Access Token Verification System and Method in Network Repository Function

By centralizing token verification within the NRF, the system addresses insecure key exchange issues in 3GPP's OAUTH, ensuring secure token validation and service provision without modifying the resource server.

JP2025524383APending Publication Date: 2025-07-30ジェイアイオー·プラットフォームズ·リミテッド
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024572460
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-06-29
Filing Date
2023-06-29
Publication Date
2025-07-30

AI Technical Summary

Technical Problem

The existing 3GPP standard for network function service access using Open Authentication (OAUTH) tokens lacks standardized key exchange mechanisms, leading to insecure key sharing methods between the Network Repository Function (NRF), consumer, and producer, which compromises security.

Method used

A system and method where the authentication server within the NRF is responsible for token verification, eliminating the need for key exchange with the resource server, ensuring secure token validation and service provision.

Benefits of technology

This approach enhances security by centralizing token verification within the NRF, providing a secure communication system without altering the resource server infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025524383000001_ABST
    Figure 2025524383000001_ABST
Patent Text Reader

Abstract

Provided is an access token verification system and method in a network repository function. The present disclosure provides a system and method for access token verification in a network repository function (NRF). The system includes an authentication server that receives tokens from various users, decrypts the tokens, and sends valid tokens to a resource server within a predetermined period. The resource server provides one or more services requested by various users via the authentication server within a predetermined period based on the valid tokens. Further, variations in the method of generating and verifying tokens are updated by the system itself without changing the resource server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] [Reservation of Rights] Part of the disclosure of this patent document includes materials that are the subject of intellectual property rights owned by Jio Platforms Limited (JPL) or its affiliates (hereinafter collectively referred to as the patentee), such as, but not limited to, copyrights, designs, trademarks, integrated circuit (IC) layout designs, and / or trade dress protection. The patentee does not object to the reproduction of the patent document or patent disclosure described in the patent file or records of the Patent and Trademark Office by a third party, but reserves all other rights. All rights to such intellectual property are fully reserved by the patentee.

[0002] Embodiments of the present disclosure generally relate to systems and methods for authentication in a network repository function. More specifically, the present disclosure relates to systems and methods for access token verification in a network repository function.

Background Art

[0003] The following description of related art is intended to provide background information related to the field of the present disclosure. This section may include specific aspects of the technology that may be related to various features of the present disclosure. However, this section is only intended to deepen the reader's understanding of the present disclosure and does not admit prior art.

[0004] As part of the authentication of network function (NF) service access, the 3rd Generation Partnership Project (3GPP (registered trademark)) provides standard authentication using an Open Authentication (OAUTH) token, in which the Network Repository Function (NRF) functions as an "authentication server", the consumer functions as an "OAUTH client", and the producer functions as an "OAUTH resource server". In the current system, when the consumer (OAUTH client) receives a token from the NRF, it sends the token to the producer (OATH resource server) that is responsible for verifying the token. With the above settings, a key can be pre-exchanged between the resource server and the authentication server, for which a clear flow is not standardized. Furthermore, since the key is specific to the deployment, a key pair (symmetric key / asymmetric key) that is usually shared between nodes by an insecure method will be used.

[0005] Therefore, there is a need in the art to provide a system and method that can mitigate problems associated with the prior art.

Summary of the Invention

Means for Solving the Problems

[0006] Some of the objectives of the present disclosure satisfied by at least one embodiment of this specification are listed below.

[0007] An objective of the present disclosure is to provide a system and method that omits the key exchange mechanism between the authentication server and the resource server and facilitates the verification process via the authentication server.

[0008] An objective of the present disclosure is to provide a system and method in which the authentication server is responsible for verifying the resources of the resource server, thereby realizing a secure implementation.

[0009] An objective of the present disclosure is to provide a system and method in which an efficient system can be obtained by verification by the authentication server.

[0010] An object of the present disclosure is to provide an enhanced secure communication system.

[0011] In this section, certain objects and aspects of the present disclosure, which will be described in detail in subsequent sections, are briefly explained. This summary is not intended to identify key features or to circumscribe the scope of the claimed subject matter.

[0012] In one aspect, the present disclosure relates to a system for token verification in a Network Repository Function (NRF). The system includes a processor and a memory operatively coupled to the processor storing instructions executed by the processor. The processor receives a token from one or more users via a computing device. The token is based on a Network Function (NF) request generated by one or more users. The processor decrypts the token received from one or more users and determines whether the decrypted token is valid. In response to an affirmative determination, the processor transmits the decrypted token to a resource server within a predetermined period. The processor receives a token verification request from the resource server within a predetermined time. The processor generates one or more requested services for one or more users via the resource server within a predetermined period.

[0013] In one embodiment, the processor may transmit a failure response to the resource server in response to a negative determination.

[0014] In one embodiment, the processor may receive a prohibition error response from the resource server at the expiration of a predetermined period.

[0015] In one embodiment, the processor may receive an access request from one or more users to the resource server based on the prohibition error response.

[0016] In one embodiment, the processor may send the network function instance identifier (NFinstanceID) to the resource server together with the decrypted token.

[0017] In one embodiment, the processor may generate a key based on the token received from one or more users, use the key to decrypt the token, and process the token verification request.

[0018] In one aspect, the present disclosure relates to a method for token verification in the NRF. The method includes receiving, by a processor associated with the system, a token from one or more users via a computing device. The token is based on an NF request generated by one or more users. The method includes decrypting, by the processor, the token received from one or more users and determining whether the decrypted token is valid. The method includes sending, in response to an affirmative determination, by the processor, the decrypted token to the resource server within a predetermined period. The method includes receiving, by the processor, a token verification request from the resource server within a predetermined period. The method includes generating, by the processor, one or more requested services for one or more users via the resource server within a predetermined period.

[0019] In one embodiment, the method may include sending, by the processor, a failure response to the resource server in response to a negative determination.

[0020] In one embodiment, the method may include receiving, by the processor, a prohibition error response from the resource server at the expiration of a predetermined period.

[0021] In one embodiment, the method may include receiving, by the processor, an access request from one or more users to the resource server based on the prohibition error response.

[0022] In one embodiment, the method may include a step of a processor sending an NFinstanceID to a resource server together with a decrypted token.

[0023] In one aspect, a user equipment (UE) for sending a token includes one or more processors communicatively coupled to a processor in the system. The one or more processors are coupled to a memory, and instructions executed by the one or more processors are stored in the memory. The one or more processors send the token to the processor via a network. The token is based on an NF request generated by one or more users. The processor is configured to receive the token from the UE. The processor is configured to decrypt the token received from one or more users and determine whether the decrypted token is valid. In response to a positive determination, the processor is configured to send the decrypted token to the resource server within a predetermined period. The processor is configured to receive a token verification request from the resource server within a predetermined period. The processor is configured to generate one or more requested services for the UE via the resource server within a predetermined period.

[0024] In one aspect, a non-transitory computer-readable medium includes a processor with executable instructions that enable the processor to receive a token from one or more users via a computing device. The token is based on an NF request generated by one or more users. The processor decrypts the token received from one or more users and determines whether the decrypted token is valid. In response to a positive determination, the processor sends the decrypted token to the resource server within a predetermined period. The processor receives a token verification request from the resource server within a predetermined period. The processor generates one or more requested services for one or more users via the resource server within a predetermined period.

[0025] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate exemplary embodiments of the disclosed methods and systems, and like reference numerals refer to like parts throughout the different views. The components in the drawings are not necessarily to scale, emphasis being placed instead on clearly illustrating the principles of the disclosure. In some of the drawings, block diagrams may be used to show components and may not represent the internal circuitry of each component. Those skilled in the art will appreciate that such a disclosure of the drawings includes a disclosure of the electrical, electronic, or circuit components generally used to implement such components.

Brief Description of the Drawings

[0026]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0027] For the purposes of the following description, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. However, it will be apparent that embodiments of the present disclosure may be practiced without these specific details. Some of the functions described below may be used independently or in combination with other functions. By themselves, the individual functions may or may not solve all of the problems described above, or may only solve some of the problems described above. Some of the problems described above may not be completely solved by any of the functions described below.

[0028] The following description provides only exemplary embodiments and is not intended to limit the scope, applicability, or configuration of the present disclosure. Rather, the purpose is to provide a valid description for those skilled in the art to implement the exemplary embodiments. It should be understood that various changes can be made to the functions and arrangements of the elements without departing from the spirit and scope of the described disclosure.

[0029] To enable a complete understanding of the embodiments, specific details are set forth in the following description. However, those skilled in the art will understand that the embodiments can be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown in block diagram form so as not to obscure the embodiments with unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail so as not to obscure the embodiments.

[0030] In addition, individual embodiments may be described as processes represented as flowcharts, flow diagrams, data flow diagrams, structure diagrams, or block diagrams. In a flowchart, operations are described as sequential processes, but many of the operations can be executed in parallel or simultaneously. Also, the order of operations can be changed. A process ends when the operation is completed, but there may be additional steps not included in the figure. A process can refer to a method, function, procedure, subroutine, subprogram, etc. When a process refers to a function, its end refers to the function returning to the calling function or the main function.

[0031] As used herein, the expressions "exemplary" and / or "illustrative" mean an example, instance, or illustration. To avoid doubt, the subject matter disclosed herein is not limited by such examples. Further, any aspect or design described as "exemplary" and / or "illustrative" herein should not necessarily be construed as more preferred or advantageous than other aspects or designs, nor is it intended to exclude equivalent exemplary structures and techniques known to those skilled in the art. Further, as long as the expressions "comprising", "having", "including", and other similar expressions are used in any of the detailed description or claims, such expressions are used in an inclusive sense without excluding additional elements or other elements.

[0032] Throughout this specification, references to "one embodiment", "an embodiment", "an example", or "one example" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the use of the expressions "in one embodiment" or "in an embodiment" in various places in this specification does not necessarily refer to the same embodiment. Further, the particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0033] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the present disclosure. As used herein, the singular forms "a," "an," and "the" are to be construed to include the plural forms as well, unless the context clearly dictates otherwise. Further, the expressions "comprises" and / or "comprising" used herein are meant to specify the presence of the stated features, integers, steps, operations, elements, or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. The expression "and / or" used herein includes any and all combinations of one or more of the associated listed items.

[0034] Various embodiments throughout the present disclosure will be described in more detail with reference to FIGS. 1-5.

[0035] FIG. 1 shows an exemplary network architecture (100) for implementing a system (108) proposed in accordance with an embodiment of the present disclosure.

[0036] As shown in FIG. 1, the network architecture (100) may include a system (108). The system (108) may be connected to one or more computing devices (104-1, 104-2... 104-N) via a network (106). The one or more computing devices (104-1, 104-2... 104-N) are equivalently designated as user equipment (UE) (104) and are operated by one or more users (102-1, 102-2... 102-N). Further, the one or more users (102-1, 102-2... 102-N) may be equivalently referred to as user (102). In one embodiment, the system (108) may be equivalently referred to as an authentication server or a network resource function (NRF).

[0037] In one embodiment, the computing device (104) includes, but is not limited to, mobile, laptop, etc. Further, the computing device (104) may include smartphones, virtual reality (VR) devices, augmented reality (AR) devices, general-purpose computers, desktops, personal digital assistants, tablet computers, and mainframe computers. Further, an input device for receiving input from a user (102) such as a touchpad, a touch screen, an electronic pen, etc. may be used. Those skilled in the art will understand that the computing device (104) is not limited to the aforementioned devices, and various other devices may be used. [[ID=***]] [[ID=***]]

[0038] [[ID=***]] In one embodiment, the network (106) may include at least a part of one or more networks, by way of example and not limitation, and this network has one or more nodes, and these nodes transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. of one or more messages, packets, signals, waves, voltage or current levels, combinations thereof, etc. The network may include, but is not limited to, one or more of a wireless network, a wired network, the Internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a public switched telephone network (PSTN), a cable network, a cellular network, a satellite network, an optical fiber network, or a combination thereof. [[ID=***]] [[ID=***]]

[0039] [[ID=***]] It should be noted that the tags ,

[0038] , , ,

[0039] , are left unchanged as required, but it seems there is an issue with the "***" placeholder in the original text where these tags are repeated in the translation template. If there is a specific rule or correct handling method for these tags in your actual scenario, it may need to be adjusted accordingly.In one embodiment, the system (108) may receive a token from one or more users (102) via a computing device (104). The token may be based on a network function (NF) request generated by one or more users (102). The system (108) can decrypt the token received from one or more users (102) and determine whether the decrypted token is valid. In response to a positive determination, the system (108) may send the decrypted token to a resource server within a predetermined period. Further, the system (108) may send a network function instance identifier (NFinstanceID) to the resource server together with the decrypted token.

[0040] In one embodiment, the system (108) may generate a key based on a token received from one or more users, use the key to decrypt the token, and process a token verification request.

[0041] Further, in one embodiment, the system (108) may receive a prohibited error response from a resource server at the expiration of a predetermined period. One or more users (102) may request access to the resource server based on the prohibited error response. The resource server may also be referred to as a producer or an open authentication (OAUTH) resource server.

[0042] In one embodiment, the system (108) may receive a token verification request from a resource server within a predetermined period. The system (108) may generate one or more requested services for one or more users (102) via the resource server within a predetermined period. Further, the resource server may send an NF service response to one or more users (102) based on a response from a processor (202).

[0043] FIG. 1 shows exemplary components of a network architecture (100), but in other embodiments of the network architecture (100), the number, type, and arrangement of components may be different from FIG. 1, or may include additional features not shown in FIG. 1. Further, or alternatively, functions described herein as being performed by one or more components of the network architecture (100) may be performed by one or more other components of the network architecture (100).

[0044] FIG. 2 shows an exemplary block diagram (200) of a system (108) according to an embodiment of the present disclosure.

[0045] According to FIG. 2, the system (108) may include one or more processors (202) that may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuits, and / or any device that processes data based on operation instructions. Among other functions, the one or more processors (202) may be configured to obtain and execute computer-readable instructions stored in the memory (204) of the system (108). The memory (204) may be configured to store one or more computer-readable instructions or routines in a non-transitory computer-readable storage medium, and these instructions or routines may be obtained and executed to create or share data packets via a network service. The memory (204) may include any non-transitory storage device, including, for example, volatile memory such as random access memory (RAM), or non-volatile memory such as erasable programmable read-only memory (EPROM), flash memory, etc.

[0046] The processing engine(s) (208) may be implemented as a combination of hardware and programming (e.g., programmable instructions) to implement one or more functions of the processing engine(s) (208). In the examples described herein, such a combination of hardware and programming may be implemented in several different ways. For example, the programming of the processing engine(s) (208) may be processor-executable instructions stored on a non-transitory machine-readable storage medium, and the hardware of the processing engine(s) (208) may include processing resources (e.g., one or more processors) for executing such instructions. In this embodiment, the machine-readable storage medium may store instructions that, when executed by the processing resources, implement the processing engine(s) (208). In such an embodiment, the system (108) may include a machine-readable storage medium that stores instructions and processing resources for executing the instructions, or the machine-readable storage medium may be separate but accessible to the system (108) and the processing resources. In other embodiments, the processing engine(s) (208) may be implemented by an electronic circuit.

[0047] In one embodiment, the system (108) may include interface(s) (206). The interface(s) (206) may include various interfaces, such as, for example, data input / output (I / O) devices and interfaces for storage devices. The interface(s) (206) may also provide a communication path to one or more components of the system (108). Examples of such components include, but are not limited to, the processing engine(s) (208) and the database (210). Examples of the processing engine(s) (208) may include, but are not limited to, a data acquisition engine (212).

[0048] In one embodiment, the processor (202) may receive tokens via a data capture engine (212). The tokens may be received from one or more users (102) via a computing device (104). The processor (202) may store the tokens in a database (210). The tokens may be based on NF requests generated by one or more users (102). The processor (202) may decrypt the tokens received from one or more users (102) and determine whether the decrypted tokens are valid. In response to a positive determination, the processor (202) may send the decrypted tokens to a resource server within a predetermined period. Further, the processor (202) may send the NF instance ID to the resource server along with the decrypted tokens.

[0049] In one embodiment, the processor (202) may generate a key based on tokens received from one or more users, use the key to decrypt the tokens, and process token verification requests.

[0050] Further, in one embodiment, the processor (202) may receive a prohibition error response from a producer at the expiration of a predetermined period. One or more users (102) may request access to the resource server based on the prohibition error response.

[0051] In one embodiment, the processor (202) may receive a token verification request from a resource server within a predetermined period. The processor (202) may generate one or more requested services for one or more users (102) via the resource server within the predetermined period. Further, the producer may send an NF service response to one or more users (102) based on a positive or negative determination from the processor (202).

[0052] FIG. 2 illustrates the components of system (108), but in other embodiments, system (108) may include a different number, type, or arrangement of components than FIG. 2, or additional features not shown in FIG. 2. Further, or alternatively, functions described herein as being performed by one or more components of system (108) may be performed by one or more other components of system (108).

[0053] FIG. 3 shows an exemplary flow diagram (300) of token verification according to one embodiment of the present disclosure.

[0054] As shown in FIG. 3, the standard flow diagram (300) of token verification may include the following steps.

[0055] Step 308: The consumer / client (302) may send an NF service request / access token to the producer / resource server (306).

[0056] Step 310: The producer / resource server (306) may verify the NF service request based on a local key generated by agreement with the NRF / authentication server (304).

[0057] Step 312: The producer / resource server (306) may send an NF service response to the consumer / client (302) based on the success or failure of the agreement with the NRF / authentication server (304).

[0058] FIG. 4 shows an exemplary flow diagram (400) of token verification by the NRF according to one embodiment of the present disclosure.

[0059] As shown in FIG. 4, the flow diagram (400) of token verification by the authentication server / NRF (404) may include the following steps.

[0060] Step 408: The consumer / client (402) may send an NF service request / access token to the producer / resource server (406). The NF service request may include an access token provided by the consumer / client (402).

[0061] Step 410: The producer / resource server (406) may send an access token verification request to the authentication server / NRF (404). The verification request of the access token may be performed based on the NF service request initiated by the consumer / client (402).

[0062] Step 412: The authentication server / NRF (404) may decrypt the success token and verify the access token based on the access token verification request from the producer / resource server (406).

[0063] Step 414: The authentication server / NRF (404) may send a success / failure response to the producer / resource server (406) based on the verification of the token.

[0064] Step 416: The producer / resource server (406) may determine whether to accept or reject the NF service request from the consumer / client (402) based on the success / failure response from the authentication server / NRF (404).

[0065] Step 418: The producer / resource server (406) may send an NF service response to the consumer / client (402) based on the success / failure response from the authentication server / NRF (404).

[0066] FIG. 5 shows an exemplary computer system (500) in which embodiments of the present invention can be implemented or are implemented.

[0067] As shown in FIG. 5, computer system (500) may include an external storage device (510), a bus (520), a main memory (530), a read-only memory (540), a mass storage device (550), communication port(s) (560), and a processor (570). Those skilled in the art will understand that computer system (500) may include multiple processors and communication ports. Processor (570) may include various modules related to embodiments of the present disclosure. Communication port(s) (560) may be an RS-232 port for use in a modem-based dial-up connection, a 10 / 100 Ethernet port, a 1 gigabit or 10 gigabit port using copper wire or fiber optic, a serial port, a parallel port, or any other existing or future port. Communication port(s) (560) may be selected according to any network to which computer system (500) connects, such as a local area network (LAN) or a wide area network (WAN).

[0068] In one embodiment, main memory (530) may be a random access memory (RAM) or any other dynamic storage device commonly known in the art. Read-only memory (540) may be any static storage device(s), such as a programmable read-only memory (PROM) chip for storing static information such as startup or basic input / output system (BIOS) instructions of processor (570), but is not limited thereto. Mass storage device (550) may be any means of current or future mass storage device capable of storing information and instructions. Exemplary means of mass storage include, but are not limited to, a parallel advanced technology attachment (PATA) or serial advanced technology attachment (SATA) hard disk drive, or a solid state drive (for internal or external use, such as having a universal serial bus (USB) and / or Firewire interface).

[0069] In one embodiment, the bus (520) can couple the processor(s) (570) to other memories, storage, and communication blocks in a communicable manner. The bus (520) can be, for example, a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus for connecting expansion cards, drives, and other subsystems, a Small Computer System Interface (SCSI), a Universal Serial Bus (USB), or other buses such as a Front Side Bus (FSB) that connects the processor (570) to the computer system (500).

[0070] In another embodiment, an operator / administrator interface, such as a display, keyboard, cursor control device, can also be coupled to the bus (520) to enable direct operation of the computer system (500) by an operator. Other operator / administrator interfaces can be connected via a network connected through communication port(s) (560). The above components are only for the purpose of exemplifying various possibilities. The aforementioned exemplary computer system (500) is in no way intended to limit the scope of the present disclosure.

[0071] Although a preferred embodiment is emphasized here, it is understood that many embodiments are feasible without departing from the principles of the disclosure, and many changes can be made to the preferred embodiment. These and other changes to the preferred embodiment of the present disclosure will be apparent to those skilled in the art from the disclosure herein, and it is clearly understood that the foregoing description is merely illustrative of the disclosure and not limiting.

[0072] [Advantages of the Invention] The present disclosure provides a system and method that provides an insecure method of key exchange by a single Network Repository Function (NRF) incorporating both token generation and verification.

[0073] The present disclosure provides a system and method that can provide additional security enhancements using various methods different from normal standards while processing requests from various consumers without changing the resource server.

[0074] The present disclosure provides a system and method that can execute changes to token generation and verification methods on the authentication server itself without making changes to the resource server.

Claims

1. A system (108) for token verification in a network repository function (NRF), the system (108) comprising: a processor (202); a memory (204) operably coupled to the processor (202), the memory (204) storing instructions which, when executed by the processor (202), receive a token from one or more users (102) via a computing device (104), the token being based on a network function (NF) request generated by the one or more users (102); decoding the token received from the one or more users (102) and determining whether the decoded token is valid; in response to a positive determination, transmitting the decoded token to a resource server within a predetermined period; receiving a token verification request from the resource server within a predetermined time; generating one or more requested services for the one or more users (102) via the resource server within a predetermined period; a system (108) for causing the processor (202) to execute.

2. The system (108) according to claim 1, wherein the processor (202) transmits a failure response to the resource server in response to a negative determination.

3. The system (108) according to claim 1, wherein the processor (202) receives a prohibited error response from the resource server when a predetermined period expires.

4. The system (108) according to claim 3, wherein the processor (202) receives an access request from the one or more users (102) to the resource server based on the prohibited error response.

5. The system (108) according to claim 1, wherein the processor (202) transmits a network function instance identifier (NFinstanceID) to the resource server together with the decoded token.

6. The system (108) according to claim 1, wherein the processor (202) generates a key based on a token received from the one or more users (102), uses the key to decode the token, and processes the token verification request.

7. A method for token verification in a network repository function (NRF), the method comprising: Receiving, by a processor (202) associated with a system (108), a token from one or more users (102) via a computing device (104), the token being based on a network function (NF) request generated by the one or more users (102); Decoding, by the processor (202), the token received from the one or more users (102) and determining whether the decoded token is valid; In response to a positive determination, transmitting, by the processor (202), the decoded token to a resource server within a predetermined period; Receiving, by the processor (202), a token verification request from the resource server within a predetermined time; Generating, by the processor (202), one or more requested services for the one or more users (102) via the resource server within a predetermined period; A method comprising.

8. The method according to claim 7, further comprising transmitting, by the processor (202), a failure response to the resource server in response to a negative determination.

9. The method according to claim 7, further comprising receiving, by the processor (202), a prohibition error response from the resource server when a predetermined period expires.

10. The method according to claim 9, further comprising receiving, by the processor (202), an access request from the one or more users (102) to the resource server based on the prohibition error response.

11. The method according to claim 7, further comprising transmitting, by the processor (202), a network function instance identifier (NFinstanceID) to the resource server together with the decoded token.

12. A user equipment (UE) (104) for transmitting a token, the UE (104) comprising: One or more processors communicatively coupled to a processor (202) associated with a system (108) Comprising. The one or more processors are coupled to a memory, and instructions are stored in the memory, and when the instructions are executed by the one or more processors, the one or more processors are caused to send a token to the processor (202) via a network (106), the token being based on a network function (NF) request generated by one or more users (102), be executed to The processor (202) receives a token from the UE (104), decodes the token and determines whether the decoded token is valid, in response to a positive determination, sends the decoded token to a resource server within a predetermined period, receives a token verification request from the resource server within a predetermined period, generate one or more services requested for the UE (104) via the resource server within a predetermined period configured user equipment (UE).

13. A non-transitory computer-readable medium comprising a processor having executable instructions, the instructions being receiving a token from one or more users (102) via a computing device (104), the token being based on a network function (NF) request generated by the one or more users (102), decoding the token received from the one or more users (102) and determining whether the decoded token is valid, in response to a positive determination, sending the decoded token to a resource server within a predetermined period, receiving a token verification request from the resource server within a predetermined time, generating one or more requested services for the one or more users (102) via the resource server within a predetermined period, causing the processor to execute the non-transitory computer-readable medium.