Network Service Authentication via Identifier Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security procedures in communication networks face challenges in authenticating service requests effectively, particularly in preventing misuse of access tokens and malicious activities by service communication proxies.
Innovation Solution
Implementing an authentication process that verifies the consistency of identifiers in access tokens and credential data elements within service requests, ensuring that only authorized network function instances or sets can access services, thereby rejecting conflicting requests and protecting the network from malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If service communication proxies are used to route service requests, then service discovery and routing capabilities are improved, but security risks increase due to potential malicious activities and access token misuse
Solution Approach 1:
The patent introduces a service communication proxy as an intermediary entity between the service consumer and service provider. The proxy receives service requests, extracts access tokens, validates them against credential data elements, and forwards authenticated requests. This intermediary structure enables centralized security control while maintaining service discovery and routing capabilities, resolving the contradiction by adding a security layer without eliminating the proxy's functional benefits
Solution Approach 2:
The patent implements a feedback mechanism where the service communication proxy validates access tokens by comparing identifiers between the access token and credential data element, then provides authentication results back to determine whether to forward the service request. This closed-loop feedback system enables dynamic security control, allowing the network to respond to authentication outcomes and block malicious requests while permitting legitimate traffic
2Reliability
If access tokens are used for service authentication, then service access control is improved, but vulnerability to token misuse and malicious activities increases
Solution Approach 1:
The patent applies preliminary action by validating the access token's authenticity and consistency with the credential data element before the service request is processed. The service communication proxy performs this validation in advance by comparing the first identifier from the access token with the second identifier from the credential data element, blocking potentially malicious requests before they reach the service provider, thus preventing token misuse rather than just detecting it
Solution Approach 2:
The patent implements preliminary anti-action by proactively blocking service requests with invalid or mismatched access tokens before they can cause harm. The service communication proxy compares identifiers, detects inconsistencies indicating potential malicious activity, and rejects these requests in advance, preventing token misuse and malicious activities from affecting the network
3Reliability
If identifier verification is performed in service requests, then network security is improved, but processing complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct components: extracting the access token from the service request, identifying the first identifier from the access token, identifying the second identifier from the credential data element, comparing these identifiers, and deciding whether to forward the request. This segmentation of the authentication workflow into manageable steps reduces processing complexity by making each step independent and straightforward while maintaining comprehensive security verification
Data Source
AI summary
According to an example aspect of the present invention, there is provided an apparatus configured to receive a service request for a service provided by the apparatus, determine whether to provide the service based at least partly on an authentication based on a first identifier, comprised in an access token in the service request, and on a second identifier, comprised in a credential data element in the service request, wherein the authentication is successful when the first identifier and the second identifier identify a same network function instance or same network function instance set, and provide the service responsive to a result of the determination indicating the service is to be provided.


