Network Exposure Function for 5G UE Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication systems face challenges in configuring and authenticating user equipment (UE) to access network exposure services efficiently within the 3GPP core network, particularly in supporting diverse service requirements and scalability for increased UE numbers.

Innovation Solution

A method involving transmitting request messages with serving PLMN IDs and UE IDs to network entities to receive necessary information for network function exposure, allowing API invocation based on the received information to support network function exposure services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network function exposure service is implemented in 5G core network, then service diversity and scalability are improved, but authentication complexity and configuration difficulty increase

Engineering Contradiction:
Improveservice diversityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Network Exposure Function (NEF) as an intermediary component between the UE and the core network. The NEF receives authentication requests from UEs, validates them against predefined criteria, and grants access to network exposure services. This mediator approach simplifies the authentication process by centralizing validation logic and isolating the complexity from individual UEs and network functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network exposure service into distinct functional components: authentication function, service provisioning function, and access control function. By dividing the authentication and service delivery process into separate modules, the system achieves better scalability and reduced complexity in each individual component while maintaining overall service diversity.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If multiple network functions are integrated in a single device, then device simplicity is maintained, but scalability for increased UE numbers decreases

Engineering Contradiction:
Improvedevice simplicityVSAvoidscalability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies segmentation by separating mobility management functions from session management functions into distinct network entities (MME and SMF). This functional decomposition enables each component to handle specific tasks independently, improving scalability for increased UE numbers while maintaining relatively simple individual device architectures through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality through the NEF, which serves multiple purposes: authentication, service discovery, access control, and resource allocation. This multi-functional design allows a single network element to support diverse service requirements for multiple UEs without requiring separate dedicated components for each function, thereby achieving scalability without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If network function exposure is enabled for all UEs, then service accessibility is improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action through pre-establishment of authentication criteria and service access policies before actual service consumption. The network pre-validates UE identities, authorizes specific services, and configures access control rules in advance. This preliminary authentication and authorization framework enables broad service accessibility while preventing unauthorized access by filtering requests against predefined security criteria before service delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the NEF continuously monitors authentication status, service consumption patterns, and access control compliance. Based on this feedback, the system dynamically adjusts access permissions, terminates unauthorized connections, and updates security policies. This feedback loop maintains service accessibility for authorized UEs while actively mitigating security risks through real-time monitoring and adaptive security control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250008309A1Method and device for supporting network function exposure service for terminal
Publication Date: 2025.01.02 SAMSUNG ELECTRONICS CO LTD
  • US20250008309A1 patent drawing
  • US20250008309A1 patent drawing
  • US20250008309A1 patent drawing

AI summary

The present disclosure relates to a communication technique for converging IoT technology with a 5G communication system for supporting a higher data transmission rate beyond a 4G system, and a system therefor. A method for supporting a network function exposure service of a terminal, according to one embodiment of the present disclosure, may comprise the steps of: transmitting, to a network entity, a first request message including information on an application programming interface (API) invocation capability of a terminal; receiving, from the network entity, as a response to the first request message, a first response message including information on whether the API invocation is allowed; and invoking the API on the basis of the information on whether the API invocation is allowed.