Storage Function Network Element Authorization for Location Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing 5G communication system's location service in a non-public network (PN) faces security issues due to direct data access from a public network, leading to user data leakage.
Innovation Solution
Implement a communication method where a storage function network element in a second network determines, based on network permissions, whether to share terminal device data with a gateway mobile location center in a first network, thereby enhancing data security by preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the GMLC in the non-public network directly accesses the storage function network element in the public network through an existing interface, then the location service can be provided, but user data leakage occurs
Solution Approach 1:
The patent introduces an authorization verification mechanism as an intermediary between the GMLC and the storage function network element. The storage function network element acts as a mediator that verifies whether the GMLC has authorization to access terminal device data before allowing access, thus preventing unauthorized data leakage while still enabling legitimate location services.
Solution Approach 2:
The patent implements preliminary authorization verification before data access. The storage function network element determines in advance whether the GMLC is authorized to obtain terminal device data by checking authorization information in the request message, preventing unauthorized access before it can occur.
2Reliability
If the storage function network element verifies network permissions for every data access request, then data security is improved, but processing time and resource overhead increase
Solution Approach 1:
The patent applies partial verification by checking only essential authorization information in the request message rather than performing comprehensive security checks. The storage function network element verifies the presence and validity of authorization information without implementing overly complex verification procedures, achieving adequate security while minimizing processing overhead.
Data Source
AI summary
A communication method is provided, including: A storage function network element in a second network receives a first request message that is from a gateway mobile location center GMLC in a first network and that is used to request to obtain data of a terminal device, where the first request message includes an identifier of the terminal device. In response to the first request message, the storage function network element determines whether the first network is a network that is allowed to obtain the data of the terminal device, and obtains a determining result. Further, based on the determining result, the storage function network element determines whether to send the data of the terminal device to the GMLC.


