Service request authorization
The system addresses interoperability issues in 5G/6G networks by transmitting customizable authorization policies for service requests, enabling flexible and secure verification of network function service consumers, thus improving authorization efficiency and consistency across diverse vendor environments.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2026-04-02
AI Technical Summary
Current service request authorization mechanisms in 5G and 6G communication networks lack interoperability and flexibility, particularly in multi-vendor environments, due to undefined policy distribution, policy content, and enforcement points, leading to challenges in authenticating network function service consumers.
A system where a first apparatus transmits a policy message to a second apparatus for service request authorization, allowing or rejecting requests based on reference information elements, with the second apparatus verifying identity and authorization information elements, and optionally forwarding the request to a fourth apparatus for authorization.
Enables dynamic and flexible service request authorization, enhancing interoperability and security by allowing verification against customizable policies, reducing signaling overhead, and ensuring consistent authorization across different vendor environments.
Smart Images

Figure CN2024121243_02042026_PF_FP_ABST
Abstract
Description
SERVICE REQUEST AUTHORIZATIONFIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for service request authorization.BACKGROUND
[0002] Communication network revolution is driven by increasing number of devices and evolving services. The fifth generation (5G) or sixth generation (6G) communication network may adopt service-based architecture (SBA) to cater to these services. Flexible SBA design consists of interconnected network functions (NFs) that provide access to network resources and capabilities. These NFs may provide various NF services. A service request for the NF service needs to be authorized.SUMMARY
[0003] In a first aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: transmit, to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.
[0004] In a second aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to: receive, from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request; receive a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; and perform at least one of: a verification of the identity information of the third apparatus, a verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to a fourth apparatus.
[0005] In a third aspect of the present disclosure, there is provided a third apparatus. The third apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third apparatus at least to: receive, from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service; generate a client credentials assertion token based on the at least one authorization information element; and transmit, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.
[0006] In a fourth aspect of the present disclosure, there is provided a fourth apparatus. The fourth apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fourth apparatus at least to: receive, from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element; receive, from a second apparatus, a service request for a network function service; and in accordance with a determination that the service request includes at least one authorization information element, perform at least a verification of the at least one authorization information element based on the at least one policy.
[0007] In a fifth aspect of the present disclosure, there is provided a method. The method comprises: transmitting, at a first apparatus to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.
[0008] In a sixth aspect of the present disclosure, there is provided a method. The method comprises: receiving, at a second apparatus from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request; receiving a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; and performing at least one of: a verification of the identity information of the third apparatus, a verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to a fourth apparatus.
[0009] In a seventh aspect of the present disclosure, there is provided a method. The method comprises: receiving, at a third apparatus from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service; generating a client credentials assertion token based on the at least one authorization information element; and transmitting, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.
[0010] In an eighth aspect of the present disclosure, there is provided a method. The method comprises: receiving, at a fourth apparatus from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element; receiving, from a second apparatus, a service request for a network function service; and in accordance with a determination that the service request includes at least one authorization information element, performing at least a verification of the at least one authorization information element based on the at least one policy.
[0011] In a ninth aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises means for transmitting, to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.
[0012] In a tenth aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises means for receiving, from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request; means for receiving a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; and means for performing at least one of: a verification of the identity information of the third apparatus, a verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to a fourth apparatus.
[0013] In an eleventh aspect of the present disclosure, there is provided a third apparatus. The third apparatus comprises means for receiving, from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service; means for generating a client credentials assertion token based on the at least one authorization information element; and means for transmitting, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.
[0014] In a twelfth aspect of the present disclosure, there is provided a fourth apparatus. The fourth apparatus comprises means for receiving, from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element; means for receiving, from a second apparatus, a service request for a network function service; and means for in accordance with a determination that the service request includes at least one authorization information element, performing at least a verification of the at least one authorization information element based on the at least one policy.
[0015] In a thirteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fifth aspect.
[0016] In a fourteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the sixth aspect.
[0017] In a fifteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the seventh aspect.
[0018] In a sixteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the eighth aspect.
[0019] In some or all examples of the first aspect, the first apparatus is further caused to: transmit, to a third apparatus, a second message indicating to include at least one authorization information element related to a service request for a network function service.
[0020] In some or all examples of the first aspect, the at least one authorization information element comprises at least one of: a type of a network function service consumer associated with the network function service, identity information of public land mobile network associated with the network function service, identity information of a slice associated with the network function service, identity information of a set of network functions associated with the network function service, identity information of a network function instance associated with the network function service, or a service name of the network function service.
[0021] In some or all examples of the first aspect, at least one of the at least one reference information element or the at least one authorization information element at least comprises a mandatory information element. At least one of the at least one reference information element or the at least one authorization information element may further comprise an optional information element.
[0022] In some or all examples of the first aspect, the at least one reference information element comprises at least one of: a type of a network function service consumer associated with the reference service request, identity information of public land mobile network associated with the reference service request, identity information of a slice associated with the reference service request, identity information of a set of network functions associated with the reference service request, identity information of a network function instance associated with the reference service request, or a service name of the reference service request, and wherein the at least one policy comprises a decision flag to allow or reject the reference service request.
[0023] In some or all examples of the first aspect, the first apparatus is further caused to: transmit, to the second apparatus, a third message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy.
[0024] In some or all examples of the first aspect, the second apparatus comprises a network function service producer, and the first apparatus is caused to: receive, from the second apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request; determine the at least one policy based on the request; and transmit the first message to the second apparatus.
[0025] In some or all examples of the first aspect, the second apparatus comprises a service communication proxy, and the first apparatus is caused to: receive, from a fourth apparatus comprising a network function service producer, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request; determine the at least one policy and the service communication proxy associated with the network function service producer based on the request; and transmit the first message to the second apparatus.
[0026] In some or all examples of the first aspect, the first apparatus is further caused to: transmit a fourth message including the at least one policy to the fourth apparatus.
[0027] In some or all examples of the first aspect, the first message further indicates the second apparatus to perform at least one of: a verification of identity information of the third apparatus, a verification of at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus.
[0028] In some or all examples of the first aspect, the first apparatus is further caused to: transmit, to at least one of the second apparatus or a fourth apparatus, an indication that at least one of the following is performed by the service communication proxy: a verification of identity information of the third apparatus, a verification of at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus.
[0029] In some or all examples of the second aspect, the second apparatus is further caused to: receive, from the first apparatus, a message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy.
[0030] In some or all examples of the second aspect, the second apparatus comprises a service communication proxy, and the second apparatus is caused to: in response to receiving the service request from the third apparatus or a further apparatus, forward the service request to the fourth apparatus, the service request including the at least one authorization information element.
[0031] In some or all examples of the second aspect, the second apparatus is further caused to: in response to the identity information of the third apparatus being verified, forward the service request to the fourth apparatus, the service request including the at least one authorization information element.
[0032] In some or all examples of the second aspect, the second apparatus comprises a service communication proxy, and the second apparatus is caused to: in response to the identity information of the third apparatus and the at least one authorization information element being verified, transmit, to the fourth apparatus, the service request and an indication of a completion of an authorization of the service request, wherein the at least one authorization information element is excluded from the service request.
[0033] In some or all examples of the second aspect, the second apparatus comprises a service communication proxy, and the first message or an indication from the first apparatus indicates the second apparatus to perform at least one of: the verification of identity information of the third apparatus, the verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus.
[0034] In some or all examples of the second aspect, the second apparatus comprises a network function service producer, and the second apparatus is caused to: authorize the service request based on a verification of the identity information of the third apparatus and a verification of the at least one authorization information element based on the at least one policy.
[0035] In some or all examples of the second aspect, the second apparatus comprises a network function service producer, and the second apparatus is caused to: transmit, to the first apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request.
[0036] In some or all examples of the second aspect, the service request comprises a client credentials assertion token including the at least one authorization information element.
[0037] In some or all examples of the second aspect, the at least one policy indicates to allow a first reference service request based on at least a first mandatory reference information element, and the verification of the at least one authorization information element is failed based on at least one of: the at least one authorization information element excluding a first mandatory authorization information element corresponding to the first mandatory reference information element, or a corresponding first mandatory information element in the at least one authorization information element mismatching the first mandatory reference information element.
[0038] In some or all examples of the second aspect, the at least one policy indicates to allow the first reference service request further based on a second optional information element, and the verification of the at least one authorization information element is failed further based on: a corresponding second optional information element in the at least one authorization information element mismatching the second optional reference information element.
[0039] In some or all examples of the second aspect, the at least one policy indicates to reject a second reference service request based on a third mandatory reference information element and a fourth optional reference information element, and the verification of the at least one authorization information element is failed based on at least one of: the at least one authorization information element excluding a third mandatory authorization information element corresponding to the third mandatory reference information element, a corresponding third mandatory information element in the at least one authorization information element matching the third mandatory reference information element, or a corresponding fourth optional information element in the at least one authorization information element matching the fourth optional reference information element.
[0040] In some or all examples of the second aspect, the second apparatus is further caused to: in accordance with a determination that the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, transmit, to the first apparatus, a request for the at least one authorization information element.
[0041] In some or all examples of the third aspect, the at least one authorization information element comprises at least one of: a type of a network function service consumer associated with the network function service, identity information of public land mobile network associated with the network function service, identity information of a slice associated with the network function service, identity information of a set of network functions associated with the network function service, identity information of a network function instance associated with the network function service, a service name of the network function service.
[0042] In some or all examples of the third aspect, the at least one authorization information element at least comprises a mandatory information element.
[0043] In some or all examples of the third aspect, the at least one authorization information element further comprises an optional information element.
[0044] In some or all examples of the third aspect, the third apparatus is caused to: transmit, to the first apparatus, a request for discovery of a network function service producer; and receive the message from the first apparatus, the message further including identity information of the network function service producer.
[0045] In some or all examples of the third aspect, at least one of the transmission of the request or the reception of the message is via a service communication proxy.
[0046] In some or all examples of the fourth aspect, the fourth apparatus is further caused to:in accordance with a determination that the service request includes the at least one authorization information element and identity information of a third apparatus, authorize the service request based on a verification of the identity information of the third apparatus and the verification of the at least one authorization information element based on the at least one policy.
[0047] In some or all examples of the fourth aspect, the second apparatus is further caused to: in accordance with a determination that the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, transmit, to the first apparatus, a request for the at least one authorization information element.
[0048] In some or all examples of the fourth aspect, the fourth apparatus further is caused to:in response to an indication from the second apparatus or the service request indicating a completion of an authorization of the service request, transmit a response of the service request to the third apparatus without verifying the at least one authorization information element or identity information of the third apparatus.
[0049] In some or all examples of the fourth aspect, the fourth apparatus is further caused to:receive, from the first apparatus, a message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy.
[0050] In some or all examples of the fourth aspect, the fourth apparatus further is caused to:transmit, to the first apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the fourth apparatus, or a rule for authorizing a service request.
[0051] In some or all examples of the fourth aspect, the service request comprises a client credentials assertion token including the at least one authorization information element.
[0052] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0054] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0055] FIG. 2A and FIG. 2B illustrate schematic diagrams for network function service consumer authentication, respectively;
[0056] FIG. 3 illustrates a signaling flow for service request authorization in accordance with some embodiments of the present disclosure;
[0057] FIG. 4 illustrates another signaling flow for service request authorization in accordance with some embodiments of the present disclosure;
[0058] FIG. 5 illustrates a signaling flow for authorization policy updating in accordance with some embodiments of the present disclosure;
[0059] FIG. 6 illustrates another signaling flow for service request authorization in accordance with some embodiments of the present disclosure;
[0060] FIG. 7 illustrates another signaling flow for service request authorization in accordance with some embodiments of the present disclosure;
[0061] FIG. 8 illustrates a flowchart of a method implemented at a first apparatus in accordance with some example embodiments of the present disclosure;
[0062] FIG. 9 illustrates a flowchart of a method implemented at a second apparatus in accordance with some example embodiments of the present disclosure;
[0063] FIG. 10 illustrates a flowchart of a method implemented at a third apparatus in accordance with some example embodiments of the present disclosure;
[0064] FIG. 11 illustrates a flowchart of a method implemented at a fourth apparatus in accordance with some example embodiments of the present disclosure;
[0065] FIG. 12 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0066] FIG. 13 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0067] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0068] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0069] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0070] References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0071] It shall be understood that although the terms “first, ” “second, ” …, etc. in front of noun (s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun (s) . For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0072] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0073] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0074] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0075] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0076] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and
[0077] (b) combinations of hardware circuits and software, such as (as applicable) :
[0078] (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and
[0079] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0080] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0081] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0082] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR) , Long Term Evolution (LTE) , LTE-Advanced (LTE-A) , Wideband Code Division Multiple Access (WCDMA) , High-Speed Packet Access (HSPA) , Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G) , the second generation (2G) , 2.5G, 2.75G, the third generation (3G) , the fourth generation (4G) , 4.5G, the fifth generation (5G) , 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0083] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP) , for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , an NR NB (also referred to as a gNB) , a Remote Radio Unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0084] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node) . In the following description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.
[0085] As used herein, the term “resource, ” “transmission resource, ” “resource block, ” “physical resource block” (PRB) , “uplink resource, ” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0086] As used herein, the term “NF service producer” or “NF producer (NFp) ” refers to an NF or entity providing an NF service to other NFs or entities. The term “NF service consumer” or “NF consumer (NFc) ” refers to an NF or entity that consumes a NF service provided by the NF service producer.
[0087] As used herein, the term “service communication proxy (SCP) ” refers to an intermediary component or entity that may be used to facilitate communications between NFs. The SCP may help in routing messages between different NFs, for example, in a indirect communication scenario.
[0088] As used herein, the term “network repository function (NRF) ” refers to a component or entity in a core network that services as a registry for NFs. The NRF may maintain information about available NF instances and their capabilities. The NRF may also facilitate discovery and interaction between NFs.
[0089] As briefly mentioned, a service request for a network function service needs to be authorized. Currently, there are two possible cases for an NF service producer to authenticate an NF service consumer based on different communication models. A first case is for where there is a direct communication between the NF service producer and the NF service consumer. In this case, information may be retrieved by a mutual transport layer security (mTLS) establishment. In other words, the authentication of the NF service consumer may be via the mTLS. A second case is responsible for indirect communication, in which the mTLS tunneling is terminated in an SCP. In this situation, the NF service consumer may need to attach a client credentials assertion (CCA) token to the service request to allow the NF service producer to authenticate the NF service consumer. In such case, the NF service producer may not be able to authenticate the NF service consumer without the CCA.
[0090] In some mechanisms, the service request authorization for the SBA architecture may be developed on top of these two cases for NF service consumer authentication. For example, the service request authorization may relay on use of OAuth2.0 protocol for the first case. For the other case, it may use a local static policy to authorize each request.
[0091] The current policy-based authorization provides a solution for static authorization, which assumes the authorization polices were pre-configured in NF service producer. Specifically, the static authorization is based on local authorization policy at the NRF and the NF service producer. It may be used when token-based authorization is not used. During the Nnrf_NFDiscovery procedure, the NRF ensures that the NF service consumer is authorized to discover the NF service producer service (s) as specified in a standard. If token-based authorization is not used within one public land mobile network (PLMN) and the NF service producer receives a service request, the NF service producer shall check authorization of the NF service consumer based on its local policy. If the NF service consumer is authorized to receive the service requested, the NF service producer shall grant the NF service consumer access to the service application programming interface (API) . However, such solution lacks specification to allow for interoperability between NF from different vendors.
[0092] As mentioned, there are two kinds of authorization defined in 5G, that is, the static (policy based) authorization and the Oauth2.0 authorization. The current standard for static authorization limits in terms requirements available in the standards and presents challenges when used in multi-vendor environments. In particular, it requires additional specification on three main aspects as follows.
[0093] 1) The first aspect regards the distribution of the static policies. The current standard does not define how policy should be distributed to the NFp, and who is responsible for their creation / distribution.
[0094] 2) The second limitation is in the policy definition. Currently there is no standard way on which information a policy should contain, and which values the NFp should verify to Authorize the NFc.
[0095] 3) The last aspect resides in where the authorization is enforced. The current specification, only discuss the possibility for the NFp to enforce static authorization but based on the different communication model as defined by a standard, different enforcement points might present different security requirements / benefit.
[0096] In order to solve at least part of the above problems or other potential problems, a solution on service request authorization is proposed. In the solution, a first apparatus transmits, to a second apparatus, a first message including at least one policy for service request authorization. The at least one policy indicates at least one rule for allowing or rejecting a reference service request based on at least one reference information element. The second apparatus receives the first message and then may authorize a service request from other apparatus. For example, the second apparatus receives a service request for a network function service from a third apparatus or a further apparatus. The service request includes identity information of the third apparatus and at least one authorization information element. In an option, the second apparatus performs a verification of the identity information of the third apparatus, and / or a verification of the at least one authorization information element in the service request based on the at least one policy. Alternatively, or in addition, the second apparatus forwards the service request to a fourth apparatus. The fourth apparatus may authorize the service request.
[0097] In this manner, the service request authorization may be achieved based on dynamic policies from the first apparatus. For example, the authorization may be achieved by verifying the at least one authorization information element in the service request based on the at least one reference information element in the at least one policy. It allows the second apparatus to verify the service request against the policy and decide whether or not to authorize (or accept) the service request.
[0098] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0099] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. In the specific example of FIG. 1, a plurality of communication devices in the communication environment 100 may communicate with each other. In an example embodiment, an NRF 110, an NF service producer 120, an NF service consumer 130 may communicate with each other. For example, the NF service producer 120 may provide an NF service. The NF service consumer 130 may request the NF service provided by the NF service producer 120. As used herein, the NF service consumer 130 may be referred to as a “requester” . The requester needs to be authorized to perform the request. The NF service producer 120 may authenticate the NF service consumer 130.
[0100] In some embodiments, the NRF 110 may create or generate at least one policy for authorize the request for the NF service. As used herein, the entity generating the policy for service request authorization may be referred to as a “policy issuer (PI) ” . It is to be understood that although in FIG. 1, the PI is illustrated as the NRF 110, in some other embodiments, the PI may be implemented as other entities or devices, such as operations, administration and maintenance (OAM) or other NF or entity in the communication environment 100.
[0101] In another example embodiments, a further device such as an SCP 140 may communicate with the NRF 110, the NF service producer 120, and / or the NF service consumer 130. In such embodiment, the NF service producer 120 and the NF service consumer 130 may not communicate directly, but instead communicate indirectly via the SCP 140. For example, the authentication of the NF service consumer 130 may be via the SCP 140.
[0102] It is to be understood that the number of devices and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. In the other example embodiments, the communication environment 100 may include any suitable number of devices configured to implementing example embodiments of the present disclosure. It is to be understood that one or more NF entities in FIG. 1 may be replaced by other suitable NF entities. There may be further devices in the communication environment 100.
[0103] Communications in the communication environment 100 may be implemented according to any proper communication protocol (s) , comprising, but not limited to, cellular communication protocols of the first generation (1G) , the second generation (2G) , the third generation (3G) , the fourth generation (4G) , the fifth generation (5G) , the sixth generation (6G) , and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA) , Frequency Division Multiple Access (FDMA) , Time Division Multiple Access (TDMA) , Frequency Division Duplex (FDD) , Time Division Duplex (TDD) , Multiple-Input Multiple-Output (MIMO) , Orthogonal Frequency Division Multiple (OFDM) , Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0104] FIG. 2A illustrates a schematic diagram for authentication of the NF service consumer 130 directly communicating with the NF service producer 120. As shown, there is an mTLS 210 between the NF service consumer 130 and the NF service producer 120. Information associated with the NF service consumer 130 such as an identifier (ID) of the NF service consumer 130 may be transmitted to the NF service producer 120 via the mTLS 210. The authentication of the NF service consumer 130 may be at least in part based on the information retrieved via the mTLS 210.
[0105] FIG. 2B illustrates a schematic diagram for authentication of the NF service consumer 130 indirectly communicating with the NF service producer 120 via the SCP 140. Information associated with the NF service consumer 130 such as the ID of the NF service consumer 130 may be transmitted to the SCP 140 via an mTLS 240 and then forwarded to the NF service producer 120 via an mTLS 240. In addition, the NF service consumer 130 may need to attach a CCA token 260 to the service request to allow the NF service producer 120 to authenticate the NF service consumer 130.
[0106] Several embodiments regarding the authentication of the NF service consumer 130 have been described. These embodiments will be applied for the service request authorization as follows.
[0107] FIG. 3 illustrates a signaling flow 300 for service request authorization in accordance with some embodiments of the present disclosure. The signaling flow 300 involves a first apparatus 301, a second apparatus 302 and a third apparatus 303 and optional a fourth apparatus 304.
[0108] In some example embodiments, the first apparatus 301 may include the NRF 110 in FIG. 1 or other PI such as OAM. The second apparatus 302 may include the NF service producer 120 in FIG. 1. The third apparatus 303 may include the NF service consumer 130 in FIG. 1.
[0109] In operation, the first apparatus 301 transmits (310) , to the second apparatus 302, a first message including at least one policy for service request authorization. The at least one policy indicates at least one rule for allowing or rejecting a reference service request based on at least one reference information element (IE) . The second apparatus 302 receives (315) the first message. The second apparatus 302 may store the at least one policy in the first message. As used herein, the at least one policy may be referred to as (service) request authorization policy or access policy. The at least one reference information element may be referred to as at least one reference field in the at least one policy. The first apparatus 301 may be referred to as the PI which is responsible to create the policy and send it to a policy enforcer (PE) such as the second apparatus 302.
[0110] By way of example, the at least one reference information element may include at least one of: a type of an NF service consumer associated with the reference service request, identity information of public land mobile network (PLMN) associated with the reference service request, identity information of a slice associated with the reference service request, identity information of a set of network functions associated with the reference service request, identity information of a network function instance associated with the reference service request, or a service name of the reference service request. In further example embodiments, the at least one reference information element may include further information element, such as other field in profile of the NF service consumer. For example, region of the NF service consumer or traffic analysis enforcement (TAE) of the NF service consumer may be included in the at least one reference IE. The at least one policy may include a decision flag to allow or reject the reference service request. If the decision flag is not present, the decision flag may be referred to be “allow” as default, or otherwise “reject” as default.
[0111] Table 1 below shows several example policies. It is to be understood that IEs, fields, parameters or values in Table 1 are only for the purpose of illustration, without suggesting any limitation. Although several policies with the decision flag being allow have been shown, in some example embodiments, at least one policy with the decision flay being rejection (or deny) will be generated. Any suitable policy with any suitable reference IE may be applied. Scope of embodiments of the present disclosure is not limited here.
[0112] Table 1
[0113] By using various reference IEs, flexible policies for authorizing the service request may be achieved. By including these policies in the first message, different policies may be configured by a single message. The signaling overhead can thus be reduced.
[0114] In some example embodiment, the at least one reference information element may at least include a mandatory information element (also referred to as mandatory reference field) . The at least one reference information element may further include an optional information element (also referred to as optional reference field) . By configuring the mandatory reference IE and optional reference IE, a same policy may be used for different scenarios. For example, for a scenario with a higher security requirement, both the mandatory reference IE and the optional reference IE may be needed for authorizing the service request. For a scenario with a lower security requirement, the mandatory reference IE may be needed for the service request authorization.
[0115] In some example embodiments, the first apparatus 301 transmits (335) , to the third apparatus 303, a second message indicating to include at least one authorization information element related to a service request for a network function service. The third apparatus 303 may receive (335) the second message. The at least one authorization information element may also be referred to as NF authorization IE.
[0116] Similar to the at least one reference information element, the at least one authorization information element may include at least one of: a type of a network function service consumer associated with the network function service, identity information of PLMN associated with the network function service, identity information of a slice associated with the network function service, identity information of a set of network functions associated with the network function service, identity information of a network function instance associated with the network function service, or a service name of the network function service. In further example embodiments, the at least one authorization information element may include further information element, such as other field in profile of the NF service consumer. For example, region of the NF service consumer or traffic analysis enforcement (TAE) of the NF service consumer may be included in the at least one authorization IE. It is to be understood that the at least one authorization IE may correspond to the at least one reference IE.
[0117] In some example embodiments, the at least one authorization information element may at least include a mandatory authorization information element (also referred to as mandatory authorization field) . The at least one authorization information element may further include an optional authorization information element (also referred to as optional authorization field) . In other words, the third apparatus 303 may be required to send both the mandatory authorization IE and optional authorization IE in the service request.
[0118] The third apparatus 303 may generate (340) the service request for the NF service based on the second message. For example, the third apparatus 303 may include the at least one authorization IE in the service request. In some example embodiments, the third apparatus 303 may generate a CCA token including the at least one authorization information element. The service request may include the CCA token and the identity information of the third apparatus 303. The identity information of the third apparatus 303 may be an ID of the third apparatus 303.
[0119] In some example embodiments, the third apparatus 303 may transmit, to the first apparatus 301, a request for discovery of a network function service producer. In response to receiving the request for discovery of the NF service producer, the first apparatus 301 may transmit the second message to the third apparatus 303. The second message may further include identity information (such as ID) of the network function service producer. In this way, if the third apparatus 303 discovers the NF service producer NF profile, the first apparatus 301 may include the authorization IEs along with the discovery response. In some example embodiments, at least one of the transmission of the request for the discovery or the transmission of the second message is via the SCP. In this way, the service request authorization procedure may be applied to communication model D.
[0120] The third apparatus 303 transmits (345) , to the second apparatus 302, the generated service request. The second apparatus 302 receives (350) the service request. The second apparatus 302 authorizes (355) the service request based on a verification of the identity information of the third apparatus 303 and a verification of the at least one authorization information element based on the at least one policy. The verification of the identity information of the third apparatus 303 may use the mTLS certificate or CCA. Elements of CCA may thus be enhanced to contain the new authorization IEs that are needed for the authorization verification by the second apparatus 302. The second apparatus 302 may decide which of the received authorization IE to verify based on the at least one policy.
[0121] In this way, the service request authorization may be achieved by using the policy configured by the first apparatus 301. In embodiments where the second apparatus 302 authorizing the authorization IE, the second apparatus 302 may be referred to as a “PE” . PE is responsible to verify each consumer request against the list of policies received from the first apparatus 301.
[0122] Taking the at least one policy indicating to allow a first reference service request based on at least a first mandatory reference information element as an example, if the at least one authorization information element excludes a first mandatory authorization information element corresponding to the first mandatory reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element is failed. If a corresponding first mandatory information element in the at least one authorization information element mismatches the first mandatory reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element is failed. If the corresponding first mandatory information element in the at least one authorization information element matches the first mandatory reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element succeeds.
[0123] In some example embodiments, the at least one policy may indicate to allow the first reference service request further based on a second optional information element. If a corresponding second optional information element in the at least one authorization information element mismatches the second optional reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element is failed. If the corresponding first mandatory information element and the second optional information element in the at least one authorization information element match the first mandatory reference information element and the second optional reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element succeeds.
[0124] In some example embodiments, the mandatory and optional IEs may be applied differently for different security requirements. For a higher security requirement, if both the corresponding first mandatory information element and the second optional information element in the at least one authorization information element match the first mandatory reference information element and the second optional reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element succeeds. For a lower security requirement, if the corresponding first mandatory information element matches the first mandatory reference information element and the second optional reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element succeeds without verifying the second optional information element.
[0125] Another example policy may indicate to reject a second reference service request based on a third mandatory reference information element and a fourth optional reference information element. If the at least one authorization information element excludes a third mandatory authorization information element corresponding to the third mandatory reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element is failed. If a corresponding third mandatory information element in the at least one authorization information element matches the third mandatory reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element is failed. If a corresponding fourth optional information element in the at least one authorization information element matches the fourth optional reference information element, the second apparatus 302 may determine that the verification of the at least one authorization information element is failed. Otherwise, the second apparatus 302 may determine that the verification of the at least one authorization information element succeeds.
[0126] In some example embodiments, if the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, the second apparatus 302 may transmit, to the first apparatus 301, a request for the at least one authorization information element. In response to receiving the request, the first apparatus 301 may transmit the profile of the third apparatus 303 such as NF service consumer profile to the second apparatus 302. The profile may include one or more authorization IEs. The second apparatus 302 may verify the authorization IE (s) in the profile of the third apparatus 303 based on the at least one policy. In this way, the authorization of the service request may by achieved based on NF service consumer profile.
[0127] Several example embodiments for verifying the authorization IE against the reference IE in the policy have been described. With these embodiments, the second apparatus 302 may verify the NF authorization IEs provided in the service request against the list of policy locally stored by the second apparatus 302, before granting access to the service.
[0128] In some example embodiments, the second apparatus 302 may transmit, to the first apparatus, a request for registration or update of a network function. The request may include at least one of: profile information of the network function service producer, or a rule for authorizing a service request. The rule for authoring the service request may be an additional authorization option. For example, if a new NF service producer is deployed, the NF service producer may use the registration procedure to register its profile at the first apparatus 301. Such registration procedure may trigger the procedure to create the local policies, e.g., a table of NFType and service similar to Table 1. The generated policies may be transmitted to the second apparatus 302.
[0129] The first apparatus 301 may determine the at least one policy based on the request. For example, internal logic of the first apparatus 301 may allow the first apparatus 301 to generate the policies out of the NF service consumer profile. The first apparatus 302 thus may include the determined at least one policy in the first message and transmit (310) the first message to the second apparatus 302. In this way, the first apparatus 301 may generate the policy based on NF service producer profile.
[0130] In some example embodiments, the first apparatus 301 may transmit, to the second apparatus 302, a third message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy. For example, the sending the policy to the PE may happen at least once when a new network element is deployed, but the system may also support a dynamic update of the policies whenever there is a change in policy.
[0131] Embodiments for service request authorization with the second apparatus 302 being the NF service producer 120 have been described. Alternatively, in some example embodiments, the first apparatus 301 may include the NRF 110 in FIG. 1 or other PI such as OAM. The second apparatus 302 may include the SCP 140 in FIG. 1. The third apparatus 303 may include the NF service consumer 130 in FIG. 1. The fourth apparatus 304 may include the NF service producer 120 in FIG. 1.
[0132] In such indirect communication embodiments, the first apparatus 301 transmits (310) the first message to the second apparatus 302 comprising the SCP. In some example embodiments, if the first apparatus 301 decides to push the policy to SCP on behalf of the NF service producer, the first apparatus 301 may determine the relevant SCP via the NF service producer profile information and push the policy to the SCP via for example registration update response or heartbeat. In such case, the PE may be the SCP on behalf of the NF service producer.
[0133] The second apparatus 302 receives (315) the first message including the at least one policy and may perform at least one of: a verification of the identity information of the third apparatus 303, a verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding (360) the service request to the fourth apparatus 304. In response to receiving (315) the service request from the third apparatus 303 or a further apparatus (not shown) , the second apparatus 302 may forward (360) the service request to the fourth apparatus 304. The service request may include the at least one authorization information element.
[0134] In an option, the second apparatus 302 may verify the identity information of the third apparatus 303. If the identity information of the third apparatus 303 is verified, the second apparatus 302 may forward (360) the service request to the fourth apparatus 304, the service request including the at least one authorization information element. The fourth apparatus 304 may receive (365) the service request. The first apparatus 301 may transmit (320) the first message including the at least one policy to the fourth apparatus 304. The fourth apparatus 304 may receive (325) the first message and store the at least one policy. The fourth apparatus 304 may (370) verify the at least one authorization IE based on the at least one policy. In this way, the verification of the identity information may be performed by the second apparatus 302 and the verification of the at least one authorization IE may be performed by the fourth apparatus 304.
[0135] In another option, the second apparatus 302 may verify the identity information of the third apparatus 303 and verify the at least one authorization IE based on the at least one policy. If the identity information of the third apparatus 303 and the at least one authorization information element are verified, the second apparatus 302 may transmit, to the fourth apparatus 304, the service request and an indication of a completion of an authorization of the service request. In such case, the at least one authorization information element may be excluded from the service request. In this way, the verification of the identity information and the verification of the at least one authorization IE may be performed by the second apparatus 302.
[0136] In a further option, the second apparatus 302 may forward (360) the service request to the fourth apparatus 304. The fourth apparatus 304 may verify the identity information of the third apparatus 303 and verify the at least one authorization IE based on the at least one policy. In this way, the verification of the identity information and the verification of the at least one authorization IE may be performed by the fourth apparatus 304.
[0137] In some example embodiments, the first message or an indication from the first apparatus 301 may indicate which of the above options may be applied. For example, the first message or the indication may indicate the second apparatus 302 to perform at least one of: the verification of identity information of the third apparatus 303, the verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus 304.
[0138] In addition, or alternatively, the first apparatus 301 may transmit, to the fourth apparatus 304, an indication that at least one of the following is performed by the second apparatus 302: a verification of identity information of the third apparatus 304, a verification of at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus 304.
[0139] In some example embodiments, if the service request received by the fourth apparatus 304 includes at least one authorization information element, the fourth apparatus 304 may perform at least a verification of the at least one authorization information element based on the at least one policy.
[0140] If the service request includes the at least one authorization information element and identity information of the third apparatus 303, the fourth apparatus 304 may authorize the service request based on the verification of the identity information of the third apparatus 303 and the verification of the at least one authorization information element based on the at least one policy.
[0141] If the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, the fourth apparatus 304 may transmit, to the first apparatus 301, a request for the at least one authorization information element.
[0142] In some example embodiments, if an indication from the second apparatus 302 or the service request indicates a completion of an authorization of the service request, the four apparatus 304 may transmit a response of the service request to the third apparatus 303 without verifying the at least one authorization information element or identity information of the third apparatus 303.
[0143] In the indirect communication embodiments with the second apparatus 302 including the SCP 140, the first apparatus 301 may receive, from the fourth apparatus 304 including the network function service producer, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request. The first apparatus 301 may determine the at least one policy and the service communication proxy associated with the network function service producer based on the request.
[0144] In some example embodiments, the first apparatus 301 may transmit, to the fourth apparatus 304, a message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy. In this way, the policy at the fourth apparatus 304 may be updated.
[0145] Several embodiments for service request authorization for indirect communication cases have been described. With these different options for service request authorization, the authorization procedure may be decentralized. For example, the verification of identity information of the third apparatus 303 and the verification of the authorization IE may be performed by different network entities. By using the PI such as the NRF 110 or OAM, the requester such as the NF service consumer 130 and the PE such as the NF service producer 120 or the SCP 140, the authorization procedures may be decentralized by splitting up the responsibility and actions performed by these different network entities.
[0146] The NRF, which already possess the logic to authorize the NF service consumer, may be reused to generate and distribute the policies to the corresponding entity. This entity may be the actual producer or proxy producer that handles the authorization on behalf of producer. This will allow the single element (e.g, NF service producer or proxy NF such as the SCP) to verify the request against the local policies and decide on whether or not accept (or authorize) the request. The PE or the authorization enforcement points may depend on the communication model. For example, for the direct communication model, the PE may be the NF service producer. For indirect communication model, the PE may be the SCP and / or the NF service producer. Therefore, it will allow to maintain similar security level and performances across all possible implementations. These embodiments may be befinet for reduction of signaling overhead and consumption of processing resources in transmitting and validating OAuth 2.0 access tokens for each SBA service request between NF service consumer and NF service producer as currently specified for the third generation partnership project (3GPP) SBA in 5G, without a need for pre-configuring a static authorization policy at the NF service producer and NRF.
[0147] Further embodiments regarding the service request authorization will be described with respect to FIG. 4 and FIG. 7. FIG. 4 illustrates another signaling flow 400 for service request authorization in accordance with some embodiments of the present disclosure. The signaling flow 400 involves the NRF 110, the NF service producer 120, and the NF service consumer 130.
[0148] The NF service producer 120 may register or update at the NRF 110 as defined in current standard of 3GPP. For example, the NF service producer 120 may transmit (410) NF_registration / Update request () to the NRF 110.
[0149] The NRF 110, upon successful registration / update, will generate the access policy in such a way that the service request from the NF service consumer 130 may be authorized based on the information present in the certificate of the NF service consumer 130. That is, if the desired information is not available in the NF service consumer 130’ certificate, the policy will rely on a more selective identifier, e.g. the most selective identifier is the NF Instance ID. After this, the NRF 110 sends (415) back the list of policy that NF service producer 120 has to enforce. For example, the NRF 110 transmit the NF_Registration / Update message with policies or authorization configuration to the NF service producer 120.
[0150] After receiving the policies, the NF service producer 120 will store (420) them locally, to be able to access them during a service request.
[0151] NF service consumer 130 may send (425) a NF discovery request as defined in a standard such as the specification 23.501.
[0152] When the NRF 110 receive the request, the NRF 110 will send (430) back the NF service producer 120 information along with the list of information (NF Authorization IEs) that NF service consumer 130 will need to insert in the service request in order to be authorized from the policy. For example, if NF service consumer 130 request Service_B NRF will send back as set_paramenters:
[0153] Service B {
[0154] NF Type (optional)
[0155] NF Instance ID (mandatory)
[0156] }.
[0157] When the CCA Authentication is used, NF service consumer 130 will dynamical create (435) a CCA with the information listed in the NF Authorization IEs. Therefore, in the case the NF Authorization IE (s) are not present in the existing elements of CCA as defined in a standard such as technical specification (TS) 33.501, Clause 13.3.8, the CCA will be enhanced to contain the new IEs that are needed for the authorization verification by the NF service producer 120.
[0158] The NF service consumer 130 sends (440) the NF_Service Request to NF service producer 120, by including only the required IE with values as indicated by the NF Authorization IEs.
[0159] The NF service producer 120 will verify (450) the NF Authorization IEs provided by the NF service consumer 130 in the Service Request against the authentication method, i.e., either mTLS certificate or CCA. After the authentication, the NF service producer 120 will verify the NF Authorization IEs provided in the service request against the list of policy locally store, before granting access to the service. If the authorization is completed, the NF service producer 120 may send (465) back a response to the received service request.
[0160] In some example embodiments, if the at least one authorization IE is not present in the service request or the verification of the at least one authorization IE is failed, the NF service producer 120 may transmit (455) a request for profile of the NF service consumer to the NRF 110. In response to the request, the NRF 110 may transmit (460) the profile of the NF service consumer 130 to the NF service producer 120. The NF service producer 120 may verify the at least one authorization IE in the profile based on the at least one policy. If the authorization is completed, the NF service producer 120 may send (465) back a response to the received service request.
[0161] FIG. 5 illustrates a signaling flow 500 for authorization policy updating in accordance with some embodiments of the present disclosure. The signaling flow 500 involves the NRF 110 and the NF service producer 120.
[0162] After the initial registration, the NRF 110 may modify the policy stored inside the NF service producer 120 by sending (510) a policy create / update / remove message to the interested NF service producer 120. The NF service producer 120 will then perform the corresponding instruction of either: adding the new policy to the local policy list; modifying an existing policy; and / or deleting an existing policy from the local list. The NF service producer 120 may store (520) the updated policy (ies) . In this way, the service authorization policies may be dynamically updated.
[0163] FIG. 6 illustrates another signaling flow 600 for service request authorization in accordance with some embodiments of the present disclosure. The signaling flow 600 involves the NRF 110, the NF service producer 120, the NF service consumer 130 and the SCP 140. The signaling flow 600 shows an indirect communication approach for the service request authorization, which differs from the signaling flow 400 in the presence of the SCP 140 between the NRF 110 and the NF service producer 120.
[0164] The NF service producer 120 may delegate some of its responsibilities to the SCP 140 by different options which will be described with respect to FIG. 6 and FIG. 7. The authorization procedure may be split into two independent sections, i. e., the verification of the NF Identity information and the comparison of the request details against the local policy. In the indirect communication model, both aspects may be carried out by the SCP 140 and / or the NF service producer 120.
[0165] One main feature of this solution is to communicate to the NF service producer120 which operations were already performed by the SCP 140 and therefore are not required anymore.
[0166] In a first variant (referred to as Variant 1) , policies are directly used to communicate to the NF the chosen solution. For example, when the SCP 140 only verify the identity, the NRF 110 may create a policy where all the NF service consumer 130 information, such as NF Type, is preceded by “SCP / ” so that a possible policy may look like “SCP / AMF Allow Service_A” .
[0167] In another variant (referred to as Variant 2) , explicit codes such as Authorization_Configuration may be used to communicate (615) to the NF service producer 120 indicating which tasks are performed by the SCP 140 on behalf of the NF service producer 120. As an example, a value 0 may indicate that the SCP 140 act as a transparent proxy, while a value of 1 indicates that the SCP 140 is performing the identity verification. It is to be understood that the example values and the meanings of the values are only for the purpose of illustration, without suggesting any limitation.
[0168] The NF service producer 120 may register (610) at the NRF 110 as defined in current standard of 3GPP. If a more fine-grained access control needs to be enforced, the NF service producer 120 may also send additional authorization options.
[0169] The NRF 110, upon successful registration, will generate the access policy in such a way that the request may be based on the information present in the certificate. That is, if the desired information is not available in the NF service consumer 130’ certificate, the policy will rely on a more selective identifier, in the worst case the NF Instance ID may be used. After this, NRF 110 sends (620) back the list of policy that NF service producer 120 has to enforce. For Variant 2, NRF 110 may also send (620) back the Authorization_Configuration, i. e., the code that identifies which authorization procedure is carried out by the SCP 140. If SCP 140 is responsible to carry out some verification, NRF 110 will send (620) the corresponding policy to SCP 140, which will store (625) them locally.
[0170] The NRF 110 transmits (615) the policies to the NF service producer 120. After receiving the policies, the NF service producer 120 will store (630) them locally, to be able to access them during a service request.
[0171] The NF service consumer 130 sends (632) a discovery request to NRF 110 as defined in 23.501. When NRF 110 receive the request, NRF 110 will send (635) back the NF service producer 120 information along with the list of information (NF Authorization IEs) that the NF service consumer 130 will need to insert in the service request in order to be authorized from the policy. For example, if the NF service consumer 130 requests Service_B, NRF 110 will send back as set_paramenters:
[0172] Service B {
[0173] NF Type (Optional)
[0174] NF Instance ID (mandatory)
[0175] }.
[0176] When CCA Authentication is used, NF service consumer 130 may optionally dynamical create (640) a CCA with the information listed in the NF Authorization IEs. Therefore, in the case the NF Authorization IE (s) are not present in the existing elements of CCA as defined in TS 33.501, Clause 13.3.8, the CCA will be enhanced to contain the new IEs that are needed for the authorization verification by the NF service producer 120.
[0177] The NF service consumer 130 sends (645) the NF_Service Request to the SCP 140 and includes only the required profile information as indicated by the NF Authorization IEs.
[0178] In an option 650 (referred to as Option A) , the SCP 140 receives the service requests and verifies (655) that the identity information in the request is correct, by comparing it with the authentication mechanism. The SCP forwards (660) the request to the corresponding NF service producer 120, with the additional parameters included by the NF service consumer 130. The NF service producer 120, which is aware of the checks performed from the SCP 140, only verifies (665) that the NF service consumer 130 requesting the service is authorized to do so. In some example embodiments, the verification from the NF service producer 120 will rely on the CCA.
[0179] In some example embodiments, if a plurality of SCPs and mTLS are in place, the first one may verify the identity of the NF service consumer 130, while intermediate one may only verify the identity of the previous SCP.
[0180] In another option 670 (referred to as Option B) , the SCP 140 receives the service requests and verifies (675) that the identity information is correct. After a successful verification, the SCP will also verify (675) that the NF service consumer 130 is allowed to request the specific service from the NF service producer 120. The SCP forwards (680) the request to the corresponding NF service producer 120. Once SCP 140 authorizes the NF service consumer 130, the SCP forwards the request to the NF service producer 120 indicating that authorization is done so that NF service producer 120 should not apply authorization policy again.
[0181] NF service producer 120, after a successful authorization, responds (685) to the service Request.
[0182] It is to be understood that a similar flow may be applied to the communication model D. That might change the order of some messages and the involved parties. For example, the NF_Discovery request would be performed from the SCP which is requesting it on behalf of the NF service consumer 130 and it would happen after the NF service consumer 130 sending the service request.
[0183] FIG. 7 illustrates another signaling flow 700 for service request authorization in accordance with some embodiments of the present disclosure. The signaling flow 700 involves the NRF 110, the NF service producer 120, the NF service consumer 130 and the SCP 140. The signaling flow 600 shows another option for the indirect communication approach for the service request authorization, which is similar to the signaling flow 600.
[0184] The NF service producer 120 may register (610) at the NRF 110 as defined in current standard of 3GPP. If a more fine-grained access control needs to be enforced, the NF service producer 120 may also send additional authorization options.
[0185] The NRF 110, upon successful registration, will generate the access policy in such a way that the request may be based on the information present in the certificate. That is, if the desired information is not available in the NF service consumer 130’ certificate, the policy will rely on a more selective identifier, in the worst case the NF Instance ID may be used. The NRF 110 transmits (615) the policies to the NF service producer 120. After receiving the policies, the NF service producer 120 will store (630) them locally, to be able to access them during a service request.
[0186] The NF service consumer 130 may send (632) a discovery request to NRF 110 as defined in 23.501. When NRF 110 receive the request, NRF 110 will send (635) back the NF service producer 120 information along with the list of information (NF Authorization IEs) that the NF service consumer 130 will need to insert in the service request in order to be authorized from the policy. For example, if the NF service consumer 130 requests Service_B, NRF 110 will send back as set_paramenters:
[0187] Service B {
[0188] NF Type (Optional)
[0189] NF Instance ID (mandatory)
[0190] }.
[0191] When CCA Authentication is used, NF service consumer 130 may optionally dynamical create (640) a CCA with the information listed in the NF Authorization IEs. Therefore, in the case the NF Authorization IE (s) are not present in the existing elements of CCA as defined in TS 33.501, Clause 13.3.8, the CCA will be enhanced to contain the new IEs that are needed for the authorization verification by the NF service producer 120.
[0192] The NF service consumer 130 sends (645) the NF_Service Request to the SCP 140 and includes only the required profile information as indicated by the NF Authorization IEs.
[0193] In the option in the signaling flow 700 (referred to as Option C) , the SCP 140 forwards (710) the service request to the corresponding NF service producer 120, as received by the NF service consumer 130, i. e., with the required NF profile information. That is, the SCP 140 performs as a transparent proxy.
[0194] The NF service producer 120 will verify (720) the NF Authorization IEs provided by the NF service consumer 130 in the service request against the CCA. After the authentication, the NF service producer 120 will verify (720) the NF Authorization IEs provided in the service request against the list of policy locally store, before granting access to the service.
[0195] In some example embodiments, in the case the authorization IE (s) of NF service consumer 130 received by the NF service producer 120 is not sufficient or not received at all, the NF service producer 120 then sends (740) a request to NRF 110 to retrieve the same. The NRF 110 may respond (750) the requested profile of the NF service consumer 130 to the NF service producer 120.
[0196] NF service producer 120, after a successful authorization, may respond (760) to the service Request.
[0197] It is to be understood that a similar flow may be applied to the communication model D. That might change the order of some messages and the involved parties. For example, the NF_Discovery request would be performed from the SCP which is requesting it on behalf of the NF service consumer 130 and it would happen after the NF service consumer 130 sending the service request.
[0198] Several embodiments regarding the service request authorization for both direct communication and indirect communication have been described. With these embodiments, the authorization procedures may be decentralized by splitting up the responsibility and action performed by the different network entities. These dynamic policies-based authorization may be beneficial for reduction of signaling overhead and consumption of processing resources in transmitting and validating OAuth 2.0 access tokens for each SBA service request between NFc and NFp as currently specified for 3GPP SBA in 5G, without a need for pre-configuring a static authorization policy at NFp and NRF.
[0199] FIG. 8 shows a flowchart of an example method 800 implemented at a first apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 800 will be described from the perspective of the first apparatus 301 in FIG. 3.
[0200] At block 810, the first apparatus 301 transmits, to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.
[0201] In some example embodiments, the method 800 further comprises: transmitting, to a third apparatus, a second message indicating to include at least one authorization information element related to a service request for a network function service. In this way, the third apparatus may be informed about which authorization information element needs to be included in the service request.
[0202] In some example embodiments, the at least one authorization information element comprises at least one of: a type of a network function service consumer associated with the network function service, identity information of public land mobile network associated with the network function service, identity information of a slice associated with the network function service, identity information of a set of network functions associated with the network function service, identity information of a network function instance associated with the network function service, or a service name of the network function service. Thus, different information may be used as the authorization information element for authorizing the related service request.
[0203] In some example embodiments, at least one of the at least one reference information element or the at least one authorization information element at least comprises a mandatory information element.
[0204] In some example embodiments, at least one of the at least one reference information element or the at least one authorization information element further comprises an optional information element.
[0205] By configuring mandatory information element and the optional information element, flexible service request authorization can be achieved. These mandatory and optional information elements may be used for different security requirements.
[0206] In some example embodiments, the at least one reference information element comprises at least one of: a type of a network function service consumer associated with the reference service request, identity information of public land mobile network associated with the reference service request, identity information of a slice associated with the reference service request, identity information of a set of network functions associated with the reference service request, identity information of a network function instance associated with the reference service request, or a service name of the reference service request, and wherein the at least one policy comprises a decision flag to allow or reject the reference service request. These various reference information elements may enable dynamic and flexible service request authorization policies.
[0207] In some example embodiments, the method 800 further comprises: transmitting, to the second apparatus, a third message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy. In this way, the service request authorization policy (ies) can be dynamically updated.
[0208] In some example embodiments, the method 800 further comprises: receiving, from the second apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request; determining the at least one policy based on the request; and transmitting the first message to the second apparatus. In this manner, the service request authorization policy may be determined based on network function service producer profile information and / or additional rule for authorizing the service request.
[0209] In some example embodiments, the method 800 further comprises: receiving, from a fourth apparatus comprising a network function service producer, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request; determining the at least one policy and the service communication proxy associated with the network function service producer based on the request; and transmitting the first message to the second apparatus. In this manner, the service request authorization policy may be determined based on profile information of the network function service producer and / or additional rule for authorizing the service request.
[0210] In some example embodiments, the method 800 further comprises: transmitting a fourth message including the at least one policy to the fourth apparatus. Thus, the at least one policy may be distributed to further apparatus (es) .
[0211] In some example embodiments, the first message further indicates the second apparatus to perform at least one of: a verification of identity information of the third apparatus, a verification of at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus. In this manner, the first apparatus may configure the second apparatus to perform different operations for authorizing the service request.
[0212] In some example embodiments, the method 800 further comprises: transmitting, to at least one of the second apparatus or a fourth apparatus, an indication that at least one of the following is performed by the service communication proxy: a verification of identity information of the third apparatus, a verification of at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus. In this manner, the second apparatus or the fourth apparatus such as an apparatus comprising the network function service producer, may be informed about that the verification of the identity of the third apparatus and / or the verification of the at least one authorization information element has been completed by the service communication proxy.
[0213] FIG. 9 shows a flowchart of an example method 900 implemented at a second apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 900 will be described from the perspective of the second apparatus 302 in FIG. 3.
[0214] At block 910, the second apparatus 302 receives, from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request.
[0215] At block 920, the second apparatus 302 receives a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element.
[0216] At block 930, the second apparatus 302 performs at least one of: a verification of the identity information of the third apparatus, a verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to a fourth apparatus.
[0217] In some example embodiments, the method 900 further comprises: receiving, from the first apparatus, a message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy. In this way, the service request authorization policy (ies) can be dynamically updated.
[0218] In some example embodiments, the method 900 further comprises: in response to receiving the service request from the third apparatus or a further apparatus, forwarding the service request to the fourth apparatus, the service request including the at least one authorization information element. In this way, the second apparatus may perform as a service communication proxy to forward the service request.
[0219] In some example embodiments, the method 900 further comprises: in response to the identity information of the third apparatus being verified, forwarding the service request to the fourth apparatus, the service request including the at least one authorization information element. In this way, the verification of the identity information of the third apparatus may be performed by the second apparatus. The second apparatus may further inform about the verification to the fourth apparatus.
[0220] In some example embodiments, the method 900 further comprises: in response to the identity information of the third apparatus and the at least one authorization information element being verified, transmitting to the fourth apparatus, the service request and an indication of a completion of an authorization of the service request, wherein the at least one authorization information element is excluded from the service request. In this way, both the verification of the identity information of the third apparatus and the verification of the at least one authorization information element may be performed by the second apparatus. The second apparatus may further inform about the verifications to the fourth apparatus.
[0221] In some example embodiments, the second apparatus comprises a service communication proxy, and the first message or an indication from the first apparatus indicates the second apparatus to perform at least one of: the verification of identity information of the third apparatus, the verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to the fourth apparatus. In this manner, the first apparatus may configure the second apparatus to perform different operations for authorizing the service request.
[0222] In some example embodiments, the method 900 further comprises: authorizing the service request based on a verification of the identity information of the third apparatus and a verification of the at least one authorization information element based on the at least one policy. In this way, the second apparatus can authorize the service request.
[0223] In some example embodiments, the method 900 further comprises: transmitting, to the first apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request. In this way, the first apparatus may obtain the profile information of the network function service producer, and / or additional rule for authorizing the service request.
[0224] In some example embodiments, the service request comprises a client credentials assertion token including the at least one authorization information element. In this way, the CCA token may be used for the service request authorization. The authorization procedure can thus be enhanced.
[0225] In some example embodiments, the at least one policy indicates to allow a first reference service request based on at least a first mandatory reference information element, and the verification of the at least one authorization information element is failed based on at least one of: the at least one authorization information element excluding a first mandatory authorization information element corresponding to the first mandatory reference information element, or a corresponding first mandatory information element in the at least one authorization information element mismatching the first mandatory reference information element. In this way, the verification of the authorization information element can be enabled based on the policy.
[0226] In some example embodiments, the at least one policy indicates to allow the first reference service request further based on a second optional information element, and the verification of the at least one authorization information element is failed further based on:a corresponding second optional information element in the at least one authorization information element mismatching the second optional reference information element. In this way, the verification of the authorization information element can be enabled based on the policy.
[0227] In some example embodiments, the at least one policy indicates to reject a second reference service request based on a third mandatory reference information element and a fourth optional reference information element, and the verification of the at least one authorization information element is failed based on at least one of: the at least one authorization information element excluding a third mandatory authorization information element corresponding to the third mandatory reference information element, a corresponding third mandatory information element in the at least one authorization information element matching the third mandatory reference information element, or a corresponding fourth optional information element in the at least one authorization information element matching the fourth optional reference information element. In this way, the verification of the authorization information element can be enabled based on the policy.
[0228] In some example embodiments, the method 900 further comprises: in accordance with a determination that the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, transmitting to the first apparatus, a request for the at least one authorization information element. In this manner, if the authorization information element is not received or if the verification of the authorization information element is failed, the second apparatus may request the first apparatus for the at least one authorization information element.
[0229] FIG. 10 shows a flowchart of an example method 1000 implemented at a third apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1000 will be described from the perspective of the third apparatus 303 in FIG. 3.
[0230] At block 1010, the third apparatus 303 receives, from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service.
[0231] At block 1020, the third apparatus 303 generates a client credentials assertion token based on the at least one authorization information element.
[0232] At block 1030, the third apparatus 303 transmits, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.
[0233] In some example embodiments, the at least one authorization information element comprises at least one of: a type of a network function service consumer associated with the network function service, identity information of public land mobile network associated with the network function service, identity information of a slice associated with the network function service, identity information of a set of network functions associated with the network function service, identity information of a network function instance associated with the network function service, a service name of the network function service. Thus, different information may be used as the authorization information element for authorizing the related service request.
[0234] In some example embodiments, the at least one authorization information element at least comprises a mandatory information element.
[0235] In some example embodiments, the at least one authorization information element further comprises an optional information element.
[0236] By configuring mandatory information element and the optional information element, flexible service request authorization can be achieved. These mandatory and optional information elements may be used for different security requirements.
[0237] In some example embodiments, the method 1000 further comprises: transmitting, to the first apparatus, a request for discovery of a network function service producer; and receiving the message from the first apparatus, the message further including identity information of the network function service producer. In this way, the third apparatus may obtain the identity information of the network function service producer.
[0238] In some example embodiments, at least one of the transmission of the request or the reception of the message is via a service communication proxy. In this way, the service communication proxy may be used for message transmission between the first and third apparatuses.
[0239] FIG. 11 shows a flowchart of an example method 1100 implemented at a fourth apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1100 will be described from the perspective of the fourth apparatus 304 in FIG. 3.
[0240] At block 1110, the fourth apparatus 304 receives, from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.
[0241] At block 1120, the fourth apparatus 304 receives, from a second apparatus, a service request for a network function service.
[0242] At block 1130, in accordance with a determination that the service request includes at least one authorization information element, the fourth apparatus 304 performs at least a verification of the at least one authorization information element based on the at least one policy.
[0243] In some example embodiments, the method 1100 further comprises: in accordance with a determination that the service request includes the at least one authorization information element and identity information of a third apparatus, authorizing the service request based on a verification of the identity information of the third apparatus and the verification of the at least one authorization information element based on the at least one policy. In this way, the fourth apparatus may authorize the service request by verifying the identity information of the third apparatus and verifying the at least one authorization information element based on the at least one policy.
[0244] In some example embodiments, the method 1100 further comprises: in accordance with a determination that the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, transmitting to the first apparatus, a request for the at least one authorization information element. In this manner, if the authorization information element is not received or if the verification of the authorization information element is failed, the fourth apparatus may request the first apparatus for the at least one authorization information element.
[0245] In some example embodiments, the method 1100 further comprises: in response to an indication from the second apparatus or the service request indicating a completion of an authorization of the service request, transmitting a response of the service request to the third apparatus without verifying the at least one authorization information element or identity information of the third apparatus. In this way, the authorization of the service request may be performed by the second apparatus. The completion of the authorization of the service request may be informed to the fourth apparatus.
[0246] In some example embodiments, the method 1100 further comprises: receiving, from the first apparatus, a message for at least one of: adding a further policy to the at least one policy, modifying the at least one policy, or removing a policy from the at least one policy. In this way, the service request authorization policy (ies) stored by the fourth apparatus can be dynamically updated.
[0247] In some example embodiments, the method 1100 further comprises: transmitting, to the first apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the fourth apparatus, or a rule for authorizing a service request. In this manner, the service request authorization policy may be determined based on profile information of the fourth apparatus and / or additional rule for authorizing the service request.
[0248] In some example embodiments, the service request comprises a client credentials assertion token including the at least one authorization information element. In this way, the CCA token may be used for the service request authorization. The authorization procedure can thus be enhanced.
[0249] In some example embodiments, a first apparatus capable of performing any of the method 800 (for example, the first apparatus 301 in FIG. 3) may comprise means for performing the respective operations of the method 800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The first apparatus may be implemented as or included in the first apparatus 301 in FIG. 3.
[0250] In some example embodiments, the first apparatus comprises means for transmitting, to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.
[0251] In some example embodiments, a second apparatus capable of performing any of the method 900 (for example, the second apparatus 302 in FIG. 3) may comprise means for performing the respective operations of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The second apparatus may be implemented as or included in the second apparatus 302 in FIG. 3.
[0252] In some example embodiments, the second apparatus comprises means for receiving, from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request; means for receiving a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; and means for performing at least one of: a verification of the identity information of the third apparatus, a verification of the at least one authorization information element in the service request based on the at least one policy, or forwarding the service request to a fourth apparatus.
[0253] In some example embodiments, a third apparatus capable of performing any of the method 1000 (for example, the third apparatus 303 in FIG. 3) may comprise means for performing the respective operations of the method 1000. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The third apparatus may be implemented as or included in the third apparatus 303 in FIG. 3.
[0254] In some example embodiments, the third apparatus comprises means for receiving, from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service; means for generating a client credentials assertion token based on the at least one authorization information element; and means for transmitting, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.
[0255] In some example embodiments, a fourth apparatus capable of performing any of the method 1100 (for example, the fourth apparatus 304 in FIG. 3) may comprise means for performing the respective operations of the method 1100. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The fourth apparatus may be implemented as or included in the fourth apparatus 304 in FIG. 3.
[0256] In some example embodiments, the fourth apparatus comprises means for receiving, from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element; means for receiving, from a second apparatus, a service request for a network function service; and means for in accordance with a determination that the service request includes at least one authorization information element, performing at least a verification of the at least one authorization information element based on the at least one policy.
[0257] FIG. 12 is a simplified block diagram of a device 1200 that is suitable for implementing example embodiments of the present disclosure. The device 1200 may be provided to implement a communication device, for example, the first apparatus 301, the second apparatus 302, the third apparatus 303 and the fourth apparatus 304 in FIG. 3. As shown, the device 1200 includes one or more processors 1210, one or more memories 1220 coupled to the processor 1210, and one or more communication modules 1240 coupled to the processor 1210.
[0258] The communication module 1240 is for bidirectional communications. The communication module 1240 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 1240 may include at least one antenna.
[0259] The processor 1210 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1200 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0260] The memory 1220 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1224, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 1222 and other volatile memories that will not last in the power-down duration.
[0261] A computer program 1230 includes computer executable instructions that are executed by the associated processor 1210. The instructions of the program 1230 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 1230 may be stored in the memory, e.g., the ROM 1224. The processor 1210 may perform any suitable actions and processing by loading the program 1230 into the RAM 1222.
[0262] The example embodiments of the present disclosure may be implemented by means of the program 1230 so that the device 1200 may perform any process of the disclosure as discussed with reference to FIG. 3 to FIG. 11. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
[0263] In some example embodiments, the program 1230 may be tangibly contained in a computer readable medium which may be included in the device 1200 (such as in the memory 1220) or other storage devices that are accessible by the device 1200. The device 1200 may load the program 1230 from the computer readable medium to the RAM 1222 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i. e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .
[0264] FIG. 13 shows an example of the computer readable medium 1300 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1300 has the program 1230 stored thereon.
[0265] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0266] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non-transitory computer readable medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0267] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0268] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0269] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0270] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0271] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1.A first apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to:transmit, to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.2.The first apparatus of claim 1, wherein the first apparatus is further caused to:transmit, to a third apparatus, a second message indicating to include at least one authorization information element related to a service request for a network function service.3.The first apparatus of claim 2, wherein the at least one authorization information element comprises at least one of:a type of a network function service consumer associated with the network function service,identity information of public land mobile network (PLMN) associated with the network function service,identity information of a slice associated with the network function service,identity information of a set of network functions associated with the network function service,identity information of a network function instance associated with the network function service, ora service name of the network function service.4.The first apparatus of claim 2 or 3, wherein at least one of the at least one reference information element or the at least one authorization information element at least comprises a mandatory information element.5.The first apparatus of claim 4, wherein at least one of the at least one reference information element or the at least one authorization information element further comprises an optional information element.6.The first apparatus of any of claims 1-5, wherein the at least one reference information element comprises at least one of:a type of a network function service consumer associated with the reference service request,identity information of public land mobile network (PLMN) associated with the reference service request,identity information of a slice associated with the reference service request,identity information of a set of network functions associated with the reference service request,identity information of a network function instance associated with the reference service request, ora service name of the reference service request, andwherein the at least one policy comprises a decision flag to allow or reject the reference service request.7.The first apparatus of any of claims 1-6, wherein the first apparatus is further caused to:transmit, to the second apparatus, a third message for at least one of:adding a further policy to the at least one policy,modifying the at least one policy, orremoving a policy from the at least one policy.8.The first apparatus of any of claims 1-7, wherein the second apparatus comprises a network function service producer, and the first apparatus is caused to:receive, from the second apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request;determine the at least one policy based on the request; andtransmit the first message to the second apparatus.9.The first apparatus of any of claims 1-7, wherein the second apparatus comprises a service communication proxy, and the first apparatus is caused to:receive, from a fourth apparatus comprising a network function service producer, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request;determine the at least one policy and the service communication proxy associated with the network function service producer based on the request; andtransmit the first message to the second apparatus.10.The first apparatus of claim 9, wherein the first apparatus is further caused to:transmit a fourth message including the at least one policy to the fourth apparatus.11.The first apparatus of claim 9 or 10, wherein the first message further indicates the second apparatus to perform at least one of:a verification of identity information of the third apparatus,a verification of at least one authorization information element in the service request based on the at least one policy, orforwarding the service request to the fourth apparatus.12.The first apparatus of any of claims 9-11, wherein the first apparatus is further caused to:transmit, to at least one of the second apparatus or a fourth apparatus, an indication that at least one of the following is performed by the service communication proxy:a verification of identity information of the third apparatus,a verification of at least one authorization information element in the service request based on the at least one policy, orforwarding the service request to the fourth apparatus.13.A second apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to:receive, from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request;receive a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; andperform at least one of:a verification of the identity information of the third apparatus,a verification of the at least one authorization information element in the service request based on the at least one policy, orforwarding the service request to a fourth apparatus.14.The second apparatus of claim 13, wherein the second apparatus is further caused to:receive, from the first apparatus, a message for at least one of:adding a further policy to the at least one policy,modifying the at least one policy, orremoving a policy from the at least one policy.15.The second apparatus of claim 13 or 14, wherein the second apparatus comprises a service communication proxy, and the second apparatus is caused to:in response to receiving the service request from the third apparatus or a further apparatus, forward the service request to the fourth apparatus, the service request including the at least one authorization information element.16.The second apparatus of claim 15, wherein the second apparatus is further caused to:in response to the identity information of the third apparatus being verified, forward the service request to the fourth apparatus, the service request including the at least one authorization information element.17.The second apparatus of claim 13 or 14, wherein the second apparatus comprises a service communication proxy, and the second apparatus is caused to:in response to the identity information of the third apparatus and the at least one authorization information element being verified, transmit, to the fourth apparatus, the service request and an indication of a completion of an authorization of the service request, wherein the at least one authorization information element is excluded from the service request.18.The second apparatus of any of claims 13-17, wherein the second apparatus comprises a service communication proxy, and the first message or an indication from the first apparatus indicates the second apparatus to perform at least one of:the verification of identity information of the third apparatus,the verification of the at least one authorization information element in the service request based on the at least one policy, orforwarding the service request to the fourth apparatus.19.The second apparatus of claim 13 or 14, wherein the second apparatus comprises a network function service producer, and the second apparatus is caused to:authorize the service request based on a verification of the identity information of the third apparatus and a verification of the at least one authorization information element based on the at least one policy.20.The second apparatus of claim 13 or 14, wherein the second apparatus comprises a network function service producer, and the second apparatus is caused to:transmit, to the first apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the network function service producer, or a rule for authorizing a service request.21.The second apparatus of any of claims 13-20, wherein the service request comprises a client credentials assertion token including the at least one authorization information element.22.The second apparatus of any of claims 13-21, wherein the at least one policy indicates to allow a first reference service request based on at least a first mandatory reference information element, and the verification of the at least one authorization information element is failed based on at least one of:the at least one authorization information element excluding a first mandatory authorization information element corresponding to the first mandatory reference information element, ora corresponding first mandatory information element in the at least one authorization information element mismatching the first mandatory reference information element.23.The second apparatus of claim 22, wherein the at least one policy indicates to allow the first reference service request further based on a second optional information element, and the verification of the at least one authorization information element is failed further based on:a corresponding second optional information element in the at least one authorization information element mismatching the second optional reference information element.24.The second apparatus of any of claims 13-23, wherein the at least one policy indicates to reject a second reference service request based on a third mandatory reference information element and a fourth optional reference information element, and the verification of the at least one authorization information element is failed based on at least one of:the at least one authorization information element excluding a third mandatory authorization information element corresponding to the third mandatory reference information element,a corresponding third mandatory information element in the at least one authorization information element matching the third mandatory reference information element, ora corresponding fourth optional information element in the at least one authorization information element matching the fourth optional reference information element.25.The second apparatus of any of claims 13-24, wherein the second apparatus is further caused to:in accordance with a determination that the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, transmit, to the first apparatus, a request for the at least one authorization information element.26.A third apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the third apparatus at least to:receive, from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service;generate a client credentials assertion token based on the at least one authorization information element; andtransmit, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.27.The third apparatus of claim 26, wherein the at least one authorization information element comprises at least one of:a type of a network function service consumer associated with the network function service,identity information of public land mobile network (PLMN) associated with the network function service,identity information of a slice associated with the network function service,identity information of a set of network functions associated with the network function service,identity information of a network function instance associated with the network function service,a service name of the network function service.28.The third apparatus of claim 26 or 27, wherein the at least one authorization information element at least comprises a mandatory information element.29.The third apparatus of claim 28, wherein the at least one authorization information element further comprises an optional information element.30.The third apparatus of any of claims 26-29, wherein the third apparatus is caused to:transmit, to the first apparatus, a request for discovery of a network function service producer; andreceive the message from the first apparatus, the message further including identity information of the network function service producer.31.The third apparatus of claim 30, wherein at least one of the transmission of the request or the reception of the message is via a service communication proxy.32.A fourth apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the fourth apparatus at least to:receive, from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element;receive, from a second apparatus, a service request for a network function service; andin accordance with a determination that the service request includes at least one authorization information element, perform at least a verification of the at least one authorization information element based on the at least one policy.33.The fourth apparatus of claim 32, wherein the fourth apparatus is further caused to:in accordance with a determination that the service request includes the at least one authorization information element and identity information of a third apparatus, authorize the service request based on a verification of the identity information of the third apparatus and the verification of the at least one authorization information element based on the at least one policy.34.The fourth apparatus of claim 32 or 33, wherein the fourth apparatus is further caused to:in accordance with a determination that the received service request excludes the at least one authorization information element or the verification of the at least one authorization information element is failed based on the at least one policy, transmit, to the first apparatus, a request for the at least one authorization information element.35.The fourth apparatus of any of claims 32-34, wherein the fourth apparatus further is caused to:in response to an indication from the second apparatus or the service request indicating a completion of an authorization of the service request, transmit a response of the service request to the third apparatus without verifying the at least one authorization information element or identity information of the third apparatus.36.The fourth apparatus of any of claims 32-35, wherein the fourth apparatus is further caused to:receive, from the first apparatus, a message for at least one of:adding a further policy to the at least one policy,modifying the at least one policy, orremoving a policy from the at least one policy.37.The fourth apparatus of any of claims 32-36, wherein the fourth apparatus further is caused to:transmit, to the first apparatus, a request for registration or update of a network function, the request including at least one of: profile information of the fourth apparatus, or a rule for authorizing a service request.38.The fourth apparatus of any of claims 32-37, wherein the service request comprises a client credentials assertion token including the at least one authorization information element.39.A method comprising:transmitting, at a first apparatus to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.40.A method comprising:receiving, at a second apparatus from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request;receiving a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; andperforming at least one of:a verification of the identity information of the third apparatus,a verification of the at least one authorization information element in the service request based on the at least one policy, orforwarding the service request to a fourth apparatus.41.A method comprising:receiving, at a third apparatus from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service;generating a client credentials assertion token based on the at least one authorization information element; andtransmitting, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.42.A method comprising:receiving, at a fourth apparatus from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element;receiving, from a second apparatus, a service request for a network function service; andin accordance with a determination that the service request includes at least one authorization information element, performing at least a verification of the at least one authorization information element based on the at least one policy.43.A first apparatus comprising:means for transmitting, to a second apparatus, a first message including at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element.44.A second apparatus comprising:means for receiving, from a first apparatus, a first message including at least one policy for authorization of a service request for a network service, the at least one policy indicating a requirement for a set of information elements associated with the service request;means for receiving a service request for a network function service, the service request including identity information of a third apparatus and at least one authorization information element; andmeans for performing at least one of:a verification of the identity information of the third apparatus,a verification of the at least one authorization information element in the service request based on the at least one policy, orforwarding the service request to a fourth apparatus.45.A third apparatus comprising:means for receiving, from a first apparatus, a message indicating to include at least one authorization information element related to a request for a network function service;means for generating a client credentials assertion token based on the at least one authorization information element; andmeans for transmitting, to a second apparatus, a service request including identity information of the third apparatus and the client credentials assertion token.46.A fourth apparatus comprising:means for receiving, from a first apparatus, a first message including the at least one policy for service request authorization, the at least one policy indicating at least one rule for allowing or rejecting a reference service request based on at least one reference information element;means for receiving, from a second apparatus, a service request for a network function service; andmeans for in accordance with a determination that the service request includes at least one authorization information element, performing at least a verification of the at least one authorization information element based on the at least one policy.47.A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 39 or the method of claim 40 or the method of claim 41 or the method of claim 42.
Citation Information
Patent Citations
Authorization verification method and device
CN116782228A
Towards robust notification mechanism in 5g sba
US20220232460A1
Security management of trusted network functions
WO2023242743A1
Method and system for improving authorization policy framework in 5g network
WO2024076105A1