SCP Routing with NF-Set Tokens for eSBA Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authorization implementation mechanism for network functions (NFs) in the enhanced Service-Based Architecture (eSBA) of a 5G core network is inadequate, particularly in scenarios involving service communication proxies (SCPs) and network repositories.

Innovation Solution

A communication method and device that utilize tokens at a set granularity, including NF set or NF service set identifiers, to facilitate service control and authorization, using a network repository function (NRF) to generate and verify tokens for service consumers and communication proxies (SCPs) to ensure secure and efficient communication between NFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authorization mechanisms are used in eSBA architecture, then individual NF authorization can be implemented, but authorization complexity increases and set-level service control cannot be achieved

Engineering Contradiction:
Improveset-level service control capabilityVSAvoidauthorization mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization token into two distinct types: NF-level tokens for individual network function authorization and NF-set-level tokens for set-level service control. This segmentation allows the system to apply appropriate authorization granularity for different scenarios, achieving set-level control capability while maintaining manageable complexity by handling each level independently with dedicated token types.

Inventive Principle:
Principle #1Segmentation

2Reliability

If tokens are verified by multiple different producers in a producer set, then service access can be controlled, but verification consistency becomes difficult to maintain

Engineering Contradiction:
Improveservice access control reliabilityVSAvoidverification consistency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges the verification authority for NF-set-level tokens to a single designated producer within the producer set, rather than requiring each producer to independently verify. This merging approach ensures that all producers in the set use the same verification criteria and process, maintaining verification consistency across the entire set while still providing reliable service access control through the unified verification mechanism.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If fine-grained authorization is implemented at NF level, then precise service control is achieved, but authorization overhead increases

Engineering Contradiction:
Improveservice control granularityVSAvoidauthorization overhead
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements dynamic authorization granularity by allowing the system to switch between NF-level and NF-set-level token verification based on the service requirements. For services requiring fine-grained control, NF-level tokens provide precise authorization. For services that can tolerate coarser granularity, NF-set-level tokens reduce verification overhead. This dynamic adaptation optimizes the balance between control precision and authorization efficiency.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250274359A1Communication method and communications device
Publication Date: 2025.08.28 HUAWEI TECH CO LTD
  • US20250274359A1 patent drawing
  • US20250274359A1 patent drawing
  • US20250274359A1 patent drawing

AI summary

A communication method and a communications device are provided. The communication method may include: A service communication proxy (SCP) receives a service request from a service consumer, where the service request carries a token, and the token includes an NF set identifier of a service producer; and the SCP sends the service request to a service producer selected from an NF set of the service producer. Solutions in embodiments of this application help resolve a problem that different producers in an NF set verify tokens, and help implement convenient authorization in a set scenario in an eSBA.