CAPIF API Access Management for Wireless Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless systems lack secure methods for user equipment (UE) to register and invoke APIs, leading to potential unpermitted and malicious access to API functionality.

Innovation Solution

The implementation of an API invoker authentication and authorization mechanism, utilizing a Common API Framework (CAPIF) to enable real-time user consent-driven API invocation and secure user service data exposure, while protecting networks from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If APIs are exposed to UEs for functionality access, then UE capability and service functionality are improved, but network security and data protection deteriorate due to potential unpermitted and malicious access

Engineering Contradiction:
ImproveAPI functionality accessVSAvoidunpermitted and malicious access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an API Framework Core Function (API FC) as an intermediary between UEs and the network's API exposing functions. This mediator authenticates UEs, manages API access permissions, and controls the exposure of network functionality, thereby enabling versatile API access while preventing unauthorized and malicious attacks on the network infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization actions through the API FC before any API functionality is exposed to UEs. The system pre-establishes trust relationships, validates UE credentials, and configures permission sets in advance, ensuring that only authenticated and authorized UEs can access specific API functions, thus preventing malicious access before it can occur

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication and authorization mechanisms are implemented for API access, then network security is improved, but system complexity and registration procedures worsen

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal API Framework Core Function that handles multiple authentication and authorization tasks through a single integrated system. The API FC provides multi-functional services including UE authentication, permission management, API exposure control, and security policy enforcement, thereby improving network security without proportionally increasing system complexity as each function is consolidated in one versatile component

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authentication and authorization functions from the general network infrastructure by creating a dedicated API Framework Core Function. This separation isolates the complex security mechanisms into a specialized module, allowing the rest of the network to operate with standard procedures while the API FC handles sophisticated authentication and authorization tasks independently

Inventive Principle:
Principle #1Segmentation

3Reliability

If real-time user consent driven API invocation is enabled, then user data protection is improved, but processing time and authorization overhead worsen

Engineering Contradiction:
Improveuser service data protectionVSAvoidreal-time authorization processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary consent management where user authorization preferences and API access permissions are established in advance through the API FC. Users pre-configure which data types and API functions they consent to share, and these permissions are cached and validated in real-time during API invocations, thereby providing strong user data protection without requiring lengthy authorization processes for each individual API call

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250133399A1Application programming interface (API) access management in wireless systems
Publication Date: 2025.04.24 LENOVO (SINGAPORE) PTE LTD
  • US20250133399A1 patent drawing
  • US20250133399A1 patent drawing
  • US20250133399A1 patent drawing

AI summary

The present disclosure relates to methods, apparatuses, and systems that support API access management in wireless systems. For instance, an API invoker (e.g., a user or UE) can be authenticated and authorized to access or register with a common API framework (CAPIF) function to enable real-time user consent driven API invocation authorization and secured user service data exposure by a network. Further, a comprehensive set of procedures are provided that ensure that networks are protected from unpermitted and/or potentially malicious access to APIs exposed by the network.