Service Communication Proxy Authentication in 5G Core Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication systems face challenges in authentication and authority management between network devices, particularly in managing data access and reception in mobile communication systems, which is crucial for secure and efficient network operations.

Innovation Solution

A method and apparatus that utilize a service communication proxy (SCP) to relay communication between network function (NF) consumers and producers, involving discovery procedures, access token requests, and client credentials assertions to ensure secure and authorized service requests and responses, leveraging NF repository functions (NRF) for authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network devices perform direct authentication and authorization without a service communication proxy, then the authentication process is simpler, but security and authority management between network devices deteriorates

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity and authority management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Service Communication Proxy (SCP) as an intermediary component between NF consumers and NF producers. The SCP receives service requests from NF consumers, performs authentication and authorization by interacting with the NRF, and forwards validated requests to NF producers. This mediator approach maintains security and authority management while keeping the authentication process manageable through standardized procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a service communication proxy is introduced for authentication and authorization, then security and authority management is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and authority managementVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Service Communication Proxy (SCP) is designed as a universal component that handles multiple functions: service request forwarding, authentication with NRF, authorization verification, and response routing. By consolidating these diverse functions into a single multi-functional proxy, the system achieves improved security and authority management without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authentication and authorization functions from the core NF consumer-producer communication path, placing them in a separate SCP component. This segmentation allows the authentication logic to be independently managed and optimized, reducing the complexity burden on individual NF instances while maintaining comprehensive security control.

Inventive Principle:
Principle #1Segmentation

3Productivity

If direct service requests are made between NF consumers and producers without token-based authentication, then communication efficiency is higher, but security deteriorates

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication and obtains access tokens from the NRF before actual service requests are made. The SCP stores these tokens and uses them for subsequent service requests, eliminating the need for repeated authentication handshakes. This preliminary action approach maintains high communication efficiency for validated requests while ensuring security through pre-verified credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once authentication is established and tokens are obtained, the SCP maintains continuous authorized communication between NF consumers and producers without interrupting the service flow. The token-based authentication enables uninterrupted service requests while maintaining security, as the continuous action is already validated and authorized.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12256318B2Method and apparatus for authentication between core network devices in mobile communication system
Publication Date: 2025.03.18 SAMSUNG ELECTRONICS CO LTD
  • US12256318B2 patent drawing
  • US12256318B2 patent drawing
  • US12256318B2 patent drawing

AI summary

A communication method of a network function (NF) consumer in a wireless communication system according to an embodiment of the disclosure may include: receiving, from an NF repository function (NRF), a discovery response message in a discovery procedure, the discovery response message including NF set information including NF instance identifiers (IDs) for providing a service; transmitting, to the NRF, an access token request message including an NF producer instance ID; receiving, from the NRF, an access token response message including an access token; transmitting, to a service communication proxy (SCP), a service request message to be transmitted to an NF producer instance, the service request message including the token received from the NRF, a client credentials assertion (CCA) of the NF consumer, and the NF set information; and receiving, from the SCP, a service response message including a CCA of the NF producer instance.