NWDAF Token Authorization for Secure Inter-PLMN Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of improving security in inter-PLMN information sharing during roaming scenarios is a critical issue that needs urgent resolution.

Innovation Solution

A communication method where a second NWDAF sends a request message to a first NWDAF with a token containing indications of allowed information, enabling the first NWDAF to authenticate and authorize the second NWDAF's access, reducing configuration complexity and overheads by using a shared token for multiple information requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for inter-PLMN information sharing, then security can be maintained, but authentication complexity and configuration overhead increase significantly

Engineering Contradiction:
Improvesecurity of inter-PLMN information sharingVSAvoidauthentication complexity and configuration overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a token as an intermediary authentication mechanism between NWDAFs of different PLMNs. The token, generated by the home PLMN's NWDAF, serves as a mediator that carries authorization information without requiring complex direct authentication protocols between visiting and home NWDAFs. This reduces authentication complexity while maintaining security through the token-based authorization framework.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by generating a token in advance at the home PLMN's NWDAF before the actual information sharing occurs. The token contains pre-configured authorization information that enables subsequent information requests without repeated complex authentication. This preliminary action reduces configuration overhead and simplifies the authentication process for multiple information exchanges.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple separate authentication mechanisms are implemented for different information requests, then security is enhanced, but communication overheads and processing time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcommunication overheads and processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a universal token that can be used for multiple different information requests between NWDAFs. Instead of implementing separate authentication mechanisms for each information type, a single token serves multiple functions by carrying authorization information that covers various data sharing scenarios. This multi-functionality reduces communication overheads and processing time while maintaining security through the comprehensive authorization framework embedded in the token.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250365206A1Communication method, system, and apparatus
Publication Date: 2025.11.27 HUAWEI TECH CO LTD
  • US20250365206A1 patent drawing
  • US20250365206A1 patent drawing
  • US20250365206A1 patent drawing

AI summary

A communication method, system, and apparatus are provided, to improve security of inter-PLMN information sharing. In this application, the communication method includes: A second NWDAF in a second PLMN sends a first request message to a first NWDAF in a first PLMN. Correspondingly, the first NWDAF receives the first request message from the second NWDAF, where the first request message includes a token and an indication of first information requested by the second NWDAF, the token includes indications of a plurality of pieces of information, and the plurality of pieces of information are allowed to be accessed by the second PLMN (or the second NWDAF). When the indications of the plurality of pieces of information that are included in the token include the indication of the first information, the first NWDAF sends the first information to the second NWDAF.