Granular Resource Access Control in 5G Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication networks, specifically 5G systems, lack the ability to allow consumers to access and perform operations on specific subsets of resources managed by producers, as the existing authorization mechanisms only provide access to entire resources, failing to restrict access to segments or parts of resources.
Innovation Solution
A method and apparatus that enable an initiator entity to send a service request with resource filters specifying a set of resource instances for a service operation, and receive a response from a responder entity, allowing for operations like filtering, selection, search, read, delete, modify, or creation of specific resource instances, along with an authorization request and response mechanism using resource filters to ensure authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing authorization mechanisms are used to provide access to resources, then consumers can access entire resources managed by producers, but consumers cannot access only specific subsets or segments of resources
Solution Approach 1:
The patent segments resources into individual resource instances that can be selectively accessed. The authorization token is segmented to include specific resource instance identifiers, allowing consumers to access only authorized subsets of resources rather than entire resources. This segmentation enables fine-grained access control while maintaining system manageability.
Solution Approach 2:
The patent applies local quality by making authorization tokens specific to particular resource instances rather than applying uniform authorization to entire resources. Each authorization token contains localized information about which specific resource instances the consumer can access, enabling differentiated access control for different parts of the same resource.
2Reliability
If authorization tokens are issued for entire resources, then consumers can perform operations on all resource instances, but consumers cannot be restricted to specific resource instances
Solution Approach 1:
The authorization mechanism is segmented to include specific resource instance identifiers within the authorization token. This segmentation ensures that consumers receive authorization for only the specific resource instances they are entitled to access, improving authorization accuracy while maintaining operational simplicity through automated token management.
Solution Approach 2:
The authorization token acts as an intermediary that carries specific resource instance information from the authorization server to the consumer. This intermediary mechanism enables precise control over which resource instances consumers can access without complicating the consumer's interaction with the system.
3Reliability
If consumers access entire resources, then resource management is simplified, but resource security and efficiency are reduced due to inability to restrict access to specific instances
Solution Approach 1:
Resources are segmented into discrete resource instances, each with its own identifier. Authorization tokens reference specific resource instance identifiers, enabling selective access control. This segmentation enhances resource security by allowing precise control over which instances consumers can access while keeping resource management straightforward through standardized token issuance.
Solution Approach 2:
The authorization mechanism changes from a binary authorized/unauthorized state for entire resources to a parameterized state where authorization is defined by specific resource instance identifiers included in the token. This parameter change enables fine-grained security control without significantly increasing management complexity.
Data Source
AI summary
There are provided measures for (enabling/realizing) network operability on a resource instance level in (a core network of) a mobile/wireless communication system. Such measures may exemplarily comprise that an initiator entity sends a service request for a service operation on a specific resource managed by a responder entity of the network, said service request comprising at least one resource filter specifying a set of resource instances of the specific resource that the service operation is to be performed on, and receives a service response to the service request from the responder entity, said service response comprising a result of performing the service operation on the set of resource instances specified by the at least one resource filter.


