IP Library › Granted Patent US 12,401,690
Granted Patent B2
US 12,401,690 · App. 18/246,707 · Granted Aug 26, 2025

Mechanism for dynamic authorization

Inventors: Iris Adam (Munich, DE); Jing Ping (Chengdu, CN); Konstantinos Samdanis (Munich, DE); Chaitanya Aggarwal (Munich, DE); Anja Jerichow (Grafing bei Munich, DE)
Assignee: NOKIA TECHNOLOGIES OY
H04L63/20H04L63/102H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,690
App. No.
18/246,707
Granted
Aug 26, 2025
Kind
B2
Abstract

Example embodiments of the present disclosure relate to dynamic authorization. According to embodiments of the present disclosure, a solution for dynamic access control to data is proposed. On receiving data registration from a data source, a first device checks the data types to be produced by the data source and adds policies for the data or updates existing policies for the data according to its property. It also serves as access control decision point to determine consumers' access rights based on centrally managed policies. Authorization for data access is granted/denied according to local attributes/policies. In this way, it achieves a dynamic, context-aware and risk-intelligent access control to different kind of data from various data sources (i.e., service producers).

Claims (29)

1. A first device comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the first device, which is an authorization policy management entity, to:

receive, from a second device which is an authorization server or a third device which is a service producer, an authorization request for authorizing a fourth device which is a service consumer to access at least a data service and data provided by the third device, the authorization request at least indicating an identity of the fourth device;

obtain a profile of the fourth device based on the identity of the fourth device, wherein the profile of the fourth device comprises at least:

a group identity of the fourth device,

a role of the fourth device, and

a context of the fourth device;

receive, from the second device or the third device, a register request for registering the third device with the first device, the register request comprising an identity of the third device;

determine a type of the data to be provided by the third device;

determine a property of the data based on the type of the data;

determine an authorization policy of the data based on the property of the data, wherein the authorization policy comprises at least:

a security requirement for accessing the data service or the data,

a service type of the data, and

a required region for accessing the data service or the data;

transmit a register response to the second device or the third device;

determine, based on the profile of the fourth device and the authorization policy of the data service or the data, authorization information of the fourth device,

wherein when the authorization request is received from the second device, the first device is caused to determine the authorization information by:

determining at least one type of data related to the data service which is accessible to the fourth device,

wherein when the authorization request is received from the third device, the first device is caused to determine the authorization information by:

determining the authorization information of the fourth device indicating whether the fourth device is to be authorized to access the data provided by the third device; or

determining whether a context of the fourth device satisfies a security requirement for accessing the data based on the authorization policy; and

in accordance with a determination that the context of the fourth device satisfies the security requirement, determining the fourth device is authorized to access the data;

based on the authorization information, authorize the fourth device to access the data;

transmit the authorization information to the second device or the third device;

receive, from the third device, a request for access control information of the data, the access control information at least comprising the authorization policy;

receive, from the third device, an update request for updating the authorization policy; and

update the authorization policy of the data based on the profile of the fourth device and a new requirement from the third device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: ADAM, IRIS; PING, JING; SAMDANIS, KONSTANTINOS; AGGARWAL, CHAITANYA; JERICHOW, ANJA
To: NOKIA SHANGHAI BELL CO., LTD.; NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 063309/0829 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: NOKIA SHANGHAI BELL CO., LTD.; NOKIA SOLUTIONS AND NETWORKS OY
To: NOKIA TECHNOLOGIES OY
Reel/Frame 063309/0837 →
Continuity (1)
Related Publication 20230362199A1 · Nov 9, 2023
References Cited (33)
US 10117097B1 · Kotara et al. · 2018 [cited by applicant]
US 20100198698A1 · Raleigh et al. · 2010 [cited by applicant]
US 20130086657A1 · Srinivasan et al. · 2013 [cited by applicant]
US 20170063931A1 · Seed et al. · 2017 [cited by applicant]
US 20180013747A1 · Marshall · 2018 [cited by examiner]
US 20190150017A1 · Yao et al. · 2019 [cited by applicant]
US 20190222489A1 · Shan · 2019 [cited by applicant]
US 20190230556A1 · Lee · 2019 [cited by applicant]
US 20190253894A1 · Bykampadi et al. · 2019 [cited by applicant]
US 20190394279A1 · Dao et al. · 2019 [cited by applicant]
US 20200112841A1 · Kim et al. · 2020 [cited by applicant]
US 20200137552A1 · Park et al. · 2020 [cited by applicant]
US 20200196169A1 · Dao et al. · 2020 [cited by applicant]
CN 105659558A · 2016 [cited by applicant]
CN 109587187A · 2019 [cited by applicant]
CN 110366159A · 2019 [cited by applicant]
CN 111345052A · 2020 [cited by applicant]
CN 111416827A · 2020 [cited by applicant]
EP 2384040A1 · 2011 [cited by applicant]
WO 2020092914A1 · 2020 [cited by applicant]
WO 2020141355A1 · 2020 [cited by applicant]
WO 2020174121A1 · 2020 [cited by applicant]
Office action received for corresponding Chinese Patent Application No. 202080106039.5, dated Apr. 25, 2024, 15 pages of office action and no page of translation available. [cited by applicant]
“Clarification on service authorization and token verification”, 3GPP TSG-SA WG3 Meeting #94, S3-190440, Huawei, Jan. 28-Feb. 1, 2019, 8 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16)”, 3GPP TS 23.501, V16.5.0, Jul. 2020, pp. 1-441. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501, V16.3.0, Jul. 2020, pp. 1-248. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Data Analytics Services; Stage 3 (Release 16)”, 3GPP TS 29.520, V16.3.0, Mar. 2020, pp. 1-83. [cited by applicant]
Hardt, “The OAuth 2.0 Authorization Framework”, RFC 6749, Internet Engineering Task Force (IETF), Oct. 2012, pp. 1-76. [cited by applicant]
“KI #1 #2 #11, New Solution: Data Collection and Sharing Architecture”, SA WG2 Meeting #139E, S2-2004526, Agenda Item: 8.1, Nokia, Jun. 1-12, 2020, pp. 1-9. [cited by applicant]
Moradi et al., “SoftBox: A Customizable, Low-Latency, and Scalable 5G Core Network Architecture”, IEEE Journal on Selected Areas in Communications, vol. 36, No. 3, Mar. 2018, pp. 438-456. [cited by applicant]
“IEEE 802.11”, Wikipedia, Retrieved on Apr. 21, 2023, Webpage available at : https://en.wikipedia.org/wiki/IEEE_802.11. [cited by applicant]
International Search Report and Written Opinion received for corresponding Patent Cooperation Treaty Application No. PCT/CN2020/120042, dated Jul. 9, 2021, 9 pages. [cited by applicant]
“Service Based Architecture in IMS”, 3GPP TSG-CT WG1 Meeting#120, C1-196154, Nokia, Oct. 7-11, 2019, pp. 1-38. [cited by applicant]