Authorization Server Function for 5G Network Function Set Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication systems lack a mechanism to generate an access token that can efficiently utilize network function (NF) reliability enhancements, specifically for NF Sets, which are designed to manage scalability and load sharing among NF instances, leading to challenges in secure access control and network reliability.

Innovation Solution

The proposed solution involves an authorization server function that receives a request from a service consumer including a service producer set identifier, identifies eligible NF producers based on factors like UE and NF consumer locations, and generates an access token with NF Instance IDs, allowing the service consumer to select suitable NF producers for secure access, thereby enhancing NF reliability and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control mechanisms are used in 5G networks, then security management is maintained, but network reliability and scalability for NF Sets cannot be effectively managed

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the service producer set into multiple identifiable instances (NF instances) with unique identifiers. The authorization server divides the access token generation process into distinct steps: receiving the service producer set identifier, identifying eligible NF instances based on location and other criteria, and generating an access token that contains specific NF instance identifiers. This segmentation enables both reliability (through multiple eligible instances) and scalability (through systematic instance management).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic selection of NF instances based on varying criteria such as UE location, NF consumer location, and real-time network conditions. The authorization server dynamically determines which NF instances within a set are eligible for access, allowing the system to adapt to changing network conditions while maintaining security. This dynamic approach enables the system to scale effectively while preserving reliability through flexible instance selection.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If NF Sets are introduced to manage scalability and load sharing, then network scalability is improved, but secure access control mechanisms become insufficient

Engineering Contradiction:
ImprovescalabilityVSAvoidsecure access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authorization server acts as an intermediary between the service consumer and the NF instances within a service producer set. It receives the service producer set identifier from the service consumer, identifies eligible NF instances based on multiple criteria including location information, and generates an access token that securely authorizes access to specific instances. This intermediary mechanism maintains secure access control while supporting scalability through systematic instance management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of access authorization from a single static target to a dynamic selection among multiple NF instances. The authorization process considers various parameters including UE location, NF consumer location, and NF instance identifiers to determine eligibility. The generated access token contains specific NF instance identifiers, enabling secure access control that adapts to different network conditions and scales across multiple instances.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access tokens include specific NF instance identifiers, then secure access control is enhanced, but system complexity increases

Engineering Contradiction:
Improvesecure access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization server performs multiple functions within a single process: it receives the service producer set identifier, identifies eligible NF instances based on location and other criteria, generates the access token with specific NF instance identifiers, and returns it to the service consumer. This multi-functional approach consolidates what could be separate complex systems into a unified authorization mechanism, enhancing secure access control while managing system complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20220240089A1Authorization for network function sets in communication system
Publication Date: 2022.07.28 NOKIA TECHNOLOGIES OY
  • US20220240089A1 patent drawing
  • US20220240089A1 patent drawing
  • US20220240089A1 patent drawing

AI summary

Improved techniques for secure access control in communication systems are provided. Secure access control in one or more examples includes authorization of network function sets. For example, in accordance with an authorization server function, a method includes receiving a request from a service consumer in a communication system for access to a service type, wherein the request comprises information including a service producer set identifier. The method determines whether the service consumer is authorized to access the service type. The method identifies service producer instances that belong to the requested service producer set identifier. The method generates an access token that comprises identifiers for identified ones of the service producer instances that belong to the requested service producer set identifier, and sends the access token to the service consumer.