IP Library Granted Patent US 12,349,051
Granted Patent B2
US 12,349,051 · App. 17/729,537 · Granted Jul 1, 2025

System and method for limiting a scope of authorization provided to NFC device

Inventors: Varini Gupta (Bangalore, IN); Rohini Rajendran (Bangalore, IN); Rajavelsamy Rajadurai (Bangalore, IN); Ashok Kumar Nayak (Bangalore, IN); Nivedya Parambath Sasi (Bangalore, IN)
Assignee: Samsung Electronics Co., Ltd.
H04W48/18H04W48/16H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,349,051
App. No.
17/729,537
Granted
Jul 1, 2025
Kind
B2
Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method for limiting a scope of authorization provided to a network function service consumer (NFC) device in a wireless network by a network repository function (NRF) server is provided. The method includes receiving an NF-registration request message from a network function producer (NFP) device. The NF-registration request message includes at least one of a set of the first information element indicating a single-network slice selection assistance information (S-NSSAI) of the NFC device allowed to access by the NFP device, a corresponding second information element indicating operations allowed on resources of the NFP device belonging to a S-NSSAI of the NFP device, and a third information element indicating a trust-level of the NFC device.

Claims (59)

1. A method performed by a network repository function (NRF) server for limiting a scope of authorization provided to a network function (NF)-service consumer (NFC) device in a wireless network, the method comprising:

receiving, by the NRF server, an NF-registration request message from a NF-service producer (NFP) device,

wherein the NF-registration request message comprises:

a first information element indicating a single-network slice selection assistance information (S-NSSAI) of the NFC device allowed to access by the NFP device,

a corresponding second information element indicating operations allowed on resources of the NFP device belonging to at least one S-NSSAI of the NFP device, and

a third information element indicating a trust-level of the NFC device, the trust-level relating to an access rule specifying a scope of access allowed for the NFC device, wherein the trust-level is used for limiting an amount of information provided to the NFC device; and

registering a profile of the NFP device based on at least one of the first information element, the second information element, or the third information element.

2. The method of claim 1 , further comprising:

receiving a NF discovery request from the NFC device to detect the NFP device; and

transmitting the profile of the NFP device to the NFC device,

wherein the profile of the NFP device comprises at-least one of the S-NSSAIs of the NFC device that are supported by the NFP device, and other profile information filtered according to the trust-level of the NFC device.

3. The method of claim 1 , further comprising:

receiving an access token request from the NFC device to access the resources of the NFP device;

determining at least one of the scope of authorization indicating the operations the NFC device is allowed to perform on the resources in the NFP device, and the trust-level of the NFC device based on at least one of the first information element, the second information element, or the third information element; and

transmitting an access token response including at least one of the scope of authorization, the S-NSSAIs of the NFC device, or the trust-level to the NFC device.

4. The method of claim 3 , wherein the trust-level indicates a partial access to the resources of the NFP device by the NFC device or a full access to the resources of the NFP device by the NFC device.

5. A method performed by a network function producer (NFP) device for limiting a scope of authorization provided to a NF service consumer (NFC) device in a wireless network, the method comprising:

transmitting, to a network repository function (NRF) server, an NF-registration request message comprising a first information element indicating a single-network slice selection assistance information (S-NSSAI) of the NFC device allowed to access by the NFP device, a corresponding second information element indicating operations allowed on resources of the NFP device belonging to at least one S-NSSAI of the NFP device, and a third information element indicating a trust-level of the NFC device, the trust-level relating to an access rule specifying a scope of access allowed for the NFC device, wherein the trust-level is used for limiting an amount of information provided to the NFC device;

receiving a service request message from the NFC device, wherein the service request message comprises an access token issued by the NRF server to allow the NFC device to access resources of the NFP device; and

allowing to access the resources of the NFP device based on the S-NSSAI of the NFP device and the access token issued by the NRF server to allow the NFC device to access the resources of the NFP device.

6. The method of claim 5 , wherein the access token comprises at least one of scope of authorization, the S-NSSAIs of the NFC device, or a trust-level of the NFC device.

7. The method of claim 5 , wherein the NFP device filters information is provided to the NFC device according to a trust-level received in the access token.

8. A method performed by a network function-service consumer (NFC) device for limiting a scope of authorization provided to the NFC device in a wireless network, the method comprising:

transmitting a NF discovery request, by the NFC device, to a network repository function (NRF) server to detect a network function producer (NFP) device;

receiving a profile of the NFP device from the NRF server, wherein the profile of the NFP device comprises single-network slice selection assistance information (S-NSSAIs) of the NFC device supported by the NFP device;

transmitting an access token request, by the NFC device, to the NRF server to access resources of the NFP device; and

receiving, from the NRF server, an access token response including a scope of authorization, the S-NSSAIs of the NFC device, and a trust-level of the NFC device, to access the resources of the NFP device, the trust-level relating to an access rule specifying a scope of access allowed for the NFC device, wherein the trust-level is used for limiting an amount of information provided to the NFC device.

9. The method of claim 8 , further comprising:

transmitting a service request message to the NFP device,

wherein the service request message comprises an access token containing at least one of scope of authorization, the S-NSSAIs of the NFC device, or the trust-level of the NFC device, issued by the NRF server, to allow the NFC device to access operations of the NFP device; and

receiving a service response message to allow access to the operations of the NFP device based on the access token issued by the NRF server.

10. The method of claim 8 , wherein the trust-level for the NFC device is determined by the NRF server based on local configuration.

11. The method of claim 8 , wherein the trust-level for the NFC device is registered in the NRF server by the NFP device as part of NF-registration based on a plurality of parameters associated with the NFC.

12. The method of claim 11 , wherein the plurality of parameters comprises:

a NF-Type;

a S-NSSAI of the NFC device;

a NF-Instance identification (ID) of the NFC device; and

a NF domain of the NFC device.

13. A network repository function (NRF) server for limiting a scope of authorization provided to a network function (NF)-service consumer device in a wireless network, wherein the NRF server comprising:

memory;

at least one processor; and

a scope authorization controller, connected to the memory and the processor, configured to:

receive an NF-registration request message from NF-service producer (NFP) device, wherein the registration request message comprises a first information element indicating a single-network slice selection assistance information (S-NSSAI) of the NFC device allowed to access by the NFP device, a corresponding second information element indicating operations allowed on resources of the NFP device belonging to at least one S-NSSAI of the NFP device, and a third information element indicating a trust-level of the NFC device, the trust-level relating to an access rule specifying a scope of access allowed for the NFC device, wherein the trust-level is used for limiting an amount of information provided to the NFC device, and

register a profile of the NFP device based on at least one of the first information element, the second information element, or the third information element.

14. A network function (NF)-service producer (NFP) device for limiting a scope of authorization provided to a NF-service consumer (NFC) device in a wireless network, the NFP device comprising:

memory;

at least one processor; and

a scope authorization controller, connected to the memory and the processor, configured to:

transmit, to a network repository function (NRF) server, an NF-registration request message comprising a first information element indicating a single-network slice selection assistance information (S-NSSAI) of the NFC device allowed to access by the NFP device, a corresponding second information element indicating operations allowed on resources of the NFP device belonging to at least one S-NSSAI of the NFP device, and a third information element indicating a trust-level of the NFC device, the trust-level relating to an access rule specifying a scope of access allowed for the NFC device, wherein the trust-level is used for limiting an amount of information provided to the NFC device;

receive a service request message from the NFC device, wherein the service request message comprises an access token issued by the NRF server to allow the NFC device to access resources of the NFP device, and

allow to access the resources of the NFP device based on the S-NSSAI of the NFP device and the access token issued by the NRF server to allow the NFC device to access the resources of the NFP device.

15. A network function (NF)-service consumer (NFC) device for limiting a scope of authorization in a wireless network, the NFC device comprising:

memory;

at least one processor; and

a scope authorization controller, connected to the memory and the processor, configured to:

transmit a NF discovery request to a network repository function (NRF) server to detect a network function (NF)-service producer (NFP) device,

receive a profile of the NFP device from the NRF server, wherein the profile of the NFP device comprises single-network slice selection assistance information (S-NSSAIs) of the NFC device supported by the NFP device,

transmit an access token request to the NRF server to access resources of the NFP device, and

receive, from the NRF server, an access token response including a scope of authorization, the S-NSSAIs of the NFC device, and a trust-level of the NFC device, to access the resources of the NFP device, the trust-level relating to an access rule specifying a scope of access allowed for the NFC device, wherein the trust-level is used for limiting an amount of information provided to the NFC device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2022
From: GUPTA, VARINI; RAJENDRAN, ROHINI; RAJADURAI, RAJAVELSAMY; NAYAK, ASHOK KUMAR; SASI, NIVEDYA PARAMBATH
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 059707/0719 →
Priority Claims (2)
IN 202141019531 · Apr 28, 2021 · national
IN 2021 41019531 · Mar 4, 2022 · national
Continuity (1)
Related Publication 20220353802A1 · Nov 3, 2022
References Cited (30)
US 11729587B1 · Engelhart · 2023 [cited by examiner]
US 11743699B2 · Bartolomé Rodrigo · 2023 [cited by examiner]
US 20200336366A1 · Kurian · 2020 [cited by examiner]
US 20230171600A1 · Baskaran · 2023 [cited by examiner]
US 20230396602A1 · Wu · 2023 [cited by examiner]
US 20240064139A1 · De Gregorio Rodriguez · 2024 [cited by examiner]
WO 2020033697A1 · 2020 [cited by applicant]
WO 2020254918A1 · 2020 [cited by applicant]
WO 2021018460A1 · 2021 [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16), 3GPP TS 23.501 V16.8.0 (Mar. 2021), Mar. 30, 2021, Sophia… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 17), 3GPP TS 23.501 V17.0.0 (Mar. 2021), Mar. 30, 2021, Sophia… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 15), 3GPP TS 23.502 V15.13.0 (Mar. 2021), Mar. 30, 2021, Sophia Antipol… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16), 3GPP TS 23.502 V16.8.0 (Mar. 2021), Mar. 30, 2021, Sophia Antipoli… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17), 3GPP TS 23.502 V17.0.0 (Mar. 2021), Mar. 31, 2021, Sophia Antipoli… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 16), 3GPP TS 29.500 V16.7.0 (Mar. 2021), Mar… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 17), 3GPP TS 29.500 V17.2.0 (Mar. 2021), Mar… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 15), 3GPP TS 29.510 V15.9.0 (Mar. 2021), Mar. 30, 2021, Sop… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 16), 3GPP TS 29.510 V16.7.0 (Mar. 2021), Mar. 30, 2021, Sop… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17), 3GPP TS 29.510 V17.1.0 (Mar. 2021), Mar. 30, 2021, Sop… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15), 3GPP TS 33.501 V15.12.0 (Mar. 2021), Apr. 6, 2021, Sophia A… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16), 3GPP TS 33.501 V16.6.0 (Mar. 2021), Apr. 6, 2021, Sophia An… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17), 3GPP TS 33.501 V17.1.0 (Mar. 2021), Apr. 6, 2021, Sophia An… [cited by applicant]
Indian Office Action dated Dec. 1, 2022, issued in Indian Application No. 202141019531. [cited by applicant]
Extended European Search Report dated Jul. 24, 2024, issued in European Application No. 22796146.3-1215. [cited by applicant]
Ericsson; NF Profile for NF as Service Consumer, 3GPP TSG-CT WG4 Meeting #101e, C4-205362; Oct. 26, 2020. [cited by applicant]
Ericsson, Nokia, Nokia Shanghai Bell, Huawei; Resource-Level Authorization; 3GPP TSG-CT WG4 Meeting #98e; C4-203318; May 22, 2020. [cited by applicant]
Samsung; Evaluation and Conclusion for Key Issue #9; 3GPP TSG-SA3 Meeting #106-e; S3-220287, Feb. 7, 2022. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17), 3GPP TS 33.501 V17.1.0, Apr. 4, 2021, Valbonne, France. [cited by applicant]
International Search Report dated Aug. 4, 2022, issued in International Application No. PCT/KR2022/006043. [cited by applicant]
Korean Office Action dated Jan. 2, 2025, issued in Korean Application No. 10-2023-7034624. [cited by applicant]