Granting authorization scope in communication networks

JP7902342B2Active Publication Date: 2026-08-07TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2023-08-03
Publication Date
2026-08-07

Smart Images

  • Figure 0007902342000001
    Figure 0007902342000001
  • Figure 0007902342000002
    Figure 0007902342000002
  • Figure 0007902342000003
    Figure 0007902342000003
Patent Text Reader

Abstract

The present disclosure provides a method for granting or permitting an authorization range in a communication network, the method comprising: receiving, at a first network node from a second network node, a first indication of a first authorization range related to a network node type, receiving, at the first network node from the second network node, a second indication of a second authorization range related to at least one second network node instance, receiving, at the first network node from the second network node, a third indication of a priority related to the first authorization range and / or the second authorization range, and granting, at the first network node, authorization to access to the second network node and / or the authorization range of the second network node based on the first indication, the second indication, and the third indication. In some embodiments, the method further comprises receiving, at the first network node from a third network node, a discovery request for a network node type of the second network node or an access token request for an authorization range of the second network node; authorizing, at the first network node, access by the third network node to the second network node and / or to the authorization range of the second network node based on the first instruction, the second instruction, and the third instruction; and sending, from the first network node to the third network node, a selection result in a discovery response or an access token in an access token response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0002] , ,

[0005] ,

[0004] , , , , ,

[0003]

[0001] The present invention generally relates to an authorization mechanism in a communication network or a mobile network. More specifically, the present invention relates to granting or permitting an authorization scope of a network node in a fifth-generation (5G) mobile network.

Background Art

[0002] <0000??9>(Representing "Open Authorization") OAuth 2.0 is a standard designed to allow a website or an application to access resources hosted by another web application on behalf of a user. In 3GPP 5GC, OAuth 2.0 is used for an NF service consumer (e.g., UDM) to authorize access to some resources in an NF service producer (e.g., UDR).

[0003] A scope is a mechanism in OAuth 2.0 for restricting an application's access to a user's account. In a 5GC network, authorization is achieved by an NRF (authorization server) that provides an access token granting permission to the requested scope. Therefore, an NF service consumer (e.g., UDM) can request one or more scopes to access (and update) resources in a requested NF type (e.g., UDR). The NRF accepts the requested scope only if the NF service producer (e.g., UDR) has registered a permission scope in the NRF for the requesting NF type (e.g., UDM) or the requesting NF instance (e.g., a unique ID for a UDM instance).

[0004] Aspects that are problematic in the current solution are described below.

[0005] It should be noted that there seems to be an unclear "??" in the tag <0000??9> in the original text. If this is an error, it should be corrected according to the actual situation.In 3GPP TS29.510, the attributes "allowedOperationsPerNfType" and "allowedOperationsPerNfInstance" in the NFService type are used to indicate whether a given consumer is permitted to invoke certain operations (e.g., read, update) on a resource, as indicated by the OAuth2.0 scope required for that resource.

[0006] A consumer can be identified either by its NF type or by its unique NF instance ID.

[0007] Under the current specification, a given scope requested by a consumer is granted / allowed if such scope is included in either the "allowedOperationsPerNfType" attribute or the "allowedOperationsPerNfInstance" attribute for the NF service consumer's NF type and NF instance ID. This means that it is not possible to have a given NF instance ID with access rights narrower than its corresponding NF type.

[0008] For example, in the current specification, if an NF type UDM is defined as having access to UDR API scope A (e.g., user access and mobility data) (by all UDR NF instances), while a particular UDM instance is defined as having access to UDR API scope B (e.g., user authentication data), then such a UDM instance will always have access to both scopes A and B. It is not possible to restrict a particular UDM instance to only have access to scope A (in other words, not allowing that particular UDM instance to access user authentication data) while granting all other UDM NF instances access to both scopes A and B. [Overview of the project]

[0009] The present invention is described in the appended claims.

[0010] The objective of the present invention is to enable the granting or authorization of a range of network nodes in a communication network.

[0011] A first aspect of the present invention relates to a method performed by a first network node to grant or authorize an authorization scope in a communication network. The method comprises: receiving a first instruction from a second network node at the first network node for a first authorization scope relating to a second network node type; receiving a second instruction from the second network node at the first network node for a second authorization scope relating to at least one second network node instance, in particular the second instruction being of a network node type; receiving a third instruction from the second network node at the first network node for a priority relating to the first and / or second authorization scopes; and granting authorization at the first network node, based on the first, second and third instructions, for access to and / or the authorization scope of the second network node, in particular the authorization being part of a network node discovery procedure or an access token request procedure. In some embodiments, the method further comprises: a first network node receiving a discovery request from a third network node regarding the network node type of a second network node, or an access token request regarding the authorization scope of the second network node; the first network node granting the third network node access to and / or the authorization scope of the second network node based on the first, second, and third instructions; and the first network node transmitting the discovery result in a discovery response or the access token in an access token response to the third network node. In some embodiments, authorization of access to and / or the authorization scope of the second network node comprises determining that the authorization scope for access to the second network node is included in the second authorization scope.In some embodiments, authorization to and / or access to the authorization scope of the second network node comprises determining, based on a third instruction, that the authorization scope of the second network node is included in an authorization scope that is preferred or has a higher priority. In some embodiments, priority relates to the priority of the first authorization scope, the priority of the second authorization scope, or the priority between the first and second authorization scopes. In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in a network node registration request for network node discovery. In some embodiments, the first network node further sends a registration response message to the second network node indicating the successful registration of the second network node. In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in a network node profile, in particular, the network node profile is a network functionality profile. In some embodiments, the selection of the second network node comprises determining that the first authorization scope has a higher priority than the second authorization scope. In some embodiments, the selection of a second network node includes determining that the first authorization scope overrides the second authorization scope. In some embodiments, the selection of a second network node includes determining that the second authorization scope has a higher priority than the first authorization scope. In some embodiments, the selection of a second network node includes determining that the second authorization scope overrides the first authorization scope. In some embodiments, a third instruction indicates that the first authorization scope has a higher priority than the second authorization scope or overrides the second authorization scope, in particular the third instruction is a Boolean instruction. In some embodiments, a third instruction indicates that the second authorization scope has a higher priority than the first authorization scope or overrides the first authorization scope, in particular the third instruction is a Boolean instruction. In some embodiments, the network node type is a network function type.In some embodiments, the second network node is a network node instance, in particular a network function instance. In some embodiments, the first and / or second authorization scopes are OAuth scopes. In some embodiments, the first directive is the allowedOperationsPerNfType attribute in the NFProfile or NFService data type. In some embodiments, the second directive is the allowedOperationsPerNfInstance attribute in the NFProfile or NFService data type. In some embodiments, the third directive is the allowedOperationsPerNfInstanceOverrides attribute in the NFProfile or NFService data type. In some embodiments, the first network node is a network repository function (NRF), the second network node is a network function producer, and the third network node is a network function consumer.

[0012] A second aspect of the present invention relates to a method performed by a second network node to grant or authorize an authorization scope in a communication network. The method comprises: transmitting a first instruction from the second network node to a first network node of a first authorization scope relating to a network node type; transmitting a second instruction from the second network node to the first network node of a second authorization scope relating to at least one instance of the second network node, in particular the second instruction being of a network node type; and transmitting a third instruction from the second network node to the first network node of priority relating to the first and / or second authorization scopes. In some embodiments, priority relates to priority of the first authorization scope, priority of the second authorization scope, or priority between the first and second authorization scopes. In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in a network node registration request for network node discovery. In some embodiments, the first network node further sends a registration response message to the second network node indicating the successful registration of the second network node. In some embodiments, the first instruction, the second instruction and / or the third instruction are included in the network node profile, in particular the network node profile is a network function profile. In some embodiments, the third instruction indicates that the first authorization scope has a higher priority than the second authorization scope or overrides the second authorization scope, in particular the third instruction is a Boolean instruction. In some embodiments, the third instruction indicates that the second authorization scope has a higher priority than the first authorization scope or overrides the first authorization scope, in particular the third instruction is a Boolean instruction. In some embodiments, the network node type is a network function type. In some embodiments, the second network node is a network node instance, in particular a network function instance.In some embodiments, the first authorization scope and / or the second authorization scope is the OAuth scope. In some embodiments, the first instruction is the allowedOperationsPerNfType attribute in the NFProfile data type or NFService data type. In some embodiments, the second instruction is the allowedOperationsPerNfInstance attribute in the NFProfile data type or NFService data type. In some embodiments, the third instruction is the allowedOperationsPerNfInstanceOverrides attribute in the NFProfile data type or NFService data type. In some embodiments, the first network node is a network repository function (NRF), and the second network node is a network function producer.

[0013] A third aspect of the present invention relates to a method performed by a third network node to grant or authorize an authorization scope in a communication network. The method comprises: the third network node sending a discovery request to a first network node for the network node type of a second network node, or an access token request for the authorization scope of the second network node; and the third network node receiving a selection result in a discovery response or an access token in an access token response from the first network node. In some embodiments, authorization of access to and / or the authorization scope of the second network node comprises determining that the authorization scope for access to the second network node is included in the second authorization scope. In some embodiments, authorization of access to and / or the authorization scope of the second network node comprises determining, based on a third instruction, that the authorization scope of the second network node is included in a preferred or higher-priority authorization scope. In some embodiments, priority relates to the priority of a first authorization scope, the priority of a second authorization scope, or the priority between the first and second authorization scopes. In some embodiments, the selection of a second network node comprises determining that the first authorization scope has a higher priority than the second authorization scope. In some embodiments, the selection of a second network node comprises determining that the first authorization scope overrides the second authorization scope. In some embodiments, the selection of a second network node comprises determining that the second authorization scope has a higher priority than the first authorization scope. In some embodiments, the selection of a second network node comprises determining that the second authorization scope overrides the first authorization scope. In some embodiments, the network node type is a network function type. In some embodiments, the second network node is a network node instance, in particular a network function instance.In some embodiments, the first authorization scope and / or the second authorization scope are OAuth scopes. In some embodiments, the first network node is a network repository function (NRF), the second network node is a network function producer, and the third network node is a network function consumer.

[0014] Other aspects of the present invention relate to mobile network nodes, in particular to a first network node (110, 500), a second network node (600), and a third network node (700) configured to perform the respective methods described herein. Other aspects of the present invention relate to computer programs and computer program products.

[0015] In some embodiments, the first network node is a network repository function (NRF). In some embodiments, the second network node is a network function producer (NFp). In some embodiments, the third network node is a network function consumer (NFc).

[0016] Advantageously, the solutions disclosed herein define multiple ranges for a given NF type, but allow for flexibility in regulating several ranges for specific NF instances of the same NF type.

[0017] Additional objectives, features, and advantages of the concepts disclosed herein may become apparent from the modes, claims, and drawings for carrying out the inventions described below, or may be learned through the practice of the described art and concepts described herein.

[0018] To best illustrate the forms in which the disclosed concepts may be implemented, and to define other purposes, advantages, and features of this disclosure, a more detailed description is provided below and illustrated in the accompanying drawings. Understanding that these drawings merely depict exemplary embodiments of the invention and should therefore not be considered limitations of scope, examples are described and illustrated with additional specificities and details by using the accompanying drawings. [Brief explanation of the drawing]

[0019] [Figure 1] This figure illustrates an exemplary networked system according to a specific embodiment of the solution described herein. [Figure 2] This figure illustrates an exemplary flowchart showing how a particular embodiment of the solution described herein is performed by a mobile network node. [Figure 3] This figure illustrates an exemplary flowchart showing how a particular embodiment of the solution described herein is performed by a mobile network node. [Figure 4] This figure illustrates an exemplary flowchart showing how a particular embodiment of the solution described herein is performed by a mobile network node. [Figure 5] This figure illustrates an exemplary block diagram of a mobile network node configured according to a specific embodiment of the solution described herein. [Figure 6] This figure illustrates an exemplary block diagram of a mobile network node configured according to a specific embodiment of the solution described herein. [Figure 7] This figure illustrates an exemplary block diagram of a mobile network node configured according to a specific embodiment of the solution described herein. [Modes for carrying out the invention]

[0020] Next, the present invention will be described in detail below with reference to the accompanying drawings illustrating examples of embodiments or implementations of the invention. The present invention, however, may be carried out or implemented in many different forms and should not be construed as being limited to the embodiments described herein. Rather, these embodiments are provided so that this disclosure may be thorough and complete and adequately convey the scope of the invention to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. It may be implicitly assumed that components from one embodiment may be present / used in another embodiment. These embodiments of the disclosed subject matter are presented as teaching examples and should not be construed as limiting the scope of the disclosed subject matter. For example, some details of the embodiments described may be modified, omitted or expanded without departing from the scope of the described subject matter.

[0021] The exemplary embodiments described herein occur in the context of a communication network, including, but not limited to, a communication network that conforms to aspects of the 5th Generation (5G) architecture and / or incorporates them in some cases. FIG. 1 is an exemplary networked system 100 according to an exemplary embodiment of the present disclosure. FIG. 1 illustrates, in detail, a (wireless) Access Network (RAN) 102, as well as a User Equipment (UE) 101 that may communicate with an Access and Mobility Management Function (AMF) 106 and a User Plane Function (UPF) 103. The AMF 106 may communicate with core network services, including a Session Management Function (SMF) 107 and a Policy Control Function (PCF) 111. The core network services may also communicate with an Application Server / Application Function (AS / AF) 113. Other networked services also include a Network Slice Selection Function (NSSF) 108, an Authentication Server Function (AUSF) 105, a User Data Management (UDM) 112, a Network Exposure Function (NEF) 109, a Network Repository Function (NRF) 110, and a Data Network (DN) 104. In some exemplary implementations of embodiments of the present disclosure, each entity in the networked system 100 is considered to be a Network Function (NF). One or more additional instances of an NF may be incorporated into the networked system.

[0022] The solutions described herein are aimed at enabling the granting or authorization of a network node's scope in a communication network.

[0023] This disclosure provides a method for granting or authorizing authorization scopes in a communications network. The method comprises: receiving a first instruction from a second network node at a first network node regarding a first authorization scope relating to a network node type; receiving a second instruction from the second network node at the first network node regarding a second authorization scope relating to at least one instance of the second network node, in particular the second instruction being of a network node type; receiving a third instruction from the second network node at the first network node regarding a priority relating to the first and / or second authorization scopes; and granting authorization at the first network node, based on the first, second, and third instructions, to access to and / or the authorization scopes of the second network node, in particular the authorization being part of a network node discovery procedure or an access token request procedure. In some embodiments, the method further comprises: a first network node receiving a discovery request from a third network node regarding the network node type of a second network node, or an access token request regarding the authorization scope of the second network node; the first network node granting the third network node access to and / or the authorization scope of the second network node based on the first, second, and third instructions; and the first network node transmitting a selection result in a discovery response or an access token in an access token response to the third network node. In some embodiments, authorization of access to and / or the authorization scope of the second network node comprises determining that the authorization scope for access to the second network node is included in the second authorization scope.In some embodiments, authorization to and / or access to the authorization scope of the second network node comprises determining, based on a third instruction, that the authorization scope of the second network node is included in an authorization scope that is preferred or has a higher priority. In some embodiments, priority relates to the priority of the first authorization scope, the priority of the second authorization scope, or the priority between the first and second authorization scopes. In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in a network node registration request for network node discovery. In some embodiments, the first network node further sends a registration response message to the second network node indicating the successful registration of the second network node. In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in a network node profile, in particular, the network node profile is a network functionality profile. In some embodiments, the selection of the second network node comprises determining that the first authorization scope has a higher priority than the second authorization scope. In some embodiments, the selection of a second network node includes determining that the first authorization scope overrides the second authorization scope. In some embodiments, the selection of a second network node includes determining that the second authorization scope has a higher priority than the first authorization scope. In some embodiments, the selection of a second network node includes determining that the second authorization scope overrides the first authorization scope. In some embodiments, a third instruction indicates that the first authorization scope has a higher priority than the second authorization scope or overrides the second authorization scope, in particular the third instruction is a Boolean instruction. In some embodiments, a third instruction indicates that the second authorization scope has a higher priority than the first authorization scope or overrides the first authorization scope, in particular the third instruction is a Boolean instruction. In some embodiments, the network node type is a network function type.In some embodiments, the second network node is a network node instance, particularly a network function instance. In some embodiments, the first authorization scope and / or the second authorization scope are OAuth scopes. In some embodiments, the first instruction is the allowedOperationsPerNfType attribute in the NFProfile data type or the NFService data type. In some embodiments, the second instruction is the allowedOperationsPerNfInstance attribute in the NFProfile data type or the NFService data type. In some embodiments, the third instruction is the allowedOperationsPerNfInstanceOverrides attribute in the NFProfile data type or the NFService data type. In some embodiments, the first network node is a network repository function (NRF), the second network node is a network function producer, and the third network node is a network function consumer.

[0024] The present disclosure also provides a first network node (110, 500), a second network node (600), and a third network node (700) configured to execute each of the methods described herein, particularly mobile network nodes. In some embodiments, the first network node is a network repository function (NRF) 110. In some embodiments, the second network node is a network function producer (NFp). In some embodiments, the third network node is a network function consumer (NFc).

[0025] The present disclosure also provides a corresponding computer program that causes a mobile network node to execute the disclosed method when run on a processing circuit of the mobile network node, and a computer program product comprising code in the form of, for example, a computer program.

[0026] The solutions and features provided in this specification are described further below.

[0027] NFp provides a new flag as part of its NFp profile during NF registration in NRF, which indicates that the range included in "allowedOperationsPerNfInstance" takes precedence (in other words, overrides) over the range included in "allowedOperationsPerNfType" when the NF type of the NF instance in the former attribute is also included in the latter.

[0028] For example, in the example described in the previous section, if allowedOperationsPerNfType includes ranges A and B, and allowedOperationsPerNfInstance includes range A only, then when new instructions are provided, the NRF will grant access to range A only for that particular NF instance, and access to ranges A and B for the rest of the NF instances of the same type.

[0029] This disclosure describes a mechanism for restricting / restricting access to specific NF instances of a given NF type, while ensuring that all other instances retain the defined (broader) access for that NF type.

[0030] The solution must maintain the essential backward compatibility in the 3GPP API, and two alternative forms are described below. 1) A new flag (allowedOperationsPerNfInstanceOverrides) that indicates that the NF instance allow range overrides the NF type allow range: For example, if the NF type allow range is 1, 2, 3, 4, 5, 6, and a particular NF instance cannot be granted range 6 (but should be granted all other ranges), then the NF instance range should be 1, 2, 3, 4, 5, and the new flag should be included and set to true. 2) A new attribute (restrictedOperationsPerNfInstance) that points to ranges of the allowed ranges for the corresponding NF type that are not allowed for the NF instance: For example, if the allowed ranges for an NF type are 1, 2, 3, 4, 5, and 6, and a particular NF instance cannot be granted range 6 (but should be granted all other ranges), then the new attribute should only include range 6. This means that the same range cannot exist simultaneously in both the new attribute restrictedOperationsPerNfInstance and the existing attribute allowedOperationsPerNfInstance.

[0031] In some embodiments, in addition to authorizing an access operation (generally understood as a read operation), other operations, such as a write operation, an update operation, or a delete operation, are authorized.

[0032] These attributes are used to determine whether a given resource / operational level range should be granted to an NF service consumer requesting an OAuth2 access token with a specific range. If the attribute "allowedOperationsPerNfInstanceOverrides" is not present or set to false, the NRF should grant such a range in the access token if the range exists in either "allowedOperationsPerNfType" for a specific NF type of the NF service consumer or "allowedOperationsPerNfInstance" for a specific instance ID of the NF service consumer. If the attribute "allowedOperationsPerNfInstanceOverrides" is present and set to true, the NRF should grant such a range in the access token if the range exists within it. Advantageously, the proposed solution defines multiple ranges for a given NF type, but allows for flexibility to regulate several ranges for a specific NF instance of the same NF type.

[0033] A flowchart illustrating an example of a solution implementation is described in detail below.

[0034] The embodiment is implemented by a first network node (110, 500), a second network node (600), and a third network node (700), and corresponds to a method involving the first network node (110, 500), the second network node (600), and the third network node (700).

[0035] Figure 2 is a flowchart illustrating the actions taken by a first network node to grant or authorize authorization scopes in a communication network.

[0036] In step S-201, the first network node receives a first instruction from the second network node relating to a first authorization scope for the network node type.

[0037] In step S-202, the first network node receives a second instruction from the second network node relating to the second network node, and the second network node is of the network node type.

[0038] In step S-203, the first network node receives a third instruction from the second network node regarding the priority relating to the first and / or second authorization scopes.

[0039] In step S-204, the first network node receives from the third network node a discovery request for the network node type of the second network node, or an access token request for the authorization scope of the second network node.

[0040] In step S-205, the first network node initiates authorization to and / or access to the authorization scope of the second network node based on the first, second, and third instructions, in particular, the authorization being part of a network node discovery procedure or an access token request procedure.

[0041] In step S-206, the first network node authorizes the third network node to access the second network node and / or the scope of authorization of the second network node, based on the first, second, and third instructions.

[0042] In step S-207, the first network node sends the selection result in the discovery response or the access token in the access token response to the third network node.

[0043] In some embodiments, authorization of access to and / or the authorization scope of the second network node comprises determining that the authorization scope for access to the second network node is included in the second authorization scope.

[0044] In some embodiments, authorization to and / or access to the authorization scope of the second network node comprises determining, based on a third instruction, that the authorization scope of the second network node is included in a preferred or higher-priority authorization scope.

[0045] In some embodiments, priority relates to the priority of a first authorization scope, the priority of a second authorization scope, or the priority between the first and second authorization scopes.

[0046] In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in the network node registration request for network node discovery.

[0047] In some embodiments, the first network node further sends a registration response message to the second network node indicating the successful registration of the second network node.

[0048] In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in the network node profile, in particular the network node profile is the network function profile.

[0049] In some embodiments, the selection of a second network node involves determining that the first authorization scope has a higher priority than the second authorization scope.

[0050] In some embodiments, the selection of a second network node comprises determining that the first authorization scope overrides the second authorization scope.

[0051] In some embodiments, the selection of a second network node involves determining that the second authorization scope has a higher priority than the first authorization scope.

[0052] In some embodiments, the selection of a second network node comprises determining that the second authorization scope overrides the first authorization scope.

[0053] In some embodiments, a third instruction indicates that the first authorization scope has a higher priority than the second authorization scope or overrides the second authorization scope, and in particular, the third instruction is a Boolean instruction.

[0054] In some embodiments, a third instruction indicates that a second authorization scope has a higher priority than or overrides a first authorization scope, and in particular, the third instruction is a Boolean instruction.

[0055] In some embodiments, the network node type is the network function type.

[0056] In some embodiments, the second network node is a network node instance, in particular a network function instance.

[0057] In some embodiments, the first authorization scope and / or the second authorization scope is the OAuth scope.

[0058] In some embodiments, the first instruction is the allowedOperationsPerNfType attribute in the NFProfile data type or NFService data type.

[0059] In some embodiments, the second instruction is the allowedOperationsPerNfInstance attribute in the NFProfile data type or NFService data type.

[0060] In some embodiments, the third instruction is the allowedOperationsPerNfInstanceOverrides attribute in the NFProfile data type or NFService data type.

[0061] In some embodiments, the first network node is a network repository function (NRF), the second network node is a network function producer, and the third network node is a network function consumer.

[0062] Figure 3 is a flowchart illustrating the actions taken by a second network node to grant or authorize authorization scopes in a communication network.

[0063] In step S-301, the second network node sends a first instruction to the first network node for a first authorization scope relating to the network node type.

[0064] In step S-302, the second network node transmits to the first network node a second instruction relating to the second network node, where the second network node is of a network node type.

[0065] In step S-303, the second network node sends a third instruction to the first network node regarding the priority relating to the first authorization scope and / or the second authorization scope.

[0066] In some embodiments, priority relates to the priority of a first authorization scope, the priority of a second authorization scope, or the priority between the first and second authorization scopes.

[0067] In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in the network node registration request for network node discovery.

[0068] In some embodiments, the first network node further sends a registration response message to the second network node indicating the successful registration of the second network node.

[0069] In some embodiments, the first instruction, the second instruction, and / or the third instruction are included in the network node profile, in particular the network node profile is the network function profile.

[0070] In some embodiments, a third instruction indicates that the first authorization scope has a higher priority than the second authorization scope or overrides the second authorization scope, and in particular, the third instruction is a Boolean instruction.

[0071] In some embodiments, a third instruction indicates that a second authorization scope has a higher priority than or overrides a first authorization scope, and in particular, the third instruction is a Boolean instruction.

[0072] In some embodiments, the network node type is the network function type.

[0073] In some embodiments, the second network node is a network node instance, in particular a network function instance.

[0074] In some embodiments, the first authorization scope and / or the second authorization scope is the OAuth scope.

[0075] In some embodiments, the first instruction is the allowedOperationsPerNfType attribute in the NFProfile data type or NFService data type.

[0076] In some embodiments, the second instruction is the allowedOperationsPerNfInstance attribute in the NFProfile data type or NFService data type.

[0077] In some embodiments, the third instruction is the allowedOperationsPerNfInstanceOverrides attribute in the NFProfile data type or NFService data type.

[0078] In some embodiments, the first network node is a network repository function (NRF), and the second network node is a network function producer.

[0079] Figure 4 is a flowchart illustrating the actions taken by a third network node to grant or authorize authorization scopes in a communication network.

[0080] In step S-401, the third network node sends to the first network node a discovery request for the network node type of the second network node, or an access token request for the authorization scope of the second network node.

[0081] In step S-402, the third network node receives either a selection result in the discovery response or an access token in the access token response from the first network node.

[0082] In some embodiments, authorization of access to and / or the authorization scope of the second network node comprises determining that the authorization scope for access to the second network node is included in the second authorization scope.

[0083] In some embodiments, authorization to and / or access to the authorization scope of the second network node comprises determining, based on a third instruction, that the authorization scope of the second network node is included in a preferred or higher-priority authorization scope.

[0084] In some embodiments, priority relates to the priority of a first authorization scope, the priority of a second authorization scope, or the priority between the first and second authorization scopes.

[0085] In some embodiments, the selection of a second network node involves determining that the first authorization scope has a higher priority than the second authorization scope.

[0086] In some embodiments, the selection of a second network node comprises determining that the first authorization scope overrides the second authorization scope.

[0087] In some embodiments, the selection of a second network node involves determining that the second authorization scope has a higher priority than the first authorization scope.

[0088] In some embodiments, the selection of a second network node comprises determining that the second authorization scope overrides the first authorization scope.

[0089] In some embodiments, the network node type is the network function type.

[0090] In some embodiments, the second network node is a network node instance, in particular a network function instance.

[0091] In some embodiments, the first authorization scope and / or the second authorization scope is the OAuth scope.

[0092] In some embodiments, the first network node is a network repository function (NRF), the second network node is a network function producer, and the third network node is a network function consumer.

[0093] Figure 5 is a block diagram illustrating the elements of a mobile network node 500 of a mobile communications network. In some embodiments, the mobile network node 500 is an NRF 110. As shown, the mobile network node may include a network interface circuit 501 (also called a network interface) configured to provide communication with the core network and / or other nodes in the network. The mobile network node may also include a processing circuit 502 (also called a processor) coupled to the network interface circuit, and a memory circuit 503 (also called memory) coupled to the processing circuit. The memory circuit 503 may include computer-readable program code that, when executed by the processing circuit 502, causes the processing circuit to perform the operation according to the embodiments disclosed herein. According to other embodiments, the processing circuit 502 may be specified to include memory such that a separate memory circuit is not required. As discussed herein, the operation of the mobile network node may be performed by the processing circuit 502 and / or the network interface circuit 501. For example, the processing circuit 502 may control the network interface circuit 501 to send communications to one or more other network nodes through the network interface circuit 501 and / or to receive communications from one or more other network nodes through the network interface circuit. Furthermore, modules may be stored in memory 503, and these modules may provide instructions such that when the instructions of the module are executed by the processing circuit 502, the processing circuit 502 performs its respective operations (for example, the operations discussed below with respect to an exemplary embodiment relating to a core network node).

[0094] Figure 6 is a block diagram illustrating the elements of a mobile network node 600 of a mobile communications network. In some embodiments, the mobile network node 600 is an NFp. As shown, the mobile network node may include a network interface circuit 601 (also called a network interface) configured to provide communication with the core network and / or other nodes in the network. The mobile network node may also include a processing circuit 602 (also called a processor) coupled to the network interface circuit, and a memory circuit 603 (also called memory) coupled to the processing circuit. The memory circuit 603 may include computer-readable program code that, when executed by the processing circuit 602, causes the processing circuit to perform the operation according to the embodiments disclosed herein. According to other embodiments, the processing circuit 602 may be specified to include memory such that a separate memory circuit is not required. As discussed herein, the operation of the mobile network node may be performed by the processing circuit 602 and / or the network interface circuit 601. For example, the processing circuit 602 may control the network interface circuit 601 to send communications to one or more other network nodes through the network interface circuit 601 and / or to receive communications from one or more other network nodes through the network interface circuit. Furthermore, modules may be stored in memory 603, and these modules may provide instructions such that when the instructions of the module are executed by the processing circuit 602, the processing circuit 602 performs its respective operations (for example, the operations discussed below with respect to an exemplary embodiment relating to a core network node).

[0095] Figure 7 is a block diagram illustrating the elements of a mobile network node 700 of a mobile communications network. In some embodiments, the mobile network node 700 is an NFc. As shown, the mobile network node may include a network interface circuit 701 (also called a network interface) configured to provide communication with the core network and / or other nodes in the network. The mobile network node may also include a processing circuit 702 (also called a processor) coupled to the network interface circuit, and a memory circuit 703 (also called memory) coupled to the processing circuit. The memory circuit 703 may include computer-readable program code that, when executed by the processing circuit 702, causes the processing circuit to perform the operation according to the embodiments disclosed herein. According to other embodiments, the processing circuit 702 may be specified to include memory such that a separate memory circuit is not required. As discussed herein, the operation of the mobile network node may be performed by the processing circuit 702 and / or the network interface circuit 701. For example, the processing circuit 702 may control the network interface circuit 701 to send communications to one or more other network nodes through the network interface circuit 701 and / or to receive communications from one or more other network nodes through the network interface circuit. Furthermore, modules may be stored in memory 703, and these modules may provide instructions such that when the instructions of the module are executed by the processing circuit 702, the processing circuit 702 performs its respective operations (for example, the operations discussed below with respect to an exemplary embodiment relating to a core network node).

[0096] Embodiments within the scope of the present invention may also include computer-readable media for carrying computer-executable instructions or data structures, or on which computer-executable instructions or data structures are stored. Such computer-readable media may be any available medium accessible by a general-purpose or dedicated computer. Such tangible computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code means in the form of computer-executable instructions or data structures. When information is transferred to or provided to a computer via a network or another communication connection (either wired, wireless, or a combination thereof), the computer appropriately considers the connection to be computer-readable media. Thus, any such connection is appropriately referred to as computer-readable media. The above combinations should also be included within the scope of tangible computer-readable media.

[0097] Computer executable instructions include instructions and data that cause, for example, a general-purpose computer, a dedicated computer, or a dedicated processing device to perform a certain function or group of functions. Computer executable instructions also include program modules that are executed by computers, either standalone or in a networked environment. Generally, program modules include routines, programs, objects, components, and data structures that perform a particular task or implement a particular abstract data type. Computer executable instructions, associated data structures, and program modules represent examples of program code means for performing steps of the methods disclosed herein. A particular sequence of such executable instructions or associated data structures represents an example of corresponding behavior for implementing the functions described in such steps.

[0098] Those skilled in the art will understand that other embodiments of the present invention can be practiced in network computing environments with many types of computer system configurations, including personal computers, handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, and mainframe computers. Embodiments can also be practiced in distributed computing environments where tasks are performed by local and remote processing devices linked through a communication network (either by wired links, wireless links, or a combination thereof). In a distributed computing environment, program modules can reside in both local and remote memory storage devices.

[0099] Communication at various stages of the described system can be carried out through local area networks, token ring networks, the internet, corporate intranets, 802.11 series radio signals, fiber optic networks, radio or microwave transmissions, and the like. While the underlying communication technologies may change, the basic principles described herein remain applicable.

[0100] The various embodiments described above are provided merely as illustrations and should not be construed as limiting the invention. For example, the principles described herein may be applied to any remotely controlled device. Furthermore, those skilled in the art will recognize that communication between remote, remotely controlled devices is not limited to communication over a local area network and may include communication over infrared channels, Bluetooth, or any other suitable communication interface. Those skilled in the art will readily recognize various modifications and changes that may be made to the invention without following the exemplary embodiments and applications illustrated and described herein, and without departing from the scope of this disclosure.

[0101] The technical terms used herein are for the purpose of describing various embodiments and do not limit the exemplary embodiments. The singular forms “a,” “an,” and “the” as used herein also include the plural form unless the context explicitly indicates otherwise. It will be further understood that, as used herein, the terms “includes,” “including,” “comprises,” and “comprising” indicate the presence of the described features, integers, steps, actions, elements, or components, and combinations thereof, but do not exclude the presence or addition of one or more other features, integers, steps, actions, elements, or components, and combinations thereof. Furthermore, all terms used in the claims should be interpreted according to their common meanings in the art unless otherwise expressly provided herein. All references to “one (a) / one (an) / the element, apparatus, component, means, module, step, etc.” should be openly understood to refer to at least one instance of that element, apparatus, component, means, module, step, etc., unless otherwise expressly stated. Unless expressly stated otherwise, the steps of any method disclosed herein do not need to be performed in the strict order disclosed.

Claims

1. A method performed by a first network node to grant or authorize an authorization scope in a communication network, wherein the method is: The first network node receives a first instruction from the second network node relating to the first authorization scope of the second network node type, The first network node receives a second instruction from the second network node relating to at least one second network node instance, and The first network node receives a third instruction from the second network node regarding the priority relating to the first authorization scope and / or the second authorization scope, Granting authorization to and / or access to the authorization scope of the second network node at the first network node based on the first instruction, the second instruction, and the third instruction, in particular granting authorization of access where the authorization is part of a network node discovery procedure or an access token request procedure. Includes, The first network node is a network repository function (NRF). method.

2. The first network node receives from the third network node a discovery request regarding the network node type of the second network node, or an access token request regarding the authorization scope of the second network node. In the first network node, granting the third network node access to and / or the second network node's authorization scope based on the first instruction, the second instruction, and the third instruction, The first network node transmits the discovery result in the discovery response, or transmits the access token in the access token response, to the third network node. The method according to claim 1, further comprising:

3. The method of claim 2, wherein the authorization of access to and / or the authorization scope of the second network node comprises determining that the authorization scope for access to the second network node is included in the second authorization scope.

4. The method of claim 2, wherein the authorization of access to and / or the authorization scope of the second network node is determined, based on the third instruction, to be included in the authorization scope of the second network node which is preferred or has a higher priority.

5. The method according to claim 1, wherein the priority relates to the priority of the first scope of authorization, the priority of the second scope of authorization, or the priority between the first scope of authorization and the second scope of authorization.

6. The method according to claim 1, wherein the selection of the second network node includes determining that the first authorization scope overrides the second authorization scope, determining that the second authorization scope has a higher priority than the first authorization scope, or determining that the second authorization scope overrides the first authorization scope.

7. The method according to claim 1, wherein the second network node is a network function producer and the third network node is a network function consumer.

8. A method performed by a second network node to grant or authorize an authorization scope in a communication network, wherein the method is: Sending a first instruction of a first authorization scope relating to the second network node type from the second network node to the first network node, Sending a second instruction of a second authorization scope relating to at least one second network node instance from the second network node to the first network node, Sending a third instruction of priority relating to the first authorization scope and / or the second authorization scope from the second network node to the first network node Includes, The first network node is a network repository function (NRF). method.

9. The method according to claim 8, wherein the priority relates to the priority of the first scope of authorization, the priority of the second scope of authorization, or the priority between the first scope of authorization and the second scope of authorization.

10. The method according to claim 8, wherein the first instruction, the second instruction and / or the third instruction are included in a network node registration request for network node discovery.

11. The method according to claim 8, wherein the first instruction, the second instruction and / or the third instruction are included in a network node profile, and in particular the network node profile is a network function profile.

12. The method according to claim 8, wherein the third instruction indicates that the first authorization scope has a higher priority than or overrides the second authorization scope, and in particular, the third instruction is a Boolean instruction.

13. The method according to claim 8, wherein the third instruction indicates that the second authorization scope has a higher priority than the first authorization scope or overrides the first authorization scope, and in particular the third instruction is a Boolean instruction.

14. The method according to claim 8, wherein the second network node is a network function producer.

15. A method performed by a third network node to grant or authorize an authorization scope in a communication network, wherein the method is: Sending a discovery request from the third network node to the first network node regarding the network node type of the second network node, or an access token request regarding the authorization scope of the second network node, The third network node receives a discovery result in a discovery response or an access token in an access token response from the first network node. Includes, The first network node is a network repository function (NRF), Authorization of access to and / or the authorization scope of the second network node includes determining the authorization scope for the access to the second network node based on a first authorization scope relating to the network node type of the second network node and a second authorization scope relating to at least one second network node instance of the second network node. method.

16. The method according to claim 15, wherein authorization for access to and / or the scope of authorization of the second network node includes determining that the scope of authorization for access to the second network node is included in the second scope of authorization.

17. The method according to claim 15, wherein authorization to and / or access of the second network node to the authorization scope of the second network node is determined, based on a third instruction, to be included in an authorization scope that is preferred or has a higher priority.

18. The method according to claim 15, wherein the priority relates to the priority of the first scope of authorization, the priority of the second scope of authorization, or the priority between the first scope of authorization and the second scope of authorization.

19. The method according to claim 15, wherein the selection of the second network node includes determining that the first authorization scope has a higher priority than the second authorization scope, determining that the first authorization scope overrides the second authorization scope, determining that the second authorization scope has a higher priority than the first authorization scope, or determining that the second authorization scope overrides the first authorization scope.

20. A device for granting or authorizing authorization scopes in a communication network, wherein the device comprises a processor and memory, the memory containing instructions executable by the processor such that the device is operable to perform the method according to any one of claims 1 to 7.

21. A device for granting or authorizing authorization scopes in a communication network, wherein the device comprises a processor and memory, the memory containing instructions executable by the processor such that the device is operable to perform the method according to any one of claims 8 to 14.

22. A device for granting or authorizing authorization scopes in a communication network, wherein the device comprises a processor and memory, the memory containing instructions executable by the processor such that the device is operable to perform the method according to any one of claims 15 to 19.

Citation Information

Patent Citations

  • Registering and Requesting Services in a Service Based Architecture

    US20220248316A1