Request-Specific Network Authorization via Signed Proxy Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network function discovery and authorization procedures in communication networks are inadequate for ensuring secure and request-specific authorization, particularly in indirect communication scenarios, leading to potential vulnerabilities from malicious service communication proxies.

Innovation Solution

Implementing a system where a network repository function issues a separate authorization token to be signed by the network function consumer, which is then verified by the service communication proxy, ensuring request-specific authorization and protection against malicious proxies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a service communication proxy is used for indirect communication in network functions, then communication flexibility and service discovery are improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a service communication proxy as an intermediary entity that mediates between network function consumers and providers. The proxy handles service discovery, authentication, and authorization on behalf of the consumer, enabling flexible indirect communication while maintaining security through centralized control and verification mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization actions before allowing service communication. The service communication proxy performs authentication with the network function consumer and issues authorization tokens before permitting access to network functions, preventing unauthorized access in advance.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If authorization tokens are issued without request-specific verification, then authorization speed is improved, but unauthorized access and malicious proxy risks increase

Engineering Contradiction:
Improveauthorization speedVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authorization process into distinct components: authentication phase (where the proxy verifies the consumer's identity) and authorization phase (where request-specific authorization tokens are issued). This segmentation allows efficient authentication while maintaining security through request-specific verification in the authorization phase.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by issuing authorization tokens with specific scopes and permissions tailored to each individual request rather than providing blanket authorization. Each authorization token contains localized authorization information relevant to the specific service request, enabling both speed and security.

Inventive Principle:
Principle #3Local quality

3Reliability

If cryptographic signatures are verified for each authorization token, then request-specific authorization security is improved, but processing complexity and time increase

Engineering Contradiction:
Improverequest-specific authorizationVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary authentication actions during the authentication phase, where the service communication proxy verifies the network function consumer's credentials and issues an authorization token. This preliminary action establishes trust before the more complex cryptographic verification is needed during the authorization phase, streamlining the overall process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the service communication proxy receives authorization tokens from the network function consumer, verifies their cryptographic signatures, and provides feedback by issuing access tokens. This feedback loop ensures request-specific authorization while maintaining efficient processing through structured verification steps.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4017052B1Authorization of network request
Publication Date: 2026.04.15 NOKIA TECHNOLOGIES OY
  • EP4017052B1 patent drawingFigure 1
  • EP4017052B1 patent drawingFigure 2
  • EP4017052B1 patent drawingFigure 3

AI summary

According to an example aspect of the present invention, there is provided an apparatus configured at least to: receive, from a service communication proxy, a request for an access token which authorizes access to a service at a network function provider, transmit an authorization token to the service communication proxy, the authorization token being specific to the request, and provide the access token to the service communication proxy responsive to determining that a cryptographic signature of a network function consumer on a signed version of the authorization token, received in the apparatus from the service communication proxy, is correct. The apparatus may work in a network serving user equipments, for example.