Network Service Authentication via Data Collection Coordination Function

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks lack indirect support for authorization of services, particularly in scenarios involving multiple network functions, leading to potential unauthorized data access and security vulnerabilities.

Innovation Solution

Implement a method and apparatus for network service authentication that involves multiple network devices exchanging credentials and access tokens to verify authorization, using a data collection coordination function (DCCF) to manage data access requests and ensure proper authentication across network functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network devices exchange credentials and access tokens to verify authorization, then security and authorization processes are enhanced, but device complexity and authentication overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Data Collection Coordination Function (DCCF) as an intermediary network device that mediates authentication between NF service consumers and producers. The DCCF receives service requests, validates credentials, coordinates with the NRF for authorization, and manages access token distribution. This intermediary approach enhances security by centralizing authentication logic while simplifying the interaction complexity for individual network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization actions before service execution. The DCCF validates credentials and obtains authorization from the NRF in advance of actual data access or service execution. Access tokens are issued beforehand with defined permissions, allowing subsequent service operations to proceed with reduced authentication overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If credentials and access tokens are validated across multiple network devices, then unauthorized access is prevented, but processing time and authentication delays increase

Engineering Contradiction:
ImproveauthorizationVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The DCCF performs credential validation and authorization acquisition in advance before actual service requests are processed. By pre-validating credentials and obtaining authorization tokens from the NRF beforehand, the system reduces authentication delays during actual service execution, as subsequent operations can proceed with already-validated credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once authorization is granted and access tokens are issued, the DCCF maintains continuous valid authentication states for multiple service operations. The system keeps authorization active and credentials valid across multiple transactions without requiring repeated full authentication cycles, thereby reducing cumulative authentication delays while maintaining continuous security validation.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP4295534B1Authentication for a network service
Publication Date: 2025.12.17 LENOVO (SINGAPORE) PTE LTD
  • EP4295534B1 patent drawingFigure 1
  • EP4295534B1 patent drawingFigure 2
  • EP4295534B1 patent drawingFigure 3

AI summary

Apparatuses, methods, and systems are disclosed for authentication for a network service. One method (800) includes receiving (802), at a first network device from a second network device, a network function service request to execute a service on a third network device. The request includes first credentials for authentication with a first network device and second credentials for authentication with the third network device. The method (800) includes determining (804) whether the first credentials provided are valid and execute the service request by determining the third network device to execute the service requested from the second network device. The method (800) includes transmitting (806), to a fourth network device, a request for authentication with the third network device. The request includes an identifier of the third network device and second credentials of the second network device.