NRF Trust Verification for Secure Network Function Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network function (NF) authentication systems in wireless communications systems lack real-time trust evaluation, allowing compromised NFs to remain unidentified and pose security risks, leading to potential network failures, data theft, and service disruptions.
Innovation Solution
Implement a Network Repository Function (NRF) that enforces access control and security policies using trust data and security state information to authenticate and authorize NFs, ensuring only trusted NFs can register, offer services, and consume services, with mechanisms for continuous trust evaluation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional NF authentication systems are used without real-time trust evaluation, then network operation simplicity is maintained, but network security deteriorates allowing compromised NFs to remain unidentified
Solution Approach 1:
The patent introduces a Network Repository Function (NRF) as an intermediary that centralizes trust evaluation and security policy enforcement. The NRF receives NF registration requests, evaluates their trustworthiness using security state information, and maintains a repository of trusted NFs. This mediator approach improves network security by filtering compromised NFs while keeping the complexity localized to the NRF rather than distributing it across all network elements.
Solution Approach 2:
The system performs preliminary trust evaluation during NF registration before the NF can provide services. The NRF assesses security state information, verifies authentication credentials, and determines trust levels in advance. This preliminary action ensures that only trusted NFs are admitted to the network, preventing compromised NFs from causing harm while maintaining operational simplicity for service providers.
2Measurement precision
If continuous trust evaluation is implemented, then identification of compromised NFs is improved, but processing time and computational resources increase
Solution Approach 1:
The patent implements periodic trust evaluation where the NRF reassesses the trustworthiness of registered NFs at scheduled intervals rather than continuously monitoring every action. This periodic approach maintains measurement precision by regularly updating trust assessments while reducing processing time and computational overhead compared to continuous evaluation, allowing the system to balance security accuracy with operational efficiency.
3Reliability
If strict access control policies are enforced for all NF services, then network security is improved, but service operation flexibility deteriorates
Solution Approach 1:
The patent applies local quality by implementing differentiated access control policies based on the specific service type, NF role, and trust level. Instead of uniform strict controls across all services, the NRF evaluates each service request against appropriate security policies tailored to that context. This allows high-security enforcement for critical services while permitting greater flexibility for less sensitive operations, maintaining both security and adaptability.
Solution Approach 2:
The system dynamically adjusts access control strictness based on real-time trust evaluation results. NFs with higher trust levels receive more flexible access permissions, while those with lower trust levels undergo stricter verification. This dynamic approach allows the system to adapt security measures to the actual risk level, improving service operation flexibility for trusted NFs while maintaining strong security controls where needed.
Data Source
AI summary
Various aspects of the present disclosure relate to a network repository function (NRF) that receives a first signaling as a network function (NF) request from a NF, the NF request including a NF type, a NF identifier (ID), and NF security state information. The NRF verifies a NF security state based on the NF ID and the NF security state information. The NRF transmits a second signaling as a NF response, where the NF response includes a security verification of the NF request.


