Network Exposure Function Access Token Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems lack the capability to authorize access to services provided by network exposure functions for specific untrusted application functions, leading to inadequate access control and security.

Innovation Solution

An apparatus comprising at least one processor and memory, which receives a request for an access token from a network function service consumer, determines eligibility based on identifiers and attributes associated with the network exposure function, untrusted application function, and network function service consumer, and provides an access token containing the identifier of the untrusted application function.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control for network exposure function is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network repository function as an intermediary component that manages access control. This mediator stores profiles of allowed network functions and facilitates authorization decisions between network function service consumers and network exposure functions, thereby improving security without requiring complex access control logic in every individual network function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control mechanism is segmented into distinct components: network function service consumers make requests, the network repository function stores profiles and makes authorization decisions, and network exposure functions provide services. This segmentation allows each component to have simplified responsibilities while collectively achieving secure access control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If fine-grained access control is implemented, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network function service consumer autonomously makes service requests and receives authorization decisions without manual intervention. The system automatically compares identifiers against stored profiles and issues access tokens or rejection responses, enabling fine-grained access control while maintaining operational simplicity through automation.

Inventive Principle:
Principle #25Self-service

3Reliability

If access token verification is performed, then reliability is improved, but processing time increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network repository function pre-stores profiles of allowed network functions with their identifiers and attributes before service requests are made. This preliminary preparation enables rapid comparison and authorization decisions during actual service access, reducing processing time while maintaining reliable access control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250039162A1Apparatus, method, and computer program
Publication Date: 2025.01.30 NOKIA TECHNOLOGIES OY
  • US20250039162A1 patent drawing
  • US20250039162A1 patent drawing
  • US20250039162A1 patent drawing

AI summary

The disclosure relates to a method comprising to: receiving (700), from a network function service consumer, a request for an access token that authorizes access to a service provided by a network exposure function, wherein the service provides data obtained from an untrusted application function connected to the network exposure function, wherein the request comprises an identifier associated with the network exposure function, an identifier associated with the network function service consumer and an identifier associated with the untrusted application function; determining (702) to provide an access token to the network function service consumer based on the identifier associated with the network exposure function, the identifier associated with the network function service consumer, the identifier associated with the untrusted application function and attributes associated with the untrusted application function included in a profile of the network exposure function stored at the network repository function; and providing (704), to the network function service consumer, the access token comprising the identifier associated with the untrusted application function comprised in the request.