Request-Specific Network Authorization via Signed Proxy Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network function discovery and authorization procedures in communication networks are inadequate for ensuring secure and request-specific authorization, particularly in indirect communication scenarios, leading to potential vulnerabilities from malicious service communication proxies.
Innovation Solution
Implementing a system where a network repository function issues a separate authorization token to be signed by the network function consumer, which is then verified by the service communication proxy, ensuring request-specific authorization and protection against malicious proxies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a service communication proxy is used for indirect communication in network functions, then communication flexibility and service discovery are improved, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent introduces a service communication proxy as an intermediary entity that mediates between network function consumers and providers. The proxy handles service discovery, authentication, and authorization on behalf of the consumer, enabling flexible indirect communication while maintaining security through centralized control and verification mechanisms.
Solution Approach 2:
The patent implements preliminary authentication and authorization actions before allowing service communication. The service communication proxy performs authentication with the network function consumer and issues authorization tokens before permitting access to network functions, preventing unauthorized access in advance.
2Productivity
If authorization tokens are issued without request-specific verification, then authorization speed is improved, but unauthorized access and malicious proxy risks increase
Solution Approach 1:
The patent segments the authorization process into distinct components: authentication phase (where the proxy verifies the consumer's identity) and authorization phase (where request-specific authorization tokens are issued). This segmentation allows efficient authentication while maintaining security through request-specific verification in the authorization phase.
Solution Approach 2:
The patent applies local quality by issuing authorization tokens with specific scopes and permissions tailored to each individual request rather than providing blanket authorization. Each authorization token contains localized authorization information relevant to the specific service request, enabling both speed and security.
3Reliability
If cryptographic signatures are verified for each authorization token, then request-specific authorization security is improved, but processing complexity and time increase
Solution Approach 1:
The patent performs preliminary authentication actions during the authentication phase, where the service communication proxy verifies the network function consumer's credentials and issues an authorization token. This preliminary action establishes trust before the more complex cryptographic verification is needed during the authorization phase, streamlining the overall process.
Solution Approach 2:
The patent implements a feedback mechanism where the service communication proxy receives authorization tokens from the network function consumer, verifies their cryptographic signatures, and provides feedback by issuing access tokens. This feedback loop ensures request-specific authorization while maintaining efficient processing through structured verification steps.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to an example aspect of the present invention, there is provided an apparatus configured at least to: receive, from a service communication proxy, a request for an access token which authorizes access to a service at a network function provider, transmit an authorization token to the service communication proxy, the authorization token being specific to the request, and provide the access token to the service communication proxy responsive to determining that a cryptographic signature of a network function consumer on a signed version of the authorization token, received in the apparatus from the service communication proxy, is correct. The apparatus may work in a network serving user equipments, for example.