Distributed network edge security architecture
A method, implemented by a security relay node in a Public Land Mobile Network, PLMN, wherein the method comprising the steps of receiving, from a Network Function, NF, within the PLMN, a control packet to be provided to a further PLMN, relaying said control packet to a remote security node for delivery of the control packet to the further PLMN, wherein the remote security node being outside of both the PLMN and being outside the further PLMN.
1 . A method, implemented by a security relay node in a Public Land Mobile Network (PLMN), the method comprising:
receiving, from a Network Function (NF) within the PLMN, a control packet to be provided to a further PLMN;
delegating, to a remote security node, a setup of a N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and
relaying the control packet to a remote security node for delivery of the control packet, over an N32-f interface, towards the further PLMN, the remote security node being outside of both the PLMN and the further PLMN.
2 . The method of claim 1 , further comprising establishing the N32-f interface between the security relay node and the remote security node.
3 . The method of claim 2 , wherein the relaying comprises relaying the control packet using Transport Layer Security (TLS).
4 . The method of claim 2 , further comprising exchanging, with the remote security node, control signaling associated with the secure interface.
5 . The method of claim 2 , wherein the secure interface is an N32-f interface.
6 . The method of claim 1 , further comprising encrypting at least an Information Element (IE) in the control packet prior to relaying the control packet.
7 . The method of claim 6 , wherein the encrypting comprises encrypting the IE using an encryption key of a peer security node of the further PLMN obtained via the remote security node.
8 . The method of claim 7 , further comprising obtaining the encryption key of the peer security node from the remote security node.
9 . The method of claim 1 , further comprising enabling discovery of the security relay node by at least one NF of the PLMN by registering with a Network Repository Function (NRF) of the PLMN as a Security Edge Protection Proxy (SEPP).
10 . The method of claim 1 , further comprising hiding a topology of the PLMN from the further PLMN.
11 . The method of claim 1 , further comprising using a telescopic fully qualified domain name of an NF in the PLMN to hide an address of the NF from the further PLMN.
12 . The method of claim 1 , wherein the remote security node is comprised in an Internet Protocol Exchange (IPX) network.
13 . The method of claim 1 , wherein the remote security node is comprised in a roaming hub network.
14 . A security relay node comprising:
processing circuitry and a memory, the memory containing instructions executable by the processing circuitry whereby the security relay node is configured to, from within a Public Land Mobile Network (PLMN):
receive, from a Network Function (NF) within the PLMN, a control packet to be provided to a further PLMN;
delegate, to a remote security node, a setup of an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and
relay the control packet to a remote security node for delivery of the control packet, over an N32-f interface, towards the further PLMN, the remote security node being outside of both the PLMN and the further PLMN.
15 . A non-transitory computer readable medium storing a computer program product for controlling a security relay node, the computer program product comprising software instructions that, when run on processing circuitry of the security relay node, cause the security relay node to:
receive, from a Network Function (NF) within a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;
delegate, to a remote security node, a setup of a N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and
relay the control packet to a remote security node for delivery of the control packet, over an N32-f interface, towards the further PLMN, the remote security node being outside of both the PLMN and the further PLMN.
16 . A method, implemented by a remote security node, the method comprising:
receiving, from a security relay node in a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;
setting up, on behalf of the remote security node, an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and
relaying the control packet, over an N32-f interface, towards the further PLMN;
wherein the remote security node being outside of both the PLMN and the further PLMN.
17 . The method of claim 16 , further comprising establishing the N32-f interface between the security relay node and the remote security node, wherein the receiving comprises receiving the control packet over the established N32-f interface.
18 . The method of claim 17 , wherein the receiving comprises receiving the control packet using Transport Layer Security (TLS).
19 . The method of claim 16 , wherein the receiving comprises receiving the control packet in which at least an Information Element (IE) is encrypted.
20 . The method of claim 19 , wherein at least the IE is encrypted using an encryption key of a peer security node of the further PLMN such that the remote security node is unable to decrypt it.
21 . The method of claim 20 , further comprising:
obtaining the encryption key from the peer security node of the further PLMN; and
providing the obtained encryption key to the remote security node.
22 . The method of claim 16 , further comprising hiding a topology of the PLMN from the further PLMN.
23 . The method of claim 16 , wherein the remote security node is comprised in an Internet Protocol Exchange (IPX) network.
24 . The method of claim 16 , wherein the remote security node is comprised in a roaming hub network.
25 . A remote security node comprising:
processing circuitry and a memory, the memory containing instructions executable by the processing circuitry whereby the remote security node is configured to:
receive, from a security relay node in a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;
set up, on behalf of the remote security node, an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and
relay the control packet, over an N32-f interface, towards the further PLMN;
wherein the remote security node being outside of both the PLMN and the further PLMN.
26 . A non-transitory computer readable medium storing a computer program product for controlling a remote security node, the computer program product comprising software instructions that, when run on processing circuitry of the remote security node, cause the remote security node to:
receive, from a security relay node in a Public Land Mobile Network (PLMN), a control packet to be provided to a further PLMN;
set up, on behalf of the remote security node, an N32-c interface towards the further PLMN such that the N32-c interface terminates at the remote security node; and
relay the control packet, over an N32-f interface, towards the further PLMN;
wherein the remote security node being outside of both the PLMN and the further PLMN.