SCP Routing with NF-Set Tokens for eSBA Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing authorization implementation mechanism for network functions (NFs) in the enhanced Service-Based Architecture (eSBA) of a 5G core network is inadequate, particularly in scenarios involving service communication proxies (SCPs) and network repositories.
Innovation Solution
A communication method and device that utilize tokens at a set granularity, including NF set or NF service set identifiers, to facilitate service control and authorization, using a network repository function (NRF) to generate and verify tokens for service consumers and communication proxies (SCPs) to ensure secure and efficient communication between NFs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authorization mechanisms are used in eSBA architecture, then individual NF authorization can be implemented, but authorization complexity increases and set-level service control cannot be achieved
Solution Approach 1:
The patent segments the authorization token into two distinct types: NF-level tokens for individual network function authorization and NF-set-level tokens for set-level service control. This segmentation allows the system to apply appropriate authorization granularity for different scenarios, achieving set-level control capability while maintaining manageable complexity by handling each level independently with dedicated token types.
2Reliability
If tokens are verified by multiple different producers in a producer set, then service access can be controlled, but verification consistency becomes difficult to maintain
Solution Approach 1:
The patent merges the verification authority for NF-set-level tokens to a single designated producer within the producer set, rather than requiring each producer to independently verify. This merging approach ensures that all producers in the set use the same verification criteria and process, maintaining verification consistency across the entire set while still providing reliable service access control through the unified verification mechanism.
3Measurement precision
If fine-grained authorization is implemented at NF level, then precise service control is achieved, but authorization overhead increases
Solution Approach 1:
The patent implements dynamic authorization granularity by allowing the system to switch between NF-level and NF-set-level token verification based on the service requirements. For services requiring fine-grained control, NF-level tokens provide precise authorization. For services that can tolerate coarser granularity, NF-set-level tokens reduce verification overhead. This dynamic adaptation optimizes the balance between control precision and authorization efficiency.
Data Source
AI summary
A communication method and a communications device are provided. The communication method may include: A service communication proxy (SCP) receives a service request from a service consumer, where the service request carries a token, and the token includes an NF set identifier of a service producer; and the SCP sends the service request to a service producer selected from an NF set of the service producer. Solutions in embodiments of this application help resolve a problem that different producers in an NF set verify tokens, and help implement convenient authorization in a set scenario in an eSBA.


