UDR Authorization Scope Control for Network Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authorization protocols in network function service consumers lack the ability to control which data forms are accessed and the types of actions performed on them within a Unified Data Repository (UDR), leading to insufficient security and access management.
Innovation Solution
An advanced authorization framework that utilizes access tokens, such as JSON Web Tokens, to manage data access and actions by distinguishing the scope of requests from Network Function (NF) service consumers, enabling the UDR to authorize specific data access and actions based on predefined profiles and scopes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If current authorization protocols are used, then network function service consumers can access data in the Unified Data Repository, but the system lacks the ability to control which data forms are accessed and the types of actions performed on them
Solution Approach 1:
The patent segments the authorization control into multiple dimensions: data form type, action type, and scope. The access token includes distinct fields for data form identifier, action identifier, and scope identifier, allowing granular control over what data can be accessed and what operations can be performed. This segmentation enables the system to control specific data forms and actions separately, resolving the contradiction between access capability and security control.
Solution Approach 2:
The patent implements preliminary action by establishing authorization rules and access tokens before data access occurs. The NF service consumer must obtain an access token with predefined scopes and permissions before accessing the UDR. The authorization framework pre-validates the requested data form, action, and scope against stored authorization rules, preventing unauthorized access before it can occur. This preliminary authorization mechanism ensures security while maintaining versatile data access control.
2Reliability
If granular control over data access and actions is implemented, then security and control are enhanced, but the authorization framework complexity increases
Solution Approach 1:
The patent applies universality by designing a multi-functional access token that handles multiple authorization dimensions simultaneously. A single access token structure encompasses data form identification, action authorization, and scope limitation all in one mechanism. The NF service consumer interacts with a unified authorization interface that manages all these aspects through standard token validation, avoiding the need for separate complex control systems for each authorization dimension. This universal approach enhances security while managing framework complexity.
Solution Approach 2:
The patent introduces an intermediary authorization framework that mediates between the NF service consumer and the UDR. This intermediary layer handles the complex validation of data forms, actions, and scopes by comparing access token contents against stored authorization rules. The intermediary absorbs the complexity of granular control logic, presenting a simplified interface to both the consumer and the data repository. This mediator pattern enhances security through detailed control while shielding the system from excessive complexity.
3Reliability
If access tokens with scope differentiation are used, then data integrity and security are improved, but the authorization protocol overhead increases
Solution Approach 1:
The patent applies partial action by implementing scope differentiation only where needed for security and integrity protection. The access token includes scope identifiers that differentiate between various levels of data access (e.g., read-only, read-write, administrative scopes). This partial implementation of scope control focuses authorization overhead on critical data access scenarios while maintaining efficiency for routine operations. The scope mechanism is activated selectively based on the sensitivity and importance of the data being accessed, improving data integrity without excessive protocol overhead across all operations.
Data Source
AI summary
Systems and methods for an advanced authorization framework that provides advanced network security and control of network hosted data. The framework provides computerized mechanisms that dictate a control of which data is accessible by particular network components, and which operations the privileged components are enabled to be performed. The framework can allow Network Function (NF) service consumers to discover and request network data that is specific to the operational status (e.g., PCF can request policy data). The framework provides an access scope of the NF service consumer that manages which hosted data is accessible, and to what degree it can be manipulated, if at all.


