5G Service Authorization Certificates for Dynamic Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing service authorization process in 5G mobile communication systems using access tokens is inflexible and inaccurate due to fixed validity periods and the need for frequent reauthorization, leading to resource wastage and potential unauthorized access.

Innovation Solution

Implementing a service authorization certificate that includes authorized resource information, allowing network elements to access multiple resources without frequent reauthorization, and incorporating a certificate authority to manage and update these certificates based on resource configuration information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If access tokens with fixed validity periods are used for service authorization, then the authorization process is simple to implement, but the flexibility and accuracy of service authorization deteriorate

Engineering Contradiction:
Improveease of implementationVSAvoidflexibility of service authorization
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static access token mechanism into a dynamic certificate-based authorization system. Service authorization certificates contain authorized resource information that can be dynamically updated, extended, or revoked by the NRF based on changing service requirements, enabling flexible adaptation without reimplementing the entire authorization framework

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the authorization parameter from fixed validity period to dynamic authorized resource information. The service authorization certificate includes resource information that can be modified, extended, or revoked without changing the fundamental authorization mechanism, allowing accurate control of service access while maintaining system simplicity

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If access tokens with fixed validity periods are used, then the authorization mechanism is easy to manage, but the accuracy of service authorization deteriorates due to inability to revoke timely

Engineering Contradiction:
Improveease of managementVSAvoidaccuracy of service authorization
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a feedback mechanism where the NRF continuously monitors service resource status and actively manages service authorization certificates. When service resources are revoked or updated, the NRF can promptly update or revoke the corresponding authorization certificates, ensuring authorization accuracy while maintaining easy management through automated feedback loops

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements preliminary action by having the NRF proactively manage service authorization certificates before unauthorized access can occur. The NRF monitors service resource status and updates or revokes authorization certificates in advance, preventing inaccurate authorization rather than reacting after problems arise

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access tokens are bound to single service resources, then the authorization scope is clear and controlled, but the productivity deteriorates due to frequent reauthorization

Engineering Contradiction:
Improveauthorization controlVSAvoidservice access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent makes the service authorization certificate universal by allowing it to cover multiple service resources simultaneously. The certificate contains authorized resource information that can encompass multiple services, enabling a single authorization mechanism to serve multiple functions and eliminating the need for frequent reauthorization while maintaining clear authorization scope through structured resource information

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If access tokens with fixed validity periods are used, then the authorization process is straightforward, but resource wastage increases due to inability to revoke timely

Engineering Contradiction:
Improvesimplicity of authorization processVSAvoidresource wastage
Core Design Contradiction:
Ease of manufactureVSLoss of energy

Solution Approach 1:

The patent uses feedback mechanism where the NRF monitors service resource status and actively updates or revokes service authorization certificates. This prevents resource wastage by ensuring authorization is maintained only when needed, while the overall process remains straightforward through automated monitoring and updates

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4618605A1Communication method and apparatus
Publication Date: 2025.09.17 HUAWEI TECH CO LTD
  • EP4618605A1 patent drawingFigure 1~2
  • EP4618605A1 patent drawingFigure 3
  • EP4618605A1 patent drawingFigure 4

AI summary

Embodiments of this application provide a communication method and apparatus. The method includes: A first network element obtains a service authorization certificate, where the service authorization certificate includes authorized resource information, and the service authorization certificate is used by the first network element to access an authorized resource indicated by the authorized resource information; the first network element generates a service request, and signs the service request, where the service request is used to request to access a target resource of a second network element, and the target resource is included in the authorized resource; the second network element receives the service authorization certificate and the signed service request from the first network element, and determines a service response based on the service authorization certificate and the signed service request, where the response message indicates whether the second network element provides an access service corresponding to the target resource. In this way, the first network element may access a service resource based on the service authorization certificate, to improve accuracy of service authorization.