IP Library Granted Patent US 12,470,915
Granted Patent B2
US 12,470,915 · App. 18/579,676 · Granted Nov 11, 2025

Distributed network edge security architecture

Inventors: Ralf Keller (Würselen, DE); George Foti (Dollard des Ormeaux, CA); Bengt Sahlin (Espoo, FI); Mary Amarisa Robison (Aachen, DE)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04W12/037H04W8/005H04W84/042H04W92/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,915
App. No.
18/579,676
Granted
Nov 11, 2025
Kind
B2
Abstract

A method, implemented by a security relay node in a Public Land Mobile Network, PLMN, wherein the method comprising the steps of receiving, from a Network Function, NF, within the PLMN, a control packet to be provided to a further PLMN, relaying said control packet to a remote security node for delivery of the control packet to the further PLMN, wherein the remote security node being outside of both the PLMN and being outside the further PLMN.

Claims (51)

1 . A method, implemented by a security relay node in a Public Land Mobile Network (PLMN), the method comprising:

receiving, from a Network Function (NF) within the PLMN, a control packet to be provided to a further PLMN;

delegating, to a remote security node, a setup of a N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and

relaying the control packet to a remote security node for delivery of the control packet, over an N32-f interface, towards the further PLMN, the remote security node being outside of both the PLMN and the further PLMN.

2 . The method of claim 1 , further comprising establishing the N32-f interface between the security relay node and the remote security node.

3 . The method of claim 2 , wherein the relaying comprises relaying the control packet using Transport Layer Security (TLS).

4 . The method of claim 2 , further comprising exchanging, with the remote security node, control signaling associated with the secure interface.

5 . The method of claim 2 , wherein the secure interface is an N32-f interface.

6 . The method of claim 1 , further comprising encrypting at least an Information Element (IE) in the control packet prior to relaying the control packet.

7 . The method of claim 6 , wherein the encrypting comprises encrypting the IE using an encryption key of a peer security node of the further PLMN obtained via the remote security node.

8 . The method of claim 7 , further comprising obtaining the encryption key of the peer security node from the remote security node.

9 . The method of claim 1 , further comprising enabling discovery of the security relay node by at least one NF of the PLMN by registering with a Network Repository Function (NRF) of the PLMN as a Security Edge Protection Proxy (SEPP).

10 . The method of claim 1 , further comprising hiding a topology of the PLMN from the further PLMN.

11 . The method of claim 1 , further comprising using a telescopic fully qualified domain name of an NF in the PLMN to hide an address of the NF from the further PLMN.

12 . The method of claim 1 , wherein the remote security node is comprised in an Internet Protocol Exchange (IPX) network.

13 . The method of claim 1 , wherein the remote security node is comprised in a roaming hub network.

14 . A security relay node comprising:

processing circuitry and a memory, the memory containing instructions executable by the processing circuitry whereby the security relay node is configured to, from within a Public Land Mobile Network (PLMN):

receive, from a Network Function (NF) within the PLMN, a control packet to be provided to a further PLMN;

delegate, to a remote security node, a setup of an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and

relay the control packet to a remote security node for delivery of the control packet, over an N32-f interface, towards the further PLMN, the remote security node being outside of both the PLMN and the further PLMN.

15 . A non-transitory computer readable medium storing a computer program product for controlling a security relay node, the computer program product comprising software instructions that, when run on processing circuitry of the security relay node, cause the security relay node to:

receive, from a Network Function (NF) within a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;

delegate, to a remote security node, a setup of a N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and

relay the control packet to a remote security node for delivery of the control packet, over an N32-f interface, towards the further PLMN, the remote security node being outside of both the PLMN and the further PLMN.

16 . A method, implemented by a remote security node, the method comprising:

receiving, from a security relay node in a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;

setting up, on behalf of the remote security node, an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and

relaying the control packet, over an N32-f interface, towards the further PLMN;

wherein the remote security node being outside of both the PLMN and the further PLMN.

17 . The method of claim 16 , further comprising establishing the N32-f interface between the security relay node and the remote security node, wherein the receiving comprises receiving the control packet over the established N32-f interface.

18 . The method of claim 17 , wherein the receiving comprises receiving the control packet using Transport Layer Security (TLS).

19 . The method of claim 16 , wherein the receiving comprises receiving the control packet in which at least an Information Element (IE) is encrypted.

20 . The method of claim 19 , wherein at least the IE is encrypted using an encryption key of a peer security node of the further PLMN such that the remote security node is unable to decrypt it.

21 . The method of claim 20 , further comprising:

obtaining the encryption key from the peer security node of the further PLMN; and

providing the obtained encryption key to the remote security node.

22 . The method of claim 16 , further comprising hiding a topology of the PLMN from the further PLMN.

23 . The method of claim 16 , wherein the remote security node is comprised in an Internet Protocol Exchange (IPX) network.

24 . The method of claim 16 , wherein the remote security node is comprised in a roaming hub network.

25 . A remote security node comprising:

processing circuitry and a memory, the memory containing instructions executable by the processing circuitry whereby the remote security node is configured to:

receive, from a security relay node in a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;

set up, on behalf of the remote security node, an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and

relay the control packet, over an N32-f interface, towards the further PLMN;

wherein the remote security node being outside of both the PLMN and the further PLMN.

26 . A non-transitory computer readable medium storing a computer program product for controlling a remote security node, the computer program product comprising software instructions that, when run on processing circuitry of the remote security node, cause the remote security node to:

receive, from a security relay node in a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;

set up, on behalf of the remote security node, an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and

relay the control packet, over an N32-f interface, towards the further PLMN;

wherein the remote security node being outside of both the PLMN and the further PLMN.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: KELLER, RALF; FOTI, GEORGE; ROBISON, MARY AMARISA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 066146/0137 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: SAHLIN, BENGT
To: OY L M ERICSSON AB
Reel/Frame 066146/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 066146/0350 →
Continuity (2)
Provisional Application 63224196 · Jul 21, 2021
Related Publication 20240334184A1 · Oct 3, 2024
References Cited (9)
US 10834571B1 · Yau · 2020 [cited by examiner]
US 20210219137A1 · Bykampadi et al. · 2021 [cited by applicant]
US 20220104020A1 · Rajput · 2022 [cited by examiner]
EP 4050968A1 · 2022 [cited by applicant]
EP 4075721A1 · 2022 [cited by examiner]
WO WO2020053480A1 · 2020 [cited by examiner]
3rd Generation Partnership Project, “Technical Specification Group Core Network and Terminals; 5G System; Public Land Mobile Network (PLMN) Interconnection; Stage 3 (Release 17)”, Technical Specification, 3GGP TS 29.573… [cited by applicant]
Nokia, “N32 interface”, Change Request, TSG-SA3 Meeting #100e, e-meeting, Aug. 17-28, 2020, pp. 1-22, S3-201796, 3GPP. [cited by applicant]
Nokia, “Adding normative text on SEPP to the security architecture section”, TSG SA WG3 (Security) Meeting #90Bis, San Diego, United States, Feb. 26, 2018-Mar. 2, 2018, pp. 1-2, S3-180675, 3GPP. [cited by applicant]