CAPIF Node AEF Grouping for Secure 5G API Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication networks lack mechanisms for securing exposed APIs during API discovery and do not restrict access to certain API provider information and service APIs, leading to potential security vulnerabilities and unauthorized usage.

Innovation Solution

Implementing Application Programming Interface (API) related groupings using the Common API Framework (CAPIF) to create API Exposure Function (AEF) groups, which allow for secure association of API invokers with authorized service APIs and enforcement of Service Level Agreement (SLA) metrics such as rate limits and bandwidth, thereby controlling access and usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If API discovery is enabled in 5G networks, then service accessibility and ease of operation are improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
ImproveAPI discoveryVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments API access control by creating AEF groups that categorize different API invokers and their authorized service APIs. This segmentation allows selective access control where different groups can discover and access only their authorized APIs, maintaining security while enabling API discovery functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CAPIF node acts as an intermediary between API invokers and service APIs. It receives AEF group creation messages, stores AEF group information, determines service API information based on group membership, and provides authorized APIs to invokers. This intermediary enforces access control policies and prevents unauthorized access while allowing legitimate API discovery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access control restrictions are implemented for API invokers, then security is improved, but device complexity and system overhead increase

Engineering Contradiction:
Improveunauthorized accessVSAvoidaccess control system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The CAPIF node performs multiple functions including storing AEF group information, determining service API information based on group membership, providing authorized APIs to invokers, and enforcing access control policies. This multi-functionality consolidates access control mechanisms into an existing network function rather than adding separate complex security infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

AEF groups are created in advance with predefined service API information and access permissions. The CAPIF node stores these group creation messages and uses them to automatically determine which APIs each invoker can access. This preliminary configuration reduces runtime complexity by pre-establishing access control rules.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11785102B1Methods, systems, and computer readable media for application programming interface (API) related groupings involving common application programming interface framework
Publication Date: 2023.10.10 ORACLE INT CORP
  • US11785102B1 patent drawing
  • US11785102B1 patent drawing
  • US11785102B1 patent drawing

AI summary

Methods, systems, and computer readable media for application programming interface (API) related groupings involving common API framework (CAPIF) are disclosed. One example method for using an API exposure function (AEF) group comprises: at a CAPIF node including at least one processor: receiving an AEF group creation message for creating an AEF group associated with an API invoker, wherein the AEF group creation message includes AEF group information indicating one or more service APIs usable by an API invoker; storing the AEF group information; determining, using the AEF group information, service API information associated with the AEF group for the API invoker; and providing the service API information to the API invoker.