Secure indirect NF discovery via intermediary NF
By introducing an authorization mechanism into the intermediary NF, verifying the authorization status of the NFc and providing an access token, the problem of unauthorized NFcs obtaining NFp details is solved, and NFp security protection and attack prevention are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-13
- Publication Date
- 2026-04-14
AI Technical Summary
In existing technologies, unauthorized network function consumers can obtain producer details through intermediary NFs, leading to security threats and potential attacks such as distributed denial-of-service attacks and sensitive data leaks.
An authorization mechanism is introduced, whereby the intermediary NF verifies whether the NFc is authorized to request services by querying the NFp profile or requesting authorization from the authorization server, and provides an access token to ensure that only authorized NFcs can obtain NFp communication information.
It effectively prevents unauthorized NFC access to NFp, protects confidential NFp data, prevents attacks, and ensures network security.
Smart Images

Figure CN121866745A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to network function (NF) discovery. Background Technology
[0002] In some cases, a consumer (which may be an NF service consumer, a user equipment (UE) (via application function (AF) / network open function (NEF)) or any other entity) may obtain (indirectly discover) details of an NF service producer (i.e., the communication information of the NF service producer) through an intermediary NF.
[0003] Some examples of these indirect findings are (the symbols x / y / z represent at least one of x, y, or z): • Access and Mobility Function (AMF) / Session Management Function (SMF) / Network Data Analysis Function (NWDAF) selection based on User Data Management (UDM): Service AMF / SMF / NWDAF can be registered with the UDM. Then, NEF / AF / NF can query the UDM to retrieve service AMF / SMF / NWDAF details. • Analytical Data Repository Function (ADRF) Discovery / Selection Based on NWDAF: NWDAF knows that the ADRF contains data for a specific model. Then, when an NF consumer (NFc) can request NWDAF, NWDAF can provide the NFc with the ADRF details. • Policy Control Function (PCF) selection based on Bootstrap Server Function (BSF): NFc can request the BSF to provide details of the PCF. Summary of the Invention
[0004] Its purpose is to improve existing technology.
[0005] According to a first aspect, an apparatus is provided, the apparatus comprising: One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the device to perform: Request communication information from the service producer of the intermediary entity; In response to a request, an instruction is given to receive communication information from producers who are not authorized to provide services by the intermediary entity.
[0006] When executed by the one or more processors, the instruction can also cause the device to perform... In response to a request, receive communication information from the producer; and Use communication information to request services from the service producer.
[0007] An intermediary entity can be a network function. An intermediary entity can be an authorization server.
[0008] The communication information of the service producer may be needed to request services from the service producer.
[0009] According to a second aspect, an apparatus is provided, the apparatus comprising: One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the device to perform: Receive queries from intermediary entities, where the query indicates whether the consumer of the query service is authorized to request the service from the producer of the service; Based on the profile stored by the service producer, check whether the service consumer is authorized to request services from the service producer. In response to a query that a service consumer is found to have made an unauthorized request for services from the service's producer: a non-permission instruction is provided to the intermediary entity, wherein the non-permission instruction indicates that the service consumer is not authorized to make a request for services from the service's producer.
[0010] When executed by the one or more processors, the instruction can also cause the device to perform... In response to the detection that the service consumer is authorized to request a service from the service producer: provide an authorization instruction to the intermediary entity, wherein the authorization instruction indicates that the service consumer is authorized to request a service from the service producer.
[0011] When executed by the one or more processors, the instruction can also cause the device to perform... Receive registrations from service providers; The registration is stored in the service producer's profile, where Registration includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers; Each of one or more first service consumers is authorized to request services from the service producer. Each of the one or more second service consumers is not authorized to request services from the service producer.
[0012] According to a third aspect, an apparatus is provided, the apparatus comprising: One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the device to perform: Receive requests, which are used to communicate stored information about the producers who provide services to service consumers; Check the registration server to see if the service consumer is authorized to request services from the service producer. Receive a non-permission instruction in response to the query from the registration server, wherein the non-permission instruction indicates that the service consumer is not authorized to request services from the service producer; In response to receiving a non-permission instruction: the producer's stored communication information is prohibited from providing services to service consumers.
[0013] When executed by the one or more processors, the instruction can also cause the device to perform... Receive a permission instruction in response to the query from the registration server, wherein the permission instruction indicates that the service consumer is authorized to request services from the service producer; In response to receiving a permission instruction: stored communication information of the producer providing services to the service consumer.
[0014] The communication information stored by the service producer may be needed to request services from the service producer.
[0015] When executed by the one or more processors, the instruction can also cause the device to perform... In response to receiving a non-permissioned instruction: Inform the service consumer that the service consumer was not authorized to request the service from the service producer.
[0016] According to a fourth aspect, an apparatus is provided, the apparatus comprising: One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the device to perform: Receive a request for a profile of the producer providing the service; In response to a received request, a profile of the producer providing the service is provided; among which The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers; Each of one or more first service consumers is authorized to request services from the service producer. Each of the one or more second service consumers is not authorized to request services from the service producer.
[0017] When executed by the one or more processors, the instruction can also cause the device to perform... Receive registrations from service providers; The registration is stored in the service producer's profile, where Registration includes at least one of the whitelist or blacklist.
[0018] According to a fifth aspect, an apparatus is provided, the apparatus comprising: One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the device to perform: Receive requests, which are communication messages from producers that provide services to service consumers; Request a profile of the service provider from the registry server; Receive the producer's profile in response to the request profile; Use the profile to check whether the service consumer is authorized to request services from the service producer; In response to a check based on the profile indicating that a service consumer has not been authorized to request services from the service producer: Communication information from the service producer providing the service to the service consumer is prohibited; whereby... The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers; Each of one or more first service consumers is authorized to request services from the service producer. Each of the one or more second service consumers is not authorized to request services from the service producer.
[0019] When executed by the one or more processors, the instruction can also cause the device to perform... In response to a service consumer's authorized request for a service from a service producer, based on a profile check, the service producer's communication information is provided.
[0020] The communication information of the service producer may be needed to request services from the service producer.
[0021] When executed by the one or more processors, the instruction can also cause the device to perform... In response to receiving a non-permissioned instruction: Inform the service consumer that the service consumer was not authorized to request the service from the service producer.
[0022] According to the sixth aspect, a method is provided, the method comprising: Request communication information from the service producer of the intermediary entity; In response to a request, an instruction is given to receive communication information from producers who are not authorized to provide services by the intermediary entity.
[0023] The method may also include In response to a request, receive communication information from the producer; and Use communication information to request services from the service producer.
[0024] An intermediary entity can be a network function. An intermediary entity can be an authorization server.
[0025] The communication information of the service producer may be needed to request services from the service producer.
[0026] According to the seventh aspect, a method is provided, the method comprising: Receive queries from intermediary entities, where the query indicates whether the consumer of the query service is authorized to request the service from the producer of the service; Based on the profile stored by the service producer, check whether the service consumer is authorized to request services from the service producer. In response to a query that a service consumer is found to have made an unauthorized request for services from the service's producer: a non-permission instruction is provided to the intermediary entity, wherein the non-permission instruction indicates that the service consumer is not authorized to make a request for services from the service's producer.
[0027] The method may also include: In response to the detection that the service consumer is authorized to request a service from the service producer: provide an authorization instruction to the intermediary entity, wherein the authorization instruction indicates that the service consumer is authorized to request a service from the service producer.
[0028] The method may also include Receive registrations from service providers; The registration is stored in the service producer's profile, where Registration includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers; Each of one or more first service consumers is authorized to request services from the service producer. Each of the one or more second service consumers is not authorized to request services from the service producer.
[0029] According to the eighth aspect, a method is provided, the method comprising: Receive requests, which are used to communicate stored information about the producers who provide services to service consumers; Check the registration server to see if the service consumer is authorized to request services from the service producer. Receive a non-permission instruction in response to the query from the registration server, wherein the non-permission instruction indicates that the service consumer is not authorized to request services from the service producer; In response to receiving a non-permission instruction: the producer's stored communication information is prohibited from providing services to service consumers.
[0030] The method may also include Receive a permission instruction in response to the query from the registration server, wherein the permission instruction indicates that the service consumer is authorized to request services from the service producer; In response to receiving a permission instruction: stored communication information of the producer providing services to the service consumer.
[0031] The communication information stored by the service producer may be needed to request services from the service producer.
[0032] The method may also include: In response to receiving a non-permissioned instruction: Inform the service consumer that the service consumer was not authorized to request the service from the service producer.
[0033] According to the ninth aspect, a method is provided, the method comprising: Receive a request for a profile of the producer providing the service; In response to a received request, a profile of the producer providing the service is provided; among which The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers; Each of one or more first service consumers is authorized to request services from the service producer. Each of the one or more second service consumers is not authorized to request services from the service producer.
[0034] The method may also include Receive registrations from service providers; The registration is stored in the service producer's profile, where Registration includes at least one of the whitelist or blacklist.
[0035] According to the tenth aspect, a method is provided, the method comprising: Receive requests, which are communication messages from producers that provide services to service consumers; Request a profile of the service provider from the registry server; Receive the producer's profile in response to the request profile; Use the profile to check whether the service consumer is authorized to request services from the service producer; In response to a profile check indicating that a service consumer has not been authorized to request services from a service producer: Communication information from the service producer providing the service to the service consumer is prohibited; whereby... The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers; Each of one or more first service consumers is authorized to request services from the service producer. Each of the one or more second service consumers is not authorized to request services from the service producer.
[0036] The method may also include In response to a service consumer's authorized request for a service from a service producer, based on a profile check, the service producer's communication information is provided.
[0037] The communication information of the service producer may be needed to request services from the service producer.
[0038] The method may also include: In response to receiving a non-permissioned instruction: Inform the service consumer that the service consumer was not authorized to request the service from the service producer.
[0039] Each of the methods in aspects six through ten can be an indirect discovery method.
[0040] According to the eleventh aspect, a computer program product including an instruction set is provided, which, when executed on a device, is configured to cause the device to perform the method according to any one of the sixth to tenth aspects. The computer program product may be embodied in a computer-readable medium or directly loadable into a computer.
[0041] According to some example embodiments, at least one of the following advantages can be achieved: • Confidential data of NF producers (NFp) can be protected; • It can prevent attacks on NFp; • It can block unauthorized service requests. Attached Figure Description
[0042] Other details, features, objects, and advantages will become apparent from the following detailed description of preferred exemplary embodiments, taken in conjunction with the accompanying drawings:
[0043] Figure 1 The message flow is shown according to some example embodiments;
[0044] Figure 2 The message flow is shown according to some example embodiments;
[0045] Figure 3 An apparatus according to an example embodiment is shown;
[0046] Figure 4 A method according to an example embodiment is shown;
[0047] Figure 5 An apparatus according to an example embodiment is shown;
[0048] Figure 6 A method according to an example embodiment is shown;
[0049] Figure 7 An apparatus according to an example embodiment is shown;
[0050] Figure 8 A method according to an example embodiment is shown;
[0051] Figure 9 An apparatus according to an example embodiment is shown;
[0052] Figure 10 A method according to an example embodiment is shown;
[0053] Figure 11 An apparatus according to an example embodiment is shown;
[0054] Figure 12 A method according to an example embodiment is shown; and
[0055] Figure 13 An apparatus according to an example embodiment is shown. Detailed Implementation
[0056] Hereinafter, certain exemplary embodiments will be described in detail with reference to the accompanying drawings, wherein, unless otherwise stated, the features of the exemplary embodiments can be freely combined with each other. However, it should be clearly understood that the description of certain exemplary embodiments is given by way of example only and is in no way intended to limit this disclosure to the details disclosed.
[0057] Furthermore, it should be understood that the device is configured to perform the corresponding method, although in some cases only the device or only the method is described.
[0058] Consumers can indirectly retrieve NFp communication information via an intermediary entity (intermediary NF or authorizing server; the remainder of the specification focuses primarily on the intermediary NF), even if the consumer is not actually authorized to access the NF service provider, because the intermediary entity does not know whether the consumer is authorized to access the NFp. Therefore, the intermediary entity provides the NFc with details of the NFp (i.e., communication information) upon request. This communication information enables the NFc to request services from the NFp.
[0059] This may cause one or more of the following problems, for example: • Consumers who are not authorized at NFp can still retrieve communication information / details related to NFp from the intermediary NF. • Consumers who are not authorized at NFp can still retrieve information / details related to NFp from the intermediary NF, and then use this communication information from NFp to retrieve / request relevant profile information of the producer from the Network Repository Function (NRF). • Furthermore, unauthorized consumers knowing the producer's NF profile or details could lead to various attacks, such as distributed denial-of-service (DDoS) attacks against the producer, and other attacks using sensitive data present in the producer profile. • This could also lead to security issues, as NFp details could be leaked to unauthorized NFCs.
[0060] The following are some use cases that could lead to at least one of the threats (problems) mentioned above: Example use case 1:
[0061] One such use case is the Network Automation Enabler (eNA), where model sharing occurs between the NWDAF Analysis Logic Function (AnLF) (NFc), the NWDAF Model Training Logic Function (MtLF) (mediating NF), and the ADRF (the NFp in which the model is stored). Even if the AnLF is not authorized to access the ADRF (because the MtLF is unaware of this and there is currently no way to verify it), the MtLF will still send ADRF communication information to the AnLF. Example use case 2:
[0062] Another use case is retrieving AMF and / or SMF-related information from the UDM. Let's assume that the NEF or AF is not authorized to obtain details (communication information) from AMF1 (the UE's current AMF). When the NEF / AF queries the UDM to retrieve the UE's current AMF address, the UDM can provide AMF1 details. Later, when the NEF / AF goes to the NRF to request data from the AMF, the NRF rejects the request because the NEF / AF is not authorized to obtain data from the AMF. This could lead to at least one of the threats mentioned above.
[0063] Some example implementations design an authorization mechanism to ensure that only genuine and authorized consumers can obtain the producer's communication information via the intermediary NF.
[0064] As a first option (option a)), according to some example embodiments • An intermediary NF can query an NFp profile from an NRF (or a registry server in the system where NFp registers which NFcs can (or cannot) access NFp; that is, NFp policies are part of the NFp profile). The NFp profile includes information indicating whether an NFc is authorized to request services from an NFp. • The intermediary NF can use the NFp profile information to verify whether the requesting NFc is authorized to come from the NFp service.
[0065] As a second option (option b), according to some example embodiments • The intermediary NF can request an authorization confirmation response (permission indication) from the NRF (or registration server), which indicates whether the NFc is authorized to request services from the NFp.
[0066] As a third option (option c), according to some example embodiments • The intermediary NF requests the NRF (or any authorized server in the system) to provide the requesting client (NFc) with an access token to access the NFp. • If the NRF (or authorization server) successfully generates an access token, the intermediary NF can provide the NFC with details of the NFp (communication information) including the access token.
[0067] Based on the verification of the access token generated by the NRF or via policy information, the intermediary NF can provide the NFc with the communication information of the NFp. However, if the intermediary NF does not receive confirmation from the NFc that it is authorized to obtain the communication information of the NFp (based on policies (options a) and b)), or if the intermediary NF does not receive the access token for the NFp (option c)), the intermediary NF will not provide the NFp communication information to the NFc.
[0068] Figure 1 The diagram illustrates a message sequence according to some example embodiments. In a single diagram, it includes the three options discussed above: a) (actions 3a and 4a), b) (actions 3b and 4b), and c) (actions 3c and 4c). Typically, in one embodiment, only one of these options a), b), and c) will be executed. Figure 1 Actions 1, 2, and 5 through 7 are shared by options a), b), and c). Figure 1 The actions in the middle are as follows:
[0069] Action 1. The NFp stores consumer information in the NRF (or another authorization and registration server (function)). For example, the NFp may store consumer information at the NRF during registration or during NFp profile updates. The consumer information indicates which NF consumers are authorized (or not authorized) to request services from the NFp, and which services the NF consumers can request from that NFp. Consumer information may include information for each NFc, such as NFc type, instance identifier (ID), Public Land Mobile Network (PLMN) information, slice information, etc.
[0070] NFc can be organized into a whitelist (NFcs that are authorized to request services from NFp) and / or a blacklist (NFcs that are not authorized to request services from NFp).
[0071] Action 1 is usually a prerequisite for subsequent actions. As an alternative to Action 1, some or all consumer information can be predefined in the NRF (e.g., through Operations, Administration and Maintenance (OAM)).
[0072] Action 2. NFc sends a request for NFp information to the intermediary NF.
[0073] Option a): License profile variant
[0074] Action 3a. The intermediary NF sends a request to the NRF to obtain the profile of the NFp that the NFc is requesting communication information from.
[0075] Action 4a. The NRF sends the requested NF profile to the intermediary NF.
[0076] Option b): Authorization confirmation response service at NRF
[0077] Action 3b. The intermediary NF sends a service request to the NRF, such as an "authorization confirmation request". The service request inquires whether the NFc is authorized to provide the service from the NFp.
[0078] Action 4b. In response, the NRF provides an allow instruction indicating that the NFc is authorized to request services from the NFp, or a disallow instruction indicating that the NFc is not authorized to request services from the NFp.
[0079] Option c): Access token-based solution.
[0080] Action 3c. The intermediary NF sends an access token request to the NRF, where NFc acts as the consumer and NFp acts as the producer.
[0081] Action 4c. If the NFc is authorized and the request comes from the NFp service, the NRF generates and produces a valid token; or if the NFc is unauthorized and the request comes from the NFp service, the NRF sends an error response.
[0082] Action 5. The intermediary NF verifies whether the NFc is authorized to request the service from the NFp based on the results of 4a, 4b, or 4c (i.e., by analyzing the NFp profile itself, processing the authorization confirmation response from the NRF, or verifying the generated access token, respectively).
[0083] Action 6. In Action 5, if the authentication request for obtaining NFc is authorized from an NFp service, the intermediary NF sends NFp details (NFp communication information) to NFc. In option c), the NFp details may include an access token.
[0084] In Action 5, if the verification reveals that the NFc is not authorized to request services from the NFp, then the intermediary NF will not send NFp details (NFp communication information) to the NFc. Instead, in some example embodiments, the intermediary NF may notify the NFc that it is not (unauthorized) to provide NFp communication information to the NFc because the NFc is not authorized to request services from the NFp.
[0085] Action 7. If NFc receives communication information from NFp in Action 6, then NFc can use the communication information from NFp to send a service request to NFp. In option c), NFc can authenticate itself to NFp using an access token.
[0086] If NFc does not receive communication information from NFp in Action 6, NFc is prevented from sending service requests to NFp. This prevents unauthorized access to NFp.
[0087] Figure 2 A message sequence diagram according to another example embodiment is shown. Figure 2 middle, Figure 1 Authorization and registration servers (such as NRF) are split into authorization servers and NRF registration servers. From the NRF's perspective, the authorization server basically corresponds to... Figure 1 The intermediate NF in the diagram. Specifically for options a) and b). Figure 2 The authorization server can be with Figure 1 The intermediary NF works in the same way.
[0088] For option c) (access token), Figure 2 The actions shown are as follows:
[0089] Actions 1 and 2 with Figure 1The same applies to NFp registration (Action 1), where the registration (Action 1) is performed at the NF registration server, and the service request (Action 2) from NFc is redirected to the authorizing server instead of the intermediary NF.
[0090] Action 3: Similar to option a), the authorizing server requests an NFp profile from the NF registry server. Additionally, it can request an NFc profile.
[0091] Action 4: In response to Action 3, the NF registry server sends a summary of NFp (and NFc, if requested) to the authorization server.
[0092] Action 5: The authorizing server checks whether the NFc is authorized to request services from NFp based on the NFp profile and the NFc profile (if any). If the NFc is authorized to request services from NFp, the authorizing server generates an access token, with the NFc acting as the consumer and the NFp as the producer. If the NFc is not authorized to request services from NFp, the authorizing server does not generate an access token. Instead, the authorizing server may notify the NFc that it is not authorized to provide the NFp access token to the NFc because the NFc is not authorized to request services from NFp.
[0093] Action 6: If the authorization server generates an access token in Action 5, the authorization server responds to the request in Action 2 by providing the access token to NFc and NFp communication information.
[0094] Action 7: NFc uses the access token received in Action 6 to send a service request to NFp.
[0095] If NFc does not receive an access token for NFp in action 6, NFc is prevented from successfully sending a service request to NFp. This prevents unauthorized access to NFp.
[0096] Figure 3 An apparatus according to an example embodiment is shown. The apparatus may be an NF consumer or an element thereof. Figure 4 A method according to an example embodiment is shown. Figure 3 The device can perform Figure 4 This method, but not limited to this method. Figure 4 The method can be derived from Figure 3 The device performs the action, but is not limited to the device performing the action.
[0097] The device includes a requesting component 110 and a receiving component 120. The requesting component 110 and the receiving component 120 can be a requesting component and a receiving component, respectively. The requesting component 110 and the receiving component 120 can be a requester and a receiver, respectively. The requesting component 110 and the receiving component 120 can be a request processor and a receiving processor, respectively.
[0098] Component 110, used for requesting, requests communication information from a service producer of an intermediary entity (such as an intermediary NF or authorization server) (S110). In response to the request in S110, component 120, used for receiving, receives an indication that the intermediary entity is not authorized to provide communication information from a service producer (S120). In some example embodiments, the indication in S120 may indicate that the intermediary entity is not authorized to provide communication information because the consumer requesting the communication information in S110 is not authorized to request services from a producer. The communication information of the service producer may be needed to request services from the service producer.
[0099] Figure 5 An apparatus according to an example embodiment is shown. The apparatus may be an NF consumer or an element thereof. Figure 6 A method according to an example embodiment is shown. Figure 5 The device can perform Figure 6 This method, but not limited to this method. Figure 6 The method can be derived from Figure 5 The device performs the action, but is not limited to the device performing the action.
[0100] The device includes a receiving component 210, an inspection component 220, and a providing component 230. The receiving component 210, the inspection component 220, and the providing component 230 can be a receiving component, an inspection component, and a providing component, respectively. The receiving component 210, the inspection component 220, and the providing component 230 can be a receiver, an inspector, and a provider, respectively. The receiving component 210, the inspection component 220, and the providing component 230 can be a receiving processor, an inspection processor, and a providing processor, respectively.
[0101] The receiving component 210 receives a query from an intermediary entity (such as an intermediary NF or an authorization server) (S210). The query determines whether the service consumer is authorized to request the service from the service producer.
[0102] The component 220 used for inspection checks whether the service consumer is authorized to request a service from the service producer based on the profile stored by the service producer (S220).
[0103] S210 and S220 can be executed in any order. They can be executed completely or partially in parallel.
[0104] In response to the detection that the service consumer was not authorized to request the service from the service producer (S220=No), the component 230 for providing the service provides a non-permission instruction to the intermediary entity in response to the query in S210 (S230). The non-permission instruction indicates that the service consumer was not authorized to request the service from the service producer.
[0105] Figure 7 An apparatus according to an example embodiment is shown. The apparatus may be an intermediary NF (such as an intermediary NF or an authorization server) or an element thereof. Figure 8 A method according to an example embodiment is shown. Figure 7 The device can perform Figure 8 This method, but not limited to this method. Figure 8 The method can be derived from Figure 7 The device performs the action, but is not limited to the device performing the action.
[0106] The device includes a first component 310 for receiving, a component 320 for querying, a second component 330 for receiving, and a component 340 for blocking. The first component 310, the component 320, the second component 330, and the component 340 for blocking can be respectively a first receiving component, a query component, a second receiving component, and a blocking component. The first component 310, the component 320, the second component 330, and the component 340 for blocking can be respectively a first receiver, a queryer, a second receiver, and a blocker. The first component 310, the component 320, the second component 330, and the component 340 for blocking can be respectively a first receiving processor, a query processor, a second receiving processor, and a blocking processor.
[0107] The first component 310 for receiving requests receives stored communication information about the producer providing services to the service consumer (S310). The component 320 for querying queries the registration server to determine whether the service consumer is authorized to request services from the service producer (S320).
[0108] In response to the query in S320, the second component 330 for receiving receives a non-permission instruction from the registration server (S330). The non-permission instruction indicates that the service consumer is not authorized to request services from the service producer. In response to receiving the non-permission instruction in S330, the prohibition component 340 prohibits the storage of communication information of the service producer from providing services to the service consumer (S340).
[0109] Figure 9 An apparatus according to an example embodiment is shown. The apparatus may be a registration server (such as an NRF) or a component thereof. Figure 10 A method according to an example embodiment is shown. Figure 9 The device can perform Figure 10 This method, but not limited to this method. Figure 10 The method can be derived from Figure 9 The device performs the action, but is not limited to the device performing the action.
[0110] The device includes a receiving component 410 and a providing component 420. The receiving component 410 and the providing component 420 can be a receiving component and a providing component, respectively. The receiving component 410 and the providing component 420 can be a receiver and a provider, respectively. The receiving component 410 and the providing component 420 can be a receiving processor and a providing processor, respectively.
[0111] The receiving component 410 receives a request for a profile of a producer providing the service (S410). The providing component 420 provides the profile of the producer providing the service in response to the request received in S410 (S420).
[0112] The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers.
[0113] Each of the one or more first service consumers in the whitelist is authorized to request services from the service producer. Each of the one or more second service consumers in the blacklist is not authorized to request services from the service producer.
[0114] Figure 11 An apparatus according to an example embodiment is shown. The apparatus may be an intermediary NF (such as an intermediary NF or an authorization server) or an element thereof. Figure 12 A method according to an example embodiment is shown. Figure 11 The device can perform Figure 12 This method, but not limited to this method. Figure 12 The method can be derived from Figure 11 The device performs the action, but is not limited to the device performing the action.
[0115] The device includes a first component 510 for receiving, a component 520 for requesting, a second component 530 for receiving, a component 540 for checking, and a component 550 for blocking. The first component 510 for receiving, the component 520 for requesting, the second component 530 for receiving, the component 540 for checking, and the component 550 for blocking can be respectively a first receiving component, a requesting component, a second receiving component, a checking component, and a blocking component. The first component 510 for receiving, the component 520 for requesting, the second component 530 for receiving, the component 540 for checking, and the component 550 for blocking can be respectively a first receiver, a requester, a second receiver, a checker, and a blocking device. The first component 510 for receiving, the component 520 for requesting, the second component 530 for receiving, the component 540 for checking, and the component 550 for blocking can be respectively a first receiving processor, a request processor, a second receiving processor, a checking processor, and a blocking processor.
[0116] The first component 510 receives a request for communication information from the producer providing services to the service consumer (S510).
[0117] Component 520, used for the request, requests a profile of the service provider from the registration server (S520). The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of the first service consumer; or - A blacklist that includes the identifiers of one or more second service consumers.
[0118] Each of the one or more first service consumers in the whitelist is authorized to request services from the service producer. Each of the one or more second service consumers in the blacklist is not authorized to request services from the service producer.
[0119] In response to the request profile in S520, the second component 530 receives the producer's profile (S530). The checking component 540 checks, based on the profile, whether the service consumer is authorized to request a service from the service producer (S540).
[0120] Combinations of S510 with S520, S530, and S540 can be executed in any order. They can be executed in complete or partial parallelism.
[0121] In response to a check based on the profile indicating that the service consumer is not authorized to request services from the service producer (S540 = No), the blocking component 550 blocks the communication information of the service producer to the service consumer (S550).
[0122] Figure 13 An apparatus according to an example embodiment is shown. The apparatus includes at least one processor 810 and at least one memory 820 storing instructions that, when executed by the at least one processor 810, cause the apparatus to perform at least one of the methods according to the following figures and related descriptions: Figure 4 , Figure 6 , Figure 8 , Figure 10 or Figure 12 .
[0123] The term "NFp details" refers to the communication information of NFp, that is, the information required to request a service from NFp. Examples of communication information include the NFp IP address, the port on which the service is requested, and the slicing supported by NFp.
[0124] Some example implementations have been explained in conjunction with 5GC. However, other example implementations can be used in other 3GPP generations (such as 4G, 6G, 7G, etc.), other wireless or wired communication devices, and other systems employing a service-based architecture.
[0125] A message can be sent from one entity to another in one or more messages. Each of these messages can include other (different) information.
[0126] The names of network elements, network functions, protocols, and methods are based on current standards or current proposals. These names are not restrictive. For example, the names of these network elements and / or network functions and / or protocols and / or methods may differ in other versions or other technologies, as long as they provide the corresponding functionality. The same applies to terminals.
[0127] Unless otherwise stated or explicitly stated in the context, different claims by two entities indicate that they perform different functions. This does not necessarily mean that they are based on different hardware. That is, each entity described in this specification may be based on different hardware, or some or all entities may be based on the same hardware. This does not necessarily mean that they are based on different software. That is, each entity described in this specification may be based on different software, or some or all entities may be based on the same software. Each entity described in this specification can be deployed in the cloud.
[0128] Based on the above description, it should be clear that the example embodiments provide, for example, an NF consumer or its components (which may or may not be actually integrated into the NF consumer), means embodying the NF consumer or its components, methods for controlling and / or operating the NF consumer or its components, and multiple computer programs for controlling and / or operating the NF consumer or its components, and a medium carrying such multiple computer programs and forming multiple computer program products. Based on the above description, it should be clear that the example embodiments provide, for example, an intermediary entity (such as an intermediary NF or authorization server) or its components (which may or may not be actually integrated into the intermediary entity), means embodying the intermediary entity or its components, methods for controlling and / or operating the intermediary entity or its components, and multiple computer programs for controlling and / or operating the intermediary entity or its components, and a medium carrying such multiple computer programs and forming multiple computer program products. Based on the above description, it should be clear that the example embodiments provide, for example, a registration function (such as a registration server or an authorization and registration server) or its components (which may or may not be actually integrated into the registration function), means embodying the registration function or its components, a method for controlling and / or operating the registration function or its components, and multiple computer programs for controlling and / or operating the registration function or its components, and a medium carrying such multiple computer programs and forming multiple computer program products.
[0129] By way of non-limiting example, implementation of any of the blocks, devices, systems, techniques, or methods described above includes implementation as hardware, software, firmware, special-purpose circuitry or logic, general-purpose hardware or controllers or other computing devices, or combinations thereof. Each entity described in this specification can be implemented in the cloud.
[0130] It should be understood that the above description represents what is currently considered a preferred exemplary embodiment. However, it should be noted that the description of the preferred exemplary embodiment is given by way of example only, and various modifications can be made without departing from the scope of disclosure defined by the appended claims.
[0131] Unless otherwise stated, the terms “first X” and “second X” include the following options: “first X” is the same as “second X”, and “first X” is different from “second X”. As used herein, “at least one of the following: ” and “<at least one item in a list of two or more elements>” and similar wording (where a list of two or more elements is connected by “and” or “or”) means at least any one of these elements, or at least any two or more of these elements, or at least all of these elements. The word “or” means a non-exclusive “or” unless otherwise stated (e.g., using “otherwise” or “or in an alternative”).
Claims
1. An apparatus comprising: One or more processors, and a memory storing instructions, which, when executed by the one or more processors, cause the device to perform: Request communication information from the service producer of the intermediary entity; In response to the request, the intermediary entity receives the communication information from the producer that is not authorized to provide the service.
2. The apparatus of claim 1, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform... In response to the request, the communication information from the producer is received; and The communication information is used to request the service from the producer of the service.
3. The apparatus according to any one of claims 1 to 2, wherein The intermediary entity is a network function; or The intermediary entity is the authorization server.
4. The apparatus according to any one of claims 1 to 3, wherein The communication information of the producer of the service is needed to request the service from the producer of the service.
5. An apparatus comprising: One or more processors, and a memory storing instructions, which, when executed by the one or more processors, cause the device to perform: Receive a query from an intermediary entity, wherein the query determines whether the service consumer is authorized to request the service from the service producer; Based on the profile stored by the producer of the service, check whether the service consumer is authorized to request the service from the producer of the service; In response to the detection that the service consumer is not authorized to request the service from the producer of the service: in response to the query, a non-permission instruction is provided to the intermediary entity, wherein the non-permission instruction indicates that the service consumer is not authorized to request the service from the producer of the service.
6. The apparatus of claim 5, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform... In response to detecting that the service consumer is authorized to request the service from the producer of the service: provide the intermediary entity with a permission instruction, wherein the permission instruction indicates that the service consumer is authorized to request the service from the producer of the service.
7. The apparatus according to any one of claims 5 to 6, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform Receive registrations from the producers for the service; The registration is stored in the profile of the producer of the service, wherein The registration includes at least one of the following: - A whitelist, which includes one or more identifiers of first service consumers; or - A blacklist, which includes identifiers of one or more second service consumers; Each of the one or more first service consumers is authorized to request the service from the producer of the service; Each of the one or more second service consumers is not authorized to request the service from the producer of the service.
8. An apparatus comprising: One or more processors, and a memory storing instructions, which, when executed by the one or more processors, cause the device to perform: Receive requests for stored communication information of producers that provide services to service consumers; The registry server is checked to see if the service consumer is authorized to request the service from the producer of the service. The service consumer receives a non-permission instruction in response to the query from the registration server, wherein the non-permission instruction indicates that the service consumer is not authorized to request the service from the producer of the service. In response to receiving the non-permission instruction: prohibiting the provision of the service to the service consumer of the communication information stored by the producer.
9. The apparatus of claim 8, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform... The service consumer receives a permission instruction in response to the query from the registration server, wherein the permission instruction indicates that the service consumer is authorized to request the service from the producer of the service; In response to receiving the permission instruction, the producer of the service provides the service consumer with the communication information stored therein.
10. The apparatus according to any one of claims 8 to 9, wherein The communication information stored by the producer of the service is needed to request the service from the producer of the service.
11. The apparatus according to any one of claims 8 to 10, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform In response to receiving the non-permission instruction: notify the service consumer that the service consumer is not authorized to request the service from the producer of the service.
12. An apparatus comprising: One or more processors, and a memory storing instructions, which, when executed by the one or more processors, cause the device to perform: Receive a request for a profile of the producer providing the service; In response to receiving the request, the producer provides the profile of the service; in The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of first service consumers; or - A blacklist, which includes identifiers of one or more second service consumers; Each of the one or more first service consumers is authorized to request the service from the producer of the service; Each of the one or more second service consumers is not authorized to request the service from the producer of the service.
13. The apparatus of claim 12, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform Receive registrations from the producers for the service; The registration is stored in the profile of the producer of the service, wherein The registration includes at least one of the whitelist or the blacklist.
14. An apparatus comprising: One or more processors, and a memory storing instructions, which, when executed by the one or more processors, cause the device to perform: Receive a request, the request being used to communicate with the producer providing the service to the service consumer; Request the profile of the producer of the service from the registration server; Receive the producer's profile in response to the request for the profile; The profile is used to check whether the service consumer is authorized to request the service from the producer of the service. In response to a check based on the profile indicating that the service consumer is not authorized to request the service from the producer of the service: the communication information of the producer of the service is prohibited from being provided to the service consumer; in The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of first service consumers; or - A blacklist, which includes identifiers of one or more second service consumers; Each of the one or more first service consumers is authorized to request the service from the producer of the service; Each of the one or more second service consumers is not authorized to request the service from the producer of the service.
15. The apparatus of claim 14, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform In response to determining, based on the profile, that the service consumer is authorized to request the service from the producer of the service, the communication information of the producer of the service is provided.
16. The apparatus according to any one of claims 14 to 15, wherein The communication information of the producer of the service is needed to request the service from the producer of the service.
17. The apparatus according to any one of claims 14 to 16, wherein the instructions, when executed by the one or more processors, further cause the apparatus to perform In response to receiving the non-permission instruction: notify the service consumer that the service consumer is not authorized to request the service from the producer of the service.
18. A method comprising: Request communication information from the service producer of the intermediary entity; In response to the request, the intermediary entity receives the communication information from the producer that is not authorized to provide the service.
19. The method of claim 18, further comprising: In response to the request, receive the communication information from the producer; as well as The communication information is used to request the service from the producer of the service.
20. The method according to any one of claims 18 to 19, wherein The intermediary entity is a network function; or The intermediary entity is the authorization server.
21. The method according to any one of claims 18 to 20, wherein The communication information of the producer of the service is needed to request the service from the producer of the service.
22. A method comprising: Receive a query from an intermediary entity, wherein the query determines whether the service consumer is authorized to request the service from the service producer; Based on the profile stored by the producer of the service, check whether the service consumer is authorized to request the service from the producer of the service; In response to the detection that the service consumer is not authorized to request the service from the producer of the service: in response to the query, a non-permission instruction is provided to the intermediary entity, wherein the non-permission instruction indicates that the service consumer is not authorized to request the service from the producer of the service.
23. The method of claim 22, further comprising: In response to detecting that the service consumer is authorized to request the service from the producer of the service: provide the intermediary entity with a permission instruction, wherein the permission instruction indicates that the service consumer is authorized to request the service from the producer of the service.
24. The method according to any one of claims 22 to 23, further comprising: Receive registrations from the producers for the service; The registration is stored in the profile of the producer of the service, wherein The registration includes at least one of the following: - A whitelist, which includes one or more identifiers of first service consumers; or - A blacklist, which includes identifiers of one or more second service consumers; Each of the one or more first service consumers is authorized to request the service from the producer of the service; Each of the one or more second service consumers is not authorized to request the service from the producer of the service.
25. A method comprising: Receive requests for stored communication information of producers that provide services to service consumers; The registry server is checked to see if the service consumer is authorized to request the service from the producer of the service. The service consumer receives a non-permission instruction in response to the query from the registration server, wherein the non-permission instruction indicates that the service consumer is not authorized to request the service from the producer of the service. In response to receiving the non-permission instruction: prohibiting the provision of the service to the service consumer of the communication information stored by the producer.
26. The method of claim 25, further comprising: The service consumer receives a permission instruction in response to the query from the registration server, wherein the permission instruction indicates that the service consumer is authorized to request the service from the producer of the service; In response to receiving the permission instruction, the producer of the service provides the service consumer with the communication information stored therein.
27. The method according to any one of claims 25 to 26, wherein The communication information stored by the producer of the service is needed to request the service from the producer of the service.
28. The method according to any one of claims 25 to 27, further comprising: In response to receiving the non-permission instruction: notify the service consumer that the service consumer is not authorized to request the service from the producer of the service.
29. A method comprising: Receive a request for a profile of the producer providing the service; In response to receiving the request, the producer provides the profile of the service; in The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of first service consumers; or - A blacklist, which includes identifiers of one or more second service consumers; Each of the one or more first service consumers is authorized to request the service from the producer of the service; Each of the one or more second service consumers is not authorized to request the service from the producer of the service.
30. The method of claim 29, further comprising: Receive registrations from the producers for the service; The registration is stored in the profile of the producer of the service, wherein The registration includes at least one of the whitelist or the blacklist.
31. A method comprising: Receive a request, the request being used to communicate with the producer providing the service to the service consumer; Request the profile of the producer of the service from the registration server; Receive the producer's profile in response to the request for the profile; The profile is used to check whether the service consumer is authorized to request the service from the producer of the service. In response to a check based on the profile indicating that the service consumer is not authorized to request the service from the producer of the service: the communication information of the producer of the service is prohibited from being provided to the service consumer; in The profile includes at least one of the following: - A whitelist, which includes one or more identifiers of first service consumers; or - A blacklist, which includes identifiers of one or more second service consumers; Each of the one or more first service consumers is authorized to request the service from the producer of the service; Each of the one or more second service consumers is not authorized to request the service from the producer of the service.
32. The method of claim 31, further comprising: In response to determining, based on the profile, that the service consumer is authorized to request the service from the producer of the service, the communication information of the producer of the service is provided.
33. The method according to any one of claims 31 to 32, wherein The communication information of the producer of the service is needed to request the service from the producer of the service.
34. The method according to any one of claims 31 to 33, further comprising: In response to receiving the non-permission instruction: notify the service consumer that the service consumer is not authorized to request the service from the producer of the service.
35. A computer program product comprising an instruction set, which, when executed on a device, is configured to cause the device to perform the method according to any one of claims 18 to 34.
36. The computer program product according to claim 35 is embodied in a computer-readable medium or can be directly loaded into a computer.