IP Library Granted Patent US 12676841
Granted Patent B2
US 12676841 · App. 17/568,102 · Granted Jul 7, 2026

Authentication of network request

Inventors: Saurabh Khare (Bangalore, IN); Chaitanya Aggarwal (Munich, DE); Anja Jerichow (Grafing bei Munich, DE)
Assignee: Nokia Technologies Oy
H04L63/08H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12676841
App. No.
17/568,102
Granted
Jul 7, 2026
Kind
B2
Abstract

According to an example aspect of the present invention, there is provided an apparatus configured to receive a service request for a service provided by the apparatus, determine whether to provide the service based at least partly on an authentication based on a first identifier, comprised in an access token in the service request, and on a second identifier, comprised in a credential data element in the service request, wherein the authentication is successful when the first identifier and the second identifier identify a same network function instance or same network function instance set, and provide the service responsive to a result of the determination indicating the service is to be provided.

Claims (44)

1 . An apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus at least to:

receive a service request for a service provided by the apparatus;

determine whether to provide the service based at least partly on an authentication based on a first identifier of a network function service consumer, comprised in an access token in the service request, and on a second identifier, comprised in a credential data element in the service request,

wherein the access token comprises a cryptographic signature of a network repository function,

wherein the authentication is successful when the first identifier and the second identifier identify a same network function instance or same network function instance set,

wherein the credential data element comprises a client credentials assertion data element comprising a network function instance identifier of the network function service consumer,

wherein the client credentials assertion data element is generated by a service consuming network function,

wherein the apparatus is further configured to decide whether or not to perform the authentication based on contents of the service request,

wherein the apparatus is further configured to perform the deciding whether or not to perform the authentication based on a network function type of a network function consumer indicated in the service request,

wherein the apparatus is further configured to perform the authentication responsive to the type of the network function consumer indicated in the service request being a network exposure function, and wherein the apparatus is configured to be a unified data management node; and

provide the service responsive to a result of the determination indicating the service is to be provided.

2 . The apparatus according to claim 1 , wherein the apparatus is further configured to receive the service request from a proxy entity.

3 . The apparatus according to claim 1 , wherein the access token comprises an OAuth token in accordance with standards established by the internet engineering task force.

4 . The apparatus according to claim 1 , wherein the credential data element comprises a cryptographic signature of the network function consumer.

5 . The apparatus according to claim 4 , wherein the credential data element comprises a transport layer security, TLS, certificate, and wherein the service request is not received in the apparatus via a service communication proxy.

6 . The apparatus according to claim 1 , wherein the apparatus is further configured to decide to perform the authentication responsive to the type of the network function consumer indicated in the service request being a function configured to provide access to exposed network services and capabilities, wherein the apparatus is configured to manage network user data in a single, centralized element.

7 . The apparatus according to claim 1 , wherein the apparatus is further configured to transmit an error message to a node from which the service request is received, responsive to the authentication being unsuccessful.

8 . An apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus at least to:

transmit a service request for a service at a network function provider to the network function provider without routing the service request to a service communication proxy,

wherein the service request comprises an access token,

wherein the access token comprises a cryptographic signature of a network repository function, and comprises an identifier of a network function service consumer,

wherein the service request indicates a network function type of a network function consumer,

wherein the service request comprises a credential data element,

wherein the credential data element comprises a client credentials assertion data element comprising a network function instance identifier of the network function service consumer, and

wherein the client credentials assertion data element is generated by a service consuming network function;

receive, from the network function provider, results of the service request, wherein the results comprise an indication of a successful authentication of the apparatus based on the access token and the credential data element; and

receive the requested service from the network function provider based on the successful authentication of the apparatus.

9 . The apparatus according to claim 8 , wherein the apparatus is further configured to include in the credential data element an identifier of a set in which a network function the apparatus is configured to perform is comprised in.

10 . A method, comprising:

receiving, in an apparatus, a service request for a service provided by the apparatus;

determining whether to provide the service based at least partly on an authentication based on a first identifier of a network function service consumer, comprised in an access token in the service request, and on a second identifier, comprised in a credential data element in the service request,

wherein the access token comprises a cryptographic signature of a network repository function,

wherein the authentication is successful when the first identifier and the second identifier identify a same network function instance or same network function instance set,

wherein the credential data element comprises a client credentials assertion data element comprising a network function instance identifier of the network function service consumer,

wherein the client credentials assertion data element is generated by a service consuming network function,

wherein the apparatus is further configured to decide whether or not to perform the authentication based on contents of the service request,

wherein the apparatus is further configured to perform the deciding whether or not to perform the authentication based on a network function type of a network function consumer indicated in the service request,

wherein the apparatus is further configured to perform the authentication responsive to the type of the network function consumer indicated in the service request being a network exposure function, and

wherein the apparatus is configured to be a unified data management node; and

providing the service responsive to a result of the determination indicating the service is to be provided.

11 . The method according to claim 10 , wherein the service request is received from a proxy entity.

12 . The method according to claim 10 , wherein the access token comprises an OAuth token in accordance with standards established by the Internet Engineering Task Force.

13 . The method according to claim 10 , wherein the credential data element comprises a cryptographic signature of the network function consumer.

14 . The method according to claim 13 , wherein the credential data element comprises a transport layer security, TLS, certificate, and wherein the service request is not received in the apparatus via a service communication proxy.