Restricted AMF Access via NRF Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for AMF re-allocation in 5G wireless networks require either an N14 interface or a well-connected network to act as a middle node for sharing security context between AMFs, with unclear information sharing limits, potentially compromising security by allowing complete access to the target AMF.
Innovation Solution
Implementing a method and system for restricted service access in 5G wireless networks using an OAuth framework, where a Network Repository Function (NRF) generates an access token with restricted scope, allowing only read-only access to security context, ensuring secure UE context transfer between AMFs without force writing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If complete access is granted to target AMF for security context sharing, then ease of operation is improved, but security is worsened due to potential unauthorized access
Solution Approach 1:
The patent segments the security context access into distinct read and write operations. The target AMF is granted read access to retrieve security context from the initial AMF, but write access is restricted to prevent unauthorized modifications. This segmentation resolves the contradiction by enabling necessary operational access while blocking harmful write operations that could compromise security.
Solution Approach 2:
The patent introduces an intermediary mechanism through the NRF (Network Repository Function) that mediates between the initial AMF and target AMF. The NRF manages the authorization and controls the scope of access, allowing the target AMF to read security context while preventing unauthorized writes. This intermediary resolves the contradiction by providing controlled access that balances operational needs with security requirements.
2Object-affected harmful factors
If restricted access control is implemented, then security is improved, but device complexity increases due to additional authorization mechanisms
Solution Approach 1:
The patent makes the NRF multi-functional by having it serve both as a network repository for storing AMF information and as an authorization server managing access control. This universal approach resolves the contradiction by consolidating multiple functions into a single entity, thereby providing robust security through centralized control without proportionally increasing overall system complexity.
3Object-affected harmful factors
If read-only access is granted to security context, then security is improved by preventing force writing, but productivity is worsened due to limited access capabilities
Solution Approach 1:
The patent segments access rights into read and write operations, granting read access to the target AMF for retrieving security context while restricting write access to prevent force writing. This segmentation resolves the contradiction by enabling necessary productivity operations (reading context for seamless handover) while blocking harmful operations that would compromise security.
Data Source
AI summary
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Embodiments herein disclose a method for providing restricted service access in a wireless network by a first network entity (i.e., target AMF entity (400)). The method includes requesting a NRF entity (600) to grant an access-token to access a second network entity (i.e., initial AMF entity (300)). Further, the method includes receiving a message comprising a restricted service access to the second network entity based on the access-token. Further, the method includes sending a restricted UE context transfer request to the second network entity based on the message comprising the restricted service access. Further, the method includes receiving a UE context transfer response from the second network entity based on the restricted UE context transfer request.


