Network Service Access Tokens With Domain Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network function discovery and service authorization methods lack robust mechanisms to verify the authenticity of network function consumers, leading to potential tampering of service requests and diversion to incorrect domains or networks, especially in dynamic and virtualized network environments.

Innovation Solution

The implementation of access tokens and credential elements that include fully qualified domain names (FQDN) and domain information ensures secure communication by verifying the authenticity of network function consumers, preventing tampering and ensuring authorized access to network services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access tokens are used to authorize network function consumers, then service authorization is enabled, but the risk of request tampering and domain diversion persists without proper verification

Engineering Contradiction:
Improveservice authorizationVSAvoidrequest tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent embeds domain verification information (FQDN, domain, SNPN) into the access token before the service request is executed. This preliminary inclusion of verification data allows the network function producer to verify the consumer's authenticity and prevent request tampering or domain diversion at the point of service delivery, rather than requiring separate verification steps.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If domain verification information is included in access tokens, then authenticity verification is improved, but token complexity increases

Engineering Contradiction:
Improveauthenticity verificationVSAvoidtoken structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges domain verification information (fully qualified domain name, domain, stand-alone non-public network) with the access token in a single integrated structure. This combination eliminates the need for separate verification messages or additional authentication steps, as all necessary verification data is embedded within the token itself that the consumer already presents for authorization.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple domain indicators are embedded in tokens, then security against diversion is enhanced, but processing overhead increases

Engineering Contradiction:
Improvesecurity against diversionVSAvoidtoken processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access token is structured to be self-contained with all verification information (FQDN, domain, SNPN) needed for authenticity verification. The network function producer can verify the consumer's domain directly from the token data without requiring additional queries to external verification services or complex multi-step validation processes, thereby maintaining processing efficiency while enhancing security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4125241B1Secure provision of network services
Publication Date: 2026.01.28 NOKIA TECHNOLOGIES OY
  • EP4125241B1 patent drawingFigure 1
  • EP4125241B1 patent drawingFigure 2
  • EP4125241B1 patent drawingFigure 3

AI summary

According to an example aspect of the present invention, there is provided an apparatus configured to function as a network function repository, and transmit to a network function consumer an access token authorizing access to a service provided by a network function producer, the access token comprising an at least one of: indication of a fully qualified domain name of the network function consumer, an indication of a domain from which access to the network function producer is allowed and an indication of a stand-alone non-public network from which access to the network function producer is allowed.