Network Repository Function Vendor Identity Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authorization methods in cellular communication networks, such as 5G core networks, lack effective mechanisms for secure and authorized sharing of vendor-specific services, particularly in multi-vendor environments, where sensitive data like trained machine learning models need to be shared between different vendors.

Innovation Solution

A network repository function verifies access requests based on vendor identities and generates access tokens that include both the consumer and producer vendor identities, ensuring that only authorized vendors can access services, thereby enabling secure sharing of vendor-specific services across multiple vendors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authorization methods are used in cellular networks, then basic access control is provided, but secure sharing of vendor-specific services in multi-vendor environments cannot be achieved

Engineering Contradiction:
Improveauthorization securityVSAvoidmulti-vendor service sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authorization system is segmented into distinct components: vendor identity verification, service producer identification, and access token generation. Each component handles a specific aspect of the authorization process, allowing the system to simultaneously maintain security while supporting multi-vendor service sharing through structured separation of authorization concerns

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An access token acts as an intermediary credential that mediates between the service consumer and service producer. The token contains verified vendor identities and service permissions, enabling secure indirect communication and authorization verification without requiring direct trust relationships between all vendors in the network

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If vendor-specific services are shared across multiple vendors, then service versatility is improved, but authorization control and data security may be compromised

Engineering Contradiction:
Improvevendor-specific service sharingVSAvoidauthorization control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The access token implements local quality by containing specific vendor identities and service-specific permissions tailored to each authorization context. This allows the system to provide customized authorization control for each vendor-service pair while maintaining overall system security, enabling versatile service sharing without compromising authorization control

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Vendor identity verification and service permission validation are performed in advance during the access token generation phase. This preliminary authorization action ensures that only verified vendors receive appropriate access tokens, establishing security controls before actual service access occurs, thereby enabling safe multi-vendor service sharing

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12167241B2Enhanced authorization in cellular communication networks
Publication Date: 2024.12.10 NOKIA TECHNOLOGIES OY
  • US12167241B2 patent drawing
  • US12167241B2 patent drawing
  • US12167241B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided an apparatus comprising means for receiving from a requesting network function, by a network repository function, an access token request, wherein the access token request is related to a network function consumer requesting access to a service provided by a network function producer and comprises an identity of a vendor of the network function consumer requesting access to the service, means for verifying by the network repository function, based at least on the identity of the vendor of the network function consumer, that the network function consumer is allowed to access the service and means for transmitting to the requesting network function, by the network repository function, an access token upon successful verification, wherein the access token generated and signed by the network repository function comprises the identity of the vendor of the network function consumer and an identity of the vendor of the network function producer.