Authorization Node Mediator for External Network Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network operators face challenges in applying policies for traffic management across multiple networks, especially when devices connect to external networks or network slices, as existing technologies lack efficient mechanisms for external entities to enforce network access parameters beyond primary authentication.
Innovation Solution
The proposed solution involves a method and apparatus for authorization in network nodes and authorization nodes that receive and send indications of network access parameters, using protocols like EAP and MUD files, to manage network access policies, allowing external entities to control access and enforce policies across networks and slices without modifying existing protocols or devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If primary authentication is performed between UE and network, then UE can connect to wireless network, but external networks cannot enforce network access parameters beyond primary authentication
Solution Approach 1:
The patent introduces an authorization node as an intermediary between the network and external networks. This intermediary receives authorization requests from network nodes, performs authorization based on stored network access parameters, and returns authorization results. This mediator enables external networks to enforce access policies without requiring direct integration with each network node, thus improving adaptability while managing complexity.
Solution Approach 2:
The patent segments the authentication and authorization processes into distinct functions. Primary authentication between UE and network remains separate from the new authorization mechanism. The authorization function is further segmented into: (1) network node sending authorization requests, (2) authorization node storing and processing network access parameters, and (3) returning authorization results. This segmentation allows each component to remain relatively simple while the overall system achieves versatile access control.
2Adaptability or versatility
If network access parameters are enforced at network node level, then external networks can control device access, but protocol modifications are required
Solution Approach 1:
The authorization node serves as a mediator that external networks can configure with specific network access parameters. Instead of modifying each network node's protocol stack, the authorization node receives standardized authorization requests and applies the externally-defined parameters. This approach enables policy enforcement capability while avoiding the complexity of modifying existing network node protocols and devices.
Solution Approach 2:
The patent creates a logical copy of the authentication/authorization functionality at the authorization node, which stores network access parameters and performs authorization decisions. This copying approach allows external networks to define policies in one place (the authorization node) that then apply across multiple network nodes without modifying each node individually, thus easing implementation while maintaining enforcement capability.
3Ease of operation
If existing protocols are used without modification, then device compatibility is maintained, but external entities cannot enforce network access parameters
Solution Approach 1:
The authorization node acts as a mediator that maintains protocol compatibility at the network node level while enabling external network control. Network nodes continue to use existing protocols for communication, but the authorization node intercepts and processes authorization requests, applying external network policies before returning results. This intermediary approach preserves ease of operation through protocol compatibility while adding adaptability for external control.
4Reliability
If authorization node stores network access parameters, then access control is tightened, but information storage requirements increase
Solution Approach 1:
The authorization node stores network access parameters with specific local quality - only the parameters necessary for authorization decisions are stored at the authorization node. The parameters are organized by external network identifiers and contain only the access control information needed for that specific external network. This localized storage approach tightens access control reliability while minimizing the quantity of stored data by storing only what is necessary for each external network's policy enforcement.
Data Source
AI summary
Methods and apparatus are provided. In an example aspect, a method of authorization in a network node is provided. The method comprises receiving, from an authorization node, an indication that a User Equipment, UE, is authorized to access a resource, and receiving, from the authorization node, an indication of network access parameters for the UE for accessing the resource.


