Network Service Authentication via Data Collection Coordination Function
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks lack indirect support for authorization of services, particularly in scenarios involving multiple network functions, leading to potential unauthorized data access and security vulnerabilities.
Innovation Solution
Implement a method and apparatus for network service authentication that involves multiple network devices exchanging credentials and access tokens to verify authorization, using a data collection coordination function (DCCF) to manage data access requests and ensure proper authentication across network functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple network devices exchange credentials and access tokens to verify authorization, then security and authorization processes are enhanced, but device complexity and authentication overhead increase
Solution Approach 1:
The patent introduces a Data Collection Coordination Function (DCCF) as an intermediary network device that mediates authentication between NF service consumers and producers. The DCCF receives service requests, validates credentials, coordinates with the NRF for authorization, and manages access token distribution. This intermediary approach enhances security by centralizing authentication logic while simplifying the interaction complexity for individual network devices.
Solution Approach 2:
The patent implements preliminary authentication and authorization actions before service execution. The DCCF validates credentials and obtains authorization from the NRF in advance of actual data access or service execution. Access tokens are issued beforehand with defined permissions, allowing subsequent service operations to proceed with reduced authentication overhead while maintaining security.
2Reliability
If credentials and access tokens are validated across multiple network devices, then unauthorized access is prevented, but processing time and authentication delays increase
Solution Approach 1:
The DCCF performs credential validation and authorization acquisition in advance before actual service requests are processed. By pre-validating credentials and obtaining authorization tokens from the NRF beforehand, the system reduces authentication delays during actual service execution, as subsequent operations can proceed with already-validated credentials.
Solution Approach 2:
Once authorization is granted and access tokens are issued, the DCCF maintains continuous valid authentication states for multiple service operations. The system keeps authorization active and credentials valid across multiple transactions without requiring repeated full authentication cycles, thereby reducing cumulative authentication delays while maintaining continuous security validation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatuses, methods, and systems are disclosed for authentication for a network service. One method (800) includes receiving (802), at a first network device from a second network device, a network function service request to execute a service on a third network device. The request includes first credentials for authentication with a first network device and second credentials for authentication with the third network device. The method (800) includes determining (804) whether the first credentials provided are valid and execute the service request by determining the third network device to execute the service requested from the second network device. The method (800) includes transmitting (806), to a fourth network device, a request for authentication with the third network device. The request includes an identifier of the third network device and second credentials of the second network device.