Proximity Service Authorization via Network Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In existing proximity service authorization methods, the lack of authorization and authentication by the ProSe server leads to inadequate control over proximity services, resulting in poor service quality, and the method is limited to user equipment within the same public land mobile network, preventing cross-PLMN authorization.
Innovation Solution
A proximity service authorization method that involves a network-side entity receiving request messages from user equipment, determining authorization based on proximity service configuration data, and performing proper control over proximity services, even across different public land mobile networks, ensuring service quality and extending the authorization scope.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proximity service authorization is implemented through a ProSe server, then service quality and control capability are improved, but system complexity increases due to additional authorization infrastructure
Solution Approach 1:
The user equipment performs self-authorization by determining whether it can perform the proximity service based on configuration data stored locally, eliminating the need for a dedicated ProSe server and reducing system complexity while maintaining service quality control
Solution Approach 2:
The core network entity acts as an intermediary that provides proximity service configuration data to user equipment, enabling decentralized authorization without requiring direct ProSe server involvement in each authorization decision
2Reliability
If proximity service authorization is limited to the same public land mobile network, then network security and control are improved, but service coverage and applicability deteriorate
Solution Approach 1:
The authorization mechanism is designed to work across multiple public land mobile networks by using universal configuration data that can be provided by core network entities, allowing proximity services to function both within and across network boundaries
Solution Approach 2:
The solution extends authorization from a single-network dimension to a multi-network dimension by enabling cross-PLMN proximity services while maintaining security through configuration-based authorization that works across network boundaries
3Reliability
If data communication between user equipments routes through core network entities, then network control and security are improved, but transmission efficiency and bandwidth utilization deteriorate
Solution Approach 1:
The network architecture is segmented into core network control functions and direct user equipment communication paths, allowing control plane traffic to route through core network entities while user plane data communication occurs directly between proximate user equipments
Solution Approach 2:
The core network entity serves as a mediator that provides authorization and configuration services without being involved in the actual data transmission path, enabling direct peer-to-peer communication while maintaining network control
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention discloses a proximity service authorization method, an apparatus, and a system. A first network-side entity receives a first request message sent by first user equipment, where the first request message includes identity information of the first user equipment and an application identifier; and it is determined, at least according to acquired proximity service configuration data of the first user equipment, that the first user equipment can perform a proximity service corresponding to the application identifier. In this way, a first proximity service server authorizes and authenticates two user equipments that require a proximity service, and service quality of the proximity service of the user equipments can be ensured.