Direct UE Network Capability Exposure via AF Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SCEF and NEF architectures in 3GPP networks are unable to directly expose their services and capabilities to user equipment (UE), necessitating the involvement of external service providers like SCS/AS, which complicates the exposure process and introduces security challenges due to the need for UE authentication and authorization.
Innovation Solution
A method and apparatus that enable network exposure entities like SCEF and NEF to directly expose services and capabilities to UE by validating and processing network exposure API invocation messages, involving authentication and authorization through data management entities such as HSS/UDM, using SIM-based authentication and storing API exposure subscriptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SCEF/NEF exposes services and capabilities to external service providers (SCS/AS) via API, then network capability exposure is enabled, but the architecture cannot expose services directly to UE and requires external intermediaries
Solution Approach 1:
The patent introduces an Application Function (AF) entity as an intermediary between the UE and SCEF/NEF. The AF receives API invocation messages from the UE, forwards them to SCEF/NEF, and relays responses back to the UE. This intermediary enables direct UE access to network capabilities while maintaining architectural integrity and security boundaries.
2Ease of operation
If SCEF/NEF exposes services directly to UE, then the exposure process is simplified, but security challenges arise due to need for UE authentication and authorization
Solution Approach 1:
The patent implements preliminary authentication and authorization actions before the actual service exposure. The AF entity authenticates the UE and obtains authorization tokens from the network before allowing API invocations. This preliminary security setup simplifies subsequent operations while maintaining strong security controls throughout the exposure process.
Solution Approach 2:
The AF entity serves as a security intermediary that handles authentication and authorization between UE and SCEF/NEF. It validates UE credentials, manages security tokens, and ensures proper authorization before forwarding requests to the network exposure functions, thereby securing direct UE access.
3Adaptability or versatility
If external service providers (SCS/AS) are involved in the exposure process, then network capabilities can be exposed, but the process becomes complicated and slower
Solution Approach 1:
The patent extracts the AF functionality from external service providers and integrates it into the network infrastructure as a dedicated network function. This extraction eliminates the need for external intermediaries, allowing UE to access network capabilities directly through the integrated AF, thereby reducing complexity and accelerating time to market.
4Ease of operation
If UE directly invokes network exposure API, then the exposure process is simplified, but authentication and authorization mechanisms must be implemented
Solution Approach 1:
The AF entity acts as an intermediary that manages authentication and authorization complexity. It handles UE authentication, token generation, and permission validation, shielding the simplicity of direct UE API invocation from the underlying security complexity. The UE interacts with AF using simplified credentials while AF manages the complex authentication mechanisms.
Data Source
AI summary
Methods and apparatuses for network capability exposure. A method at a network exposure entity comprises receiving, from a terminal device, a network exposure application programming interface (API) invocation message. The method further comprises validating whether the terminal device is allowed to use the invocated network exposure API. The method further comprises processing the network exposure API invocation message based on the validating result.


