Restricted AMF Access via NRF Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for AMF re-allocation in 5G wireless networks require either an N14 interface or a well-connected network to act as a middle node for sharing security context between AMFs, with unclear information sharing limits, potentially compromising security by allowing complete access to the target AMF.

Innovation Solution

Implementing a method and system for restricted service access in 5G wireless networks using an OAuth framework, where a Network Repository Function (NRF) generates an access token with restricted scope, allowing only read-only access to security context, ensuring secure UE context transfer between AMFs without force writing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If complete access is granted to target AMF for security context sharing, then ease of operation is improved, but security is worsened due to potential unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security context access into distinct read and write operations. The target AMF is granted read access to retrieve security context from the initial AMF, but write access is restricted to prevent unauthorized modifications. This segmentation resolves the contradiction by enabling necessary operational access while blocking harmful write operations that could compromise security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism through the NRF (Network Repository Function) that mediates between the initial AMF and target AMF. The NRF manages the authorization and controls the scope of access, allowing the target AMF to read security context while preventing unauthorized writes. This intermediary resolves the contradiction by providing controlled access that balances operational needs with security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If restricted access control is implemented, then security is improved, but device complexity increases due to additional authorization mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent makes the NRF multi-functional by having it serve both as a network repository for storing AMF information and as an authorization server managing access control. This universal approach resolves the contradiction by consolidating multiple functions into a single entity, thereby providing robust security through centralized control without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If read-only access is granted to security context, then security is improved by preventing force writing, but productivity is worsened due to limited access capabilities

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent segments access rights into read and write operations, granting read access to the target AMF for retrieving security context while restricting write access to prevent force writing. This segmentation resolves the contradiction by enabling necessary productivity operations (reading context for seamless handover) while blocking harmful operations that would compromise security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240121610A1Methods and systems for restricted service access between network functions in wireless network
Publication Date: 2024.04.11 SAMSUNG ELECTRONICS CO LTD
  • US20240121610A1 patent drawing
  • US20240121610A1 patent drawing
  • US20240121610A1 patent drawing

AI summary

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Embodiments herein disclose a method for providing restricted service access in a wireless network by a first network entity (i.e., target AMF entity (400)). The method includes requesting a NRF entity (600) to grant an access-token to access a second network entity (i.e., initial AMF entity (300)). Further, the method includes receiving a message comprising a restricted service access to the second network entity based on the access-token. Further, the method includes sending a restricted UE context transfer request to the second network entity based on the message comprising the restricted service access. Further, the method includes receiving a UE context transfer response from the second network entity based on the restricted UE context transfer request.