NF Management Device for Centralized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network function (NF) management in evolved packet core (EPC) architectures is inflexible, requiring lengthy redesigns and high costs to introduce new NFs, leading to delayed network service releases due to solidified service features and limited access control between NF components, which can result in network rule violations.

Innovation Solution

An NF management method and device that centralizes discovery and access control between NF components by using an NF management device to process NF discovery requests, determine access based on preset discovery policies, and ensure compliance with network rules, allowing NF components to access only authorized NF components within specified network slices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If new NF is introduced to support user requirements, then service capability is improved, but processing logic and procedure interaction of NE needs to be redefined and redesigned, resulting in long development cycle and high costs

Engineering Contradiction:
Improveservice capabilityVSAvoiddevelopment cycle
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the network function into NF components that can be independently deployed and managed. Each NF component can be discovered and accessed through standardized interfaces, allowing new services to be introduced by adding or modifying individual NF components without redesigning the entire network element processing logic and procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal NF management mechanism that can handle multiple NF types and service scenarios through standardized discovery and access procedures. The NF component discovery mechanism and access authorization framework provide multi-functional support for different network services, eliminating the need for custom redesign for each new service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If access control between NF components is implemented to prevent rule violations, then network security is improved, but access complexity between NF components increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an NF management device as an intermediary that centralizes the discovery and access control of NF components. This mediator handles the complex authorization logic by receiving NF component discovery requests, determining access authorization based on discovery policies, and returning authorized NF component information, thereby simplifying the access control implementation for individual NF components while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the NF management device provides authorization decisions based on discovery policies to NF components. The system continuously monitors and enforces access rules, providing feedback on authorized access patterns and maintaining network security through policy-based control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3883188B1Network function NF management method and NF management device
Publication Date: 2023.09.27 HUAWEI TECH CO LTD
  • EP3883188B1 patent drawingFigure 1
  • EP3883188B1 patent drawingFigure 2
  • EP3883188B1 patent drawingFigure 3

AI summary

This application discloses an NF management method and an NF management device, to perform centralized management on discovery and access between NF components, thereby facilitating a normal network operation. The method in embodiments of this application includes: receiving an NF discovery request sent by a first NF component, where the NF discovery request includes a second NF identifier, and the second NF identifier is used to indicate a second NF; obtaining component information of a second NF component based on the second NF identifier, where the second NF component has the second NF, and the component information includes a discovery policy of the second NF component and a second NF component identifier; determining, based on the discovery policy in the component information, whether the first NF component can access the second NF component; and if yes, sending the second NF component identifier to the first NF component.