NRF Service Discovery via TLS Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G network service-based architecture, network function (NF) services across different network slices need to be isolated and dynamically discovered, posing challenges in service registration and discovery due to varying resource requirements and performance indicators, as well as the dynamic deployment of NFs.
Innovation Solution
A method and device for NF service discovery using a network function repository function (NRF) that performs TLS/DTLS two-way authentication to verify service names and management domain names, allowing NFs to query service addresses within or across network slices without modifying existing NFs, using digital certificates with extension fields for service security and compatibility with existing TLS/DNS standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NFs in different network slices are isolated to meet SLA requirements, then service security and performance isolation are improved, but service discovery complexity and deployment flexibility deteriorate
Solution Approach 1:
The patent segments the service discovery mechanism by introducing slice-specific domain names (e.g., slice1.service.example.com, slice2.service.example.com) for different network slices. This allows isolated service discovery within each slice while maintaining overall system security. The NRF maintains separate service registries for different slices, enabling independent service management and discovery processes for each slice.
Solution Approach 2:
The NRF acts as an intermediary between NFs in different slices and the service discovery process. It receives service registration requests from NFs, stores service information in slice-specific registries, and handles service discovery queries by returning appropriate service addresses based on the requesting NF's slice context. This intermediary mechanism simplifies the discovery process while maintaining slice isolation.
2Adaptability or versatility
If NFs are dynamically deployed in network slices, then network service innovation and adaptability are improved, but service registration and discovery reliability deteriorate
Solution Approach 1:
The patent implements preliminary action by requiring NFs to register their service information with the NRF before becoming accessible to other NFs. The NRF pre-establishes service registries for each network slice and maintains updated service catalogs. This preliminary registration and pre-establishment of service information ensures that dynamic NF deployments are reliably tracked and discoverable from the outset.
Solution Approach 2:
The system implements feedback mechanisms where the NRF continuously monitors and updates service registration status. When NFs are dynamically deployed or modified, they provide feedback to the NRF through registration requests, and the NRF provides feedback by confirming registration or returning service discovery information. This bidirectional feedback ensures reliability in dynamic deployment scenarios.
3Reliability
If TLS/DTLS two-way authentication is implemented for service discovery, then security is improved, but authentication process complexity and time consumption worsen
Solution Approach 1:
The patent applies preliminary action by performing TLS/DTLS two-way authentication during the initial service registration phase with the NRF. NFs authenticate themselves to the NRF before service discovery operations. This preliminary authentication establishes secure communication channels in advance, so that subsequent service discovery interactions within the slice inherit this security context, reducing the need for repeated full authentication cycles.
Data Source
AI summary
Embodiments of this application provide a network function service discovery method and a device. The method performed by an NRF includes: after establishing a communication connection to the NF, obtaining a digital certificate of the NF in a TLS or DTLS two-way authentication process, where the digital certificate of the NF carries a service name of the NF, a service name list on which the NF relies, and a service name list that relies on the NF; receiving a query request for querying an address of a target service that is sent by the NF, where the query request carries a complete domain name of the target service; and performing verification based on the service name of the target service and the digital certificate of the NF, and sending the address of the target service to the NF when the verification succeeds. Therefore, the NF services are discovered.


