IP Library Granted Patent US 12,477,337
Granted Patent B2
US 12,477,337 · App. 18/337,194 · Granted Nov 18, 2025

Access token revocation in security management

Inventors: Chaitanya Aggarwal (Munich, DE); Saurabh Khare (Bangalore, IN); Gerald Kunzmann (Augsburg, DE); Iris Adam (Munich, DE)
Assignee: Nokia Technologies Oy
H04W12/082H04W12/084
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,337
App. No.
18/337,194
Granted
Nov 18, 2025
Kind
B2
Abstract

Example embodiments of the present disclosure relate to access token revocation in security management. In an example method, in response to providing, to a second device, an access token for the second device to access a NF service from a third device, a first device stores a mapping indicating an association among the access token, the second device and the third device. In response to determining that the second device is abnormal, the first device sends, to at least one target device based on the mapping, an indication of revoking the access token. In this way, at least one target device associated with revoked access token can be informed and potential damage caused by the abnormal NF can be eliminated.

Claims (53)

1 . A device comprising:

at least one processor; and

at least one memory storing instructions of a network repository function of a communication network, wherein the instructions when executed by the at least one processor, cause the device at least to perform operations comprising:

in response to providing, to a network function service consumer of the communication network, an access token for the network function service consumer to use to access a service of a network function service producer, storing a mapping indicating an association among the access token, the network function service consumer, and at least one target; and

in response to determining that the network function service consumer is abnormal, revoking the access token to be used by the network function service consumer, and sending, to the at least one target based on the mapping, a first indication indicating the access token provided by the network function service consumer is to be ignored by the at least one target, wherein the at least one target comprises at least one of the network function service producer or a proxy of the communication network, wherein the proxy is configured to verify the access token for the network function service producer.

2 . The device of claim 1 , wherein the operations further comprise:

receiving, from a network data analytics function (NWDAF), an indication that the network function service consumer is abnormal.

3 . The device of claim 1 , wherein the operations further comprise:

receiving a first callback uniform resource identifier (URI) from the network function service producer while the network function service producer registers with the network repository function, or

receiving the first callback URI from the proxy while the proxy registers with the network repository function device.

4 . The device of claim 3 , wherein the sending comprises:

sending the first indication based on the first callback URI.

5 . The device of claim 1 , wherein the operations further comprise:

sending a second indication that the access token is revoked to at least one of the network function service consumer or another proxy requesting the access token from the network repository function on behalf of the network function service consumer.

6 . The device of claim 5 , wherein the operations further comprise:

receiving, from the network function service consumer, a second callback URI while the network function service consumer requests the access token from the network repository function, or

receiving, from the other proxy, the second callback URI while the other proxy requests the access token from the network repository function.

7 . The device of claim 6 , wherein the sending of the second indication comprises:

sending the second indication based on the second callback URI.

8 . The device of claim 1 , wherein the operations further comprise:

in response to determining that the access token is generated for a second public land mobile network (PLMN) different from a first PLMN associated with the network repository function, sending, to a security edge protection proxy associated with the first PLMN, a third indication of blocking traffic from the second PLMN.

9 . The device of claim 1 , wherein the operations further comprise at least one of:

discarding the mapping in response to expiry of the access token;

rejecting a further request for the access token sent by the network function service consumer; or

sending an error code in response to receiving a further access token request for the network function service consumer.

10 . The device of claim 1 , wherein the determining that the network function service consumer is abnormal comprises:

receiving, from a network function, an indication indicating that the network function service consumer is abnormal.

11 . The device of claim 10 , wherein the network function comprises at least one of:

a network data analytics function (NWDAF);

a network function providing a management data analytics service (MDAS); or

an operations, administration and maintenance (OAM) function.

12 . A method of a network repository function of a communication network, the method comprising:

in response to providing, to a network function service consumer of the communication network, an access token for the network function service consumer to use to access a service from a network function service producer of the communication network, storing, at the network repository function, a mapping indicating an association among the access token, the network function service consumer, and at least one target; and

in response to determining that the network function service consumer is abnormal, revoking the access token, and sending, from the network repository function and to the at least one target based on the mapping, a first indication indicating the access token provided by the network function service consumer is to be ignored by the at least one target, wherein the at least one target comprises at least one of the network function service producer or a proxy of the communication network, wherein the proxy is configured to verify the access token for the network function service producer.

13 . The method of claim 12 , further comprising:

receiving, from a network data analytics function (NWDAF), an indication that the network function service consumer is abnormal.

14 . The method of claim 12 , further comprising:

receiving a first callback uniform resource identifier (URI) from the network function service producer while the network function service producer registers with the network repository function; or

receiving the first callback URI from the proxy while the proxy registers with the network repository function.

15 . The method of claim 14 , wherein the sending comprises:

sending the first indication based on the first callback URI.

16 . The method of claim 12 , further comprising:

sending a second indication that the access token is revoked to at least one of the network function service consumer or another proxy requesting the access token from the network repository function on behalf of the network function service consumer.

17 . The method of claim 16 , further comprising:

receiving, from the network function service consumer, a second callback URI while the network function service consumer requests the access token from the network repository function; or

receiving, from the other proxy, the second callback URI while the other proxy requests the access token from the network repository function, wherein

the sending of the second indication comprises sending the second indication based on the second callback URI.

18 . A device comprising:

at least one processor; and

at least one memory storing instructions of a network repository function, wherein when the instructions are executed by the at least one processor, the device is caused to perform operations comprising:

in response to providing, to a network function service consumer, an access token for the network function service consumer to use to access a service of a network function service producer, storing a mapping indicating an association among the access token, the network function service consumer, and the network function service producer;

in response to determining that the network function service consumer is abnormal, sending, to the network function service producer based on the mapping, an indication of revoking the access token; and

in response to determining that the access token is generated for a second public land mobile network (PLMN) different from a first PLMN associated with the network repository function, sending, to a security edge protection proxy associated with the first PLMN, an indication of blocking of traffic received from the second PLMN.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2023
From: AGGARWAL, CHAITANYA; KUNZMANN, GERALD; ADAM, IRIS
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 064277/0442 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2023
From: KHARE, SAURABH
To: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
Reel/Frame 064277/0445 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2023
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 064277/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2023
From: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
To: NOKIA TECHNOLOGIES OY
Reel/Frame 064277/0458 →
Priority Claims (1)
IN 202241035289 · Jun 20, 2022 · national
Continuity (1)
Related Publication 20230413052A1 · Dec 21, 2023
References Cited (18)
US 10404477B1 · Deck · 2019 [cited by examiner]
US 11063925B1 · Vera · 2021 [cited by examiner]
US 11615206B2 · Watkins · 2023 [cited by examiner]
US 20040153667A1 · Kastelewicz · 2004 [cited by examiner]
US 20130191884A1 · Leicher · 2013 [cited by examiner]
US 20140237553A1 · Feuer · 2014 [cited by examiner]
US 20150039444A1 · Hardin · 2015 [cited by examiner]
US 20160226859A1 · Sondhi · 2016 [cited by examiner]
US 20160261425A1 · Horton · 2016 [cited by examiner]
US 20170026369A1 · Hao · 2017 [cited by examiner]
US 20230132478A1 · Robinson · 2023 [cited by examiner]
US 20230239288A1 · Zhou · 2023 [cited by examiner]
EP 2925037A1 · 2015 [cited by examiner]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.5.0, Mar. 2022, pp. 1-293. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enablers for Network Automation for 5G—phase 3; (Release 18)”, 3GPP TR 33.738, V0.1.0, May 202… [cited by applicant]
“Study on Zero Trust Security”, 3GPP TSG-SA3 Meeting #107-e, S3-221172, Agenda Item: 6, Lenovo, May 16-20, 2022, 3 pages. [cited by applicant]
“OAuth 2.0”, Oauth, Retrieved on Jul. 26, 2023, Webpage available at : https://oauth.net/2/. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on applicability of the Zero Trust Security principles in mobile networks (Release 18)”, 3GPP TR 33.894 , V0.5.0, Feb… [cited by applicant]