GPSI Verification via NEF for Secure Edge Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In edge application service scenarios, unauthorized services may be provided to malicious users due to the use of incorrect or fraudulent generic public subscription identifiers (GPSIs), leading to charging invalidation and reduced reliability of edge services.

Innovation Solution

A method and apparatus for verifying GPSIs by entities such as AF, NEF, BSF, and UDM, involving requests and responses to authenticate and verify the legitimacy of GPSIs, ensuring only authorized services are provided.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If public subscription identifiers are made globally unique to enable universal communication across different networks, then interoperability and connectivity are improved, but the risk of identifier theft and unauthorized access increases

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the unique identifier into two separate components: a public subscription identifier (visible to others) and a private subscription identifier (secret key). This segmentation allows the public ID to be globally unique for interoperability while the private ID provides security against theft and unauthorized access. The split enables different functions to be performed by different identifiers without compromising either goal.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a verification mechanism that acts as an intermediary between the public identifier and the actual subscription content. This verification process uses the private identifier to authenticate and authorize access, mediating between the need for public visibility and the need for private security. The intermediary verification step ensures that only authorized entities can access subscribed content.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If subscription identifiers are publicly visible to enable easy access and discovery, then ease of operation is improved, but the ability to prevent unauthorized access deteriorates

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the identifier system so that the public subscription identifier can be freely displayed and accessed for ease of operation, while the private subscription identifier remains secret and is only used for authentication. This allows the system to maintain both accessibility and security by using the appropriate identifier for each function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a copy of the identifier system where the public identifier serves as a visible representation for accessibility, while the private identifier serves as the authenticating copy for security. The public copy can be freely shared and displayed, while the private copy maintains the security function without compromising accessibility.

Inventive Principle:
Principle #26Copying

3Reliability

If a verification mechanism is implemented to prevent identifier theft and unauthorized access, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a verification mechanism as an intermediary layer that sits between the public identifier and the subscription content. This intermediary verification process provides security without requiring complex changes to the core identifier system. The verification mechanism is a separate, manageable component that handles security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security verification function from the identifier itself and places it in a separate verification mechanism. This extraction allows the identifier to remain simple while the verification mechanism handles the complexity of security checks. The verification mechanism can be implemented as a separate module or service that processes authentication requests.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4712528A1Generic public subscription identifier verification methods, and apparatuses
Publication Date: 2026.03.18 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • EP4712528A1 patent drawingFigure 1~3
  • EP4712528A1 patent drawingFigure 4~5
  • EP4712528A1 patent drawingFigure 6~8

AI summary

Disclosed in the embodiments of the present disclosure are generic public subscription identifier verification methods and apparatuses, which can be used in the technical field of communications. A method implemented by an application function (AF) entity comprises: sending a first request to a network exposure function (NEF) entity; and receiving a first response sent by the NEF entity, the first response containing a verification result of a first generic public subscription identifier (GPSI), or the first response containing a second GPSI. Thus, the present disclosure verifies first GPSIs of terminal devices, so as to prevent AF entities from providing unauthorized services or avoid invalid charging, thus improving edge service reliability.