IP Library › Granted Patent US 12,335,851
Granted Patent B2
US 12,335,851 · App. 17/817,489 · Granted Jun 17, 2025

Apparatus, method, and computer program

Inventors: Saurabh Khare (Bangalore, IN); Bruno Landais (Pleumeur-Bodou, FR); Anja Jerichow (Grafing bei München, DE)
Assignee: Nokia Technologies Oy
H04W48/16H04W84/042H04W92/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,851
App. No.
17/817,489
Granted
Jun 17, 2025
Kind
B2
Abstract

The disclosure relates to a first apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to: send ( 500 ), to a second apparatus, a request comprising information indicating a list of public land mobile network identifiers identifying a first public land mobile network supported by the first apparatus, and information to derive a second public land mobile network supported by the second apparatus; and receive ( 502 ), from the second apparatus, a response comprising information indicating a list of public land mobile network identifiers identifying the second public land mobile network supported by the second apparatus.

Claims (27)

1. A first security edge protection proxy node comprising: at least one processor and at least one memory storing computer code the computer code being configured, when executed by the at least one processor, to cause the first security edge proxy node at least to perform:

sending, to a second security edge protection proxy node a security capability negotiation request, the security capability negotiation request comprising a target public land mobile network identifier, and a first list of public land mobile network identifiers, wherein the first list comprises a first public land mobile network identifier identifying a first public land mobile network supported by the first security edge proxy node and a second public land mobile network identifier identifying a second public land mobile network supported by the first security edge proxy, wherein the first public land mobile network and the second public mobile network are different public land mobile networks;

receiving, from the second security edge protection proxy node, a response to the security capability negotiation request, the response comprising a second list of public land mobile network identifiers, wherein each respective public land mobile identifier in the second list identifies a public land mobile network supported by the second apparatus security edge protection proxy node; and

establishing a N32 connection between the first public land mobile network supported by the first security edge protection proxy node and the public land mobile network supported by the second security edge protection proxy node separate from another N32 connection between the second public land mobile network supported by the first security edge protection proxy node and the public land mobile network supported by the second security edge protection proxy node.

2. The first security edge protection proxy node of claim 1 , wherein the security capability negotiation request comprises an information element, and wherein the information element comprises the target public land mobile network identifier and the first list of public land mobile network identifiers.

3. The first security edge protection proxy of claim 2 , wherein the information element is a SecNegotiateReqData information element.

4. The first security edge protection proxy node of claim 1 , wherein the response comprises a SecNegotiateRespData information element, and wherein the SecNegotiateRespData information element the second list of public land mobile network identifiers.

5. The first security edge protection proxy node of claim 1 , wherein the first security edge protection proxy is an initiating security edge protection proxy and the second security edge protection proxy is a responding security edge protection proxy.

6. The first security edge protection proxy node of claim 1 , wherein the connection established between the first security edge protection proxy and the second security edge protection proxy is a signalling connection to be used to exchange security and protection policies, and to be used for forwarding of service requests and responses between the first public land mobile network and the second public land mobile network.

7. A second security edge protection proxy comprising; at least one processor; and at least one memory storing computer code, the computer code being configured, when executed by the at least one processor, to cause the second at least to perform:

receiving, from a first security edge protection proxy, a security capability negotiation request, the security capability negotiation reques comprising a target public land mobile identifier and a first list of public land mobile network identifiers, wherein the first list comprises a first public land mobile identifier identifying a first public land mobile network supported by the first security edge protection proxy and a second public land mobile identifier identifying a second public land mobile network supported by the first security edge protection proxy, wherein the first public land mobile network and the second public mobile network are different public land mobile networks;

selecting a public land mobile network supported by the second security edge protection proxy based on the target public land mobile network identifier; and

sending, to the first security edge protection proxy node, a response to the security capability negotiation request, the response comprising a second list of public land mobile network identifiers, wherein each respective public land mobile identifier in the second list identifies the public land mobile network supported by the second security edge protection proxy node that is selected; and

establishing a N32 connection between the first public land mobile network supported by the first security edge protection proxy node and the public land mobile network supported by the second security edge protection proxy node separate from another N32 connection between the second public land mobile network supported by the first security edge protection proxy node and the public land mobile network supported by the second security edge protection proxy node.

8. The second security edge protection proxy of claim 7 , wherein the security comprises an information element and wherein the information element comprises the first list of public land mobile network identifiers and the second public land mobile network identifier identifying the second public land mobile network supported by the second security edge protection proxy node.

9. The second security edge protection proxy of claim 8 , wherein the information element is a SecNegotiateReqData information element.

10. The second apparatus of claim 7 , wherein the the response comprises a SecNegotiateRespData information element, and wherein the SecNegotiateRespData information element comprises.

11. The second apparatus of claim 7 , wherein the connection between the first apparatus and the second apparatus is a signalling connection to be used to exchange security and protection policies, to be used for forwarding of service requests and responses between the first public land mobile network and the second public land mobile network.

12. A method for a first security edge protection proxy, the method comprising:

sending, to a second security edge protection proxy, a security capability negotiation request, the security capability negotiation request comprising a target public land mobile network identifier and a first list of public land mobile network identifiers, wherein the first list comprise a first public land mobile network identifier identifying a first public land mobile network supported by the first security edge protection proxy and a second public land mobile identifier identifying a second public land mobile network supported by the first security edge protection proxy, wherein the first public land mobile network and the second public mobile network are different public land mobile networks; and

receiving, from the second security edge protection proxy, a response to the security capability negotiation request, the response comprising a second list of public land mobile network identifiers, wherein each respective public land mobile network identifier in the second list identifies a public land mobile network supported by the second security edge protection proxy;

establishing a N32 connection between the first public land mobile network supported by the first security edge protection proxy node and the public land mobile network supported by the second security edge protection proxy node separate from another N32 connection between the second public land mobile network supported by the first security edge protection proxy node and the public land mobile network supported by the second security edge protection proxy node.

13. The method of claim 12 , wherein the request comprises an information element, and wherein the information element comprises the target public land mobile network identifier and the first list of public land mobile network identifiers.

14. The method of claim 13 , wherein the information element is a SecNegotiateReqData information element.

15. The method of claim 12 , wherein the response comprises a SecNegotiateRespData information element, and wherein the SecNegotiateRespData information element the second list of public land mobile network identifiers.

16. The method of claim 12 , wherein the first security edge protection proxy is an initiating security edge protection proxy and the second security edge protection proxy is a responding security edge protection proxy.

17. The method of claim 12 , wherein the connection established between the first security edge protection proxy and the second security edge protection proxy is a signalling connection to be used to exchange security and protection policies, and to be used for forwarding of service requests and responses between the first public land mobile network and the second public land mobile network.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: LANDAIS, BRUNO
To: ALCATEL-LUCENT INTERNATIONAL S.A.
Reel/Frame 061189/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: JERICHOW, ANJA
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 061189/0728 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: KHARE, SAURABH
To: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
Reel/Frame 061189/0736 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: ALCATEL-LUCENT INTERNATIONAL S.A.
To: NOKIA TECHNOLOGIES OY
Reel/Frame 061189/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 061189/0748 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
To: NOKIA TECHNOLOGIES OY
Reel/Frame 061189/0752 →
Priority Claims (1)
IN 202141035715 · Aug 7, 2021 · national
Continuity (1)
Related Publication 20230052658A1 · Feb 16, 2023
References Cited (8)
US 20230388273A1 · Rajput · 2023 [cited by examiner]
Extended European Search Report received for corresponding European Patent Application No. 22188989.2, dated Jan. 5, 2023, 7 pages. [cited by applicant]
“PLMN ID handling over N32”, 3GPP TSG-CT4 Meeting #101-e, C4-205820, Huawei, Nov. 3-13, 2020, 7 pages. [cited by applicant]
“Clarification on the number of PLMN IDuse by SEPP over N32”, 3GPP TSG-SA3 Meeting #103-e, S3-212287, Vodafone, May 17-28, 2021, 2 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17)”, 3GPP TS 29.510, V17.2.0, Jun. 2021, pp. 1-256. [cited by applicant]
“PLMN Specific N32-C connection”, 3GPP TSG-CT WG4 Meeting #105-e, C4-21xxxx, Nokia, Aug. 17-27, 2021, 6 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.2.1, Jun. 2021, pp. 1-257. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Public Land Mobile Network (PLMN) Interconnection; Stage 3 (Release 17)”, 3GPP TS 29.573, V17.1.0, Jun. 2021, pp.… [cited by applicant]
Cited By (1)
US 12,457,244