API Access Management in Wireless Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless systems lack secure methods for user equipment (UE) to register and invoke APIs, leading to potential unpermitted and malicious access to API functionality.
Innovation Solution
The implementation of an API invoker authentication and authorization mechanism, which includes onboarding procedures with a Common API Framework (CAPIF) core function, ensures real-time user consent-driven API invocation and secure exposure of user service data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If wireless systems expose APIs for UE access, then functionality and service capability are improved, but security and protection from unauthorized access deteriorate
Solution Approach 1:
The patent implements preliminary authentication and authorization actions before API access is granted. The UE must complete authentication with the AF and obtain authorization tokens before it can invoke any APIs. This preliminary security action prevents unauthorized access while maintaining API functionality for authenticated users.
Solution Approach 2:
The patent introduces an intermediary authorization management system between the UE and the exposed APIs. The AF acts as a mediator that verifies UE credentials, manages authorization tokens, and controls API access. This intermediary layer protects the API infrastructure from direct unauthorized access while preserving service functionality.
2Reliability
If authentication and authorization procedures are implemented, then security is improved, but device complexity and procedural overhead worsen
Solution Approach 1:
The patent implements a universal authentication and authorization framework that handles multiple API access scenarios through a single standardized procedure. The same authentication mechanism and token-based authorization system apply across all API invocations and UE types, reducing the need for multiple specialized security procedures and simplifying the overall system complexity.
3Ease of operation
If real-time user consent driven authorization is implemented, then control and security are improved, but processing time and system complexity worsen
Solution Approach 1:
The patent implements preliminary consent acquisition during the authentication phase, before API invocation. Users provide consent upfront, and the system caches the authorization decisions. This preliminary action eliminates the need for real-time consent verification during each API call, reducing processing time while maintaining user control.
Solution Approach 2:
The patent implements a feedback mechanism where the AF monitors and manages authorization states based on user consent. The system tracks authorization tokens and their validity, providing real-time feedback on access permissions without requiring repeated user interactions. This feedback loop maintains security while optimizing processing efficiency.
Data Source
AI summary
The present disclosure relates to methods, apparatuses, and systems that support API access management in wireless systems. For instance, an API invoker (e.g., a user or UE) can be authenticated and authorized to access or register with a common API framework (CAPIF) function to enable real-time user consent driven API invocation authorization and secured user service data exposure by a network. Further, a comprehensive set of procedures are provided that ensure that networks are protected from unpermitted and/or potentially malicious access to APIs exposed by the network.


