API Token Revocation for Secure UE Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication technologies lack the ability for the API invoker and CAPIF core function/authorization function to actively revoke related tokens, posing a threat of token disclosure.
Innovation Solution
A method and apparatus for authorization revocation, where the CAPIF core function/authorization function receives and verifies a first authorization revocation request from an API invoker, and upon verification, revokes the corresponding token, and the API exposure function sets the token as invalid.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If tokens are issued to API invokers for accessing UE resources, then resource access capability is improved, but security risk increases due to inability to actively revoke tokens
Solution Approach 1:
The patent implements preliminary action by establishing a token revocation mechanism before potential security threats can materialize. The CAPIF core function/authorization function maintains the ability to proactively revoke tokens through authorization revocation requests, preventing unauthorized access before it occurs rather than reacting after a breach. This aligns with the principle of performing required actions in advance to prevent adverse effects.
Solution Approach 2:
The patent implements feedback by creating a closed-loop authorization system where the CAPIF core function/authorization function can receive authorization revocation requests from API invokers or resource owners and actively respond by revoking tokens. This feedback mechanism allows the system to dynamically adjust authorization states based on current security requirements, transforming the static token issuance model into a dynamic, controllable system.
2Reliability
If active token revocation capability is implemented, then security control is improved, but system complexity increases
Solution Approach 1:
The patent applies universality by enabling the CAPIF core function/authorization function to perform multiple roles: it not only issues tokens but also receives authorization revocation requests, verifies them, and executes token revocation. This multi-functionality consolidates authorization management capabilities within a single entity, avoiding the need for separate revocation systems and reducing overall system complexity while improving security control.
Solution Approach 2:
The patent implements self-service by allowing API invokers to autonomously initiate authorization revocation requests when they detect security threats or no longer need access. The system enables entities to manage their own authorization states without requiring external intervention, simplifying the overall control architecture while maintaining strong security controls through decentralized initiation of revocation actions.
Data Source
AI summary
An authorization revocation method and apparatus. The method comprises: receiving a first authorization revocation request sent by an API invoking entity, verifying the first authorization revocation request; and if the verification is passed, revoking a token corresponding to the first authorization revocation request. A processing method is provided for the situation of “authorization revocation”, so that a CAPIF core function or authorization function revokes, according to an authorization revocation request sent by the API invoking entity, a related token used when accessing a resource of a UE, and thus potential threats caused by token leakage can be reduced.


