CAPIF Node AEF Grouping for Secure 5G API Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G communication networks lack mechanisms for securing exposed APIs during API discovery and do not restrict access to certain API provider information and service APIs, leading to potential security vulnerabilities and unauthorized usage.
Innovation Solution
Implementing Application Programming Interface (API) related groupings using the Common API Framework (CAPIF) to create API Exposure Function (AEF) groups, which allow for secure association of API invokers with authorized service APIs and enforcement of Service Level Agreement (SLA) metrics such as rate limits and bandwidth, thereby controlling access and usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If API discovery is enabled in 5G networks, then service accessibility and ease of operation are improved, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent segments API access control by creating AEF groups that categorize different API invokers and their authorized service APIs. This segmentation allows selective access control where different groups can discover and access only their authorized APIs, maintaining security while enabling API discovery functionality.
Solution Approach 2:
The CAPIF node acts as an intermediary between API invokers and service APIs. It receives AEF group creation messages, stores AEF group information, determines service API information based on group membership, and provides authorized APIs to invokers. This intermediary enforces access control policies and prevents unauthorized access while allowing legitimate API discovery.
2Object-affected harmful factors
If access control restrictions are implemented for API invokers, then security is improved, but device complexity and system overhead increase
Solution Approach 1:
The CAPIF node performs multiple functions including storing AEF group information, determining service API information based on group membership, providing authorized APIs to invokers, and enforcing access control policies. This multi-functionality consolidates access control mechanisms into an existing network function rather than adding separate complex security infrastructure.
Solution Approach 2:
AEF groups are created in advance with predefined service API information and access permissions. The CAPIF node stores these group creation messages and uses them to automatically determine which APIs each invoker can access. This preliminary configuration reduces runtime complexity by pre-establishing access control rules.
Data Source
AI summary
Methods, systems, and computer readable media for application programming interface (API) related groupings involving common API framework (CAPIF) are disclosed. One example method for using an API exposure function (AEF) group comprises: at a CAPIF node including at least one processor: receiving an AEF group creation message for creating an AEF group associated with an API invoker, wherein the AEF group creation message includes AEF group information indicating one or more service APIs usable by an API invoker; storing the AEF group information; determining, using the AEF group information, service API information associated with the AEF group for the API invoker; and providing the service API information to the API invoker.


