Method and system for authenticating network function in a network

The method and system authenticate NFs by verifying CCA parameters, addressing interoperability challenges and ensuring seamless communication across NF versions, thereby enhancing network reliability and robustness.

WO2026062709A1PCT designated stage Publication Date: 2026-03-26JIO PLATFORMS LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Interoperability challenges arise in telecommunications networks due to varying support for Client Credentials Assertion (CCA) features among different versions of Network Functions (NFs), leading to potential disruptions and communication failures.

Method used

A method and system for authenticating NFs that proactively verify CCA configuration parameters using both configured and global parameters, ensuring seamless communication by validating authentication credentials against a centralized repository.

Benefits of technology

Ensures compatibility and reliability across NF versions, reducing the risk of service disruptions and enhancing network robustness by addressing interoperability issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025051538_26032026_PF_FP_ABST
    Figure IN2025051538_26032026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a method (600) and a system (108) for authenticating at least one Network Function (NF) in a network (106) A distributed NF receives a service request from the at least one NF. Upon reception, the distributed NF determines whether one or more configured parameters, are present in the received request. Based on this determination, the distributed NF verifies one or more authentication credentials associated with the identified parameters. Upon successful verification of the authentication credentials, the distributed NF processes the received request to authenticate the NF, thereby ensuring secure inter-NF communication. If configured parameters are absent, the distributed NF may retrieve predefined global parameters from a database to authenticate the at least one NF.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND SYSTEM FOR AUTHENTICATING NETWORK FUNCTION IN A NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to JIO PLATFORMS LIMITED or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD

[0002] The present disclosure relates generally to the field of telecommunications. More particularly, the present disclosure relates to a method and a system for authenticating at least one network function in a network.DEFINITION

[0003] The term ‘NFs’ refers to network functions. The NFs are software components that are designed to perform specific tasks within a Fifth Generation (5G) network, such as managing a user session, enforcing policies, handling data traffic, and other tasks. The NFs in the 5G network are a fundamental part of the 5G service-based architecture (SB A) where different NFs (such as access and mobility management function (AMF), session management function (SMF), and policy control function (PCF)), etc., interact with each other to deliver various network services.

[0004] The term ‘NRF’ refers to a Network Repository Function. The NRF serves as a central repository and maintains profiles of all the NFs. The NRF allows NFs to discover and communicate with each other by storing and providing information about the available services that different NFs offer within the 5G network.

[0005] The term ‘PLMN’ refers to Public Land Mobile Network. The PLMN is a network that provides mobile communication services to users / subscribers. In PLMN, a unique identifier (ID) is used, namely PLMN ID, which uniquely identifies a mobile network, among others.

[0006] The term ‘CCA’ refers to Client Credentials Assertion. The CCA is a security mechanism or protocol to authenticate and authorize an NF. It includes digital certificates, tokens, and similar elements to authenticate the NF when communicating with other NFs.

[0007] The term ‘NF Instance ID’ refers to a unique identifier used to identify a particular instance of the NF. The instance ID allows the separate management of configuration policies or sessions associated with the NF.

[0008] The term ‘CCA token’ refers to a Client Credentials Assertion token, the CCA is a security token that is used in the network to authenticate and authorize the communication between different NFs.

[0009] These definitions are in addition to those expressed in the art.BACKGROUND

[0010] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0011] In the telecommunications network, Network Functions (NFs) communicate with multiple NFs of varying NF types, often supplied by differentvendors. These NFs may be in terms of their versions, capabilities, and supported features. The challenges that arise while authenticating communication between the different NF types are due to a client credentials assertion (CCA) feature. For instance, a Network Repository Function (NRF) may require a CCA feature for authenticating NFs when a request is received or sent to the NFs. However, not all NFs support the CCA feature, which can pose interoperability challenges if CCA is either globally enabled or enabled only at the NF Type level.

[0012] Additionally, a significant issue arises when older versions of the NRF lack CCA support, whereas newer versions necessitate it. In this scenario, older NF versions may fail to transmit data to newer versions expecting CCA support, exacerbating interoperability concerns and potentially disrupting network functionality. Thus, ensuring compatibility between different versions of NFs and their supported features is paramount to maintaining seamless communication and operation within the network infrastructure.

[0013] There is, therefore, a need in the art to provide a method and a system that can mitigate the disadvantages of the prior art.SUMMARY OF THE DISCLOSURE

[0014] In an exemplary embodiment, a method for authenticating at least one network function (NF) in a network is disclosed. The method includes receiving by a distributed network function (NF), a request from the at least one NF. The method includes determining, by the distributed NF, whether one or more configured parameters are present in the received request. The method includes verifying, by the distributed NF, one or more authentication credentials associated with the one or more configured parameters based on the determination. The method includes processing by the distributed NF, the received request to authenticate the at least one NF upon successful verification of the one or more authentication credentials.

[0015] In some embodiments, the method further includes retrieving, by the distributed NF, one or more predefined global parameters from a database, wherein the one or more predefined global parameters are retrieved when the one or more configured parameters are unavailable in the received request.

[0016] In some embodiments, upon successful verification, the method further includes determining, by the distributed NF, whether the one or more authentication credentials satisfy one or more predefined conditions.

[0017] In some embodiments, the one or more configured parameters comprise at least one of: an NF type, an NF instance identifier (ID), a public land mobile network (PLMN) identifier, an NF authentication type, an NF version, and an NF service type.

[0018] In some embodiments, the one or more predefined global parameters comprise at least one of: a default NF type, a default NF instance ID, a default PLMN ID, and a default NF authentication type, a default NF version, a default NF service type, wherein the one or more global predefined parameters are retrieved when the one or more configured parameters are unavailable in the received request.

[0019] In some embodiments, the one or more predefined conditions comprise at least one of: an expiration time of the one or more authentication credentials, and an audience associated with the one or more authentication credentials, a key validity period associated with the one or more authentication credentials, or any additional security-related condition that validates the authorization of the one or more authentication credentials.

[0020] In some embodiments, the one or more authentication credentials are one of: Client Credentials Assertion (CCA) token, an Open Authorization access (OAuth) token, a bearer token, a Security Assertion Markup Language (SAML) token, a JavaScript Object Notation Web Token or any other suitable token type that satisfies the one or more predefined conditions.

[0021] In some embodiments, verifying the one or more authentication credentials includes validating, by the distributed NF, the one or more authentication credentials against a centralized authentication repository.

[0022] In another exemplary embodiment, a system authenticating at least one network function (NF) in a network is disclosed. The system includes a receiving unit and a processing unit at a distributed network function (NF). The receiving unit is configured to receive a request from at least one NF. The processing unit is configured to determine whether one or more configured parameters are present in the received request, based on the determination, verify one or more authentication credentials associated with the one or more configured parameters, and upon successful verification of the one or more authentication credentials, process the received request to authenticate the at least one NF.

[0023] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to perform a method for authenticating at least one network function (NF) in a network is disclosed. The method includes receiving by a distributed network function (NF), a request from the at least one NF. The method includes determining, by the distributed NF, whether one or more configured parameters are present in the received request. The method includes verifying, by the distributed NF, one or more authentication credentials associated with the one or more configured parameters based on the determination. The method includes processing by the distributed NF, the received request to authenticate the at least one NF upon successful verification of the one or more authentication credentials.

[0024] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure, and are not restrictive.OBJECTIVES OF THE PRESENT DISCLOSURE

[0025] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:

[0026] An object of the present disclosure is to provide a method and a system for checking a Client Credentials Assertion (CCA) configuration by a Network Repository Function (NRF) during sending or receiving one or more requests to Network Functions (NFs).

[0027] Another objective of the present disclosure is to ensure seamless communication within a telecommunications network by proactively validating parameters associated with requests and responses exchanged between NFs.

[0028] Another objective of the present disclosure is to mitigate interoperability challenges by integrating checks related to a Public Land Mobile Network (PLMN), instance ID, NF type, and other configuration attributes when requests are sent or received.

[0029] Another objective of the present disclosure is to proactively identify and address potential conflicts between NFs before they can cause disruptions in network operations.

[0030] Another objective of the present disclosure is to reduce the risk of service degradation or network disruptions caused by incompatibility between the NFs by emphasizing compatibility, reliability, and user satisfaction.

[0031] Another objective of the present disclosure is to provide a robust and resilient telecommunications infrastructure capable of supporting dynamic service requirements while minimizing operational overhead.

[0032] Other objectives and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWING

[0033] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale; emphasis is instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components, or circuitry commonly used to implement such components.

[0034] FIG. 1 illustrates an exemplary network architecture in which or with a system configured for authenticating at least one network function (NF) in a network may be implemented, in accordance with embodiments of the present disclosure.

[0035] FIG. 2 illustrates an exemplary block diagram of the system configured for authenticating the at least one NF in the network, in accordance with embodiments of the present disclosure.

[0036] FIG. 3 illustrates an exemplary system architecture for authenticating the at least one NF in the network, in accordance with an embodiment of the present disclosure.

[0037] FIG. 4 illustrates an exemplary process flow for authenticating the at least one NF upon receiving a request, in accordance with an embodiment of the present disclosure.

[0038] FIG. 5 illustrates an exemplary process flow for authenticating the at least one NF during sending the request, in accordance with an embodiment of the present disclosure.

[0039] FIG. 6 illustrates an exemplary flow diagram of a method for authenticating the at least one NF in the network, in accordance with an embodiment of the present disclosure.

[0040] FIG. 7 illustrates an exemplary computer system in which or with which the embodiments of the present disclosure may be implemented.

[0041] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network Architecture102 - User(s)104 - User Equipments (UEs)106 - Network108 - System200 -Block Diagram202 - Receiving Unit204 - Memory206 - Interface(s)208 - Processing Unit210 - Database302 - Network Function304 - Network Repository Function400 - Process Flow Diagram500 - Process Flow Diagram600 - Method Flow Diagram700 - Computer System710 - External Storage Device720 - Bus730 - Main Memory740 - Read Only Memory750 - Mass Storage Device760 - Communication Port(S)770 - ProcessorDETAILED DESCRIPTION

[0042] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodimentsof the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.

[0043] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0044] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of the ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0045] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminatedwhen its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0046] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.

[0047] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0048] The terminology used herein is to describe particular embodiments only and is not intended to limit the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features,integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.

[0049] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment as well as other embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.

[0050] In the telecommunications network, Network Functions (NFs) communicate with multiple NFs of varying NF types, often supplied by different vendors. These NFs may be in terms of their versions, capabilities, and supported features. The challenges that arise while authenticating communication between the different NF types are due to a client credentials assertion (CCA) feature. For instance, a Network Repository Function (NRF) may require a CCA feature for authenticating NFs when a request is received or sent to the NFs. However, not all NFs support theCCA feature, which can pose interoperability challenges, if CCA is either globally enabled or enabled only at the NF Type level. A significant issue arises when older versions of the NRF lack CCA support, whereas newer versions necessitate it. In this scenario, older NF versions may fail to transmit data to newer versions expecting CCA support, exacerbating interoperability concerns and potentially disrupting network functionality. Thus, ensuring compatibility between different versions ofNFs and their supported features is paramount to maintaining seamless communication and operation within the network infrastructure. To mitigate these challenges, the present disclosure provides a method and a system to enable proactive verification of CCA configuration parameters by the NRF during request transmission or reception. The method ensures that authentication is performed based on either the configured parameters associated with the requesting NF or global parameters retrieved from a database, thereby providing flexibility across different NF deployments. By adopting this approach, the system addresses interoperability issues, reduces the risk of communication failures, and enhances the robustness and reliability of NF-to-NF interactions within the telecommunications network.

[0051] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0052] FIG. 1 illustrates an exemplary network architecture 100 in which or with which a system 108 configured for authenticating at least one network function (NF) in a network 106 may be implemented, in accordance with embodiments of the present disclosure.

[0053] In an embodiment, the network architecture (100) may include one or more user equipment (UEs) 104-1, 104-2... 104-N associated with one or more users 102-1, 102-2... 102-N in an environment. A person of ordinary skill in the art will understand that one or more users 102-1, 102-2... 102-N may be individually referred to as the user 102 and collectively referred to as the users 102. Further, the user 102may correspond to a network administrator or a network service provider. Similarly, a person of ordinary skill in the art will understand that one or more UEs 104-1, 104- 2... 104-N may be individually referred to as the UE 104 and collectively referred to as the UEs 104. Although three UEs 104 are depicted in FIG. 1, however, any number of the UEs 104 may be included without departing from the scope of the ongoing description.

[0054] In another implementation, the UE 104 may function as smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the UE 104 may include, but is not limited to, smart phones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV), computers, smart security system, smart home system, other devices for monitoring or interacting with or for the users 102 and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE 104 may include, but is not limited to, intelligent, multisensing, network- connected devices, which can integrate seamlessly with each other and / or with a central server or a cloud- computing system or any other device that is network-connected.

[0055] In an embodiment, the UE 104 may include, but is not limited to, any electrical, electronic, electro-mechanical, or an equipment, or a combination of one or more of the above devices such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general-purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device, wherein the UE 104 may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user 102 or the entity such as touch pad,touch enabled screen, electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (104) may not be restricted to the mentioned devices and various other devices may be used.

[0056] In FIG. 1, the UE 104 may communicate with the system 108 via a telecommunication network 106 (interchangeably referred to as a network 106). In order to establish communication, initially, the telecommunication network 106 is configured to receive a connection request from the UE 104. In response to receiving the connection request, the telecommunication network 106 is configured to send an acknowledgment of the connection request to the UE 104. Further, a plurality of signals is transmitted in response to the connection request. Based on the connection request, the sessions are created in the telecommunication network 106. In an embodiment, the network 106 includes at least one of the 4G network, the 5G network, the 6G network, or the like. The telecommunication network 106 may enable the UE 104 to communicate with other devices in the network architecture 100 and / or with the system 108.

[0057] The network 106 may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network 106 may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), an internet, an intranet, a public network, a private network, a packet- switched network, a circuit- switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof. In another embodiment, the telecommunication network 106 includes, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc.one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth.

[0058] In an exemplary embodiment, the UE 104 interacts with the telecommunications system 108 via the network 106. In an example, the system 108 may be associated with, or embedded within, a Network Repository Function (NRF). The UE 104 may initiate a service request, which is transmitted over the network 106 to a corresponding Network Function (NF), such as an Authentication and Management Function (AMF). The NF, upon receiving the request from the UE 104, further transmits the request to the system 108 for authentication.

[0059] In response, the system 108 determines a set of configured parameters such as NF type, Instance ID, and public land mobile network (PLMN) ID associated with the request. The NRF verifies whether any of these parameters are present in the received request. If the parameters are available, the NRF checks the Client Credentials Assertion (CCA) token linked to the parameter and validates it. Upon successful verification of the CCA, the request is processed further. In case the requested parameter is not available locally within the NRF, the system retrieves the corresponding global configuration variable from a database, validates the CCA associated with the global variable, and then processes the request accordingly. This ensures that both configured parameters and global variables are consistently leveraged with valid CCA tokens, thereby enabling secure and efficient request handling.

[0060] In an exemplary scenario, when the system 108 itself initiates or sends a request to one or more NFs for facilitating service continuity, it performs a similar verification and validation of authentication credentials associated with the targeted NF prior to transmitting the request. The verification ensures that the recipient NF supports the required CCA feature, and, where such support is absent, the system 108 retrieves and applies the relevant configuration details from its database to maintain interoperability. Only upon successful validation does the system 108 permit theoutgoing communication, thereby avoiding failed interactions or service interruptions. The system 108 ensures proactive identification and resolution of interoperability challenges between heterogeneous NFs, irrespective of their vendor, version, or capability differences.

[0061] Although FIG. 1 shows exemplary components of the network architecture 100, in other embodiments, the network architecture 100 may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture 100 may perform functions described as being performed by one or more other components of the network architecture 100.

[0062] FIG. 2 illustrates an exemplary block diagram of the system 108 configured for authenticating the at least one NF in the network 106, in accordance with an embodiment of the present disclosure.

[0063] In an embodiment, the system 108 may include a receiving unit 202. The receiving unit 202 may be configured to receive data signals, messages, or instructions from one or more external sources over the telecommunication network 106. In an embodiment, the receiving unit 202 may include one or more transceivers, antennas, ports, or communication modules compatible with various protocols such as Ethernet, 4G / 5G, or other network technologies. The receiving unit 202 may further include signal conditioning components such as filters, amplifiers, or decoders to process incoming signals and convert them into a format suitable for further analysis by a processing unit 208, which is included in the system 108.

[0064] In an embodiment, the system 108 may include a memory 204. The memory 204 may be configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may befetched and executed to create or share data packets over a network service. The memory 204 may include any non-transitory storage device including, for example, volatile memory such as a Random- Access Memory (RAM), or a non-volatile memory such as an Erasable Programmable Read Only Memory (EPROM), a flash memory, and the like.

[0065] In an embodiment, the system 108 may include an interface(s) 206. The interface(s) 206 may include a variety of interfaces, for example, interfaces for data input and output devices (VO), storage devices, and the like. The interface(s) 206 may facilitate communication through the system 108. The interface(s) 206 may also provide a communication pathway for one or more components of the system 108. Examples of such components include, but are not limited to, the processing unit 208 and a database 210.

[0066] The processing unit 208 may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing unit 208. In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing unit 208 may be processor-executable instructions stored on a non-transitory machine-readable storage medium and the hardware for the processing unit 208 may include a processing resource (for example, one or more processors) to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing unit 208. In such examples, the system 108 may include the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine- readable storage medium may be separate but accessible to the system 108 and the processing resource. In other examples, the processing unit 208 may be implemented by an electronic circuitry.

[0067] In one implementation, the receiving unit 202 may be operatively coupled to the interface(s) 206 and the processing unit 208 to enable seamless data acquisition, decoding, and dispatching of received information for further handling or storage.

[0068] In an embodiment, the receiving unit 202 and the processing unit 208 may be associated with a distributed network function (NF). In an example, the distributed NF may be a Network Repository Function (NRF) or any other type of distributed network function.

[0069] In an embodiment, the receiving unit 202 is configured to receive a request from the at least one NF. The request may include but not limited to a service discovery request, a registration request for registering instances of the at least one NF, an authentication request for validating credentials of the at least one NF, a subscription request for obtaining notifications regarding status or configuration changes, a policy query request for retrieving policy rules and enforcement parameters, or a deregistration request for removing NF-related data from the system. In an aspect, the at least one NF is also referred to as a consumer NF. The consumer NF refers to a Network Function that invokes or consumes services exposed by another NF, commonly referred to as a producer NF, such as the distributed NF (NRF). Examples of the at least one NF include, but are not limited to, an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a Policy Control Function (PCF), or a Network Slice Selection Function (NSSF).

[0070] In an embodiment, the processing unit 208 is configured to determine whether one or more configured parameters are present in the received request. The one or more configured parameters may be provisioned by network operators or system administrators during network configuration to ensure interoperability and authentication consistency across NFs. In an aspect, the one or more configured parameters include an NF type, an NF instance identifier (ID), a public land mobilenetwork (PLMN) identifier, an NF authentication type, an NF version, and an NF service type. The NF type identifies the functional role of the at least one NF. This parameter is included in the request to indicate the nature and operational role of the NF, such as whether the at least one NF is the AMF, SMF, PCF, etc. The NF instance ID represents the unique identifier for a specific NF instance, and it is included in the request to distinguish among multiple instances of the at least one NF. The PLMN ID denotes the mobile network identity associated with the at least one NF, and it is embedded in the request to ensure NF-to-NF interactions are valid within the serving operator domain. The NF authentication type specifies the authentication mechanism, and it is included in the request to enable the system 108 to apply the appropriate verification procedure. The NF version indicates the version of the at least one NF release level, and it is included in the request for determining compatibility with other NFs and avoiding version mismatch issues. The NF service type refers to the particular service or capability being requested (e.g., session management, policy control), and it is included in the request to route and process the service appropriately.

[0071] In an aspect, the processing unit 208 determines the presence of the one or more configured parameters in the received request by performing a parsing and a validation procedure. In an example, when the request is received, the processing unit 208 may extract header and body fields of the request and parse encoded information elements (IES) associated with the request. During this process, the processing unit 208 may check whether the one or more configured parameters are included in the form of IEs within the received request. For instance, the processing unit 208 may verify whether an IE of NF type field is present in the request to identify whether the at least one NF is AMF, SMF, etc. Similarly, the processing unit 208 may check whether the NF ID IE is present to uniquely identify the requesting NF among multiple instances. The processing unit 208 may further inspect whether the PLMN ID IE, NF authentication type IE, etc, is specified in the request. In one aspect, if the processing unit 208 determines that the one or more configured parameters are present, theextracted IES are validated against a predefined parameter registry. The predefined parameter registry may be stored in a repository associated with the distributed NF. The predefined parameter registry primarily serves as a reference dataset that contains valid entries, formats, and mappings for explicitly configured parameters. For example, if the request indicates an NF type as “SMF,” the processing unit 208 checks whether “SMF” exists as a valid entry in the registry, if an NF instance ID “SMF-001” is received, it validates whether the identifier matches an existing registered NF instance, if the PLMN ID is “404-45,” it validates that the PLMN ID corresponds to a recognized operator; and if the NF service type is “Session Management,” it ensures that such a service type is supported by the corresponding NF type. If the entries match, the one or more configured parameters are confirmed as valid and present.

[0072] In an aspect, upon determining that the one or more configured are unavailable or absent in the request, the processing unit 208 is configured to retrieve one or more predefined global parameters from the database. The one or more predefined global parameters serve as fallback or default parameters to ensure the continuity of operation in the absence of explicitly provided one or more configured parameters in the request. In contrast to the configured parameters, which are explicitly specified in the received request, the one or more predefined global parameters act as default baseline values applied universally when the received request lacks such explicit configuration. The one or more predefined global parameters may include but are not limited to a default NF type, a default NF instance ID, a default PLMN ID, and a default NF authentication type, a default NF version, and a default NF service type. In an aspect, the one or more predefined global parameters may be configured and provisioned by the network operator or system administrator during the initial setup of the NFs.

[0073] In an aspect, the one or more predefined global parameters may be stored in the database 210. The database 210 may be implemented as a distributeddatabase, a centralized repository, or an integrated storage unit within the NRF. In an example, the database 210 may be deployed across multiple data centers to ensure high availability, redundancy, and fault tolerance. In an aspect, the one or more predefined global parameters may be stored in the database 210 in association with a global configuration table, where each global parameter entry may be structured in key- value form, indexed by identifiers such as default NF type, default PLMN ID, etc. Upon identifying the absence of the one or more configured parameters in the received request, the distributed NF triggers a lookup operation in the database 210 to fetch the relevant global parameter. Once retrieved, the global parameter is substituted in place of the missing configured parameter, thereby enabling the distributed NF to continue the request processing. For example, if the received request does not include a PLMN ID, the processing unit 208 retrieves the default PLMN ID from the stored in the database 210, ensuring that the request can still be processed without rejection.

[0074] In particular, upon receiving the request, the NRF is configured to first verify the presence of the explicitly configured parameters in the request. When one or more of such configured parameters are unavailable, invalid, or absent, the NRF may apply a predefined decision logic to determine whether the corresponding global parameters are to be retrieved from the database 210. The NRF subsequently fetches such parameters, such as the default NF type, default NF instance ID, default PLMN ID, default NF authentication type, default NF version, and default NF service type, from the database 210. Once retrieved, the NRF applies the global parameters as default substitutes to ensure continuity of NF discovery, registration, or authentication processes.

[0075] In an aspect, the processing unit 208 is configured to verify one or more authentication credentials associated with the one or more configured parameters. The one or more authentication credentials may include, but are not limited to, a Client Credentials Assertion (CCA) token, an Open Authorization access (OAuth) token, abearer token, a Security Assertion Markup Language (SAML) token, or a JavaScript Object Notation Web Token. The CCA is a security mechanism for communication between different NFs, particularly during authentication and authorization. The CCA token is a digitally signed assertion issued by a trusted entity to authenticate a client (e.g., a network function instance) in machine-to-machine communication. The OAuth access token is generated by an identity provider to grant a client application access to protected resources without exposing user credentials. The bearer token is a security token that grants access based on possession, without requiring proof of identity beyond the token value. The SAML token is an XML-based assertion containing authentication and authorization information issued by an identity provider. The JavaScript Object Notation Web Token (JWT) is a compact, JSON-based token containing claims, digitally signed or encrypted, that allows secure transmission of authentication information. In an aspect, the verification of the one or more authentication credentials associated with the one or more configured parameters involves identifying whether the at least one NF with NF ID, NF PLMN ID etc., from which the request is received requires or supports the at least one of one of the one or more authentication credentials such as the CCA, the OAuth token, the bearer token, the SAML token, JWT or any other types of authentication credentials. In another aspect, the processing unit 208 is further configured to verify whether the one or more authentication credentials associated with the one or more predefined global parameters.

[0076] In an aspect, in order to verify the one or more authentication credentials, the processing unit 208 is configured to validate the one or more authentication credentials against a centralized authentication repository. The centralized authentication repository may maintain registered client information, cryptographic keys, token metadata, certificate chains, and validity rules. For example, in the case of the CCA token, the processing unit 208 extracts the digital signature from the CCA and validates it against a corresponding public key stored in the centralizedauthentication repository. The centralized authentication repository may further include associated attributes of the CCA token, such as the client identifier, token issuance timestamp, expiration validity, and allowed NF service scope, which are used by the processing unit 208 to ensure the CCA is authentic and authorized for the intended request. In order to preserve data integrity and privacy protection during token retrieval and verification, the processing unit 208 and the centralized authentication repository may communicate over encrypted channels. Additionally, the stored cryptographic keys may be protected using secure key management practices, such as hardware security modules (HSMs) or encrypted storage, to prevent unauthorized disclosure. Each credential may further be cryptographically signed, ensuring that any tampering or unauthorized modification of the credential is immediately detectable during the validation process.

[0077] In an aspect, a verification logic may be applied to the one or more authentication credentials. For instance, the applied verification logic is dynamically determined based on the type of the credential. The processing unit 208 is configured to identify the authentication credential format from the received request and select an appropriate verification mechanism. For example, in case the authentication credential is the SAME token, the verification logic includes parsing XML-based assertions and validating associated conditions such as issuer, subject, and audience fields. When the credential is in the form of the JWT or the CCA, the verification logic includes validating the embedded digital signature using cryptographic material obtained from a trusted repository, and confirming that the key pair used for signing is valid and unexpired. Similarly, when the credential corresponds to the OAuth token, the verification logic includes confirming the access scope and comparing it against policy rules that define permissible operations for the requesting NF.

[0078] In an embodiment, the system 108 may be configured to operate in a dynamic manner such that it can adapt to evolving network configurations withoutrequiring manual re-provisioning. In an example, upon detection of a new network function (NF) type, the system (108) may be configured to automatically provision and store authentication credentials for the new NF type in the centralized authentication repository. For instance, if a new NF type, such as Network Data Analytic Function (NWDAF) is introduced into the network, the system 108 may automatically provision and store the required authentication credentials (e.g., certificates, cryptographic keys, or token metadata) corresponding to the newly introduced NF in the centralized authentication repository.

[0079] In an aspect, upon successful verification of the one or more authentication credentials, the processing unit 208 is further configured to determine whether the one or more authentication credentials satisfy one or more predefined conditions. The one or more predefined conditions may include an expiration time associated with the one or more authentication credentials, an intended audience specified within the one or more authentication credentials, a key validity period linked to the cryptographic material of the one or more authentication credentials, or any additional security-related condition that validates the authorization scope of the one or more authentication credentials. To determine whether the one or more predefined conditions are satisfied, the processing unit 208 is configured to parse credential metadata (e.g., token claims, certificate fields, or assertion attributes) and compare the extracted values against locally stored policy rules or reference parameters in the centralized authentication repository. For instance, the processing unit 208 checks if the expiration timestamp of the CCA is still valid relative to the system clock. Further, the processing unit 208 may verify that the audience field contained in the CCA matches the identity of the target NF or service for which the request is intended. Additionally, the processing unit 208 confirms that the cryptographic key used for signing the CCA remains within its defined validity period, thereby ensuring that compromised or expired keys are not trusted for ongoing transactions. The processing unit 208 considers the successful verification of the one or more authenticationcredentials only if all predefined conditions are satisfied. Additionally, for scope- related checks, the processing unit 208 compares the scope or authorization attributes present in the credential against a policy to ensure that the requesting NF is permitted to access only the intended service functions. Furthermore, the integrity conditions may also be checked by recalculating and verifying digital signatures associated with the credential using the stored cryptographic keys. The NRF considers the conditions satisfied only if every comparison results in compliance with the predefined policy rules. Any failure in one or more conditions results in immediate termination of the authentication process.

[0080] In an exemplary embodiment, the verification of the one or more authentication credentials may be performed using a Public or Private Key Infrastructure (PKI). In such a case, the processing unit 208 extracts the digital signature embedded in the one or more authentication credentials (such as the CCA) and validates it against a public key obtained from a trusted certificate authority (CA). During verification, the processing unit 208 reconstructs the original signed data, applies the corresponding public key, and checks the integrity and authenticity of the credential. If the signature matches, the authentication credential is considered valid. In another exemplary embodiment, the verification of the one or more authentication credentials may be carried out using a decentralized blockchain-based approach in which each authentication credential (CCA, OAuth, JWT, etc.) is recorded in the blockchain. In this approach, the processing unit 208 checks the blockchain records to confirm whether the authentication credential is valid.

[0081] In an embodiment, upon successful verification, the processing unit 208 is configured to process the received request. The processing unit 208 may process the request by initiating services that are requested.

[0082] In an embodiment, when the at least one request is sent to the at least one NF, the processing unit 208 is configured to perform the similar operation asdescribed above. Initially, the processing unit 208 checks whether the one or more configured parameters associated with the target NF are available. If such configured parameters are present, the processing unit 208 verifies one or more authentication credentials corresponding to the configured parameters. Upon successful verification, the processing unit 208 sets or includes the verified authentication credentials in the request message and transmits the request to the at least one NF. In an aspect, if the one or more configured parameters are unavailable, the processing unit 208 fetches the applicable one or more predefined global parameters corresponding to the at least one NF to which the request is to be sent form the database 210. The processing unit 208 then verifies the one or more authentication credentials based on the global parameters. If the credentials are successfully verified, the processing unit 208 includes the verified authentication credentials in the request and transmits the request to the at least one NF.

[0083] In case the one or more authentication credentials are not verified, the processing unit 208 transmits an error response, indicating the failure of authentication validation for the request. The error response may include specific error codes or messages that help the requesting NF understand the cause of the failure. For example, if the authentication credential has expired, the error response may contain an “Invalid Token Expired” error code. If the intended audience in the credential does not match the target NF or service, the error response may include an “Audience Mismatch” message. Similarly, if the digital signature validation fails, the error response may indicate a “Signature Verification Failed” error.

[0084] Although FIG. 2 shows exemplary components of the system 108, in other embodiments, the system 108 may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 2. Additionally, or alternatively, one or more components of thesystem 108 may perform functions described as being performed by one or more other components of the system 108.

[0085] FIG. 3 illustrates an exemplary system architecture 300 for authenticating the at least one NF in the network, in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with FIGS. 1 and 2.

[0086] Referring to FIG. 3, a communication flow between an NF 302 interchangeably referred to as consumer NF 302 and an NRF 304 is depicted. As shown in FIG. 3, the NRF 304 may receive or send the request to the NF 302 and vice versa. The NF 302 may include but not limited to the AMF, SMF, and PCF.

[0087] In an embodiment, upon receiving the request, the NRF 304 checks if the one or more configured parameters are present in the request. If the one or more configured parameters are present in the request, the NRF 304 verifies whether the authentication credential, such as the CCA or any other authentication credentials, such as OAuth, JWT, etc., is associated with the one or more configured parameters. This involves verifying whether the at least one NF requires or supports the one or more authentication credentials such as the CCA. If the CCA support is available and it meets the required one or predefined conditions, the NRF 304 proceeds to process the at least one request.

[0088] Alternatively, if the NRF 304 verifies that the one or more configured parameters are unavailable in the request, the NRF 304 retrieves corresponding one or more predefined global parameters. Further, the NRF 304 verifies whether the authentication credential, such as the CCA or any other authentication credentials, is associated with one or more predefined global parameters. Upon successful verification of CCA, the NRF 304 completes the request processing, ensuring that the configured parameters are utilized effectively to fulfil the at least one request.

[0089] In an embodiment, the NRF 304 sends the request to the NF 302. While sending the request, the NRF 304 may check if the one or more configured parameters are present in the request. If the one or more parameters are present in the request, the NRF 304 checks the CCA availability for the configured parameters. If the CCA is available and meets the required predefined conditions, the NRF 304 sets or includes the CCA token and sends the request to the NF 302. If the one or more configured parameters are unavailable, the NRF 304 retrieves the one or more predefined global parameters and checks the CCA availability. If the CCA is available for the one or more predefined global parameters, the NRF 304 sets or includes the CCA token in the request and sends the request to the NF 302.

[0090] FIG. 4 illustrates an exemplary process flow 400 for authenticating the at least one NF corresponding to a received request, in accordance with an embodiment of the present disclosure. FIG. 4 is explained in conjunction with FIG 1, FIG. 2 and FIG. 3.

[0091] At step 402, the NRF 304 receives the request from the NF 302. The request may be a registration, update, discovery, or subscription request.

[0092] At step 404, upon receiving the request, the NRF 304 fetches data from the request and verifies whether one or more configured parameters are present in the request. The one or more configured parameters may include, but are not limited to, the NF type, the NF instance ID, the PLMN ID, the NF authentication type, the NF version, and the NF service type.

[0093] If it is determined that the one or more configured parameters are present, the branch ‘yes’ is followed from step 404. Further, at step 406, the NRF 304 checks whether the CCA is associated with the one or more configured parameters. The CCA represents a security credential or protocol that ensures the authenticity andlegitimacy of the NF 302. The NRF 304 verifies whether the NF, identified by the combination of the one or more configured parameters, requires or supports the CCA.

[0094] If the NF supports the CCA, the branch ‘yes’ is followed from step 406. At step 408, the NRF 304 verifies the CCA to ensure that it satisfies one or more predefined conditions. The one or more predefined conditions may include, for example, verification of the CCA expiration timestamp, confirmation of the intended audience field, or validation of the cryptographic key validity period. Only upon satisfying these predefined conditions is the CCA deemed valid.

[0095] At step 410, if the CCA verification is successful, the NRF 304 proceeds to process the request. Alternatively, if the branch ‘no’ is followed from step 406 (i.e., when the NF does not support CCA), the NRF 304 may still process the request at step 410, although without CCA verification, and may optionally record or notify about the compatibility issue for troubleshooting.

[0096] If it is determined at step 404 that the one or more configured parameters are not present in the request, the branch ‘no’ is followed. At step 412, the NRF 304 retrieves one or more predefined global parameters, including a global key (i.e., the one or more predefined global parameters), from the database 210. The global key represents the default parameter set used for ensuring continuity of processing in the absence of the one or more configured parameters.

[0097] Following step 412, the process flow resumes at step 406, where the NRF 304 checks whether the CCA is available for the global key. If the CCA is available, the branch ‘yes’ is followed from step 406, and at step 408, the NRF 304 verifies the CCA against the one or more predefined conditions as described above. Upon successful verification, the NRF 304 proceeds to step 410 and processes the request using the one or more predefined global parameters.

[0098] Alternatively, if the branch ‘no’ is followed from step 406 (i.e., when the CCA is not available or supported for the global key), the NRF 304 proceeds to step 410 and processes the request using the one or more predefined global parameters, while optionally generating a notification indicating the absence of CCA verification. This ensures that even in cases where configured parameters are missing, the request is processed reliably with fallback security measures.

[0099] FIG. 5 illustrates an exemplary process flow 500 for authenticating the at least one NF during sending the request, in accordance with an embodiment of the present disclosure. FIG. 5 is explained in conjunction with FIG. 1, FIG. 2, FIG. 3, and FIG. 4.

[0100] In an embodiment, the process flow 400 and the process flow 500 may be executed in parallel. Process flow 500 of FIG. 5 depicts sending the request from the NRF 304 to the NF 302 (i.e., the at least one NF).

[0101] At step 502, the NRF 304 initiates sending the request to the consumer NF 302. While sending the request, at step 504, the NRF 304 fetches data from the request and verifies whether the one or more configured parameters are present.

[0102] If the one or more configured parameters are present in the request, the branch ‘yes’ is followed from step 504. At step 506, the NRF 304 checks whether the CCA is associated with the one or more configured parameters.

[0103] If the branch ‘yes’ is followed from step 506 (i.e., the CCA is available and satisfies the required one or more predefined conditions). Further at step 508, the NRF 304 sets a CCA token (includes the CCA token) corresponding to the one or more configured parameters.

[0104] At step 510, after setting the CCA token, the NRF 304 sends the request to the NF 302. Alternatively, if the branch ‘no’ is followed from step 506 (i.e., the CCAis unavailable or unsupported), the NRF 304 proceeds directly to step 510 and sends the request without the CCA token.

[0105] Further, if the one or more configured parameters are not present in the request, the branch ‘no’ is followed from step 504. At step 512, the NRF 304 retrieves the global key (i.e., the one or more predefined global parameters).

[0106] After retrieving the global key, the process continues to step 506, where the NRF 304 determines whether the CCA is associated with the global key.

[0107] If the branch ‘yes’ is followed from step 506 (i.e., the CCA is available for the global key and satisfies the required conditions), at step 508, the NRF 304 sets the CCA token.

[0108] At step 510, after setting the CCA token, the NRF 304 sends the request to the consumer NF 302 using the global key.

[0109] Alternatively, if the branch ‘no’ is followed from step 506 (i.e., the CCA is not available or not supported for the global key), the NRF 304 proceeds directly to step 510 and sends the request to the consumer NF 302 without the CCA token. In such a case, the NRF 304 may append a notification or message indicating a potential compatibility issue, thereby enabling the consumer NF 302 or network administrator to troubleshoot and resolve the issue.

[0110] FIG. 6 illustrates an exemplary flow diagram 600 of a method for authenticating the at least one NF in the network, in accordance with an embodiment of the present disclosure. FIG. 6 is explained in conjunction with FIG. 2.

[0111] At step 602, the method 600 includes receiving, by a distributed network function (NF), a request from the at least one NF. In an aspect, the distributed NF may be the NRF.

[0112] At step 604, the method 600 includes determining, by the distributed NF, whether one or more configured parameters are present in the received request. The one or more configured parameters include at least one of: the NF type, the NF instance identifier (ID), the PLMN identifier, the NF authentication type, the NF version, and the NF service type.

[0113] At step 606, the method 600 includes, based on the determination, verifying, by the distributed NF, one or more authentication credentials associated with the one or more configured parameters. The one or more authentication credentials are one of: the CCA token, the OAuth token, the bearer token, the SAML token, the JWT or any other suitable token type that satisfies the one or more predefined conditions. In an aspect, to verify the one or more authentication credentials, the method 600 includes, validating the one or more authentication credentials against a centralized authentication repository.

[0114] The method further includes retrieving the one or more predefined global parameters from the database 210. In an aspect, the one or more predefined global parameters are retrieved when the one or more configured parameters are unavailable in the received request. In an aspect, the one or more predefined global parameters include at least one of: the default NF type, the default NF instance ID, the default PLMN ID, the default NF authentication type, the default NF version, the default NF service type.

[0115] At step 608, the method includes upon successful verification of the one or more authentication credentials, processing, by the distributed NF, the received request to authenticate the at least one NF.

[0116] In an aspect, upon successful verification, the method includes determining, by the distributed NF, whether the one or more authentication credentials satisfy one or more predefined conditions. The one or more predefined conditionsinclude at least one of: the expiration time of the one or more authentication credentials, and the audience associated with the one or more authentication credentials, the key validity period associated with the one or more authentication credentials, or any additional security-related condition that validates the authorization of the one or more authentication credentials.

[0117] FIG. 7 illustrates an example computer system 700 in which or with which the embodiments of the present disclosure may be implemented.

[0118] As shown in FIG. 7, the computer system 700 may include an external storage device 710, a bus 720, a main memory 730, a read-only memory 740, a mass storage device 750, a communication port(s) 760, and a processor 770. A person skilled in the art will appreciate that the computer system 700 may include more than one processor and communication ports. The processor 770 may include various modules associated with embodiments of the present disclosure. The communication port(s) 760 may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication ports(s) 760 may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system 700 connects.

[0119] In an embodiment, the main memory 730 may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory 740 may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chip for storing static information e.g., start-up or basic input / output system (BIOS) instructions for the processor 770. The mass storage device 750 may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives(internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces).

[0120] In an embodiment, the bus 720 may communicatively couple the processor(s) 770 with the other memory, storage, and communication blocks. The bus 720 may be, e.g. a Peripheral Component Interconnect PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor 770 to the computer system 700.

[0121] In another embodiment, operator, and administrative interfaces, e.g., a display, keyboard, and cursor control device may also be coupled to the bus 720 to support direct operator interaction with the computer system 700. Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) 760. Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system 700 limit the scope of the present disclosure.

[0122] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to perform a method for authenticating at least one network function (NF) in a network is disclosed. The method includes receiving by a distributed network function (NF), a request from the at least one NF. The method includes determining, by the distributed NF, whether one or more configured parameters are present in the received request. The method includes verifying, by the distributed NF, one or more authentication credentials associated with the one or more configured parameters based on the determination. The method includes processing by the distributed NF, thereceived request to authenticate the at least one NF upon successful verification of the one or more authentication credentials.

[0123] The present disclosure provides a technical advancement in the field of authentication and security management within 5G telecommunication networks. By enabling the verification of one or more authentication credentials of Network Functions (NFs) at the Network Repository Function (NRF) during both inbound and outbound transactions, the system introduces a robust and bi-directional trust enforcement mechanism. The use of configurable and global parameters for each NF allows the NRF to dynamically authenticate requests while adapting to evolving network configurations, such as changes in NF types, network identifiers, or security protocols. Furthermore, the system ensures that validated authentication credentials are seamlessly included in the request prior to forwarding, while invalid credentials result in error signaling, thereby preventing unauthorized communication. This architectural approach leads to significant improvements in network security, reduced chances of credential misuse, minimized signaling overhead associated with repetitive authentication procedures, and enhanced interoperability of NFs across diverse network scenarios. Overall, the system and method improve the resilience, scalability, and adaptability of authentication frameworks in modern 5G core networks.

[0124] While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.

[0125] The method and system of the present disclosure may be implemented in a number of ways. For example, the methods and systems of the present disclosuremay be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order for the steps of the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above unless specifically stated otherwise. Further, in some embodiments, the present disclosure may also be embodied as programs recorded in a recording medium, the programs including machine-readable instructions for implementing the methods according to the present disclosure. Thus, the present disclosure also covers a recording medium storing a program for executing the method according to the present disclosure.

[0126] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter to be implemented merely as illustrative of the disclosure and not as limitation.ADVANCEMENTS OF THE PRESENT DISCLOSURE

[0127] The present disclosure described herein above has several technical advantages as follows:

[0128] The present disclosure provides enhanced compatibility between different Network Functions (NFs). By incorporating a Public Land Mobile Network (PLMN), an instance ID, and the NF type checks, the method and the system ensure that only compatible NFs interact. This reduces the risk of interoperability conflicts and provides seamless communication between NFs of varying types and vendors.

[0129] The present disclosure provides a method and system for improving error handling in the network. Including PLMN, instance ID, and NF type checksallows for targeted error handling and response mechanisms. When encountering unsupported PLMNs, instance IDs, NF Types, or similar issues, the system can provide specific statements or notifications, facilitating easier troubleshooting and resolution of compatibility issues.

[0130] The present disclosure prevents data transmission failures in the communication network by proactively identifying compatibility issues between older and newer versions of the NFs. This ensures that the network functionality is not disrupted, maintaining smooth operation within the telecommunications infrastructure.

[0131] The present disclosure increases the network's reliability and performance. The method and system enhance overall network reliability and performance by mitigating interoperability concerns. This ensures that users experience fewer disruptions and can rely on the network for consistent communication and data transmission.

[0132] The present disclosure promotes scalability and adaptability within the network by adding the PLMN, the instance ID, and the NF type checks. Further, it allows for easier integration of new NFs and technologies while ensuring compatibility with existing systems.

Claims

CLAIMS1. A method (600) for authenticating at least one network function (NF) in a network (106), the method (600) comprising: receiving (602), by a distributed network function (NF), a request from the at least one NF; determining (604), by the distributed NF, whether one or more configured parameters are present in the received request; based on the determination, verifying (606), by the distributed NF, one or more authentication credentials associated with the one or more configured parameters; and upon successful verification of the one or more authentication credentials, processing (608), by the distributed NF, the received request to authenticate the at least one NF.

2. The method (600) as claimed in claim 1, further comprising: retrieving, by the distributed NF, one or more predefined global parameters from a database (210), wherein the one or more predefined global parameters are retrieved when the one or more configured parameters are unavailable in the received request.

3. The method (600) as claimed in claim 1, wherein upon successful verification, the method comprising: determining, by the distributed NF, whether the one or more authentication credentials satisfies one or more predefined conditions.

4. The method (600) as claimed in claim 1, wherein the one or more configured parameters comprise at least one of: an NF type, an NF instance identifier (ID), a public land mobile network (PLMN) identifier, an NF authentication type, an NF version, and an NF service type.

5. The method (600) as claimed in claim 2, wherein the one or more predefined global parameters comprise at least one of: a default NF type, a default NF instance ID, a default PLMN ID, and a default NF authentication type, a default NF version, a default NF service type, wherein the one or more global predefined parameters are retrieved when the one or more configured parameters are unavailable in the received request.

6. The method (600) as claimed in claim 3, wherein the one or more predefined conditions comprise at least one of: an expiration time of the one or more authentication credentials, and an audience associated with the one or more authentication credentials, a key validity period associated with the one or more authentication credentials, or an authorization scope associated with the authorization of the one or more authentication credentials.

7. The method (600) as claimed in claim 1 , wherein the one or more authentication credentials are one of: Client Credentials Assertion (CCA) token, an Open Authorization access (OAuth) token, a bearer token, a Security Assertion Markup Language (SAML) token, a JavaScript Object Notation Web Token or any other suitable token type that satisfies the one or more predefined conditions.

8. The method (600) as claimed in claim 1, wherein verifying the one or more authentication credentials comprising:validating, by the distributed NF, the one or more authentication credentials against a centralized authentication repository.

9. A system (108) for authenticating at least one network function (NF) in a network (106), the system (108) comprising: a receiving unit (202) at a distributed network function (NF) configured to receive a request from at least one NF; a processing unit (208) at the distributed NF configured to: determine whether one or more configured parameters are present in the received request; verify one or more authentication credentials associated with the one or more configured parameters, based on the determination; and process the received request to authenticate the at least one NF, upon successful verification of the one or more authentication credentials.

10. The system (108) as claimed in claim 9, wherein the processing unit (208) is configured to retrieve one or more predefined global parameters from a database, wherein the one or more predefined global parameters are retrieved when the one or more configured parameters are unavailable in the received request.

11. The system (108) as claimed in claim 9, wherein upon successful verification, the processing unit (208) is configured to determine whether the one or more authentication credentials satisfies one or more predefined conditions, wherein the one or more predefined conditions comprise at least one of: an expiration time of the one or more authentication credentials, and an audience associated with the one or more authentication credentials, a key validity period associated with the one or more authentication credentials, or an authorization scope associated with the one or more authentication credentials.

12. The system (108) as claimed in claim 9, wherein the one or more configured parameters comprise at least one of: an NF type, an NF instance identifier (ID), a public land mobile network (PLMN) identifier, an NF authentication type, an NF version, and an NF service type.

13. The system (108) as claimed in claim 10, wherein the one or more predefined global parameters comprise at least one of: a default NF type, a default NF instance ID, a default PLMN ID, and a default NF authentication type, a default NF version, a default NF service type, wherein the one or more global predefined parameters are retrieved when the one or more configured parameters are unavailable in the received request.

14. The system (108) as claimed in claim 9, wherein the one or more authentication credentials are one of: Client Credentials Assertion (CCA) token, an Open Authorization access (OAuth) token, a bearer token, a Security Assertion Markup Language (SAML) token, a JavaScript Object Notation Web Token or any other suitable token type that satisfies the one or more predefined conditions.

15. The system (108) as claimed in claim 9, wherein to verify the one or more authentication credentials, the processing unit (208) is configured to validate the one or more authentication credentials against a centralized authentication repository.

16. A computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method (600) for authenticating at least one network function (NF) in a network, the method (600) comprising:receiving (602), by a distributed network function (NF), a request from the at least one NF; determining (604), by the distributed NF, whether one or more configured parameters are present in the received request; based on the determination, verifying (606), by the distributed NF, one or more authentication credentials associated with the one or more configured parameters; and upon successful verification of the one or more authentication credentials, processing (608), by the distributed NF, the received request to authenticate the at least one NF.