Verification of authenticity of network function in public land mobile network hosted non-public network system

The solution for verifying NF authenticity in PLMN-hosted NPNs involves determining security domains and enforcing access policies to secure NFs, addressing security risks and unauthorized activities in PLMN-hosted NPNs.

WO2025206673A1PCT designated stage Publication Date: 2025-10-02SAMSUNG ELECTRONICS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/003710
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-26
Filing Date
2025-03-24
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In Public Land Mobile Networks (PLMNs) hosting Non-Public Networks (NPNs), compromised Network Functions (NFs) at customer premises can be exploited by attackers for malicious activities such as topology information collection, sending malformed messages, launching Denial of Service (DoS) attacks, and unauthorized service operations, posing security risks.

Method used

Implement methods and apparatuses for verifying the authenticity of NFs by determining their security domains and performing security checks based on access policies, using mechanisms like ID tokens, certificate-bound access tokens, mutual TLS, and different security protocol profiles, and ensuring secure inter-NF communication across domains.

Benefits of technology

Enhances security by authenticating and authorizing NFs, preventing unauthorized access and ensuring the integrity of NFs across different security domains, thereby mitigating risks of attacks and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025003710_02102025_PF_FP_ABST
    Figure KR2025003710_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Embodiments disclosed herein describe a method and apparatus for verifying the authenticity of a Network Function (NF) in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system. The method involves receiving an access token request message sent from an NFc apparatus located in a consumer premises to request an access token. The request includes determining if the security domain of the consumer apparatus is outside a PLMN operational domain based on the NF instance ID. The NFc apparatus undergoes security checks based on an access policy. If authorized, an access token is generated, including the access policy with security checks to verify the consumer's security domain. Further, the access token response message containing the token is sent to the NFc apparatus.
Need to check novelty before this filing date? Find Prior Art

Description

VERIFICATION OF AUTHENTICITY OF NETWORK FUNCTION IN PUBLIC LAND MOBILE NETWORK HOSTED NON-PUBLIC NETWORK SYSTEM

[0001] The present application relates to a wireless communication and more particularly, to a method and apparatus for verification of authenticity of a Network Function (NF) in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system.

[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.

[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.

[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.

[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.

[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.

[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.

[0008] In the context of modern telecommunications networks, Non-Public Networks (NPNs) can be hosted by Public Land Mobile Networks (PLMNs). NPN customers may request dedicated Network Functions (NFs) to be deployed on their premises for reasons related to performance and privacy. Public Network Integrated NPNs (PNI-NPNs) are a type of NPN that is made available through PLMNs, for example, by means of dedicated Data Network Names (DNNs) or by allocating one or more Network Slice instances specifically for the NPN. Consequently, NFs within PNI-NPN Network Slice instances may necessitate interfaces that span the operational domains between PNI-NPNs and PLMNs. Further, Application Functions (AFs) within the operational domain of PNI-NPN DNNs may also require interfaces that cross these operational domains.

[0009] When dedicated User Plane Functions (UPFs) and portions of Control Plane (CP) functions are deployed at customer premises (referred to as Security Domain 1), the interface between the dedicated NFs at the customer premises and the NFs at the operator premises (referred to as Security Domain 2) is typically a Service-Based Architecture (SBA) interface. However, if the NFs at the customer premises are compromised, attackers may exploit these compromised NFs to execute various malicious activities.

[0010] Several problems arise if a NF is compromised by an attacker:

[0011] Topology Information Collection: An attacker may gather topology information of the PLMN or NPN and use it to orchestrate further attacks on these networks.

[0012] Malformed Signaling Messages: The attacker may send malformed signaling messages to NFs, thereby degrading the NFs' ability to process normal signaling messages.

[0013] Incorrect NF Type Messages: The attacker may transmit messages to NFs in the opposite domain with incorrect NF types, contrary to 3GPP specifications.

[0014] Denial of Service (DoS) Attacks: The attacker may launch DoS attacks to flood and disrupt the availability of NFs in the operator domain and vice versa.

[0015] Unauthorized Service Operations: The attacker may initiate unauthorized service operations, which is particularly challenging to prevent when access tokens cross the security / trust boundary between operator and customer premises.

[0016] Unauthorized Service Requests: A compromised NF at the customer premises may request services from NFs in a PLMN that are not permitted at the customer premises, and vice versa.

[0017] Replay Attacks: If an access token is leaked or a communication message is eavesdropped on a compromised NF, the attacker may launch a replay attack on the producer within the validity period of the token.

[0018] Unauthorized Network Access: An attacker can gain unauthorized access to the network and restrict the usage of NF resources / services.

[0019] User Equipment (UE) Privacy Data Leakage: Unauthorized access by the attacker may lead to the leakage of UE privacy data stored in the NF. Therefore, it becomes imperative to implement mechanisms to perform attestation and determine the trustworthiness of the NFs at customer premises to mitigate these security risks.

[0020] It is desired to address the above-mentioned disadvantages or other short-comings or at least provide an authentication and authorization of the NFs in the customer premises and operator premises over the trust boundary.

[0021] The principal object of the invention herein is to provide methods and apparatuses for verification of authenticity of an NF in a PLMN hosted NPN system.

[0022] Another object of the invention herein is to enforce policy checks based on a domain of an NF service consumer (NFc) either by an Network Repository Function (NRF) before generating and providing the access token or by an NF service producer (NFp) when the NFc requests the service.

[0023] Yet another object of the invention herein is to identify for the NFc deployed outside the PLMN operational domain (i.e., in the customer premises) a domain of the NFc by the NRF or NFp using an NF instance Identifier (ID) included in a request message.

[0024] Yet another object of the invention herein is to perform additional security checks based on access policy by either the NRF, a Service Communication Proxy (SCP), or by the NFp once the domain of the NF Service Consumer is determined to be outside the PLMN operational domain (operator premises).

[0025] Yet another object of the invention herein is to perform a security policy check by the NRF before providing the access token or by the NF producer based on the access policy present in the access token.

[0026] In an aspect, the objects are achieved by providing a method for verification of authenticity of the NF in the PLMN hosted NPN system. The method includes receiving, by a NRF apparatus, an access token request message for an access token from an NFc apparatus when the NFc apparatus is in a consumer premises. The access token request message comprises an NF instance identifier (ID) indicating a security domain to which the NFc apparatus belongs. Further, the method includes determining, by the NRF apparatus, whether the security domain of the NFc apparatus is outside a PLMN operational domain based on the NF instance ID received in the access token request message. When the security domain of the NFc is determined to be outside the PLMN operational domain, the NRF apparatus authorizes the NFc apparatus by performing a plurality of security checks based on an access policy. Upon successful authorization of the NFc apparatus, the NRF apparatus generates an access token response message by adding the access token. The access token comprises the access policy indicating the plurality of security checks to be performed by a NF service producer (NFp) apparatus to verify the security domain of the NFc apparatus. Furthermore, the NRF apparatus sends the access token response message to the NFc apparatus.

[0027] In another aspect, the objects are achieved by providing a method for verification of authenticity of the NF in the PLMN hosted NPN system. The method includes receiving, by an NFp apparatus, an NF service request message from an NFc apparatus. The NF service request message comprises an access token to access an NF service from the NFp apparatus. Further, the method includes determining, by the NFp apparatus, whether the NF service request message comprises an access policy included in the access token. The access policy comprises a plurality of security checks to be performed successfully by the NFp apparatus before providing the NF service to the NFc apparatus. Further, the method includes performing, by the NFp apparatus, one of the following steps: configuring the plurality of security checks for the NFc apparatus based on the access policy when the access policy is included in the access token; authorizing the NFc apparatus by performing the plurality of security checks based on the access policy; and sending an NF service response message to provide the NF service when authorization of the NFc apparatus is successful. Furthermore, the method includes pre-configuring an access policy locally and using the pre-configured access policy to enforce the plurality of security checks for the NFc apparatus when the access policy is not included in the access token. The NFc apparatus is authorized by performing the plurality of security checks based on the pre-configured access policy. Furthermore, the method includes sending an NF service response message to provide the NF service when authorization of the NFc apparatus is successful.

[0028] In another aspect, the objects are achieved by providing a method for verification of authenticity of the NF in the PLMN hosted NPN system. The method includes generating, by an NFc apparatus, an access token request message by adding an NF instance ID indicating a security domain to which the NFc apparatus belongs. Further, sending by the NFc apparatus the access token request message for an access token to an NRF apparatus when the NFc apparatus is in a consumer premises. Further, the method includes receiving, by the NFc apparatus, an access token response message from the NRF apparatus, which includes the access token comprising an access policy indicating a plurality of security checks to be performed by an NFp apparatus to verify the security domain of the NFc apparatus. Generating, by the NFc apparatus, an NF service request message by adding the access token to access an NF service from the NFp apparatus. Further, the method includes sending, by the NFc apparatus, the NF service request message to an NFp apparatus. Furthermore, the access token comprises the access policy indicating the plurality of security checks to be performed successfully by the NFp apparatus before providing the NF service to the NFc apparatus. Further, the method includes receiving, by the NFc apparatus, an NF service response message from the NFp apparatus.

[0029] In another aspect, the objects are achieved by providing an NRF apparatus for verification of the authenticity of an NF in a PLMN-hosted NPN system. The NRF apparatus comprises a memory, which includes information about an NFc apparatus and an NFp apparatus, a processor, and an NRF security check enforcement controller. The NRF security check enforcement controller is connected to both the memory and the processor. Upon receiving an access token request message for an access token from an NFc apparatus located in a consumer premises, the NRF security check enforcement controller processes the request. The access token request message includes an NF instance ID that indicates the security domain to which the NFc apparatus belongs. The NRF security check enforcement controller determines whether the security domain of the NFc apparatus is outside the PLMN operational domain based on the NF ID received in the access token request message. When the security domain of the NFc apparatus is determined to be outside the PLMN operational domain, the NRF security check enforcement controller authorizes the NFc apparatus by performing a plurality of security checks based on an access policy. If the authorization is successful, the NRF security check enforcement controller generates an access token response message by adding the access token. The access token includes the access policy, which indicates the plurality of security checks to be performed by the NFp apparatus to verify the security domain of the NFc apparatus. Furthermore, the NRF security check enforcement controller sends the access token response message to the NFc apparatus.

[0030] In another aspect, the objects are achieved by providing an NFc apparatus for verifying the authenticity of an NF in a PLMN-hosted NPN system. The NFc apparatus comprises a memory, which includes information about an NRF apparatus and an NFp apparatus. Further, the apparatus includes a processor and an NFc security check enforcement controller. The NFc security check enforcement controller is connected to both the memory and the processor. The NFc security check enforcement controller generates an access token request message by adding an NF instance ID that indicates the security domain to which the NFc apparatus belongs. This access token request message is sent to an NRF apparatus when the NFc apparatus is on consumer premises. Upon sending, the NFc apparatus receives an access token response message from the NRF apparatus. The access token in the response message comprises an access policy that indicates a plurality of security checks to be performed by the NFp apparatus to verify the security domain of the NFc apparatus. Further, the NFc security check enforcement controller generates an NF service request message by adding the access token to access an NF service from the NFp apparatus. This NF service request message is sent to the NFp apparatus. The access token includes the access policy, which specifies the plurality of security checks that is successfully performed by the NFp apparatus before providing the NF service to the NFc apparatus. Furthermore, the NFc apparatus receives an NF service response message from the NFp apparatus.

[0031] In another aspect, the objects are achieved by providing an NFp apparatus for verification of the authenticity of an NF in a PLMN-hosted NPN system. The NFp apparatus comprises a memory, which includes information about the NRF apparatus and an NFc apparatus, a processor, and an NFp security check enforcement controller. The NFp security check enforcement controller is connected to the memory and processor.

[0032] In another aspect, the objects are achieved by providing an SCP apparatus for enforcing security check and verification of the authenticity of an NF in a PLMN-hosted NPN system. The SCP apparatus comprises a memory, which includes information about the NRF apparatus and an NFc apparatus, a processor, and an SCP security check enforcement controller. The SCP security check enforcement controller is connected to the memory and processor.

[0033] In another aspect, the objects are achieved by providing a Proxy entity apparatus for verification of the authenticity of an NF in a PLMN-hosted NPN system. The Proxy entity apparatus comprises a memory, which includes information about the NRF apparatus and an NFc apparatus, a processor, and a Proxy entity security check enforcement controller. The Proxy entity security check enforcement controller is connected to the memory and processor.

[0034] The NFp security check enforcement controller receives an NF service request message from an NFc apparatus. The NF service request message comprises an access token to access an NF service from the NFp apparatus or SCP apparatus or Proxy entity apparatus. The NFp security check enforcement controller determines whether the NF service request message includes an access policy in the access token. The access policy comprises a plurality of security checks to be performed successfully by the NFp apparatus before providing the NF service to the NFc apparatus. When the access policy is included in the access token, the NFp security check enforcement controller performs one of the following actions: configuring the plurality of security checks for the NFc apparatus based on the access policy, authorizing the NFc apparatus by performing the plurality of security checks based on the access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus is successful. When the access policy is not included in the access token, the NFp security check enforcement controller pre-configures an access policy locally and uses the pre-configured access policy to enforce the plurality of security checks for the NFc apparatus. The NFp security check enforcement controller authorizes the NFc apparatus by performing the plurality of security checks based on the pre-configured access policy and sends an NF service response message to provide the NF service when authorization of the NFc apparatus is successful.

[0035] Embodiments of the present disclosure provides methods and apparatus for ensuring the authenticity of the NF consumer by performing certain security checks based on an access policy.

[0036] The invention is illustrated in the accompanying drawings, where like reference letters indicate corresponding parts. The embodiments will be better understood from the following description with reference to the drawings.

[0037] FIG. 1 is a block diagram that illustrates a scenario of PNI-NPN with dedicated UPF deployed in the customer premises according to the prior art.

[0038] FIG. 2 is a block diagram that illustrates a scenario of PNI-NPN with dedicated UPF and part of CP functions deployed in the customer premises according to the prior art.

[0039] FIG. 3 is a block diagram of a Network Repository Function (NRF) apparatus for verification of authenticity of a Network Function (NF) in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system according to embodiments as disclosed herein.

[0040] FIG. 4 is a block diagram of an NFc apparatus for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0041] FIG. 5A is a block diagram of an NFp apparatus for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0042] FIG. 5B is a block diagram of an SCP apparatus for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0043] FIG. 5C is a block diagram of a Proxy entity apparatus for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0044] FIG. 6 is a flowchart that illustrates a method for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0045] FIG. 7 is a flowchart that illustrates a method for performing the security check based on the access policy according to embodiments as disclosed herein.

[0046] FIG. 8 is a flowchart that illustrates a method for generation of an access token request message, sending the access token request message, and verification for authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0047] FIG. 9 is a sequence diagram that illustrates a scenario of the NFc / NFp registration with the OAuth 2.0 server (NRF) according to embodiments as disclosed herein.

[0048] FIG. 10 is a sequence diagram that illustrates the events of NFc service discovery according to the embodiments as disclosed herein.

[0049] FIG. 11 is a sequence diagram that illustrates the events of NFc verification by NRF according to the embodiments as disclosed herein.

[0050] FIG. 12 is a sequence diagram that illustrates the events of NFc verification by OAM / CH / NF validator according to the embodiments as disclosed herein.

[0051] FIG. 13 is a sequence diagram that illustrates the events of the NFp verifying NF based on access policy according to the embodiments as disclosed herein.

[0052] FIG. 14 is a block diagram that illustrates the Authorization code flow of OpenID Connect according to the embodiments as disclosed herein.

[0053] FIG. 15 is a sequence diagram that illustrates the events of NF attestation according to the embodiments as disclosed herein.

[0054] The embodiments and their features are detailed with reference to the non-limiting examples shown in the drawings and described below. Well-known components and techniques are omitted to avoid unnecessary detail. The described embodiments are not mutually exclusive and can be combined to form new embodiments. The term "or" is used in a non-exclusive sense unless stated otherwise. The examples provided are for illustrative purposes to aid understanding and should not be seen as limiting the scope of the embodiments.

[0055] As is existing in the field, embodiments can be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which can be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and can optionally be driven by firmware and software. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block can be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments can be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments can be physically combined into more complex blocks without departing from the scope of the disclosure.

[0056] The accompanying drawings aid in understanding the technical features, but the embodiments are not limited to these drawings. The disclosure extends to any alterations, equivalents, and substitutes beyond those shown. Terms like first, second, etc., are used for distinction and do not limit the elements.

[0057] Embodiments disclosed herein provide a method and apparatus for verifying the authenticity of NFs in the PLMN hosted NPN system. The method includes determining the security domain of the NFc and / or NFp. It also comprises methods for authentication and authorization of the NFc and / or NFp that are registering to the NRF based on the security domain of the NFs. Further, a method is provided to perform security checks in the access policy of the consumer when the NFs are in different security domains. This can be achieved using one of the following: including an ID token along with an access token, using certificate-bound access tokens, using mutual TLS, and / or using different security protocol profiles. The method mandates the use of TLS, IPSec, and HTTPS for inter-NF communication across different security domains and includes performing attestation to determine the trustworthiness of the NFs in different security domains, such as customer premises and / or EDGE premises.

[0058] NPN can be hosted by a PLMN. NPN customers can request dedicated NFs to be deployed in the customer premises for performance and privacy reasons. Public Network Integrated NPNs (PNI-NPNs) are NPNs made available via PLMNs, for example, by means of dedicated Data Network Names (DNNs) or by one or more Network Slice Instances (NSIs) allocated for the NPN. Therefore, NFs which may reside within PNI-NPN Network Slice Instances may require interfaces that cross the operational domains between PNI-NPNs and PLMNs. Further, Application Functions (AFs) which reside within a PNI-NPN DNN operational domain may require interfaces that cross the operational domains between PNI-NPNs and PLMNs.

[0059] The creation, modification, and termination of an NSI are supported by Management Services provided by the 5G management systems. Therefore, NFs which provide NSI Management Services may cross the operational domains between PNI-NPNs and PLMNs. NFs which reside in the PNI-NPN operational domain may require interfaces that cross the trust boundary between PNI-NPN and PLMN. Consequently, these interfaces require security controls to mutually protect the NFs residing in the PLMN operational domain and the PNI-NPN operational domain.

[0060] Security assumptions for various deployment scenarios include several possible deployment scenarios in the PNI-NPN model, Edge computing, and multisite Core Network (CN) where parts of the control plane, user plane, and radio access are shared between the operator and the customer / third party / public cloud / private cloud. As illustrated in FIG. 1 (Prior Art) and FIG. 2 (Prior Art), the issue and the proposed solution apply to scenarios where NFs are hosted by third party / public cloud / private cloud and / or Edge network. Dedicated NFs can be owned and managed by the operator yet deployed in the customer premises (or at the Edge network or public / private cloud) for providing enhanced services. In such cases, the dedicated NFs are considered to be hosted in an untrusted security domain, necessitating appropriate security measures compared to NFs communication within a trusted security domain. Trusted security domains correspond to infrastructure managed by the operator's network, while untrusted security domains correspond to infrastructure not managed by the operator's network. NFs deployed in an untrusted security domain need to adhere to stricter security controls, such as inter-NF communication even within the same security domain.

[0061] The system 100 depicted in FIG 1 illustrates a Public Network Integrated Non-Public Network (PNI-NPN) with a dedicated User Plane Function (UPF) deployed within customer premises according to the prior art. This system is designed to facilitate secure and communication between various network functions and domains. The system (100) includes several network functions located in the operator premises, which is identified as Security Domain 2. These network functions include the Network Slice Selection Function (NSSF) (101), Network Exposure Function (NEF) ((102)), Network Repository Function (NRF) (103), Policy Control Function (PCF) (104), Unified Data Management (UDM) (105), Application Function (AF) (106), and External Application Server Discovery Function (EASDF) (107).

[0062] The NSSF (101) is responsible for selecting the appropriate network slice for a particular service request. The NEF (102) provides secure exposure of network services and capabilities. The NRF (103) maintains an updated repository of available network functions and their profiles. The PCF (104) manages policy control decisions. The UDM (105) handles user data management and storage. The AF (106) supports application services, and the EASDF (107) is responsible for discovering external application servers.

[0063] Further, the system (100) includes additional network functions that facilitate cross-domain communication. These include the Network Slice Specific Authentication and Authorization Function (NSSAAF) (108), Authentication Server Function (AUSF) (109), Access and Mobility Management Function (AMF) (110), Session Management Function (SMF) (111), Service Communication Proxy (SCP) (112), and Network Slice Authentication and Authorization Control Function (NSACF) (113). These functions are responsible for various tasks such as authentication, authorization, mobility management, session management, and service communication.

[0064] The customer premises, identified as Security Domain 1, houses the dedicated User Plane Function (UPF) (114) and the Data Network (DN) (115). The UPF (114) is responsible for handling user plane traffic and is connected to the DN (115) via the N6 interface. The UPF (114) communicates with the SMF (111) in the operator premises via the N4 interface and with other UPFs or network functions via the N9 interface. In this system, a dedicated UPF ((114)) is deployed in customer premises. The N4 interface, which is a non-Service-Based Architecture (non-SBA) interface, connects the dedicated UPF ((114)) to the Session Management Function (SMF) ((111)) in the operator premises. The challenge encountered by this mechanism is that if NFs at the customer premises are compromised, attackers may utilize compromised NFs to collect topology information, steal access tokens, send malformed messages, or launch Denial of Service (DoS) attacks.

[0065] FIG. 2 illustrates the PNI-NPN with a dedicated UPF (114) and part of CP functions deployed in customer premises according to prior art. The AMF (110) and SMF (111) are part of the CP functions deployed in the customer premises. The UPF (114) is connected to the SMF (111) via the N4 interface. The UPF (114) is also connected to the DN (115) via the N6 interface. Further, there is an N9 interface for communication between different UPFs. This configuration allows for enhanced local control and management of network resources within the customer premises, providing improved performance and security for the PNI-NPN.

[0066] In this system, both the UPF (114) and part of CP functions are deployed in the customer premises. The CP functions include components like the SMF (111) and the AMF (110). The communication between the customer premises and the operator premises is established using the SBA interface. The challenge encountered by this mechanism is that attackers may initiate unauthorized service operations, and safeguarding access tokens from attackers is challenging when crossing the security / trust boundary between the operator premises and the customer premises.

[0067] In a system, when dedicated UPF (114) and part of CP functions are deployed in the customer premises (Security Domain 1), the interface between the dedicated NFs in the customer premises (third party / public cloud / private cloud / Edge network) and NFs in the operator premises (Security Domain 2) is the SBA interface. If the NFs at the customer premises are compromised, attackers may utilize compromised NFs to collect topology information, steal access tokens, send malformed messages, or launch DoS attacks, resulting in several security issues.

[0068] In contrast to the system, the present disclosure introduces a novel approach to determine the security domain and to authenticate and authorize the NFc and / or NFp. It also includes performing security checks in the access policy of the consumer when the NFs are in different security domains using one of the following: including an ID token along with an access token, using certificate-bound access tokens, using mutual TLS, and / or using different security protocol profiles. Furthermore, the method mandates the use of TLS for inter-NF communication across different security domains and includes performing attestation to determine the trustworthiness of the NFs in customer premises.

[0069] Referring now to the drawings, and more particularly to FIGS. 3 through 15, there are shown preferred embodiments.

[0070] FIG. 3 is the block diagram of NRF apparatus (300) for verification of authenticity of the NF in the PLMN hosted NPN system.

[0071] PLMN hosted NPN system is a network configuration that allows private network services to be provided over the infrastructure of a public mobile network. This system leverages the existing cellular infrastructure, such as base stations and core network elements, to offer dedicated services to specific users or organizations. By utilizing the PLMN, the NPN can ensure wide coverage and robust connectivity, while still maintaining the privacy and security of a private network.

[0072] In an embodiment, the NRF apparatus (300) includes a processor (301), a memory (302), a communicator (303), and an NRF security check enforcement controller (304). The processor (301) is coupled with the memory (302), the communicator (303), and the NRF security check enforcement controller (304).

[0073] The processor (301) is responsible for verification of authenticity of the NF in the PLMN hosted NPN system. The processor (301) communicates with the memory (302), the communicator (303), and the NRF security check enforcement controller (304). The processor (301) is configured to execute instructions stored in the memory (302) and to manage verification of authenticity of the NF in the PLMN hosted NPN system. The processor (301) may include one or a plurality of processors, maybe a general-purpose processor such as a Central Processing Unit (CPU), an Application Processor (AP), or the like, a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a Neural Processing Unit (NPU).

[0074] The memory (302) stores the operating system, application software, and temporary data used by the processor (301). The memory (302) stores instructions to be executed by the processor (301). The memory (302) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (302) may in some examples be considered a non-transitory storage medium. The term non-transitory may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term non-transitory should not be interpreted that the memory (302) is non-movable. The memory (302) includes NFc apparatus (400) information, NFp apparatus (500) information as a total number of stored messages, a record of the stored message, and a reference to the NF configuration that needs to be applied to the delivery of the message.

[0075] The communicator (303) facilitates NF communication between the processor (301) and the memory (302), supporting various communication protocols such as Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Transport Layer Security (TLS), Internet Protocol Security (IPSec), Hypertext Transfer Protocol Secure (HTTPS). Further, the communicator (303) is configured for communicating internally between internal hardware components. The communicator (303) includes an electronic circuit specific to a standard that enables wired or wireless communication. The communicator (303) facilitates the transmission of messages.

[0076] The NRF security check enforcement controller (304) is specialized hardware designed for verification of authenticity of the NF in the PLMN hosted NPN system. In an embodiment, the structure of such an innovative integrated circuit of the NRF security check enforcement controller (304) can include a multi-core architecture that enables the verification of authenticity of the NF in the PLMN hosted NPN system. Each core is optimized for specific tasks such as generating access tokens and performing the verification of authenticity based on the access policy, security check, etc. The integrated circuit of the NRF security check enforcement controller (304) is made of a combination of analog and digital components designed to enable configuration of verification of authenticity of the NF in the PLMN hosted NPN system. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include a microcontroller unit (MCU) and a digital signal processor (DSP) that work in tandem to introduce one new attribute of this NF that includes information related to the storage format to be used by the NRF apparatus (300), respectively.

[0077] The NRF security check enforcement controller (304) receives an access token request message for an access token from an NFc apparatus (400) when the NFc apparatus (400) is in a consumer premises. Further, the access token request message comprises an NF instance ID indicating a security domain to which the NFc apparatus (400) belongs. The NRF security check enforcement controller (304) determines whether the security domain of the NFc apparatus (400) is outside a PLMN operational domain based on an NF instance ID received in the access token request message.

[0078] The NRF security check enforcement controller (304) authorizes the NFc apparatus (400) by performing at least one security check based on an access policy when the security domain of the NFc is determined to be outside the PLMN operational domain. The NRF security check enforcement controller (304) also generates an access token response message by adding the access token when authorization of the NFc apparatus (400) is successful. Further, the access token comprises the access policy indicating the at least one security check to be performed by an NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) to verify the security domain of the NFc apparatus (400) and sends the access token response message to the NFc apparatus (400).

[0079] The comprehensive management capabilities of the NRF security check enforcement controller (304) ensure seamless verification of authenticity of the NF in the PLMN hosted NPN system. This optimizes the security checks in the access policy, ensuring verifying NFc authenticity.

[0080] FIG. 4 is the block diagram of the NFc apparatus (400) for verification of authenticity of the NF in the PLMN hosted NPN system.

[0081] In an embodiment, the NFc apparatus (400) is associated with a NFc customer includes a processor (401), a memory (402), a communicator (403), and an NFc security check enforcement controller (404). The processor (401) is coupled with the memory (402), the communicator (403), and the NFc security check enforcement controller (404).

[0082] The processor (401) is responsible for verification of authenticity of the NF in the PLMN hosted NPN system. The processor (401) communicates with the memory (402), the communicator (403), and the NFc security check enforcement controller (404). The processor (401) is configured to execute instructions stored in the memory (402) and to manage verification of authenticity of the NF in the PLMN hosted NPN system. The processor (401) may include one or a plurality of processors, maybe a general-purpose processor such as a Central Processing Unit (CPU), an Application Processor (AP), or the like, a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a Neural Processing Unit (NPU).

[0083] The memory (402) stores the operating system, application software, and temporary data used by the processor (401). The memory (402) stores instructions to be executed by the processor (401). The memory (402) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (402) may, in some examples, be considered a non-transitory storage medium. The term non-transitory may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term non-transitory should not be interpreted that the memory (402) is non-movable. The memory (402) includes a NF, NRF apparatus information, and NFp apparatus information.

[0084] The communicator (403) facilitates NF communication between the processor (401) and the memory (402), supporting various communication protocols such as TCP / IP, UDP, TLS, IPSec, HTTPS. Further, the communicator (403) is configured for communicating internally between internal hardware components. The communicator (403) includes an electronic circuit specific to a standard that enables wired or wireless communication. The communicator (403) facilitates the transmission of messages.

[0085] The NFc security check enforcement controller (404) is specialized hardware designed for verification of authenticity of the NF in the PLMN hosted NPN system. In an embodiment, the structure of such an innovative integrated circuit of the NFc security check enforcement controller (404) can include a multi-core architecture that enables the verification of authenticity of the NF in the PLMN hosted NPN system. Each core is optimized for specific tasks such as generating access tokens to support the access policy and performing the verification of authenticity based on the access policy security check, etc. The integrated circuit of the NFc security check enforcement controller (404) is made of a combination of analog and digital components designed to enable configuration of verification of authenticity of the NF in the PLMN hosted NPN system. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include an MCU and a DSP that work in tandem to introduce one new attribute of this NF that includes information related to the storage format to be used by the NRF apparatus (300), respectively.

[0086] The NFc security check enforcement controller (404) generates an access token request message by adding an NF instance identifier (ID) indicating a security domain to which the NFc apparatus (400) belongs.

[0087] The NFc security check enforcement controller (404) sends the access token request message for an access token to a Network Repository Function (NRF) apparatus when the NFc apparatus (400) is in consumer premises. The NFc security check enforcement controller (404) receives an access token response message from the NRF apparatus (300). Further, the access token comprises an access policy indicating at least one security check to be performed by an NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) to verify the security domain of the NFc apparatus (400).

[0088] The NFc security check enforcement controller (404) generates an NF service request message by adding the access token to access an NF service from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520), further sends the NF service request message from an NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520). The access token comprises the access policy indicating the at least one security check to be performed successfully by the NFp apparatus (500) before providing the NF service to the NFc apparatus (400) and receives an NF service response message from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520).

[0089] The comprehensive management capabilities of the NFc security check enforcement controller (404) ensure seamless verification of authenticity of the NF in the PLMN hosted NPN system. This optimizes the security checks in the access policy, ensuring verifying NFc authenticity.

[0090] FIG. 5A is the block diagram of the NFp apparatus (500) for verification of authenticity of the NF in the PLMN hosted NPN system.

[0091] In an embodiment, the NFp apparatus (500) is associated with a NF producer. The NFp apparatus (500) includes a processor (501), a memory (502), a communicator (503), and an NFp security check enforcement controller (504). The processor (501) is coupled with the memory (502), the communicator (503), and the NFp security check enforcement controller (504).

[0092] The processor (501) is responsible for verification of authenticity of the NF in the PLMN hosted NPN system. The processor (501) communicates with the memory (502), the communicator (503), and the NFp security check enforcement controller (504). The processor (501) is configured to execute instructions stored in the memory (502) and to manage verification of authenticity of the NF in the PLMN hosted NPN system. The processor (501) may include one or a plurality of processors, maybe a general-purpose processor such as a Central Processing Unit (CPU), an Application Processor (AP), or the like, a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a Neural Processing Unit (NPU).

[0093] The memory (502) stores the operating system, application software, and temporary data used by the processor (501). The memory (502) stores instructions to be executed by the processor (501). The memory (502) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (502) may in some examples be considered a non-transitory storage medium. The term non-transitory may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term non-transitory should not be interpreted that the memory (502) is non-movable. The memory (502) includes a NF, NRF apparatus information, and NFc apparatus information.

[0094] The communicator (503) facilitates NF communication between the processor (501) and the memory (502), supporting various communication protocols such as TCP / IP, UDP, TLS, IPSec, HTTPS. Further, the communicator (503) is configured for communicating internally between internal hardware components. The communicator (503) includes an electronic circuit specific to a standard that enables wired or wireless communication. The communicator (503) facilitates the transmission of messages.

[0095] The NFp security check enforcement controller (504) is specialized hardware designed for verification of authenticity of the NF in the PLMN hosted NPN system. In an embodiment, the structure of such an innovative integrated circuit of the NFc security check enforcement controller (404) can include a multi-core architecture that enables the verification of authenticity of the NF in the PLMN hosted NPN system. Each core is optimized for specific tasks such as generating access tokens to support the access policy and performing the verification of authenticity based on the access policy security check, etc. The integrated circuit of the NFp security check enforcement controller (504) is made of a combination of analog and digital components designed to enable configuration of verification of authenticity of the NF in the PLMN hosted NPN system. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include an MCU and a DSP that work in tandem to introduce one new attribute of this NF that includes information related to the storage format to be used by the NRF apparatus (300), respectively.

[0096] The NFp security check enforcement controller (504) receives an NF service request message from an NFc apparatus (400), wherein the NF service request message comprises an access token to access an NF service from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520).

[0097] The NFp security check enforcement controller (504) determines whether the NF service request message comprises an access policy included in the access token, wherein the access policy comprises at least one security check to be performed successfully by the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) before providing the NF service to the NFc apparatus (400).

[0098] The NFp security check enforcement controller (504) performs one of configuring the at least one security check for the NFc apparatus (400) based on the access policy when the access policy is included in the access token, authorizing the NFc apparatus (400) by performing the at least one security check based on the access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful, and pre-configuring an access policy locally and using the pre-configured access policy to enforce at least one security check for the NFc apparatus (400) when the access policy is not included in the access token, authorizing the NFc apparatus (400) by performing the at least one security check based on the pre-configured access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful.

[0099] The comprehensive management capabilities of the NFp security check enforcement controller (504) ensure seamless verification of authenticity of the NF in the PLMN hosted NPN system. This optimizes the security checks in the access policy and ensures verifying NFc authenticity.

[0100] FIG. 5B is a block diagram of an SCP apparatus (510) for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0101] In an embodiment, the SCP apparatus (510) is associated with a NF producer. The SCP apparatus (510) includes a processor (511), a memory (512), a communicator (513), and an SCP security check enforcement controller (514). The processor (511) is coupled with the memory (512), the communicator (513), and the SCP security check enforcement controller (514).

[0102] The processor (511) is responsible for verification of authenticity of the NF in the PLMN hosted NPN system. The processor (511) communicates with the memory (512), the communicator (513), and the SCP security check enforcement controller (514). The processor (511) is configured to execute instructions stored in the memory (512) and to manage verification of authenticity of the NF in the PLMN hosted NPN system. The processor (511) may include one or a plurality of processors, maybe a general-purpose processor such as a Central Processing Unit (CPU), an Application Processor (AP), or the like, a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a Neural Processing Unit (NPU).

[0103] The memory (512) stores the operating system, application software, and temporary data used by the processor (511). The memory (512) stores instructions to be executed by the processor (511). The memory (512) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (512) may in some examples be considered a non-transitory storage medium. The term non-transitory may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term non-transitory should not be interpreted that the memory (512) is non-movable. The memory (512) includes a NF, NRF apparatus information, and NFc apparatus information.

[0104] The communicator (513) facilitates NF communication between the processor (511) and the memory (512), supporting various communication protocols such as TCP / IP, UDP, TLS, IPSec, HTTPS. Further, the communicator (513) is configured for communicating internally between internal hardware components. The communicator (513) includes an electronic circuit specific to a standard that enables wired or wireless communication. The communicator (513) facilitates the transmission of messages.

[0105] The SCP security check enforcement controller (514) is specialized hardware designed for verification of authenticity of the NF in the PLMN hosted NPN system. In an embodiment, the structure of such an innovative integrated circuit of the SCP security check enforcement controller (514) can include a multi-core architecture that enables the verification of authenticity of the NF in the PLMN hosted NPN system. Each core is optimized for specific tasks such as generating access tokens to support the access policy and performing the verification of authenticity based on the access policy security check, etc. The integrated circuit of the SCP security check enforcement controller (514) is made of a combination of analog and digital components designed to enable configuration of verification of authenticity of the NF in the PLMN hosted NPN system. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include an MCU and a DSP that work in tandem to introduce one new attribute of this NF that includes information related to the storage format to be used by the NRF apparatus (300), respectively.

[0106] The SCP security check enforcement controller (514) receives an NF service request message from an NFc apparatus (400), wherein the NF service request message comprises an access token to access an NF service from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520).

[0107] The SCP security check enforcement controller (514) determines whether the NF service request message comprises an access policy included in the access token, wherein the access policy comprises at least one security check to be performed successfully by the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) before providing the NF service to the NFc apparatus (400).

[0108] The SCP security check enforcement controller (514) performs one of configuring the at least one security check for the NFc apparatus (400) based on the access policy when the access policy is included in the access token, authorizing the NFc apparatus (400) by performing the at least one security check based on the access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful, and pre-configuring an access policy locally and using the pre-configured access policy to enforce at least one security check for the NFc apparatus (400) when the access policy is not included in the access token, authorizing the NFc apparatus (400) by performing the at least one security check based on the pre-configured access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful.

[0109] The comprehensive management capabilities of the SCP security check enforcement controller (514) ensure seamless verification of authenticity of the NF in the PLMN hosted NPN system. This optimizes the security checks in the access policy and ensures verifying NFc authenticity.

[0110] FIG. 5C is a block diagram of a Proxy entity apparatus (520) for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0111] In an embodiment, the Proxy entity apparatus (520) is associated with a NF producer. The Proxy entity apparatus (520) includes a processor (521), a memory (522), a communicator (523), and a Proxy entity security check enforcement controller (524). The processor (521) is coupled with the memory (522), the communicator (523), and the Proxy entity security check enforcement controller (524).

[0112] The processor (521) is responsible for verification of authenticity of the NF in the PLMN hosted NPN system. The processor (511) communicates with the memory (522), the communicator (523), and the Proxy entity security check enforcement controller (524). The processor (521) is configured to execute instructions stored in the memory (522) and to manage verification of authenticity of the NF in the PLMN hosted NPN system. The processor (521) may include one or a plurality of processors, maybe a general-purpose processor such as a Central Processing Unit (CPU), an Application Processor (AP), or the like, a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a Neural Processing Unit (NPU).

[0113] The memory (522) stores the operating system, application software, and temporary data used by the processor (521). The memory (522) stores instructions to be executed by the processor (521). The memory (522) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (522) may in some examples be considered a non-transitory storage medium. The term non-transitory may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term non-transitory should not be interpreted that the memory (522) is non-movable. The memory (522) includes a NF, NRF apparatus information, and NFc apparatus information.

[0114] The communicator (523) facilitates NF communication between the processor (521) and the memory (522), supporting various communication protocols such as TCP / IP, UDP, TLS, IPSec, HTTPS. Further, the communicator (523) is configured for communicating internally between internal hardware components. The communicator (523) includes an electronic circuit specific to a standard that enables wired or wireless communication. The communicator (523) facilitates the transmission of messages.

[0115] The Proxy entity security check enforcement controller (524) is specialized hardware designed for verification of authenticity of the NF in the PLMN hosted NPN system. In an embodiment, the structure of such an innovative integrated circuit of the Proxy entity security check enforcement controller (524) can include a multi-core architecture that enables the verification of authenticity of the NF in the PLMN hosted NPN system. Each core is optimized for specific tasks such as generating access tokens to support the access policy and performing the verification of authenticity based on the access policy security check, etc. The integrated circuit of the Proxy entity security check enforcement controller (524) is made of a combination of analog and digital components designed to enable configuration of verification of authenticity of the NF in the PLMN hosted NPN system. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include an MCU and a DSP that work in tandem to introduce one new attribute of this NF that includes information related to the storage format to be used by the NRF apparatus (300), respectively.

[0116] The Proxy entity security check enforcement controller (524) receives an NF service request message from an NFc apparatus (400), wherein the NF service request message comprises an access token to access an NF service from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520).

[0117] The Proxy entity security check enforcement controller (524) determines whether the NF service request message comprises an access policy included in the access token, wherein the access policy comprises at least one security check to be performed successfully by the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) before providing the NF service to the NFc apparatus (400).

[0118] The Proxy entity security check enforcement controller (524) performs one of configuring the at least one security check for the NFc apparatus (400) based on the access policy when the access policy is included in the access token, authorizing the NFc apparatus (400) by performing the at least one security check based on the access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful, and pre-configuring an access policy locally and using the pre-configured access policy to enforce at least one security check for the NFc apparatus (400) when the access policy is not included in the access token, authorizing the NFc apparatus (400) by performing the at least one security check based on the pre-configured access policy, and sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful.

[0119] The comprehensive management capabilities of the Proxy entity security check enforcement controller (524) ensure seamless verification of authenticity of the NF in the PLMN hosted NPN system. This optimizes the security checks in the access policy and ensures verifying NFc authenticity.

[0120] FIG. 6 is a flowchart that illustrates a method for verification of authenticity of the NF in the PLMN hosted NPN system according to embodiments as disclosed herein.

[0121] At step 601, the method includes receiving an access token request message for an access token from a NFc apparatus (400) when the NFc apparatus (400) is in a consumer premises. In an embodiment, the method includes receiving, by the NRF apparatus, an access token request message for an access token from the NFc apparatus (400) when the NFc apparatus (400) is in a consumer premises. The access token request message comprises an NF instance identifier (ID) indicating a security domain to which the NFc apparatus (400) belongs.

[0122] In an embodiment, the method includes adding, by the NRF apparatus (300), identification information of the NFc apparatus (400) and the access policy in the access token. The NRF apparatus (300) then transmits the access token to a Service Communication Proxy(SCP) or the NFp apparatus (500) to enforce at least one security check according to the access policy.

[0123] At step 602, the method includes determining whether the security domain of the NFc apparatus (400) is outside a PLMN operational domain based on the NF instance ID received in the access token request message. In an embodiment, the method includes determining, by the NRF apparatus (300), whether the security domain of the NFc apparatus (400) is outside a PLMN operational domain based on the NF instance ID received in the access token request message.

[0124] At step 603, the method includes authorizing the NFc apparatus (400) by performing at least one security check based on an access policy when the security domain of the NFc is determined to be outside the PLMN operational domain.

[0125] In an embodiment, the method includes a plurality of security checks. These checks comprise performing mandatory mutual TLS, providing an ID token along with the access token to facilitate certificate-bound access token validation, and performing an NF attestation. Further, the method involves using a different security protocol profile, which includes one or more of encryption and integrity protection activation. Different modes of a cryptographic technique are utilized, and a different key size, such as 256-bit, is employed.

[0126] The method includes generating an access token response message by adding the access token when authorization of the NFc apparatus (400) is successful at step 604. At step 605, the method includes sending the access token response message to the NFc apparatus (400).

[0127] In an embodiment, the method includes performing a plurality of security checks based on the access policy. This comprises enforcing mandatory transport layer protection for communications between the NFc apparatus (400) and the NFp apparatus (500). Further, mutual authentication is enforced between the NFc apparatus (400) and the NFp apparatus (500) when direct communication is preferred. Further, a consistency check is enforced between the NFc certificate and the NFc profile of the NFc apparatus (400). The method ensures the integrity of the NFc apparatus (400) and ensures that a service access request is routed through a service communication proxy (SCP) when indirect communication is preferred.

[0128] FIG. 7 is a flowchart illustrating a method for performing a security check based on the access policy according to embodiments disclosed herein. At step 701, the method includes receiving an NF service request message from an NFc apparatus (400). In an embodiment, the method includes receiving, by an NFp apparatus (500), an NF service request message from an NFc apparatus (400), wherein the NF service request message comprises an access token to access an NF service from the NFp apparatus (500).

[0129] At step 702, the method includes determining whether the NF service request message comprises an access policy included in the access token. In an embodiment, the method includes determining, by the NFp apparatus (500), whether the NF service request message comprises an access policy included in the access token, wherein the access policy comprises at least one security check to be performed successfully by the NFp apparatus (500) before providing the NF service to the NFc apparatus (400).

[0130] At step 703, the method includes performing one of the following: configuring the at least one security check for the NFc apparatus (400) based on the access policy when the access policy is included in the access token, At step 704, authorizing the NFc apparatus (400) by performing the at least one security check based on the access policy, and At step 705, sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful.

[0131] At step 706, the method includes pre-configuring an access policy locally and using the pre-configured access policy to enforce at least one security check for the NFc apparatus (400) when the access policy is not included in the access token. At step 707, the method further includes authorizing the NFc apparatus (400) by performing the at least one security check based on the pre-configured access policy and At step 708, sending an NF service response message to provide the NF service when authorization of the NFc apparatus (400) is successful.

[0132] In an embodiment, the method includes a plurality of security checks. These checks comprise performing mandatory mutual TLS, providing an ID token along with the access token to facilitate certificate-bound access token validation, and performing an NF attestation. Further, the method involves using a different security protocol profile, which includes one or more of encryption and integrity protection activation. Different modes of a cryptographic technique are utilized, and a different key size, such as 256-bit, is employed.

[0133] In an embodiment, the method includes a plurality of security checks based on the access policy. These checks enforce mandatory transport layer protection for communications between the NFc apparatus (400) and the NFp apparatus (500). Mutual authentication between the NFc apparatus (400) and the NFp apparatus (500) is enforced when direct communication is preferred. Further, a consistency check between the NFc certificate and the NFc profile of the NFc apparatus (400) is enforced, ensuring the integrity of the NFc apparatus (400). When indirect communication is preferred, the method ensures that a service access request is routed through a service communication proxy (SCP).

[0134] In an embodiment, the method includes performing the plurality of security checks based on the access policy. This involves the NFp apparatus (500) establishing a TLS connection with the NFc apparatus (400) after successful mutual authentication. The NFp apparatus (500) ensures that the established TLS conforms to a TLS profile as defined by the access policy.

[0135] FIG. 8 is a flowchart illustrating a method for generating an access token request message, sending the access token request message, and verifying the authenticity of the NF in the PLMN-hosted NPN system according to embodiments disclosed herein.

[0136] At step 801, the method includes generating an access token request message by adding an NF instance ID indicating a security domain to which the NFc apparatus (400) belongs. In an embodiment, the method includes generating, by the NFc apparatus (400), an access token request message by adding an NF instance identifier (ID) indicating a security domain to which the NFc apparatus (400) belongs.

[0137] At step 802, the method includes sending the access token request message for an access token to an NRF apparatus (300) when the NFc apparatus (400) is in a consumer premises.

[0138] At step 803, the method includes receiving an access token response message from the NRF apparatus (300). In an embodiment, the method includes receiving, by the NFc apparatus (400), an access token response message from the NRF apparatus (300). Further, the access token comprises an access policy indicating at least one security check to be performed by an NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) to verify the security domain of the NFc apparatus (400).

[0139] At step 804, the method includes generating an NF service request message by adding the access token to access an NF service from the NFp apparatus (500).

[0140] At step 805, the method includes sending the NF service request message from the NFp apparatus (500). In an embodiment, the method includes sending, by the NFc apparatus (400), the NF service request message from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520). Further, the access token comprises the access policy indicating the at least one security check to be performed successfully by the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) before providing the NF service to the NFc apparatus (400).

[0141] In an embodiment, the method includes a plurality of security checks. These checks comprise performing mandatory mutual TLS, providing an ID token along with the access token to facilitate certificate-bound access token validation, and performing an NF attestation. Further, the method involves using a different security protocol profile, which includes one or more of encryption and integrity protection activation. Different modes of a cryptographic technique are utilized, and a different key size, such as 256-bit, is employed.

[0142] At step 806, the method includes receiving a NF service response message from the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520).

[0143] FIG. 9 is a sequence diagram that illustrates a scenario of the NFc / NFp registration with the OAuth 2.0 server (the NRF (300)) according to embodiments as disclosed herein. Initially, at step 1, an NFc apparatus (400) or NFp apparatus (500) sends an Nnrf_NFManagement_NFRegister Request message to the NRF for registration. Further, the NFp / NFc (500 / 400) informs the NRF of its NF profile. At step 2, the NRF stores the NF profile of the NFc and / or the NFp after successful verification of the authenticity and / or authorization of the NFc and / or the NFp. Further, at step 3, the NRF acknowledges the NF that the registration is accepted via an Nnrf_NFManagement_NFRegister response. In an embodiment, the NRF provides an access policy to the NF as part of the Nnrf_NFManagement_NFRegister response message.

[0144] The NF profile, in an embodiment, contains at least one of the following: NF instance ID, Security Domain ID / Network Domain ID, PLMN ID, PLMN ID+NID (NPN ID), PLMN ID+CAG ID, CAG ID, NF set ID, NF Region ID, NF set FQDN, TAI, and other possible parameters. The NF instance ID indicates the domain to which the NFc / NFp belongs.

[0145] A client ID is sent in the request message in an embodiment. This client ID should indicate the domain of the NF. The OAM configures the NF profile along with the Security / Network Domain ID In an embodiment. Further, the OAM holds the mapping between at least two of the following: NF instance ID, Security Domain / Network Domain ID, PLMN ID, PLMN ID+NID, PLMN+CAG ID, CAG ID, TAI, and other possible parameters.

[0146] In an embodiment, at least one of the parameters and / or identifiers in the Nnrf_NFManagement_NFRegister Request should indicate the security domain of the NF(s). The access policy of the NF from different security domains might differ (with additional security mechanisms / levels / checks) from the access policy of the NFs within the same security domain. When the NRF apparatus (300) determines that the security domain of the NF is different from the operator domain, the access policy of the NF from a different security domain should include the possible (additional) security mechanisms / levels / checks to be performed successfully before authorizing the NF and providing the access token. The security mechanisms / levels / checks in the access policy include a plurality of mandatory mutual TLS, mandatory secure communication (e.g., mandatory use of TLS), ID token to be provided along with the access token to provide certificate-bound access token, NF attestation, use of different security protocol profiles (e.g., encryption and / or integrity protection to be activated / enabled, different modes of the cryptographic algorithm to be used, different key sizes such as 256 bits), and similar measures.

[0147] FIG. 10 is a sequence diagram illustrating the events of the NFc apparatus (400) discovery according to the disclosed embodiments. The NFc service discovery includes, at step 1.2, the transfer of Nnrf_NFDiscovery_Request from the NFc apparatus (400) to the SeGW (600), which Further sends the Nnrf_NFDiscovery_Request to NRF in PLMN. At step 2, the NRF stores the information and sends the Nnrf_NFDiscovery_Response to the NFc apparatus (400) through the SeGW (600).

[0148] In an embodiment, the NFc apparatus (400) includes one or more of the following parameters in the Nnrf_NFDiscovery_Request: NF instance ID, NF Set ID, NF Service Set ID, SUPI, security domain ID / network domain ID, PLMN ID, NID, PLMN ID+NID, CAG ID, PLMN ID+CAG ID, and other possible parameters. At step 3, the NRF apparatus (300) stores this information as a mapping.

[0149] For Access and Mobility Management (AMF) discovery, the parameters included are a plurality of AMF Region ID, AMF Set ID, TAI, and AMF set FQDN. The format of the AMF region ID, AMF set ID, TAI, and AMF set FQDN indicates the domain of the NFs (AMF). For example, the format can be set<AMF Set Id>region<AMF Region Id>amfset5gcnid<NID>mnc<MNC>mcc<MCC>3gppnetworkorg or set<AMF Set Id>region<AMF Region Id>amfset<NPN domain name>.

[0150] The mapping information between one of NF instance ID, NF Set ID, NF Service Set ID, security domain ID / domain ID, PLMN ID, NID, PLMN ID+NID, CAG ID, PLMN ID+CAG ID, AMF Region ID, AMF Set ID, TAI, and AMF set FQDN is stored in the Credential Holder (CH) hosting AUSF / UDM.

[0151] When TAI needs to be identified in the context of the PNI-NPN, the CAG ID is included as part of the TAI. At step 4.5, the Nnrf_Discovery_Response (Success [access policy]) is indicated for a successful response.

[0152] FIG. 11 is a sequence diagram that illustrates the events of NFc verification by NRF according to the embodiments disclosed herein. At step 1, the method includes transferring of Nnrf_AccessToken_Get_Request from NFc apparatus (400) to the authorization server (NRF Apparatus). At steps 2a and 2b, the NRF checks and verifies the NFc apparatus (400) and its authorization, performing a security check based on the access policy. Further, the NRF apparatus (300) sends Nnrf_AccessToken_Get_Response to the NFc apparatus (400).

[0153] In an embodiment, the NFc apparatus (400) possesses the access policy through pre-configuration by the OAM and / or receives it as part of the Nnrf_NFManagement_NFRegister Response from the NRF. At step 2c, the NFc performs the configured access policy security procedure and / or the security mechanisms / levels / checks specified in the access policy received from the NRF apparatus (300) before requesting services from the NFp apparatus (500). The NFc apparatus (400) executes the configured access policy (pre-configured by the OAM) security procedure and / or the security mechanisms / levels / checks specified in the access policy as pre-configured by the OAM.

[0154] In an embodiment, the NFc apparatus (400) obtains an access token before service access to the NFp of a specific NF type is granted. The NFc, from a different security domain (NPN), requests an access token from the NRF in the PLMN (Operator domain / different security domain) using the Nnrf_AccessToken_Get request operation. The request message includes one or more of the following: NF Instance Id(s) of the NFc, client ID, security domain ID / domain ID, PLMN ID, PLMN+NID, CAG ID, PLMN ID+CAG ID, NF set ID, NF region ID, NF set FQDN, TAI, in addition to existing parameters like "scope" (including the expected NF Service name(s)) and optionally "additional scope" information (i.e., requested resources and requested actions (service operations) on the resources), NF type of the expected NFp instance, and NFc list of NSSAIs or list of NSI IDs for the expected NFp instances and other possible parameters.

[0155] The above-mentioned parameters in the request message indicate the domain of the NFc (whether it is in the same PLMN or in a private network). The NRF verifies that the input parameters NF Instance ID, NF type, and PLMN ID(s) in the access token request match the corresponding ones in the public key certificate of the NFc or those in the stored NF profile of the NFc. If the verification of the parameters in the access token request fails, the access token request is not further processed.

[0156] If the NFc is authorized, the NRF, based on the received parameters in the request message, determines if the NF is in a different security domain (not in the same PLMN / in a private network / customer premises). The NRF is pre-configured with one or more of the NF Instance Id(s) of the NFc, client ID, security domain ID / network domain ID, PLMN ID, PLMN+NID, CAG ID, PLMN ID+CAG ID, NF set ID, NF region ID, NF set FQDN, NF type, TAI, and other possible parameters for verifying the security domain of the NFc apparatus (400).

[0157] At step 2c, the NRF apparatus (300) is also pre-configured with the access policy for performing one or more of the security checks based on the access policy as specified in one or more embodiments enclosed herein before generating and providing the access token. If the NF is in a different security domain, before generating and providing the access token to the NF, the NRF performs one or more of the security checks based on the access policy as specified in one or more embodiments enclosed herein.

[0158] In addition to the existing parameters, the claims in the access token should also include the PLMN+NID, NID, CAG ID, PLMN ID+CAG ID, NF set ID, NF instance ID, NF Region ID, NF Set FQDN, TAI, and other possible parameters. At step 3, when the NRF successfully determines that the security domain of the NF is different, the NRF provides an access policy to the NFc apparatus (400) as part of the claims of the access token. The access policy should include the possible security checks to be performed successfully by the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) before providing the service to the NFc apparatus (400). The security checks in the access policy include one or more of the following: mandatory mutual TLS, ID token to be provided along with the access token to provide certificate-bound access token, NF attestation, use of different security protocol profiles (e.g., encryption and / or integrity protection to be activated / enabled, different modes of the cryptographic algorithm to be used, different key sizes (256 bits to be used), etc.).

[0159] If the authorization is successful, the NRF apparatus (300) sends the access token to the NFc in the Nnrf_AccessToken_Get response operation. The Nnrf_AccessToken_Get response should also include the access policy for the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) to verify the security domain of the NFc apparatus (400).

[0160] FIG. 12 is a sequence diagram illustrating the events of NFc verification by the OAM / CH / NF validator according to the disclosed embodiments. The method includes the transfer of an Nnrf_AccessToken_Get_Request from the NFc apparatus (400) to the OAM / CH / NF validator through the authorization server (NRF). The OAM / CH / NF validator checks and verifies the NFc and sends an Nnrf_AccessToken_Get_Response to the NFc apparatus (400).

[0161] The procedure describing how the NFc apparatus (400) obtains an access token before accessing the NFp apparatus (500) of a specific NF type is as follows:

[0162] At steps 1 and 1a, the NFc apparatus (400) from a different security domain (NPN) requests an access token from the NRF in the PLMN (Operator domain / different security domain) using the Nnrf_AccessToken_Get request operation. In an embodiment, the request message includes at least one of the following: NF Instance Id(s) of the NFc, client ID, security domain ID / network domain ID, PLMN ID, PLMN+NID, CAG ID, PLMN ID+CAG ID, NF set ID, NF region ID, NF set FQDN, TAI, and other possible parameters. These are in addition to existing parameters like "scope," which includes the expected NF Service name(s) and optionally "additional scope" information (i.e., requested resources and requested actions (service operations) on the resources), NF type of the expected NFp instance, and NFc list of NSSAIs or list of NSI IDs for the expected NFp instances. The parameters in the request message indicate the domain of the NFc (whether it is in the same PLMN or in a private network). The NRF forwards the request to the OAM / Credential Holder / NF validator to determine the security domain of the NF if it is not in the same PLMN, private network, or customer premises.

[0163] At step 2a, the OAM / CH / NF validator verifies that the input parameters―NF Instance ID, NF type, PLMN ID(s)―in the access token request match the corresponding ones in the public key certificate of the NFc apparatus (400) and / or those in the NF profile of the NFc apparatus (400) and / or information stored at the OAM / CH / NF validator. At step 2b, if the verification of the parameters in the access token request fails, the access token request is not further processed.

[0164] In one embodiment, if the NFc apparatus (400) is authorized, the OAM / CH / NF validator determines, based on the received parameters in the request message, if the NF is in a different security domain (not in the same PLMN, private network, or customer premises).

[0165] In an embodiment, if the NF is in a different security domain, the OAM / CH / NF validator requests the NRF apparatus (300) to perform one or more of the security checks specified in one or more embodiments enclosed herein before generating and providing the access token.

[0166] At step 2c, when the OAM / CH / NF validator successfully determines that the security domain of the NF is different, it provides an access policy to the NFc apparatus (400) as part of the response message. The access policy includes the possible security checks to be performed successfully by the NFp before providing the service to the NFc. These security checks in the access policy include at least one of the following: mandatory mutual TLS, ID token to be provided along with the access token to provide certificate-bound access token, NF attestation, use of different security protocol profiles (e.g., encryption and / or integrity protection to be activated / enabled, different mode of the cryptographic algorithm to be used, different key size (256 bits to be used), etc.). In addition to the existing parameters, the claims in the access token should also include the PLMN+NID / NID / CAG ID / PLMN ID+CAG ID / NF Region ID / NF Set FQDN / TAI.

[0167] If the authorization is successful, and upon performing the security checks, at step 3, the NRF sends the access token to the NFc apparatus (400) in the Nnrf_AccessToken_Get response operation. In an embodiment, the Nnrf_AccessToken_Get response also includes the access policy for the NFp apparatus (500) or SCP apparatus (510) or Proxy entity apparatus (520) to verify the security domain of the NFc apparatus (400).

[0168] FIG. 13 is a sequence diagram illustrating the events of the NFp verifying NF based on access policy according to the embodiments disclosed herein. The method describes the transfer of an NF Service Request from the NFc apparatus (400) to an NFp apparatus (500) and further receiving an NF Service Response from the NFp apparatus (500).

[0169] In one embodiment, at step 1, the NFc apparatus (400) possesses a valid access token before requesting service access from the NFp apparatus (500). The NFc apparatus (400) requests service from the NFp, including the access token in the request message. The NFc apparatus (400) performs the configured access policy security procedure and / or the security mechanisms / levels / checks specified in the access policy received from the NRF apparatus (300).

[0170] At step 2a, the NFp verifies the access token and the NF's security domain based on one or more of the NF Instance Id(s) of the NFc, client ID, security domain ID / network domain ID, PLMN ID, PLMN+NID, CAG ID, PLMN ID+CAG ID, NF set ID, NF region ID, NF set FQDN, TAI, and other possible parameters present in the access token claims.

[0171] In an embodiment, at step 2b, if the NFp apparatus (500) determines the NFc apparatus (400) is in a different security domain, it further performs the security check based on the access policy present in the access token. If the NFp apparatus (500) determines the NFc apparatus (400) is in a different security domain, it retrieves the access policy from the NRF / NF validator / CH / OAM. Based on the retrieved access policy, the NFp apparatus (500) performs the mandatory security mechanisms / levels / checks before executing the requested service(s).

[0172] Based on the access policy, the NFp apparatus (500) ensures that the security mechanisms / levels / checks are performed and / or enabled by the NFc apparatus (400). For example, the NFp ensures that TLS is established after successful mutual authentication and with the specified TLS profile.

[0173] At step 3, if the verification is successful, the NFp apparatus (500) executes the requested service and responds back to the NFc apparatus (400). Otherwise, it replies based on the OAuth 2.0 error response.

[0174] In an embodiment, if the NFp apparatus (500) is not aware of the consumer profile information, the NFp apparatus (500) performs an on-demand mechanism to retrieve and verify the supported security mechanism.

[0175] Methods to perform security checks (if NF is in a different security domain) before providing the access token include authentication or authorization request messages and / or access token request messages indicating one or more of these security checks: mandatory mutual TLS authentication, ID token to be provided with the access token, generating and providing certificate-bound access tokens, and NF attestation. Further, the use of different security protocol profiles (e.g., encryption and / or integrity protection to be activated / enabled, different modes of the cryptographic algorithm to be used, different key sizes such as 256 bits) is included.

[0176] Mandating existing transport layer protection, as described in an embodiment, includes mutual TLS and Hypertext Transfer Protocol Secure (HTTPS) as specified in RFC 9113 and RFC 2818. This is mandated for inter-NF communication between trusted and untrusted security domains or within an untrusted security domain.

[0177] FIG. 14 is a block diagram that illustrates the Authorization code flow of OpenID Connect according to the embodiments as disclosed herein.

[0178] At step 1, secure tunnel establishment occurs between both NFc apparatus (400) / NFp apparatus (500) with client (800) and NRF apparatus (300). At step 2, an OIDC auth request is sent from NFc apparatus (400) / NFp apparatus (500) with client (800) to NRF apparatus (300). At step 3, an OIDC auth response (Code) is received from NRF apparatus (300) to the NFc apparatus (400) / NFp apparatus (500) with client (800). At step 4, tokens are requested from NRF apparatus (300) by NFc apparatus (400) / NFp apparatus (500) with client (800) after successful verification. At step 5, a token response (Access token, ID token) is generated from NRF apparatus (300) to the NFc apparatus (400) / NFp apparatus (500) with client (800).

[0179] In an embodiment, the NRF apparatus (300) should provide an ID token (as per OpenID Connect) along with the access token to the NF for inter-NF communication between trusted and untrusted security domains or within an untrusted security domain.

[0180] Certificate-bound access tokens encompass various procedures, particularly for Mutual-TLS certificate-bound access tokens. The / auth / token API receives a client certificate as a request parameter and binds it with an access token to be issued. When JWT-formatted access tokens are enabled, the API includes a thumbprint of the client certificate into the access token to be issued.

[0181] The / auth / introspection API receives an access token and a client certificate as request parameters and checks if both are bound to each other. Further, the / auth / introspection / standard API receives an access token (token) as a value included in one of the request parameters (parameters) and provides a thumbprint of the client certificate bound to the token.

[0182] With these APIs, only the NFs that can submit their client (800) certificates through a mutual TLS connection are able to prove their possession of access tokens and use the tokens for API requests. In other words, the tokens are no longer useful for other NFs.

[0183] Binding the access token to the certificate will prevent any unauthorized or illegitimate NFs from using leaked or stolen access tokens by binding an access token to a public key upon issuance and requiring that the NF proves its possession of the corresponding private key when using the token. This constrains the legitimate sender of the access token to only the party with access to the private key and gives the server receiving the access token added assurances that the sender is legitimately authorized to use it.

[0184] FIG. 15 is a sequence diagram that illustrates the events of the NFc apparatus (400) attestation in customer premises according to the embodiments disclosed herein. At steps 1, 3, 4, and 7, the method includes the transfer of Nnrf_NFManagement_NFRegister_Request from the NFc apparatus (400) to the NRF apparatus (300). Further, the NRF apparatus (300) sends Nnrf_NFManagement_NFRegister_Response to the NFc apparatus (400).

[0185] In an embodiment, the NF's integrity is verified via attestation during the registration of the NFs with NRF apparatus (300). At step 6, the NF validator, which can be a new NF or an existing NF, validates the NFs. In an embodiment verifies the NF's integrity via attestation when an access token request is received by the NRF apparatus (300).

[0186] During NF registration, at steps 2a and 5, the NRF apparatus (300) determines the information about the NF's network domain / security domain. In an embodiment, the NRF apparatus (300) determines the information about the NF's network domain / security domain during the access token request and stores the NF profile at the step 2b.

[0187] The description of the specific embodiments provided here will clearly reveal their general nature, allowing others to modify or adapt them for various applications without straying from the core concept. Such adaptations and modifications are intended to be included within the scope of the disclosed embodiments. The terminology used is for descriptive purposes only and not meant to limit the scope. Therefore, while preferred embodiments are described, those skilled in the art will understand that modifications can be made within the scope of the described embodiments.

Claims

1.A method performed by a Network Repository Function (NRF) for verification of authenticity of a Network Function (NF) in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system, the method comprising:receiving, from a NF service consumer (NFc), an access token request message for an access token, wherein the access token request message comprises an NF instance identifier (ID) indicating a security domain to which the NFc belongs;determining whether the security domain of the NFc apparatus is outside a PLMN operational domain based on the NF instance ID;authorizing the NFc by performing at least one security check based on an access policy in case that the security domain of the NFc apparatus is determined to be outside the PLMN operational domain;generating an access token response message by adding the access token in case that an authorization of the NFc is successful, wherein the access token comprises the access policy indicating the at least one security check to be performed by a NF service producer (NFp) to verify the security domain of the NFc; andtransmitting, to the NFc, the access token response message.2.The method of claim 1, further comprising:adding identification information of the NFc and the access policy in the access token; andtransmitting, to the NFp, the access token to enforce the at least one security check according to the access policy.3.The method of claim 1, wherein the at least one security check comprises at least one of performing mandatory mutual Transport Layer Security (TLS), providing an ID token along with the access token to facilitate certificate-bound access token validation, performing an NF attestation, using a different security protocol profile, including one or more of encryption and integrity protection activation, utilizing different modes of a cryptographic technique, or employing a different key size.4.The method of claim 1, wherein performing the at least one security check based on the access policy comprises at least one of:enforcing a mandatory transport layer protection for communications between the NFc and the NFp;enforcing a mutual authentication between the NFc and the NFp in case that a direct communication is preferred;enforcing a consistency check between a NFc certificate and a NFc profile of the NFc apparatus;ensuring an integrity of the NFc apparatus; orensuring that a service access request is routed through a Service Commuincation Proxy (SCP) in case that an indirect communication is preferred.5.The method of claim 1, wherein the NRF is pre-configured with the access policy.6.A method performed by a Network Function service consumer (NFc) for verification of authenticity of a NF in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system, the method comprising:generating an access token request message by adding an NF instance identifier (ID) indicating a security domain to which the NFc belongs;transmitting, to a Network Repository Function (NRF), the access token request message for an access token;receiving, from the NRF, an access token response message, wherein the access token comprises an access policy indicating at least one security check to be performed by a NF service producer (NFp) to verify the security domain of the NFc;generating a NF service request message by adding the access token to access a NF service from the NFp;transmitting, to the NFp, the NF service request message, wherein the access token comprises the access policy indicating the at least one security check to be performed by the NFp before providing the NF service to the NFc; andreceiving, from the NFp, a NF service response message.7.The method of claim 6, wherein the at least one security check comprises at least one of performing mandatory mutual TLS, providing an ID token along with the access token to facilitate certificate-bound access token validation, performing an NF attestation, using a different security protocol profile, including one or more of encryption and integrity protection activation, utilizing different modes of a cryptographic technique, or employing a different key size.8.The method of claim 6, wherein the NFc is in a consumer premises.9.A Network Repository Function (NRF) for verification of authenticity of a Network Function (NF) in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system, the NRF comprising:a communicator; anda controller coupled with the communicator and configured to:receive, from a NF service consumer (NFc), an access token request message for an access token, wherein the access token request message comprises an NF instance identifier (ID) indicating a security domain to which the NFc belongs,determine whether the security domain of the NFc apparatus is outside a PLMN operational domain based on an NF instance ID,authorize the NFc by performing at least one security check based on an access policy in case that the security domain of the NFc apparatus is determined to be outside the PLMN operational domain,generate an access token response message by adding the access token in case that an authorization of the NFc is successful, wherein the access token comprises the access policy indicating the at least one security check to be performed by a NF service producer (NFp) to verify the security domain of the NFc, andtransmit, to the NFc, the access token response message.10.The NRF of claim 9, wherein the controller is further configured to:add identification information of the NFc and the access policy in the access token, andtransmit, to the NFp, the access token to enforce the at least one security check according to the access policy.11.The NRF of claim 9, wherein the at least one security check comprises at least one of performing mandatory mutual Transport Layer Security (TLS), providing an ID token along with the access token to facilitate certificate-bound access token validation, performing an NF attestation, using a different security protocol profile, including one or more of encryption and integrity protection activation, utilizing different modes of a cryptographic technique, or employing a different key size.12.The NRF of claim 9, wherein performing the at least one security check based on the access policy comprises at least one of:enforcing a mandatory transport layer protection for communications between the NFc and the NFp;enforcing a mutual authentication between the NFc and the NFp in case that a direct communication is preferred;enforcing a consistency check between a NFc certificate and a NFc profile of the NFc apparatus;ensuring an integrity of the NFc apparatus; orensuring that a service access request is routed through a Service Communication Proxy (SCP) in case that an indirect communication is preferred.13.A Network Function service consumer (NFc) for verification of authenticity of a NF in a Public Land Mobile Network (PLMN) hosted Non-Public Network (NPN) system, the NFc comprising:a communicator; anda controller coupled with the communicator and configured to:generate an access token request message by adding an NF instance identifier (ID) indicating a security domain to which the NFc belongs,transmit, to a Network Repository Function (NRF), the access token request message for an access token,receive, from the NRF, an access token response message, wherein the access token comprises an access policy indicating at least one security check to be performed by a NF service producer (NFp) to verify the security domain of the NFc,generates a NF service request message by adding the access token to access a NF service from the NFp,transmit, to the NFp, the NF service request message, wherein the access token comprises the access policy indicating the at least one security check to be performed by the NFp before providing the NF service to the NFc, andreceive, from the NFp, a NF service response message.14.The NFc of claim 13, wherein the at least one security check comprises at least one of performing mandatory mutual TLS, providing an ID token along with the access token to facilitate certificate-bound access token validation, performing an NF attestation, using a different security protocol profile, including one or more of encryption and integrity protection activation, utilizing different modes of a cryptographic technique, or employing a different key size.15.The NFc of claim 13, wherein the NFc is in a consumer premises.

Citation Information

Patent Citations

  • Service authorization method, apparatus, and system

    US20230019000A1