Network Repository Function Vendor Identity Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authorization methods in cellular communication networks, such as 5G core networks, lack effective mechanisms for secure and authorized sharing of vendor-specific services, particularly in multi-vendor environments, where sensitive data like trained machine learning models need to be shared between different vendors.
Innovation Solution
A network repository function verifies access requests based on vendor identities and generates access tokens that include both the consumer and producer vendor identities, ensuring that only authorized vendors can access services, thereby enabling secure sharing of vendor-specific services across multiple vendors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authorization methods are used in cellular networks, then basic access control is provided, but secure sharing of vendor-specific services in multi-vendor environments cannot be achieved
Solution Approach 1:
The authorization system is segmented into distinct components: vendor identity verification, service producer identification, and access token generation. Each component handles a specific aspect of the authorization process, allowing the system to simultaneously maintain security while supporting multi-vendor service sharing through structured separation of authorization concerns
Solution Approach 2:
An access token acts as an intermediary credential that mediates between the service consumer and service producer. The token contains verified vendor identities and service permissions, enabling secure indirect communication and authorization verification without requiring direct trust relationships between all vendors in the network
2Adaptability or versatility
If vendor-specific services are shared across multiple vendors, then service versatility is improved, but authorization control and data security may be compromised
Solution Approach 1:
The access token implements local quality by containing specific vendor identities and service-specific permissions tailored to each authorization context. This allows the system to provide customized authorization control for each vendor-service pair while maintaining overall system security, enabling versatile service sharing without compromising authorization control
Solution Approach 2:
Vendor identity verification and service permission validation are performed in advance during the access token generation phase. This preliminary authorization action ensures that only verified vendors receive appropriate access tokens, establishing security controls before actual service access occurs, thereby enabling safe multi-vendor service sharing
Data Source
AI summary
According to an example aspect of the present invention, there is provided an apparatus comprising means for receiving from a requesting network function, by a network repository function, an access token request, wherein the access token request is related to a network function consumer requesting access to a service provided by a network function producer and comprises an identity of a vendor of the network function consumer requesting access to the service, means for verifying by the network repository function, based at least on the identity of the vendor of the network function consumer, that the network function consumer is allowed to access the service and means for transmitting to the requesting network function, by the network repository function, an access token upon successful verification, wherein the access token generated and signed by the network repository function comprises the identity of the vendor of the network function consumer and an identity of the vendor of the network function producer.


