Priority Session Authorization via NEF for Fast Secure Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication processes for priority-based network services are resource-intensive and time-consuming, especially in scenarios requiring immediate access, hindering efficient allocation of network resources.

Innovation Solution

A dynamic authorization mechanism for priority sessions is implemented, utilizing a network exposure function (NEF) to authenticate and authorize priority service requests based on subscription credentials and network functions, enabling on-demand priority service provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication processes are used for priority-based network services, then network security is maintained, but the authentication becomes resource-intensive and time-consuming

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by verifying subscription credentials and authorizing priority service access before the actual service request is processed. The NEF pre-establishes authorization tokens and service level agreements, so that when a priority service request arrives, the authentication is already complete or can be rapidly validated, eliminating time-consuming authentication steps during critical service delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The Network Exposure Function (NEF) acts as an intermediary between the authentication system and the priority service request system. It handles the complex authentication and authorization processes, translating subscription credentials into service authorizations, and managing the interaction between multiple network functions without requiring the service request system to perform resource-intensive authentication tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication processes are used for priority-based network services, then proper authorization is ensured, but the process becomes resource-intensive

Engineering Contradiction:
Improveauthorization accuracyVSAvoidauthentication resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts and separates the authentication and authorization functions from the main service request processing flow. The NEF independently handles credential verification and authorization decision-making, allowing the priority service system to focus on service delivery while authentication resources are consumed by the specialized authorization function rather than the entire system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates and uses authorization tokens as copies of the authentication result. Once a user's credentials are verified and priority service is authorized, a token or credential indicator is generated that can be rapidly validated without re-performing the full authentication process, reducing resource consumption while maintaining authorization accuracy.

Inventive Principle:
Principle #26Copying

3Speed

If rapid authorization is implemented for priority services, then access speed is improved, but system complexity increases

Engineering Contradiction:
Improveauthorization speedVSAvoidauthorization system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The authorization system is segmented into distinct functional components: subscription credential verification, service level agreement validation, authorization token generation, and priority queue management. Each component handles a specific aspect of the authorization process, allowing for optimized processing in each segment while maintaining overall system manageability through clear functional separation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12598460B2System and method for dynamic authorization of priority-based session
Publication Date: 2026.04.07 VERIZON PATENT & LICENSING INC
  • US12598460B2 patent drawing
  • US12598460B2 patent drawing
  • US12598460B2 patent drawing

AI summary

A method, network device, system, and non-transitory computer-readable storage medium are described in relation to priority-based service authorization, including receiving, via an application service, a session request from a user equipment device (UE), wherein the session request includes a priority service subscription indicator associated with invoking a priority service session with the UE; determining, based on an applicable policy, a first authorization of the application service for the priority service; obtaining, from a user data function and based on the first authorization, a subscriber profile associated with the UE; sending, to an authenticator, a request for a second authorization of the UE for the priority service based on a verification of the priority service subscription indicator to the subscriber profile; receiving, from the authenticator, a verification message of the second authorization; and notifying, based on the verification message, the application service of the invoking of the priority service session.