Application Serial No. 202280032824.X (Mar. 4, 2025). [cited by applicant]
Cited By (1)
US 12,556,512