IP Library Granted Patent US 12,052,233
Granted Patent B2
US 12,052,233 · App. 17/512,627 · Granted Jul 30, 2024

Identity verification method for network function service and related apparatus

Inventors: Bo Zhang (Shenzhen, CN); Fei Li (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L63/0823H04L63/102H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,233
App. No.
17/512,627
Granted
Jul 30, 2024
Kind
B2
Abstract

In an identity verification method for a network function service, a network element receives from a requesting network element a network function (NF) service request that includes a token, The token includes first certificate information. The network element verifies the first certificate information to determine whether an identity represented by the first certificate information is consistent with an identity of the requesting network element. When the network element determines that the identity represented by the first certificate information is inconsistent with the identity of the requesting network element, the network element rejects the NF service request.

Claims (28)

1. An identity verification method performed by a managing network element in a service network, comprising:

receiving, via the service network, a network function (NF) service request from a requesting network element in the service network, wherein the NF service request comprises a service token for a first NF service provided by the managing network element, the service token is provided by a service token server of the service network for the first NF service and comprises first certificate information, wherein the first certificate information is related to a certificate of a requester of the service token and comprises identity information of the requester of the service token as used in the certificate of the requester of the service token, wherein the managing network element is a control plane network element of the service network, and the first certificate information comprises an identifier or an NF type of the requester of the service token;

obtaining, via the service network, a certificate of the requesting network element;

determining-whether the identity information of the requester of the service token in the first certificate information is consistent with identity information of the requesting network element in the certificate of the requesting network element; and

upon determining that the identity information of the requester of the service token in the first certificate information is inconsistent with the identity information of the requesting network element in the certificate of the requesting network element, rejecting the NF service request.

2. The method according to claim 1 , wherein the identity information of the requester of the service token in the first certificate information comprises an identifier of the requester of the service token, and the identity information in the certificate of the requesting network element comprises an identifier of the requesting network element.

3. The method according to claim 1 , wherein the first certificate information comprises an NF type of the requester of the service token, and the certificate of the requesting network element indicates an NF type of the requesting network element.

4. A requester identity verification method performed by a requesting network element in a service network, comprising:

obtaining, from a service token server in the service network, a service token corresponding to a first NF service provided by a managing network element in the service network, wherein the service token comprises first certificate information related to a certificate of a requester of the service token and comprising identity information of the requester of the service token as used in the certificate of the requester of the service token, wherein the managing network element is a control plane network element of the service network, and the first certificate information comprises an identifier or an NF type of the requester of the service token;

sending an NF service request for the first NF service to the managing network element, wherein the NF service request comprises the service token; and

receiving a reject message from the managing network element, wherein receiving the reject message indicates that the managing network element fails to verify the requesting network element based on the service token in the NF service request.

5. The method according to claim 4 , wherein the identity information in the first certificate information comprises an identifier of the requester of the service token.

6. The method according to claim 4 , wherein the identity information in the first certificate information comprises an NF type of the requester of the service token.

7. The method according to claim 4 , wherein the step of obtaining the service token corresponding to the first NF service comprises:

sending a token obtaining request to the service token server in a control plane network of the service network; and

receiving, by the requesting network element, the service token returned by the service token server.

8. A network element in a service network comprising:

a transceiver for network communications;

a memory storing executable instructions;

a processor configured to execute the executable instructions to:

receive, via the service network, a network function (NF) service request for a first NF service from a requesting network element in the service network, wherein the NF service request comprises a service token provided by a service token server of the service network for the first NF service, the service token comprises first certificate information related to a certificate of a requester of the service token and comprising identity information of the requester of the service token as used in the certificate of the requester of the service token, wherein the network element is a control plane network element of the service network, and the first certificate information comprises an identifier or an NF type of the requester of the service token;

obtaining, via the service network, a certificate of the requesting network element;

determine whether the identity information of the requester of the service token in the first certificate information is consistent with identity information of the requesting network element in the certificate of the requesting network element; and

upon determining that the identity information of the requester in the service token in the first certificate information is inconsistent with the identity information of the requesting network element in the certificate of the requesting network element, reject the NF service request.

9. The network element according to claim 8 , wherein the processor is further configured to:

process the NF service request when the identity information of the requester of the service token in represented by the first certificate information is consistent with the identity information of the requesting network element in the certificate of the requesting network element.

10. The network element according to claim 8 , wherein identify information in the first certificate information comprises an identifier of the requester of the service token, and the identity information in the certificate of the requesting network element comprises an identifier of the requesting network element.

11. The network element according to claim 8 , wherein the identify information in the first certificate information comprises an NF type of the requester of the service token, and the identify information of the requesting network element in the certificate of the requesting network element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2024
From: ZHANG, BO; LI, FEI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 067069/0046 →
Priority Claims (2)
CN 201910359634.9 · Apr 28, 2019 · national
CN 201910766373.2 · Aug 16, 2019 · national
Continuity (2)
Continuation PCTCN2020080971 · Mar 24, 2020
Related Publication 20220052992A1 · Feb 17, 2022