Middleware Trust Establishment for Vertical Application Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, vertical applications lack a trust relationship with management and control plane services, preventing them from accessing necessary services for managing and controlling network slices, as they are not trusted by the management service producers or control planes.

Innovation Solution

Establishing a trust relationship between the vertical application entity and the management service producer or control plane using a middleware with pre-existing trust relationships, through client credential assertions and network address identifiers, to facilitate secure authentication and access to management and control plane services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If vertical applications directly access management and control plane services, then service access efficiency is improved, but security and trust relationship are compromised

Engineering Contradiction:
Improveservice access efficiencyVSAvoidtrust relationship
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a middleware component that acts as an intermediary between vertical applications and management/control plane services. The middleware establishes trust relationships with network functions and provides authenticated access to applications, thereby maintaining security while enabling efficient service access without requiring direct trust relationships between applications and network services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trust relationship is established between application entity and second network function, then secure communication is enabled, but system complexity increases

Engineering Contradiction:
Improvesecure communicationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication actions where the middleware pre-establishes trust relationships with network functions before vertical applications need to access services. The middleware performs authentication requests, receives authentication results, and pre-configures access permissions, thereby enabling secure communication while reducing the complexity burden on the application layer.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If middleware is introduced to establish trust relationships, then security is improved, but device and network complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the middleware with multi-functional capabilities, allowing it to perform multiple roles: establishing trust relationships with network functions, authenticating vertical applications, managing security credentials, and facilitating service access. This universal approach consolidates security functions in a single component, improving security while minimizing the overall network complexity compared to implementing separate security mechanisms for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240313969A1Establishing a trust relationship between an application entity and a wireless communication network
Publication Date: 2024.09.19 LENOVO (SINGAPORE) PTE LTD
  • US20240313969A1 patent drawing
  • US20240313969A1 patent drawing
  • US20240313969A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for establishing a trust relationship between an application entity and a wireless communication network. One apparatus (600) includes a processor (605) and a transceiver (625). The transceiver (625) sends, from an application entity, a request to a first network function to authenticate the application entity to a second network function that does not have a trust relationship with the application entity and receives a result of the authentication from at least one of the first and second network functions. The processor (605) establishes a trust relationship between the application entity and the second network function such that the application entity can communicate with the second network function in response to the application entity being authenticated.