Service Communication Proxy Authentication in 5G Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G communication systems face challenges in authentication and authority management between network devices, particularly in managing data access and reception in mobile communication systems, which is crucial for secure and efficient network operations.
Innovation Solution
A method and apparatus that utilize a service communication proxy (SCP) to relay communication between network function (NF) consumers and producers, involving discovery procedures, access token requests, and client credentials assertions to ensure secure and authorized service requests and responses, leveraging NF repository functions (NRF) for authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network devices perform direct authentication and authorization without a service communication proxy, then the authentication process is simpler, but security and authority management between network devices deteriorates
Solution Approach 1:
The patent introduces a Service Communication Proxy (SCP) as an intermediary component between NF consumers and NF producers. The SCP receives service requests from NF consumers, performs authentication and authorization by interacting with the NRF, and forwards validated requests to NF producers. This mediator approach maintains security and authority management while keeping the authentication process manageable through standardized procedures.
2Reliability
If a service communication proxy is introduced for authentication and authorization, then security and authority management is improved, but device complexity increases
Solution Approach 1:
The Service Communication Proxy (SCP) is designed as a universal component that handles multiple functions: service request forwarding, authentication with NRF, authorization verification, and response routing. By consolidating these diverse functions into a single multi-functional proxy, the system achieves improved security and authority management without proportionally increasing overall system complexity.
Solution Approach 2:
The patent segments the authentication and authorization functions from the core NF consumer-producer communication path, placing them in a separate SCP component. This segmentation allows the authentication logic to be independently managed and optimized, reducing the complexity burden on individual NF instances while maintaining comprehensive security control.
3Productivity
If direct service requests are made between NF consumers and producers without token-based authentication, then communication efficiency is higher, but security deteriorates
Solution Approach 1:
The system performs preliminary authentication and obtains access tokens from the NRF before actual service requests are made. The SCP stores these tokens and uses them for subsequent service requests, eliminating the need for repeated authentication handshakes. This preliminary action approach maintains high communication efficiency for validated requests while ensuring security through pre-verified credentials.
Solution Approach 2:
Once authentication is established and tokens are obtained, the SCP maintains continuous authorized communication between NF consumers and producers without interrupting the service flow. The token-based authentication enables uninterrupted service requests while maintaining security, as the continuous action is already validated and authorized.
Data Source
AI summary
A communication method of a network function (NF) consumer in a wireless communication system according to an embodiment of the disclosure may include: receiving, from an NF repository function (NRF), a discovery response message in a discovery procedure, the discovery response message including NF set information including NF instance identifiers (IDs) for providing a service; transmitting, to the NRF, an access token request message including an NF producer instance ID; receiving, from the NRF, an access token response message including an access token; transmitting, to a service communication proxy (SCP), a service request message to be transmitted to an NF producer instance, the service request message including the token received from the NRF, a client credentials assertion (CCA) of the NF consumer, and the NF set information; and receiving, from the SCP, a service response message including a CCA of the NF producer instance.


