Authentication of network services
The method and system for authenticating network services using multiple credentials and access tokens address the lack of indirect authorization in wireless communication networks, ensuring valid credentials and secure service authorization.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- LENOVO (SINGAPORE) PTE LTD
- Filing Date
- 2022-02-18
- Publication Date
- 2026-06-02
AI Technical Summary
Certain wireless communication networks lack support for indirect authorization of services, leading to inefficiencies in network service authentication.
A method and system for authenticating network services by using multiple credentials and access tokens to facilitate communication between network devices, enabling indirect authorization through a network function service request and response mechanism.
Enhances network service authentication by ensuring valid credentials and access permissions, allowing for efficient and secure indirect service authorization.
Smart Images

Figure 0007869232000001 
Figure 0007869232000002 
Figure 0007869232000003
Abstract
Description
Technical Field
[0001] Cross - Reference to Related Applications This application claims priority to U.S. Patent Application No. 63 / 151,490, titled "APPARATUSES, METHODS, AND SYSTEMS FOR AUTHORIZING AN NF SERVICE CONSUMER TO ACCESS A SERVICE FROM AN NF SERVICE PRODUCER INDIRECTLY VIA AN INTERMEDIATE NF", filed on February 19, 2021, by Dimitrios Karampatsis, which is hereby incorporated by reference in its entirety.
[0002] The subject matter disclosed herein generally relates to wireless communication, and more particularly to the authentication of network services.
Background Art
[0003] In certain wireless communication networks, a device may be authorized to access a service. In such networks, the authorization of services may not be supported indirectly.
Summary of the Invention
Means for Solving the Problems
[0004] A method for authenticating network services is disclosed. Devices and systems also perform the functions of the method. One embodiment of the method includes the step of a first network device receiving a network function service request from a second network device for performing a service on a third network device. The request includes first credentials for authentication by the first network device and second credentials for authentication by the third network device. In some embodiments, the method includes the step of performing the service request by determining whether the provided first credentials are valid and determining the third network device to perform the requested service from the second network device. In certain embodiments, the method includes the step of sending an authentication request from the third network device to a fourth network device. The request includes an identifier for the third network device and second credentials for the second network device. In various embodiments, the method includes the step of receiving third credentials from the fourth network device for initiating a network function (NF) service using the third network function. In some embodiments, the method includes the step of sending an NF service initiation request to the third network device. The request includes authentication credentials, including the second and third credentials.
[0005] One device for authenticating network services includes a first network device. In some embodiments, the device includes a receiver that receives a network function service request from a second network device for performing a service on a third network device. This request includes first credentials for authentication by the first network device and second credentials for authentication by the third network device. In various embodiments, the device includes a processor that performs the service request by determining whether the provided first credentials are valid and determining which third network device will perform the service requested by the second network device. In certain embodiments, the device includes a transmitter that sends an authentication request from the third network device to a fourth network device. The request includes an identifier for the third network device and second credentials for the second network device. The receiver receives third credentials from the fourth network device for initiating a network function (NF) service using the third network function. The transmitter sends an NF service initiation request to the third network device. The request includes authentication credentials, including the second and third credentials.
[0006] Another embodiment of a method for authenticating network services includes the step of sending a request for authorization from a second network device to a fourth network device to access services of a first network device. In some embodiments, the method includes the step of receiving first credentials, including an access token, from the fourth network device. In certain embodiments, the method includes the step of sending a network function service request to the first network device for performing services from a third network device, the network function service request comprising first credentials for authentication by the first network device and second credentials for authentication by the third network device. The first credentials include a first access token, and the second credentials include a second access token generated by the second network device. In various embodiments, the method includes the step of receiving a response to the network function service request from the first network device.
[0007] Another device for authenticating network services includes a second network device. In some embodiments, this device includes a transmitter that sends a request for authorization to a fourth network device to access services from the first network device. In various embodiments, this device includes a receiver that receives first credentials, including an access token, from the fourth network device. The transmitter sends a network function service request to the first network device for performing services from the third network device, the network function service request including first credentials for authentication by the first network device and second credentials for authentication by the third network device. The first credentials include a first access token, and the second credentials include a second access token generated by the second network device. The receiver receives a response from the first network device to the network function service request.
[0008] Further embodiments of the method for authenticating network services include the step of a fourth network device receiving an authentication request from a first network device to a third network device. The request includes first credentials, which include an access token for the second network device and an identifier for the third network device. In some embodiments, the method includes the step of determining whether the first and second network devices are permitted to access the services of the third network device. In certain embodiments, the method includes the step of generating second credentials, which include a second access token, in response to the determination that the first and second network devices are permitted to access the services. In various embodiments, the method includes the step of sending the second credentials to the first network device to initiate the NF service.
[0009] Further devices for authenticating network services include a fourth network device. In some embodiments, this device includes a receiver that receives an authentication request from a third network device from a first network device. The request includes first credentials, which include an access token for the second network device and an identifier for the third network device. In various embodiments, this device includes a processor that determines whether the first and second network devices are permitted to access the services of the third network device, and, in response to the determination that the first and second network devices are permitted to access the services, generates second credentials, which include a second access token. In certain embodiments, this device includes a transmitter that sends the second credentials to the first network device for initiating an NF service.
[0010] A more specific description of the embodiments briefly outlined above is made by reference to the specific embodiments shown in the accompanying drawings. Understanding that these drawings illustrate only a few embodiments and should therefore not be considered limiting in scope, the embodiments are described and explained more specifically and in detail through the use of the accompanying drawings. [Brief explanation of the drawing]
[0011] [Figure 1] This is a schematic block diagram showing one embodiment of a wireless communication system for authentication of network services. [Figure 2] This is a schematic block diagram showing one embodiment of a device that may be used for authenticating network services. [Figure 3] This is a schematic block diagram showing one embodiment of a device that may be used for authenticating network services. [Figure 4] This is a schematic block diagram showing one embodiment of a system for data acquisition via DCCF. [Figure 5] This is a schematic block diagram showing one embodiment of a system for an NF service consumer requesting access to services from an NF service producer via an NRF. [Figure 6] This is a schematic block diagram illustrating one embodiment of a system for an NF service producer to perform requested services based on an access token. [Figure 7] This is a schematic block diagram illustrating one embodiment of a system that authorizes access to a service via an intermediate NF. [Figure 8] This flowchart illustrates one embodiment of a method for authenticating network services. [Figure 9] This flowchart illustrates another embodiment of a method for authenticating network services. [Figure 10] This flowchart illustrates a further embodiment of a method for authenticating network services. [Modes for carrying out the invention]
[0012] As those skilled in the art will understand, embodiments of an embodiment can be embodied as a system, apparatus, method, or program product. Thus, an embodiment can take the form of a purely hardware embodiment, a purely software embodiment (including firmware, resident software, microcode, etc.), or a combination of software and hardware embodiments, which may be commonly referred to herein as “circuits,” “modules,” or “systems.” Furthermore, an embodiment can take the form of a program product embodied in one or more computer-readable storage devices that store machine-readable code, computer-readable code, and / or program code, hereinafter referred to as code. The storage device may be tangible, non-transient, and / or non-transmitting. The storage device may not embody signals. In certain embodiments, the storage device uses only signals for accessing the code.
[0013] Certain functional units described herein may be labeled as modules to more specifically emphasize the independence of their implementation forms. For example, modules may be implemented as hardware circuits comprising custom very-large-scale integration (VLSI) circuits or off-the-shelf semiconductors such as gate arrays, logic chips, transistors, or other discrete components. Modules may also be implemented in programmable hardware devices such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0014] Modules can also be implemented in code and / or software for execution by various types of processors. An identified module of code may contain one or more physical or logical blocks of executable code, which can be organized, for example, as objects, procedures, or functions. Nevertheless, the executable files of an identified module do not need to be physically located together, but may contain heterogeneous instructions stored in different locations, which, when logically combined, constitute the module and achieve the stated purpose of the module.
[0015] In fact, a module of code may be a single instruction or a number of instructions, and may even be distributed across several different code segments, across different programs and multiple memory devices. Similarly, operational data may be identified and illustrated within a module as herein, embodied in any suitable form, and organized within any suitable type of data structure. Operational data may be collected as a single dataset or distributed across different locations, including different computer-readable storage devices. If a module or part of a module is implemented in software, the software portion may be stored in one or more computer-readable storage devices.
[0016] Any combination of one or more computer-readable media may be used. The computer-readable media may be computer-readable storage media. The computer-readable storage media may be a storage device that stores code. The storage device may be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, holographic, micromechanical, or semiconductor system, apparatus, or device, or any suitable combination thereof.
[0017] More specific examples of storage devices (a non-exclusive list) include electrical connections having one or more wires, portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In the context of this specification, a computer-readable storage medium may be any tangible medium that can contain or store programs for use by or in connection with an instruction execution system, apparatus, or device.
[0018] The code for performing the operations of the embodiments may consist of any number of lines and may be written in any combination of one or more programming languages, including object-oriented programming languages such as Python, Ruby, Java, Smalltalk, and C++, and traditional procedural programming languages such as the "C" programming language, and / or machine languages such as assembly language. The code may run entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), and may be connected to an external computer (for example, via the Internet using an Internet Service Provider).
[0019] Throughout this specification, references to "one embodiment", "an embodiment", or similar terms mean that the particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment. Thus, appearances of the phrases "in one embodiment", "in an embodiment", and similar terms throughout this specification are not necessarily all referring to the same embodiment, but may be, although not necessarily so, unless otherwise explicitly specified, they mean "one or more but not all embodiments". The terms "including", "comprising", "having", and variations thereof mean "including but not limited to" unless otherwise explicitly specified. A list of listed items does not mean that some or all of the items are mutually exclusive unless otherwise explicitly specified. The terms "a", "an", and "the" also mean "one or more" unless otherwise explicitly specified.
[0020] Furthermore, the described features, structures, or characteristics of the embodiments may be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., in order to provide a thorough understanding of the embodiments. However, those skilled in the art will recognize that embodiments may be implemented without one or more of the specific details, or with other methods, components, materials, etc. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the embodiments.
[0021] Aspects of the embodiments will be described below with reference to schematic flowcharts and / or schematic block diagrams of methods, apparatuses, systems, and program products according to the embodiments. It will be understood that each block of the schematic flowcharts and / or schematic block diagrams, as well as combinations of blocks in the schematic flowcharts and / or schematic block diagrams, can be implemented by code. The code creates means for implementing the functions / operations specified in the blocks of the schematic flowchart and / or schematic block diagram by providing instructions that are executed via a processor of a computer or other programmable data processing device, and can be provided to the processor of a general-purpose computer, a dedicated computer, or other programmable data processing device to create a machine.
[0022] The code can also be stored in a storage device that, when the instructions stored in the storage device implement the functions / acts specified in the blocks of the schematic flowchart and / or schematic block diagram, enables a computer, other programmable data processing device, or other device to function in a particular manner.
[0023] The code can also be loaded onto a computer, other programmable data processing device, or other device such that a series of operational steps executed on the computer or other programmable device implement a process for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram, and a process executed by the computer is generated.
[0024] The schematic flowcharts and / or schematic block diagrams in the drawings illustrate the architecture, function, and operation of possible implementations of devices, systems, methods, and program products in various embodiments. In this regard, each block in the schematic flowcharts and / or schematic block diagrams may represent a module, segment, or portion of code containing one or more executable instructions of code for implementing a specified logical function.
[0025] It should also be noted that in some alternative embodiments, the functions described in a block may differ from the order shown in the drawing. For example, two blocks shown consecutively may actually be executed substantially simultaneously, or, depending on the related functions, the blocks may be executed in reverse order. Other steps and methods may be conceivable that are equivalent in function, logic, or effect to one or more blocks or parts thereof in the shown drawing.
[0026] In flowcharts and / or block diagrams, various types of arrows and lines may be used, but it should be understood that these do not limit the scope of the corresponding embodiment. In fact, some arrows or other connectors may be used to show only the logical flow of the illustrated embodiment. For example, an arrow may indicate an unspecified waiting or monitoring period between the enumerated steps of the depicted embodiment. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, can be implemented by a dedicated hardware-based system or a combination of dedicated hardware and code that performs a specified function or operation.
[0027] The descriptions of elements in each drawing may refer to elements in previous drawings. Similar numbers refer to the same element in all drawings, including alternative embodiments of the same element.
[0028] Figure 1 shows an embodiment of a wireless communication system 100 for authentication of network services. In one embodiment, the wireless communication system 100 includes a remote unit 102 and a network unit 104. Although a specific number of remote units 102 and network units 104 are shown in Figure 1, those skilled in the art will recognize that any number of remote units 102 and network units 104 may be included in the wireless communication system 100.
[0029] In one embodiment, the remote unit 102 may include computing devices such as desktop computers, laptop computers, personal digital assistants (PDAs), tablet computers, smartphones, smart TVs (e.g., Internet-connected TVs), set-top boxes, game consoles, security systems (including security cameras), in-vehicle computers, network devices (e.g., routers, switches, modems), aircraft, drones, and the like. In some embodiments, the remote unit 102 includes wearable devices such as smartwatches, fitness bands, and optical head-mounted displays. Furthermore, the remote unit 102 may be referred to as subscriber units, mobile, mobile stations, users, terminals, mobile terminals, fixed terminals, subscriber stations, user equipment (UE), user terminals, devices, or other terms used in the art. The remote unit 102 may communicate directly with one or more of the network units 104 via UL communication signals. In certain embodiments, the remote unit 102 may communicate directly with other remote units 102 via side-link communication.
[0030] The network unit 104 can be distributed across geographical areas. In certain embodiments, the network unit 104 also includes access points, access terminals, base stations, base stations, location servers, core network (CN), radio network entities, node B, evolved node-B (eNB), 5G node-B (gNB), home node B, relay nodes, devices, core network, airborne servers, radio access nodes, access points (AP), new radio (NR), network entities, access and mobility management function (AMF), unified data management (UDM), unified data repository (UDR), UDM / UDR, policy control function (PCF), radio access network (RAN), network slice selection function (NSSF), operations, administration, and management (OAM), session management function (SMF), and user plane function ( It may be referred to as UPF, application function, authentication server function (AUSF), security anchor functionality (SEAF), trusted non-3GPP gateway function (TNGF), or any other term used in the art, and / or may include them.A network unit 104 is generally part of a wireless access network that includes one or more controllers commutably coupled to one or more corresponding network units 104. A wireless access network is generally commutably coupled to one or more core networks, which may be coupled to other networks, including the Internet and public switched telephone networks. These and other elements of wireless access and core networks are not shown but are generally well known to those skilled in the art.
[0031] In one implementation, the wireless communication system 100 conforms to the NR protocol standardized in the third-generation partnership project (3GPP), the network unit 104 transmits using OFDM modulation on the downlink (DL), and the remote unit 102 transmits on the uplink (UL) using either single-carrier frequency division multiple access (SC-FDMA) or orthogonal frequency division multiplexing (OFDM). However, more generally, the wireless communication system 100 may implement other open or proprietary communication protocols, such as WiMAX, a variant of the Institute of Electrical and Electronics Engineers (IEEE) 802.11, Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Universal Mobile Telecommunications System (UMTS), a variant of Long Term Evolution (LTE), Code Division Multiple Access 2000 (CDMA2000), Bluetooth®, ZigBee, and Sigfoxx. This disclosure is not intended to be limited to any particular wireless communication system architecture or protocol implementation.
[0032] The network unit 104 may provide services to several remote units 102 within a service area, such as a cell or cell sector, via a wireless communication link. The network unit 104 transmits DL communication signals to provide services to the remote units 102 in the domains of time, frequency, and / or space.
[0033] In various embodiments, the network unit 104 may receive a network function service request from a second network device at a first network device for performing a service on a third network device. This request includes first credentials for authentication by the first network device and second credentials for authentication by the third network device. In some embodiments, the network unit 104 may perform the service request by determining whether the provided first credentials are valid and determining which third network device will perform the requested service from the second network device. In certain embodiments, the network device 104 may send an authentication request from the third network device to a fourth network device. The request includes an identifier for the third network device and second credentials for the second network device. In various embodiments, the network unit 104 may receive third credentials from the fourth network device for initiating a network function (NF) service using the third network function. In some embodiments, the network unit 104 may send an NF service initiation request to the third network device. The request includes authentication credentials, which include a second and a third set of credentials. Therefore, the network unit 104 can be used for authentication of network services.
[0034] In certain embodiments, network unit 104 may send an authorization request from a second network device to a fourth network device for access to services of the first network device. In some embodiments, network unit 104 may receive first credentials, including an access token, from the fourth network device. In certain embodiments, network unit 104 may send a network function service request to the first network device for performing services from a third network device, the network function service request comprising first credentials for authentication by the first network device and second credentials for authentication by the third network device. The first credentials include a first access token, and the second credentials include a second access token generated by the second network device. In various embodiments, network unit 104 may receive a response to the network function service request from the first network device. Thus, network unit 104 can be used for authentication of network services.
[0035] In some embodiments, the network unit 104 may receive an authentication request from the first network device to the third network device at the fourth network device. This request includes first credentials, which include an access token for the second network device and an identifier for the third network device. In some embodiments, the network unit 104 may determine whether the first and second network devices are permitted to access the services of the third network device. In certain embodiments, in response to the determination that the first and second network devices are permitted to access the services, the network unit 104 may generate second credentials, which include a second access token. In various embodiments, the network unit 104 may send second credentials to the first network device to initiate an NF service. Thus, the network unit 104 can be used for authentication of network services.
[0036] Figure 2 shows one embodiment of a device 200 that may be used for authenticating network services. The device 200 includes one embodiment of a remote unit 102. Furthermore, the remote unit 102 may include a processor 202, memory 204, an input device 206, a display 208, a transmitter 210, and a receiver 212. In some embodiments, the input device 206 and the display 208 are coupled to a single device such as a touchscreen. In certain embodiments, the remote unit 102 may not include any input device 206 and / or a display 208. In various embodiments, the remote unit 102 may include one or more of the processor 202, memory 204, transmitter 210, and receiver 212, and may not include the input device 206 and / or a display 208.
[0037] In one embodiment, the processor 202 may include any known controller capable of executing computer-readable instructions and / or logical operations. For example, the processor 202 may be a microcontroller, microprocessor, central processing unit (CPU), graphics processing unit (GPU), auxiliary processing unit, field programmable gate array (FPGA), or similar programmable controller. In some embodiments, the processor 202 executes instructions stored in memory 204 to perform the methods and routines described herein. The processor 202 is communicatively coupled to memory 204, input device 206, display 208, transmitter 210, and receiver 212.
[0038] In one embodiment, memory 204 is a computer-readable storage medium. In some embodiments, memory 204 includes a volatile computer storage medium. For example, memory 204 may include RAM, including dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), and / or static RAM (SRAM). In some embodiments, memory 204 includes a non-volatile computer storage medium. For example, memory 204 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, memory 204 includes both volatile and non-volatile computer storage media. In some embodiments, memory 204 also stores program code and associated data, such as an operating system or other controller algorithms running on the remote unit 102.
[0039] In one embodiment, the input device 206 may include any known computer input device, such as a touch panel, buttons, a keyboard, a stylus, or a microphone. In some embodiments, the input device 206 may be integrated with the display 208, for example, as a touchscreen or similar touch-sensitive display. In some embodiments, the input device 206 includes a touchscreen so that text can be entered using a virtual keyboard displayed on the touchscreen and / or by writing on the touchscreen. In some embodiments, the input device 206 includes two or more different devices, such as a keyboard and a touch panel.
[0040] In one embodiment, the display 208 may include any known electronically controllable display or display device. The display 208 may be designed to output visual signals, auditory signals, and / or tactile signals. In some embodiments, the display 208 includes an electronic display that can output visual data to a user. For example, the display 208 may include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, an organic light-emitting diode (OLED) display, a projector, or a similar display device that can output images, text, etc., to a user. In another non-limiting example, the display 208 may include a wearable display such as a smartwatch, smart glasses, or a head-up display. Furthermore, the display 208 may be a component of a smartphone, personal digital assistant, television, table computer, notebook (laptop) computer, personal computer, or vehicle dashboard.
[0041] In certain embodiments, the display 208 includes one or more speakers for generating sound. For example, the display 208 may generate audible alerts or notifications (e.g., beeps or chimes). In some embodiments, the display 208 includes one or more haptic devices for generating vibration, motion, or other tactile feedback. In some embodiments, all or part of the display 208 may be integrated with an input device 206. For example, the input device 206 and the display 208 may form a touchscreen or similar touch-sensitive display. In other embodiments, the display 208 may be positioned near the input device 206.
[0042] Although only one transmitter 210 and one receiver 212 are shown, the remote unit 102 may have any appropriate number of transmitters 210 and receivers 212. The transmitters 210 and receivers 212 can be any appropriate type of transmitter and receiver. In one embodiment, the transmitters 210 and receivers 212 may be part of a transceiver.
[0043] Figure 3 shows one embodiment of a device 300 that may be used for authenticating network services. The device 300 includes one embodiment of a network unit 104. Furthermore, the network unit 104 may include a processor 302, memory 304, input device 306, display 308, transmitter 310, and receiver 312. As can be understood, the processor 302, memory 304, input device 306, display 308, transmitter 310, and receiver 312 may be substantially the same as the processor 202, memory 204, input device 206, display 208, transmitter 210, and receiver 212 of a remote unit 102, respectively.
[0044] In certain embodiments, receiver 312 receives a network function service request from a second network device for performing a service on a third network device. This request includes first credentials for authentication by the first network device and second credentials for authentication by the third network device. In various embodiments, processor 302 performs the service request by determining whether the provided first credentials are valid and determining which third network device will perform the service requested by the second network device. In certain embodiments, transmitter 310 transmits an authentication request from the third network device to a fourth network device. The request includes an identifier for the third network device and second credentials for the second network device. Receiver 312 receives third credentials from the fourth network device for initiating a network function (NF) service using the third network function. Transmitter 310 transmits an NF service initiation request to the third network device. The request includes authentication credentials, which include second and third credentials.
[0045] In some embodiments, the transmitter 310 sends a request to a fourth network device for authorization to access services from the first network device. In various embodiments, the receiver 312 receives first credentials, including an access token, from the fourth network device. The transmitter 310 sends a network function service request to the first network device for performing services from the third network device, the network function service request including first credentials for authentication by the first network device and second credentials for authentication by the third network device. The first credentials include a first access token, and the second credentials include a second access token generated by the second network device. The receiver 312 receives a response to the network function service request from the first network device.
[0046] In various embodiments, the receiver 312 receives an authentication request from the first network device for the third network device. This request includes first credentials, which include an access token for the second network device and an identifier for the third network device. In various embodiments, the processor 302 determines whether the first and second network devices are permitted to access the services of the third network device, and, in response to the determination that the first and second network devices are permitted to access the services, generates second credentials, which include a second access token. In certain embodiments, the transmitter 310 transmits the second credentials to the first network device for initiating the NF service.
[0047] In certain embodiments, there may be a data collection coordination function (DCCF) that coordinates the collection of data from one or more network functions ("NFs") based on data collection requests from one or more consumer NFs.
[0048] Figure 4 is a schematic block diagram showing one embodiment of system 400 for data acquisition via DCCF. System 400 includes DCCF402, Network Repository Function ("network repository function: NRF") 404 (DCCF402 discovers NF by sending to NRF404 (406)), Data Producer NF Instance 408 (e.g., AMF) (DCCF402 sends event exposures (e.g., event IDs) to Data Producer NF Instance 408 (410)), Data Producer NF Instance 412 (e.g., SMF) (DCCF402 sends event exposures (e.g., event IDs) to Data Producer NF Instance 412 (414)), Data Producer NF Instance 416 (e.g., Application Function ("application function: AF")) (DCCF402 sends event exposures (e.g., event IDs) to Data Producer NF Instance 416 (418)), and Consumer NF (e.g., Network Data Analytics Function ("network data analytics function: NWDAF))420 (Consumer NF420 sends Ndccf_Request data with an event ID to DCCF402 (422)). DCCF402 determines the data producer NF based on one or more event IDs (424).
[0049] The procedure for collecting data via DCCF402, as shown in Figure 4, is as follows: 1) Consumer NF420 requests data by calling the Ndccf service operation to DCCF402, in which the consumer NF420 includes an event ID for data collection (e.g., an event ID supported by each NF), 2) since there is a specific event ID supported by each NF, DCCF402 determines the NF type (e.g., AMF, SMF, AF) from the event ID requested by consumer NF420, determines the NF instance that has the required data from NRF404, and 3) DCCF402 then subscribes to receive notifications of events from each NF type using the Nnf_Event_Exposure subscription.
[0050] In some embodiments, when an NF service consumer requests a service invocation (e.g., a data collection request) from an NF service producer, the NF service consumer requests access to the service from the NRF, as shown in Figure 5. The NRF determines whether the NF service consumer is authorized to access the service, and if authorization is granted, provides the NF service consumer with an access token to include when the service consumer initiates a service request to the NF service producer, as shown in Figure 6. The NF service producer uses the NRF to verify whether the access token is valid before accepting the service.
[0051] Figure 5 is a schematic block diagram showing one embodiment of a system 500 for an NF service consumer requesting access to services from an NF service producer via an NRF. The system 500 includes an NF service consumer 502 (e.g., NWDAF) and an authorization (e.g., auth.) server 504 (e.g., NRF). Each illustrated communication may contain one or more messages.
[0052] In the first communication 506, the NF service consumer 502 sends an Nnrf_Access Token_Get request to the authorization server 504, which may include the expected NF service name and NF type: source NF. The authorization server 504 may authorize the client (508) and generate an access token. In the second communication 510, the authorization server 504 sends an Nnrf_Access Token_Get response to the NF service consumer 502, which may include expires_in and access_token.
[0053] Figure 6 is a schematic block diagram showing one embodiment of a system 600 for an NF service producer to perform requested services based on an access token. The system 600 includes an NF service consumer 602 and an NF service producer 604. Each of the illustrated communications may include one or more messages.
[0054] In the first communication 606, the NF service consumer 602 sends an NF service request, which may include an access token, to the NF service producer 604. The NF service producer 604 may verify the integrity and claims within the access token. If successful, the NF service producer 604 may perform the requested service. In the second communication 610, the NF service producer 604 sends an NF service response to the NF service consumer 602.
[0055] In certain embodiments, DCCF enables an NF service consumer ("NF service consumer: NFc") to access data from a data source or NF service producer ("NF service producer: NFp"). Because DCCF is used between consumers and producers, existing security mechanisms may not be sufficient, and the following may be addressed: 1) Based on a request from DCCF, the messaging framework may provide data from the producer to a consumer requesting the data, even if the consumer is not authorized to receive this data; and / or 2) Based on a request from DCCF, data received from the data producer is stored in a data repository function ("data repository function: DRF"). If the data is to be retrieved later, DCCF may, upon request, provide the stored data to the unauthorized consumer.
[0056] In some embodiments, data requests are sent from DCCF on behalf of the consumer, which may prevent the data producer from accurately verifying the data consumer's identity.
[0057] In various embodiments, authorization to access the service is not indirectly supported via an intermediate NF (e.g., DCCF).
[0058] In certain embodiments, DCCF verifies that a request for data acquisition by a data consumer NF (e.g., NWDAF) is authorized to be acquired by identified data producers NF (e.g., AMF, SMF, AF) and OAM.
[0059] In the first embodiment, an access token-based solution is possible.
[0060] In some embodiments, if an NF service consumer (e.g., NWDAF) determines that it can collect data via a data collection coordination function before establishing an NF service request (e.g., Ndccf_DataManagement_request service operation) to obtain the necessary data using DCCF, the NF service consumer may request authorization from the NRF by requesting an access token. In the request, the NF service consumer includes information to identify the target NF (e.g., DCCF) and information to identify the NF service consumer (e.g., NWDAF). The NF service consumer uses the received access token provided by the NRF to establish an NF service to request data using DCCF. This token is an intermediate_access_token. In various embodiments, the NF consumer may generate a client credentials assertion ("CCA") token and include the CCA in the NF service request to DCCF. The CCA may be used to verify the trustworthiness of the NF service consumer.
[0061] In certain embodiments, if DCCF determines that data must be retrieved by a different NF service producer, DCCF determines whether the NF service consumer is authorized to retrieve data (and access NF services) from the identified NF service producer NF. This may be supported by DCCF requesting authorization by requesting an access token using a transmission to NRF. DCCF includes in authorization request information that identifies the target NF (e.g., NF service producer), information for identifying the NF service initiator (e.g., DCCF), and additional authorization information for identifying the NF service consumer that will ultimately receive the data. DCCF may also include a CCA, if provided by the NF service consumer. In some embodiments, as additional authorization information, DCCF includes an intermediate_access_token provided by the NF service consumer. NRF authorizes the request by verifying that DCCF can access services from the NF service producer and, based on the received intermediate_access_token, verifying whether the NF service consumer is also authorized to access services from the service producer NF. The NRF may also use the CCA of the service consumer NF, if provided by the DCCF, to verify the trustworthiness of the NF service consumer. The NRF assigns a new access token (e.g., dccf_access_token) to send a service request (e.g., a request for data using the event publishing service behavior) to the service producer NF.
[0062] Figure 7 is a schematic block diagram showing one embodiment of a system 700 that authorizes access to a service via an intermediate NF. The system 700 includes an NF service consumer 702 (e.g., NWDAF), a DCCF 704, an NF service producer 706, and an authorization server 708 (e.g., NRF). Each of the communications in Figure 7 may include one or more messages.
[0063] In the first communication 710, the NF service consumer 702 (e.g., NWDAF) discovers DCCF704NF to retrieve data. The NF service consumer 702 requests authorization from the NRF by calling an Nnrf_AccessToken_Get request that includes information to identify the target NF (e.g., DCCF704) and the source NF.
[0064] The NRF approves the request (712) and generates an access token.
[0065] In the second communication 714, an access token (e.g., intermediate_access_token) is provided to the NF service consumer 702. The intermediate_access_token contains information that includes information to identify the NRF (e.g., the issuer of the access token), the NF instance ID of the NF consumer (e.g., the NF service requester), and the NF instance ID of the NF service producer (e.g., DCCF704).
[0066] In the third communication 716, the NF service consumer 702 initiates an NF service request to the DCCF 704 that includes an intermediate_access_token (for example, if the NF service consumer is an NWDAF, the NWDAF sends an Ndccf_DataManagement request). In some embodiments, in the request to the DCCF 704, the NF service consumer 702 generates a CCA token to authenticate itself to the NRF when the request is sent via the DCCF 704 and includes it in the request message.
[0067] DCCF704 verifies that the intermediate access token is valid (718) and then executes the service.
[0068] Furthermore, DCCF704 determines that the requested service is provided by a different NF service producer other than DCCF704 (720) (for example, in the case of NWDAF, DCCF704 determines that the requested data is generated by a different NF). Because the service is provided by a different NF, DCCF704 verifies that the NF service consumer 702 can access the service provided by the identified NF service producer (for example, indirectly).
[0069] In the fourth communication 722, DCCF704 requests authorization from the NRF by calling an Nnrf_AccessToken_Get request which includes additional authorization information, including information to identify the target NF (e.g., NF service producer 706), the source NF (e.g., DCCF704), and an intermediate_access_token. Furthermore, DCCF704 includes a CCA token if provided by an NF service consumer 702. The additional authorization information is provided to verify that the NF service consumer 702 is authorized to use the service provided by the identified NF service consumer.
[0070] The NRF determines whether DCCF704 and service consumer NF702 are permitted to access services provided by the identified NF service producer (for example, based on an intermediate access token) (724). If the received authorization request includes a CCA token generated by NF service consumer 706, the NRF verifies NF service consumer 706 based on the CCA token.
[0071] In the fifth communication 726, the NRF generates an access token and provides it to the DCCF704.
[0072] In the sixth communication 728, DCCF704 uses the access token to initiate an NF service to the identified NF service producer (for example, NF service producer 706). If provided by an NF service consumer, DCCF also includes a CCA token.
[0073] The NF service producer 706 (or multiple producers) verifies the access token and CCA token if they are provided (730) and then executes the service.
[0074] In the seventh communication 732, the NF service producer 706 (or more producers) provides the requested data in the response.
[0075] In the eighth communication 734, DCCF704 forwards the provided data to NF service consumer 702 in response.
[0076] In some embodiments, to ensure efficient use of signaling, if DCCF704 receives an access_token and determines that DCCF704 has an existing NF service connection from the same NF service producer 706 instance, DCCF704 may reuse the existing NF instance to retrieve the data requested by the NF service consumer 702, instead of creating a new NF service request that is sent to the same NF service producer 706 instance to retrieve the data.
[0077] In various embodiments, if DCCF704 stores data acquired by NF service producer 706 in a data repository function ("DRF"), DCCF704 also stores the ID of NF service producer 706 in the data repository function. When DCCF704 receives a service request and DCCF704 determines that the data is available in the data repository function (for example, if the data repository function is NF service producer 706), DCCF704 must also verify whether the data acquired by NF service producer 706 and stored in the data repository function is authorized to be provided to NF service consumer 702. This is supported by verifying that NF service consumer 702 is authorized to access the service provided by NF service producer 706. This may be supported as follows: 1) If the target NF is a data repository function, DCCF704 requests an access token from the NRF to verify that NF service consumer 702 is authorized to access the service provided by the data repository (DR). and / or, 2) DCCF704 requests a second access token from the NRF to verify that the NF service consumer 702 is also authorized to access services provided by the NF service producer 706, where the data is stored in the data repository function, and the target NF is the NF service producer 706. In various embodiments, to optimize signaling, DCCF704 may include both requests in a single message to the NRF.
[0078] In a particular embodiment, if DCCF704 receives a valid authorization token, DCCF704 verifies that the NF service consumer 702 is authorized to access the data stored in the data repository function.
[0079] In some embodiments, when DCCF704 receives NF service consumer 702, DCCF704 may extract information from the access_token (e.g., NRF issuer) and include the NF instance ID of the target NF instance (e.g., NF service producer 706) in the authorization request to the NRF. Furthermore, DCCF704 may include a CCA token if provided by NF service consumer 702. Using the provided information, the NRF authorizes NF service consumer 702 to indirectly access the services of NF service producer 706 and authorizes DCCF704 to initiate an NF service request by sending it to the NF service producer.
[0080] Figure 8 is a flowchart illustrating one embodiment of method 800 for authenticating network services. In some embodiments, method 800 is performed by a device such as a network unit 104. In certain embodiments, method 800 may be performed by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.
[0081] In various embodiments, method 800 includes step 802 of receiving a network function service request from a second network device at a first network device for performing a service on a third network device. This request includes first credentials for authentication by the first network device and second credentials for authentication by the third network device. In some embodiments, method 800 includes step (804) of performing the service request by determining whether the provided first credentials are valid and determining which third network device will perform the requested service from the second network device. In certain embodiments, method 800 includes step (806) of sending an authentication request from the third network device to a fourth network device. The request includes an identifier for the third network device and second credentials for the second network device. In various embodiments, method 800 includes step (808) of receiving third credentials from the fourth network device for initiating a network function (NF) service using the third network function. In some embodiments, method 800 includes the step (810) of sending an NF service initiation request to a third network device. The request includes authentication credentials, which include a second credential and a third credential.
[0082] In certain embodiments, the first network device includes a Data Collection Coordination Function (DCCF). In some embodiments, the second network device includes an NF Service Consumer. In various embodiments, the fourth network device includes a Network Repository Function (NRF).
[0083] In one embodiment, first credentials are provided for authentication to access a service of a first network device, and second credentials are provided for authentication to access a service of a third network device. In certain embodiments, the third network device comprises an NF service producer. In some embodiments, the service comprises a data request.
[0084] In various embodiments, the first credentials comprise a first access token of a second network device assigned by a third network device. In one embodiment, the second credentials comprise a second access token generated by a second network device. In a particular embodiment, the third credentials comprise an access token generated by a fourth network device.
[0085] Figure 9 is a flowchart illustrating another embodiment of method 900 for authenticating network services. In some embodiments, method 900 is performed by a device such as a network unit 104. In certain embodiments, method 900 may be performed by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.
[0086] In various embodiments, method 900 includes the step (902) of sending an authorization request from a second network device to a fourth network device for access to services of a first network device. In some embodiments, method 900 includes the step (904) of receiving first credentials, including an access token, from the fourth network device. In certain embodiments, method 900 includes the step (906) of sending a network function service request to the first network device for performing services from a third network device, the network function service request comprising first credentials for authentication by the first network device and second credentials for authentication by the third network device. The first credentials include a first access token, and the second credentials include a second access token generated by the second network device. In various embodiments, method 900 includes the step (908) of receiving a response to the network function service request from the first network device.
[0087] In certain embodiments, the first network device includes a Data Collection Coordination Function (DCCF). In some embodiments, the second network device includes a Network Function (NF) service consumer. In various embodiments, the fourth network device includes a Network Repository Function (NRF).
[0088] Figure 10 is a flowchart illustrating further embodiments of method 1000 for authenticating network services. In some embodiments, method 1000 is performed by a device such as a network unit 104. In certain embodiments, method 1000 may be performed by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.
[0089] In various embodiments, method 1000 includes the step (1002) of a fourth network device receiving an authentication request from a first network device by a third network device. The request includes first credentials, which include an access token for the second network device and an identifier for the third network device. In some embodiments, method 1000 includes the step (1004) of determining whether the first and second network devices are permitted to access the services of the third network device. In certain embodiments, method 1000 includes the step (1006) of generating second credentials, which include a second access token, in response to the determination that the first and second network devices are permitted to access the services. In various embodiments, method 1000 includes the step (1008) of sending the second credentials to the first network device to initiate an NF service.
[0090] In certain embodiments, the first network device includes a Data Collection Coordination Function (DCCF). In some embodiments, the second network device includes a Network Function (NF) service consumer. In various embodiments, the fourth network device includes a Network Repository Function (NRF).
[0091] In one embodiment, the device comprises a first network device. The device further comprises a receiver that receives a network function service request from a second network device for performing a service on a third network device, wherein the request comprises a first credential for authentication by the first network device and a second credential for authentication by the third network device; a processor that performs the service request by determining whether the provided first credential is valid and determining which third network device will perform the service requested by the second network device; and a transmitter that sends an authentication request from the third network device to a fourth network device, wherein the request comprises an identifier for the third network device and a second credential for the second network device, the receiver receives a third credential from the fourth network device for starting a network function (NF) service using the third network function, and the transmitter sends an NF service start request to the third network device, wherein the request comprises authentication credentials comprising the second credential and the third credential.
[0092] In certain embodiments, the first network device includes a data acquisition coordination function (DCCF).
[0093] In some embodiments, the second network device includes an NF service consumer.
[0094] In various embodiments, the fourth network device includes a network repository function (NRF).
[0095] In one embodiment, first credentials are provided for authentication to access a service of a first network device, and second credentials are provided for authentication to access a service of a third network device.
[0096] In certain embodiments, the third network device includes an NF service producer.
[0097] In some embodiments, the service includes a data request.
[0098] In various embodiments, the first credentials include a first access token of a second network device assigned by a third network device.
[0099] In one embodiment, the second credentials include a second access token generated from a second network device.
[0100] In a particular embodiment, the third credentials include an access token generated from a fourth network device.
[0101] In one embodiment, the method of a first network device includes the steps of: receiving a network function service request from a second network device for performing a service on a third network device, wherein the request comprises first credentials for authentication by the first network device and second credentials for authentication by the third network device; performing the service request by determining whether the provided first credentials are valid and determining which third network device will perform the service requested by the second network device; transmitting an authentication request from the third network device to a fourth network device, wherein the request comprises an identifier for the third network device and second credentials for the second network device; receiving third credentials from the fourth network device for starting a network function (NF) service using the third network function; and transmitting an NF service start request to the third network device, wherein the request comprises authentication credentials including second credentials and third credentials.
[0102] In certain embodiments, the first network device includes a data acquisition coordination function (DCCF).
[0103] In some embodiments, the second network device includes an NF service consumer.
[0104] In various embodiments, the fourth network device includes a network repository function (NRF).
[0105] In one embodiment, first credentials are provided for authentication to access a service of a first network device, and second credentials are provided for authentication to access a service of a third network device.
[0106] In certain embodiments, the third network device includes an NF service producer.
[0107] In some embodiments, the service includes a data request.
[0108] In various embodiments, the first credentials include a first access token of a second network device assigned by a third network device.
[0109] In one embodiment, the second credentials include a second access token generated from a second network device.
[0110] In a particular embodiment, the third credentials include an access token generated from a fourth network device.
[0111] In one embodiment, the device comprises a second network device. The device further comprises a transmitter that transmits an authorization request to a fourth network device to access services of a first network device, and a receiver that receives first credentials comprising an access token from the fourth network device, wherein the transmitter transmits a network function service request to the first network device to perform services from a third network device, the network function service request comprising first credentials for authentication by the first network device and second credentials for authentication by the third network device, the first credentials comprising a first access token and the second credentials comprising a second access token generated by the second network device, and the receiver receives a response to the network function service request from the first network device.
[0112] In certain embodiments, the first network device includes a data acquisition coordination function (DCCF).
[0113] In some embodiments, the second network device comprises a network function (NF) service consumer.
[0114] In various embodiments, the fourth network device includes a network repository function (NRF).
[0115] In one embodiment, the method of the second network device comprises the steps of: sending an authorization request to a fourth network device for accessing a service of the first network device; receiving first credentials comprising an access token from the fourth network device; sending a network function service request to the first network device for performing a service from the third network device, wherein the network function service request comprises first credentials for authentication by the first network device and second credentials for authentication by the third network device, the first credentials comprising a first access token and the second credentials comprising a second access token generated by the second network device; and receiving a response to the network function service request from the first network device.
[0116] In certain embodiments, the first network device includes a data acquisition coordination function (DCCF).
[0117] In some embodiments, the second network device comprises a network function (NF) service consumer.
[0118] In various embodiments, the fourth network device includes a network repository function (NRF).
[0119] In one embodiment, the device comprises a fourth network device. The device further comprises a receiver that receives an authentication request from a third network device from a first network device, wherein the request comprises first credentials comprising an access token for a second network device and an identifier for a third network device; a processor that determines whether the first and second network devices are permitted to access the services of the third network device, and in response to the determination that the first and second network devices are permitted to access the services, generates second credentials comprising a second access token; and a transmitter that transmits the second credentials to the first network device for initiating an NF service.
[0120] In certain embodiments, the first network device includes a data acquisition coordination function (DCCF).
[0121] In some embodiments, the second network device comprises a network function (NF) service consumer.
[0122] In various embodiments, the fourth network device includes a network repository function (NRF).
[0123] In one embodiment, the method for a fourth network device includes the steps of: receiving an authentication request from a first network device by a third network device, wherein the request comprises first credentials comprising an access token for a second network device and an identifier for a third network device; determining whether the first and second network devices are permitted to access the services of the third network device; generating second credentials comprising a second access token in response to the determination that the first and second network devices are permitted to access the services; and transmitting the second credentials to the first network device for initiating an NF service.
[0124] In certain embodiments, the first network device includes a data acquisition coordination function (DCCF).
[0125] In some embodiments, the second network device comprises a network function (NF) service consumer.
[0126] In various embodiments, the fourth network device includes a network repository function (NRF).
[0127] The embodiments described may be carried out in other specific forms. The embodiments described should be considered in all respects as illustrative and not restrictive. Accordingly, the scope of the invention is indicated by the appended claims rather than by the foregoing description. All modifications that fall within the meaning and scope of equivalence of the claims should be encompassed within that scope. [Explanation of Symbols]
[0128] 100 Wireless Communication Systems 102 Remote Unit 104 Network Units 200 equipment 202 processors 204 memory 206 Input Devices 208 displays 210 Transmitter 212 Receiver 300 equipment 302 Processors 304 memory 306 Input Devices 308 displays 310 Transmitter 312 Receiver 400 System 402 Data acquisition adjustment function, DCCF 404 Network Repository Function ("NRF") 408 Data Producer NF Instances 412 Data Producer NF Instances 416 Data Producer NF Instances 420 Consumer NF 500 Systems 502 NF Service Consumer 504 Approval Server 506 First Communication 510 Second communication 600 System 602 NF Service Consumer 604 NF Service Producer 606 First Communication 610 Second communication 700 System 702 NF Service Consumer 704 Data acquisition adjustment function, DCCF 706 NF Service Producer 708 Approval Server 710 First communication 714 Second communication 716 Third Communication 722 The fourth communication 726 Fifth Communication 728 The Sixth Communication 732 The 7th Communication 734 Eighth Communication 800 ways 900 ways 1000 ways
Claims
1. A first network device for performing network functions (NF), At least one memory, The system comprises at least one processor coupled to the at least one memory, and the at least one processor is Receiving an NF service request from a second network device for performing a service on a third network device, wherein the request comprises a first credential for authentication by the first network device and a second credential for authentication by the third network device. Executing the service request by determining whether the provided first credentials are valid and determining the third network device to perform the service requested by the second network device, The transmission of an authentication request from the third network device to the fourth network device, wherein the request comprises the identifier of the third network device and the second credential information of the second network device. The third network device receives third credentials from the fourth network device for starting the NF service, Sending a request to start the NF service to the third network device, wherein the request includes authentication credentials comprising the second credentials and the third credentials. The first network device is configured to perform the above-mentioned operation. The first network device.
2. The first network device according to claim 1, wherein the first network device includes a data collection coordination function (DCCF).
3. The first network device according to claim 1, wherein the second network device comprises an NF service consumer.
4. The first network device according to claim 1, wherein the fourth network device includes a network repository function (NRF).
5. The first network device according to claim 1, wherein the first credentials include a first access token of the second network device assigned by the third network device.
6. The first network device according to claim 1, wherein the second credentials include a second access token generated from the second network device.
7. The first network device according to claim 1, wherein the third credentials include an access token generated from the fourth network device.
8. A second network device for performing network functions (NF), At least one memory, The system comprises at least one processor coupled to the at least one memory, and the at least one processor is Sending a request to the fourth network device for authorization to access the services of the first network device, Receiving first credentials comprising an access token from the fourth network device, Sending an NF service request to a first network device for performing a service from a third network device, wherein the NF service request comprises a first credential for authentication by the first network device and a second credential for authentication by the third network device, wherein the first credential comprises a first access token and the second credential comprises a second access token generated by the second network device. Receiving a response to the NF service request from the first network device, The second network device is configured to perform the following: The second network device.
9. The second network device according to claim 8, wherein the first network device includes a data collection coordination function (DCCF).
10. The second network device according to claim 8, wherein the second network device comprises an NF service consumer.
11. The second network device according to claim 8, wherein the fourth network device includes a network repository function (NRF).
12. A fourth network device for performing network functions (NF), At least one memory, The system comprises at least one processor coupled to the at least one memory, and the at least one processor is The first network device receives an authentication request from a third network device, wherein the request comprises first credentials comprising the access token of the second network device and the identifier of the third network device. Determining whether the first network device and the second network device are permitted to access the services of the third network device, In response to a decision that the first network device and the second network device are permitted to access the service, a second set of credentials comprising a second access token is generated, Sending the second credentials for starting the NF service to the first network device The fourth network device is configured to perform the following: The fourth network device.
13. The fourth network device according to claim 12, wherein the first network device comprises a data collection coordination function (DCCF).
14. The fourth network device according to claim 12, wherein the second network device comprises an NF service consumer.
15. The fourth network device according to claim 12, wherein the fourth network device includes a network repository function (NRF).
16. A method for performing a network function (NF) using a first network device, A receiving step of receiving an NF service request from a second network device for performing a service on a third network device, wherein the request comprises a first credential for authentication by the first network device and a second credential for authentication by the third network device. The steps of performing the service request include determining whether the provided first credentials are valid and determining the third network device to perform the service requested by the second network device, A step of transmitting an authentication request from the third network device to a fourth network device, wherein the request comprises an identifier of the third network device and second credentials of the second network device. The steps include receiving third credentials from the fourth network device for starting the NF service using the third network device, The process includes sending a request to start the NF service to the third network device, wherein the request comprises authentication credentials comprising the second credentials and the third credentials. method.
17. The aforementioned NF is performed by the data collection coordination function (DCCF). The method according to claim 16.
18. The second network device includes an NF service consumer. The method according to claim 16.
19. The fourth network device includes a network repository function (NRF). The method according to claim 16.
20. The first credentials include a first access token of the second network device assigned by the third network device. The method according to claim 16.