Network Entity Data Authorization via Embedded Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network security management lacks a mechanism to ensure authorized data access, particularly when data is stored in analytics data repositories without direct access to the original data producer.

Innovation Solution

Appending metadata such as NF type and identifier of the data producer to the stored data, which is then verified against access tokens by the analytics data repository to ensure authorized data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is stored in analytics data repositories without direct access to the original data producer, then data accessibility and network efficiency are improved, but security authorization capability deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity authorization capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding metadata (including data producer identifier, data type, and authorization information) into the data packet at the source before storage. This pre-packaging of authorization information enables the analytics data repository to perform autonomous authorization verification without needing to contact the original data producer, thus resolving the contradiction between improved data accessibility and maintained security authorization capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If metadata is appended to stored data for authorization verification, then security authorization capability is improved, but data structure complexity increases

Engineering Contradiction:
Improvesecurity authorization capabilityVSAvoiddata structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authorization metadata with the original data packet into a single integrated structure. Instead of creating separate authorization records or complex multi-layered data structures, the metadata is appended directly to the data packet, combining the data payload and authorization information into one unified structure that simplifies processing and verification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12206671B2Data management for authorizing data consumers in communication network
Publication Date: 2025.01.21 NOKIA TECHNOLOGIES OY
  • US12206671B2 patent drawing
  • US12206671B2 patent drawing
  • US12206671B2 patent drawing

AI summary

Techniques for data management in a network entity to authorize data consumers in a communication network are disclosed. For example, a method comprises receiving, at a network entity of a communication network, data generated by a data producer in the communication network, and storing, at the network entity, the data generated by the data producer. The stored data has metadata, associated with the data producer, appended thereto.