Network Service Authentication via Identifier Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security procedures in communication networks face challenges in authenticating service requests effectively, particularly in preventing misuse of access tokens and malicious activities by service communication proxies.

Innovation Solution

Implementing an authentication process that verifies the consistency of identifiers in access tokens and credential data elements within service requests, ensuring that only authorized network function instances or sets can access services, thereby rejecting conflicting requests and protecting the network from malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If service communication proxies are used to route service requests, then service discovery and routing capabilities are improved, but security risks increase due to potential malicious activities and access token misuse

Engineering Contradiction:
Improveservice discovery and routingVSAvoidsecurity risks from malicious activities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service communication proxy as an intermediary entity between the service consumer and service provider. The proxy receives service requests, extracts access tokens, validates them against credential data elements, and forwards authenticated requests. This intermediary structure enables centralized security control while maintaining service discovery and routing capabilities, resolving the contradiction by adding a security layer without eliminating the proxy's functional benefits

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the service communication proxy validates access tokens by comparing identifiers between the access token and credential data element, then provides authentication results back to determine whether to forward the service request. This closed-loop feedback system enables dynamic security control, allowing the network to respond to authentication outcomes and block malicious requests while permitting legitimate traffic

Inventive Principle:
Principle #23Feedback

2Reliability

If access tokens are used for service authentication, then service access control is improved, but vulnerability to token misuse and malicious activities increases

Engineering Contradiction:
Improveservice access controlVSAvoidtoken misuse and malicious activities
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary action by validating the access token's authenticity and consistency with the credential data element before the service request is processed. The service communication proxy performs this validation in advance by comparing the first identifier from the access token with the second identifier from the credential data element, blocking potentially malicious requests before they reach the service provider, thus preventing token misuse rather than just detecting it

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by proactively blocking service requests with invalid or mismatched access tokens before they can cause harm. The service communication proxy compares identifiers, detects inconsistencies indicating potential malicious activity, and rejects these requests in advance, preventing token misuse and malicious activities from affecting the network

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If identifier verification is performed in service requests, then network security is improved, but processing complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct components: extracting the access token from the service request, identifying the first identifier from the access token, identifying the second identifier from the credential data element, comparing these identifiers, and deciding whether to forward the request. This segmentation of the authentication workflow into manageable steps reduces processing complexity by making each step independent and straightforward while maintaining comprehensive security verification

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20220217127A1Authentication of network request
Publication Date: 2022.07.07 NOKIA TECHNOLOGIES OY
  • US20220217127A1 patent drawing
  • US20220217127A1 patent drawing
  • US20220217127A1 patent drawing

AI summary

According to an example aspect of the present invention, there is provided an apparatus configured to receive a service request for a service provided by the apparatus, determine whether to provide the service based at least partly on an authentication based on a first identifier, comprised in an access token in the service request, and on a second identifier, comprised in a credential data element in the service request, wherein the authentication is successful when the first identifier and the second identifier identify a same network function instance or same network function instance set, and provide the service responsive to a result of the determination indicating the service is to be provided.