5G Authorization via NEF Identifier Transformation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current 3GPP standard for third-party authorization is not designed for the 5G service-based network architecture, which requires a technical solution to enable effective third-party authorization in this new architecture.

Innovation Solution

A method and network elements that involve replacing the first user identifier with a second user identifier, sending an authorization request to an authorization server through a network exposure function (NEF), and allocating network resources based on the authorization result, while ensuring security and reducing repeated identity authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the current 3GPP standard third-party authorization function is used, then authorization capability is provided, but it is not designed for the 5G service-based network architecture

Engineering Contradiction:
Improveadaptability to 5G service-based network architectureVSAvoidauthorization reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the authorization architecture parameters from traditional 3GPP EPC-based authorization to 5G service-based authorization. This involves transforming the authorization flow to work with service-based interfaces (SBIs) and adapting the authorization server to function within the 5G core network architecture, thereby achieving both adaptability to 5G and maintaining authorization reliability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an authorization server as an intermediary component specifically designed for 5G service-based architecture. This authorization server acts as a mediator between the network exposure function and external third-party authorization systems, enabling seamless integration and maintaining reliable authorization while adapting to the new 5G architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity authentication is performed repeatedly on the terminal device, then security is enhanced, but message overheads increase

Engineering Contradiction:
ImprovesecurityVSAvoidmessage overheads
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs identity authentication in advance during the initial access procedure. The terminal device completes identity authentication before requesting network services, and the authentication result is cached and reused for subsequent authorization operations. This preliminary authentication action enhances security while avoiding repeated authentication messages, thereby reducing message overheads

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the authorization server stores and recalls authentication results. When a terminal device requests authorization, the system checks for existing valid authentication results and reuses them when applicable, providing feedback that avoids redundant authentication messages while maintaining security through selective re-authentication

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11431695B2Authorization method and network element
Publication Date: 2022.08.30 HUAWEI TECH CO LTD
  • US11431695B2 patent drawing
  • US11431695B2 patent drawing
  • US11431695B2 patent drawing

AI summary

An authorization method and a network element are disclosed, to implement a third-party authorization function based on a 5G service-based network architecture. The method is: receiving, by a resource control network element, a resource usage request message sent by a terminal device; replacing a first user identifier in the resource usage request message with a second user identifier; sending an authorization request message carrying the second user identifier to an authorization server by using an NEF; receiving, by using the NEF, an authorization response message sent by the authorization server, where the authorization response message includes an authorization result that is obtained by performing authorization based on the second user identifier and the resource usage request message; and allocating a network resource to the terminal device based on the authorization result, and sending a resource allocation response message to the terminal device.