Direct UE Network Capability Exposure via AF Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SCEF and NEF architectures in 3GPP networks are unable to directly expose their services and capabilities to user equipment (UE), necessitating the involvement of external service providers like SCS/AS, which complicates the exposure process and introduces security challenges due to the need for UE authentication and authorization.

Innovation Solution

A method and apparatus that enable network exposure entities like SCEF and NEF to directly expose services and capabilities to UE by validating and processing network exposure API invocation messages, involving authentication and authorization through data management entities such as HSS/UDM, using SIM-based authentication and storing API exposure subscriptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SCEF/NEF exposes services and capabilities to external service providers (SCS/AS) via API, then network capability exposure is enabled, but the architecture cannot expose services directly to UE and requires external intermediaries

Engineering Contradiction:
Improvenetwork capability exposureVSAvoidexposure architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an Application Function (AF) entity as an intermediary between the UE and SCEF/NEF. The AF receives API invocation messages from the UE, forwards them to SCEF/NEF, and relays responses back to the UE. This intermediary enables direct UE access to network capabilities while maintaining architectural integrity and security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If SCEF/NEF exposes services directly to UE, then the exposure process is simplified, but security challenges arise due to need for UE authentication and authorization

Engineering Contradiction:
Improveexposure processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before the actual service exposure. The AF entity authenticates the UE and obtains authorization tokens from the network before allowing API invocations. This preliminary security setup simplifies subsequent operations while maintaining strong security controls throughout the exposure process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The AF entity serves as a security intermediary that handles authentication and authorization between UE and SCEF/NEF. It validates UE credentials, manages security tokens, and ensures proper authorization before forwarding requests to the network exposure functions, thereby securing direct UE access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If external service providers (SCS/AS) are involved in the exposure process, then network capabilities can be exposed, but the process becomes complicated and slower

Engineering Contradiction:
Improveservice exposure capabilityVSAvoidtime to market
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent extracts the AF functionality from external service providers and integrates it into the network infrastructure as a dedicated network function. This extraction eliminates the need for external intermediaries, allowing UE to access network capabilities directly through the integrated AF, thereby reducing complexity and accelerating time to market.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If UE directly invokes network exposure API, then the exposure process is simplified, but authentication and authorization mechanisms must be implemented

Engineering Contradiction:
ImproveAPI invocation processVSAvoidauthentication mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The AF entity acts as an intermediary that manages authentication and authorization complexity. It handles UE authentication, token generation, and permission validation, shielding the simplicity of direct UE API invocation from the underlying security complexity. The UE interacts with AF using simplified credentials while AF manages the complex authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12382277B2Method and apparatus for network capability exposure
Publication Date: 2025.08.05 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12382277B2 patent drawing
  • US12382277B2 patent drawing
  • US12382277B2 patent drawing

AI summary

Methods and apparatuses for network capability exposure. A method at a network exposure entity comprises receiving, from a terminal device, a network exposure application programming interface (API) invocation message. The method further comprises validating whether the terminal device is allowed to use the invocated network exposure API. The method further comprises processing the network exposure API invocation message based on the validating result.