Service Communication Proxy Authentication in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G mobile communication systems, managing authentication and authorization between network devices connected through a service communication proxy or repeater is challenging, particularly due to security concerns and limitations in direct communication between network function consumers and producers.
Innovation Solution
A method is provided where network function consumers and producers communicate through a service communication proxy, with the proxy authenticating the consumer using client credentials assertions and generating a service response message including the producer's credentials, ensuring secure authentication and authorization without direct mutual authentication between consumers and producers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network function consumers and producers communicate directly with each other, then authentication and authorization can be performed mutually between them, but security risks increase and system complexity increases when intermediaries like service communication proxies are introduced
Solution Approach 1:
The patent introduces a service communication proxy as an intermediary between network function consumers and producers. The proxy receives service requests from consumers, obtains credentials for the target producer, forwards requests with appropriate credentials, and handles authentication responses. This mediator approach maintains security by centralizing credential management while reducing overall system complexity through standardized interaction patterns.
Solution Approach 2:
The authentication and authorization process is segmented into distinct functional components: credential management, request forwarding, response handling, and token validation. Each component operates independently but coordinates through standardized interfaces, allowing the system to maintain security requirements while reducing complexity through modular design and clear separation of concerns.
2Reliability
If service communication proxies are introduced to manage authentication, then security is improved, but the complexity of authentication and authorization procedures increases
Solution Approach 1:
The service communication proxy is designed as a universal component that handles multiple authentication and authorization functions: obtaining credentials for different producers, forwarding various types of service requests, validating responses, and managing token lifecycles. This multi-functional approach consolidates security management in a single entity, improving security while reducing overall procedural complexity compared to implementing these functions at multiple points in the system.
3Reliability
If direct mutual authentication between consumers and producers is implemented, then security is enhanced, but the difficulty of detecting and measuring authentication states increases when proxies are involved
Solution Approach 1:
The patent implements feedback mechanisms where the service communication proxy receives authentication responses from producers and translates them into meaningful authentication states for consumers. The proxy provides feedback about successful authentication, credential validity, and authorization status, making the authentication state detectable and measurable despite the presence of the intermediary. This feedback loop maintains mutual authentication reliability while simplifying state verification.
Data Source
AI summary
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Provided is a method by which a network function (NF) service consumer entity operates in a wireless communication system. The method by which the NF service consumer entity operates includes transmitting, to a service communication proxy (SCP) entity, a service request message including at least one of a client credentials assertion (CCA) credential of the NF service consumer entity, or information related to an NF service producer entity, receiving, from the SCP entity, a service response message, wherein the service response message generated by the NF service producer entity is forwarded by the SCP entity to the NF service consumer entity, and authenticating the NF service producer entity based on the service response message.


