CAPIF Access Tokens With Resource Owner IDs for Secure UE API Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G networks lack mechanisms to limit access to UE resources by API invokers to only authorized resources owned by the UE, compromising security and confidentiality.
Innovation Solution
Implement methods for the CAPIF core function (CCF) to generate access tokens with resource owner identifiers, ensuring that API invokers can only access resources associated with the identified owner, using authentication procedures to obtain and verify these identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If API invokers are allowed to access UE resources without resource owner identification, then access flexibility and ease of operation are improved, but security and confidentiality are compromised
Solution Approach 1:
The patent introduces an access token as an intermediary element that mediates between API invokers and UE resources. The token contains resource owner identification and authorization information, allowing the system to maintain both ease of operation (through token-based access) and security (through verified ownership). This resolves the contradiction by providing a structured intermediate layer that enables flexible access while ensuring proper authorization.
Solution Approach 2:
The system performs preliminary authentication and authorization actions by generating access tokens before API invokers can access UE resources. The CCF authenticates the API invoker, obtains resource owner identification, and creates a token in advance. This preliminary action ensures security is established before access occurs, while still maintaining operational ease through the pre-configured token mechanism.
2Reliability
If resource access is restricted to only authorized owners through identification mechanisms, then security is improved, but device complexity and authentication overhead increase
Solution Approach 1:
The patent changes the parameter of authorization from direct complex authentication to token-based access. The access token encapsulates resource owner identification and authorization scope, transforming the authentication process into a simpler token verification operation. This reduces device complexity while maintaining security, as the token serves as a pre-validated credential that simplifies subsequent access control.
Solution Approach 2:
The system extracts the authentication and authorization logic into a separate access token generated by the CCF. This extraction removes the complex authentication mechanism from the resource access path, placing it instead in the token issuance phase. The result is simplified resource access operations while security requirements are met through the extracted and encapsulated authorization information in the token.
3Measurement precision
If access tokens include detailed resource owner identifiers and scope information, then access control precision is improved, but information processing overhead increases
Solution Approach 1:
The access token implements partial action by including only the necessary resource owner identification and scope information required for authorization, rather than complete user profiles or all possible access parameters. This selective inclusion provides sufficient precision for access control while minimizing information processing overhead by excluding unnecessary data elements.
Data Source
AI summary
Embodiments include methods for application programming interface (API) invoking entity of a communication network. Such methods include sending, to a common API framework (CAPIF) core function (CCF) of the communication network, a request for an access token granting the API invoking entity permission to access a resource, in the communication network, that is owned by a resource owner. The request includes an indication related to the resource owner. Such methods include receiving, from the CCF, an access token in accordance with the request. The access token includes the following: a first identifier associated with the resource owner; and a second identifier associated with the API invoking entity. Such methods include invoking, via an API exposing function (AEF), an API for the resource using the access token. Other embodiments include complementary methods for a CCF and for an AEF.


