NRF Trust Verification for Secure Network Function Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network function (NF) authentication systems in wireless communications systems lack real-time trust evaluation, allowing compromised NFs to remain unidentified and pose security risks, leading to potential network failures, data theft, and service disruptions.

Innovation Solution

Implement a Network Repository Function (NRF) that enforces access control and security policies using trust data and security state information to authenticate and authorize NFs, ensuring only trusted NFs can register, offer services, and consume services, with mechanisms for continuous trust evaluation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional NF authentication systems are used without real-time trust evaluation, then network operation simplicity is maintained, but network security deteriorates allowing compromised NFs to remain unidentified

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Network Repository Function (NRF) as an intermediary that centralizes trust evaluation and security policy enforcement. The NRF receives NF registration requests, evaluates their trustworthiness using security state information, and maintains a repository of trusted NFs. This mediator approach improves network security by filtering compromised NFs while keeping the complexity localized to the NRF rather than distributing it across all network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary trust evaluation during NF registration before the NF can provide services. The NRF assesses security state information, verifies authentication credentials, and determines trust levels in advance. This preliminary action ensures that only trusted NFs are admitted to the network, preventing compromised NFs from causing harm while maintaining operational simplicity for service providers.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If continuous trust evaluation is implemented, then identification of compromised NFs is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvetrust evaluation accuracyVSAvoidauthentication processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements periodic trust evaluation where the NRF reassesses the trustworthiness of registered NFs at scheduled intervals rather than continuously monitoring every action. This periodic approach maintains measurement precision by regularly updating trust assessments while reducing processing time and computational overhead compared to continuous evaluation, allowing the system to balance security accuracy with operational efficiency.

Inventive Principle:
Principle #19Periodic action

3Reliability

If strict access control policies are enforced for all NF services, then network security is improved, but service operation flexibility deteriorates

Engineering Contradiction:
Improveaccess control securityVSAvoidservice operation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing differentiated access control policies based on the specific service type, NF role, and trust level. Instead of uniform strict controls across all services, the NRF evaluates each service request against appropriate security policies tailored to that context. This allows high-security enforcement for critical services while permitting greater flexibility for less sensitive operations, maintaining both security and adaptability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts access control strictness based on real-time trust evaluation results. NFs with higher trust levels receive more flexible access permissions, while those with lower trust levels undergo stricter verification. This dynamic approach allows the system to adapt security measures to the actual risk level, improving service operation flexibility for trusted NFs while maintaining strong security controls where needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250379868A1Security management of trusted network functions
Publication Date: 2025.12.11 LENOVO (SINGAPORE) PTE LTD
  • US20250379868A1 patent drawing
  • US20250379868A1 patent drawing
  • US20250379868A1 patent drawing

AI summary

Various aspects of the present disclosure relate to a network repository function (NRF) that receives a first signaling as a network function (NF) request from a NF, the NF request including a NF type, a NF identifier (ID), and NF security state information. The NRF verifies a NF security state based on the NF ID and the NF security state information. The NRF transmits a second signaling as a NF response, where the NF response includes a security verification of the NF request.