Network Function Access Tokens for Tamper-Resistant Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network function discovery and service authorization mechanisms are vulnerable to tampering, leading to incorrect routing of service requests to unauthorized domains or networks, particularly in dynamic and virtualized network environments.
Innovation Solution
The use of access tokens and credential elements containing fully qualified domain names (FQDN), domains, and stand-alone non-public network (SNPN) information to authenticate and authorize network function consumers and producers, ensuring secure service provisioning by verifying the authenticity of service requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network function discovery and service authorization mechanisms are implemented in dynamic and virtualized network environments, then service provisioning capability is improved, but vulnerability to tampering and unauthorized access increases
Solution Approach 1:
The system performs preliminary authentication and authorization by embedding FQDN, domain, and SNPN information in access tokens before service requests are processed. This preliminary action ensures that the identity and intended destination of service requests are verified in advance, preventing tampering and unauthorized routing before they can occur in the dynamic network environment.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that acts as a mediator between network function consumers and producers. The access token serves as an intermediary carrier that conveys authenticated identity information (FQDN, domain, SNPN) and authorization details, ensuring that service requests are routed to the intended destinations without being vulnerable to tampering.
2Reliability
If access tokens with FQDN, domain, and SNPN information are used to authenticate network function consumers, then security against unauthorized routing is improved, but device complexity increases
Solution Approach 1:
The access token is designed as a universal authentication mechanism that handles multiple functions simultaneously: it carries FQDN for domain name verification, domain information for network identification, and SNPN information for stand-alone non-public network identification. This multi-functional approach consolidates multiple authentication requirements into a single token structure, managing complexity through universality rather than separate mechanisms.
3Adaptability or versatility
If service requests are routed dynamically in virtualized networks, then network flexibility is improved, but risk of incorrect routing to unauthorized domains increases
Solution Approach 1:
The authentication mechanism incorporates feedback by verifying the FQDN, domain, and SNPN information contained in access tokens against the intended service destination. This feedback loop ensures that even in dynamically routed service requests, the actual routing path can be verified against the authenticated information, preventing incorrect routing to unauthorized domains while maintaining network flexibility.
Data Source
AI summary
According to an example aspect of the present invention, there is provided an apparatus configured to function as a network function repository, and transmit to a network function consumer an access token authorizing access to a service provided by a network function producer, the access token comprising an at least one of: indication of a fully qualified domain name of the network function consumer, an indication of a domain from which access to the network function producer is allowed and an indication of a stand-alone non-public network from which access to the network function producer is allowed.


