Service Provision Logging for Network Function Traceability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 3GPP service-based architecture, there is no mechanism to trace the activities of network functions (NFs), network repository functions (NRFs), and service communication proxies (SCPs), making it difficult to detect malicious behavior, such as unauthorized service access or token misuse, which can lead to security issues and financial losses.
Innovation Solution
Implementing a mechanism to generate and analyze logs associated with service provisioning, allowing devices to receive and report logs from NFs, NRFs, and SCPs, which include details like access token requests, service access status, and token validity, to facilitate the analysis of service provision and detect potential malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a service-based architecture with NF, NRF, and SCP is implemented to enable service provisioning, then service accessibility and flexibility are improved, but the ability to trace and detect malicious behavior deteriorates due to lack of logging mechanisms
Solution Approach 1:
The patent introduces a logging mechanism as an intermediary component that intercepts and records activities between NF, NRF, and SCP. The log generator captures service requests, access token operations, and provisioning events, creating a traceable record without disrupting the service flow. This mediator approach enables monitoring while preserving the service-based architecture's flexibility.
Solution Approach 2:
The patent implements feedback through log collection and analysis mechanisms that provide information about service provisioning activities. The system collects logs from multiple sources, analyzes them to detect anomalies or malicious behavior, and can trigger responses based on the analysis results. This feedback loop enables continuous monitoring and improvement of security while maintaining service accessibility.
2Difficulty of detecting and measuring
If logging mechanisms are added to trace NF, NRF, and SCP activities, then detection capability is improved, but system complexity increases
Solution Approach 1:
The patent segments the logging functionality into distinct components: log generation at the NF level, additional logging at NRF and SCP levels, and separate log collection and analysis mechanisms. This segmentation allows each component to handle logging independently, reducing the complexity burden on any single element while collectively providing comprehensive tracing capability.
Solution Approach 2:
The patent creates a universal logging framework that can be applied across different network functions (NF, NRF, SCP) with a common structure. The log format, collection mechanism, and analysis approach are standardized and can be reused throughout the system, reducing overall complexity compared to implementing separate custom logging solutions for each component.
3Reliability
If comprehensive logs are generated from NF, NRF, and SCP to facilitate service provision analysis, then security monitoring is improved, but information processing load increases
Solution Approach 1:
The patent extracts only the essential and relevant information from service provisioning activities into logs, rather than recording all possible data. The logging mechanism focuses on capturing key events such as service requests, access token operations, and provisioning outcomes, filtering out redundant information. This extraction approach maintains security monitoring capability while reducing the volume of data that requires processing and storage.
Data Source
AI summary
Example embodiments of the present disclosure relate to devices, methods and computer readable storage media for service provisioning to facilitate analysis of a service from a network function (NF). In example embodiments, one or more logs are received from at least one of a first NF, a network repository function (NRF) and a service communication proxy (SCP). The one or more logs are associated with a service from a second NF. Further, analysis of provision of the service from the second NF is facilitated based on the one or more logs.


