5G Service Authorization Certificates for Dynamic Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing service authorization process in 5G mobile communication systems using access tokens is inflexible and inaccurate due to fixed validity periods and the need for frequent reauthorization, leading to resource wastage and potential unauthorized access.
Innovation Solution
Implementing a service authorization certificate that includes authorized resource information, allowing network elements to access multiple resources without frequent reauthorization, and incorporating a certificate authority to manage and update these certificates based on resource configuration information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If access tokens with fixed validity periods are used for service authorization, then the authorization process is simple to implement, but the flexibility and accuracy of service authorization deteriorate
Solution Approach 1:
The patent transforms the static access token mechanism into a dynamic certificate-based authorization system. Service authorization certificates contain authorized resource information that can be dynamically updated, extended, or revoked by the NRF based on changing service requirements, enabling flexible adaptation without reimplementing the entire authorization framework
Solution Approach 2:
The patent changes the authorization parameter from fixed validity period to dynamic authorized resource information. The service authorization certificate includes resource information that can be modified, extended, or revoked without changing the fundamental authorization mechanism, allowing accurate control of service access while maintaining system simplicity
2Ease of operation
If access tokens with fixed validity periods are used, then the authorization mechanism is easy to manage, but the accuracy of service authorization deteriorates due to inability to revoke timely
Solution Approach 1:
The patent introduces a feedback mechanism where the NRF continuously monitors service resource status and actively manages service authorization certificates. When service resources are revoked or updated, the NRF can promptly update or revoke the corresponding authorization certificates, ensuring authorization accuracy while maintaining easy management through automated feedback loops
Solution Approach 2:
The patent implements preliminary action by having the NRF proactively manage service authorization certificates before unauthorized access can occur. The NRF monitors service resource status and updates or revokes authorization certificates in advance, preventing inaccurate authorization rather than reacting after problems arise
3Reliability
If access tokens are bound to single service resources, then the authorization scope is clear and controlled, but the productivity deteriorates due to frequent reauthorization
Solution Approach 1:
The patent makes the service authorization certificate universal by allowing it to cover multiple service resources simultaneously. The certificate contains authorized resource information that can encompass multiple services, enabling a single authorization mechanism to serve multiple functions and eliminating the need for frequent reauthorization while maintaining clear authorization scope through structured resource information
4Ease of manufacture
If access tokens with fixed validity periods are used, then the authorization process is straightforward, but resource wastage increases due to inability to revoke timely
Solution Approach 1:
The patent uses feedback mechanism where the NRF monitors service resource status and actively updates or revokes service authorization certificates. This prevents resource wastage by ensuring authorization is maintained only when needed, while the overall process remains straightforward through automated monitoring and updates
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Embodiments of this application provide a communication method and apparatus. The method includes: A first network element obtains a service authorization certificate, where the service authorization certificate includes authorized resource information, and the service authorization certificate is used by the first network element to access an authorized resource indicated by the authorized resource information; the first network element generates a service request, and signs the service request, where the service request is used to request to access a target resource of a second network element, and the target resource is included in the authorized resource; the second network element receives the service authorization certificate and the signed service request from the first network element, and determines a service response based on the service authorization certificate and the signed service request, where the response message indicates whether the second network element provides an access service corresponding to the target resource. In this way, the first network element may access a service resource based on the service authorization certificate, to improve accuracy of service authorization.