Service function authorization
Inter-alia, methods and apparatuses are disclosed for authorization of a network function consumer by a network function provider.
1 . An apparatus for a network function consumer, NFc, comprising:
at least one processor; and
at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to perform:
obtaining a network function certificate, NF certificate; wherein
the NF certificate is indicative of an identity of the NFc for authentication of the NFc by at least one network function producer, NFp; and
the NF certificate comprises at least one information element of authorization information indicative of a service authorization specifying that the NFc is permitted to access at least one permitted service provided by at least one permitted NFp, wherein the NF certificate comprises an X.509 certificate and/or a transport layer security certificate, TLS certificate, comprising and/or being embedded with the at least one information element of authorization information;
transmitting a network function service request, NF service request, to the NFp via a mutual transport layer security protocol, wherein
the mutual transport layer security protocol is based upon the at least one information element of authorization information indicative of the service authorization of the NF certificate;
the NF service request comprises the NF certificate; and
the NF service request is indicative of at least one desired service provided by the NFp; and
obtaining a service response from the NFp, wherein at least a part of the service response depends on the at least one information element of authorization information.
2 . The apparatus according to claim 1 , wherein the at least one memory and the instructions, when executed by the at least one processor, further cause the user equipment at least to perform:
obtaining the NF certificate from a network manager.
3 . The apparatus according to claim 1 , wherein the at least one memory and the instructions, when executed by the at least one processor, further cause the user equipment at least to perform:
obtaining at least one service authorization detail indicative of the service authorization from a network manager;
transmitting a network function certificate request, NF certificate request, to a certification authority server, CA server, wherein the NF certificate request is indicative of the service authorization; and
obtaining the NF certificate from the CA server.
4 . The apparatus according to claim 1 , wherein
the NF certificate is at least partially or entirely constructed by a CA server, and/or
the service authorization is configured by a network manager.
5 . The apparatus according to claim 1 , wherein the service authorization specifies at least one of the following:
one or more permitted services the NFc is allowed to access;
at least one NFp instance on which the NFc is allowed to access the at least one or more permitted services;
a type of NFp on which the NFc is allowed to access the at least one or more permitted services;
a duration during which and/or a time limit until which the NFc is allowed to access the at least one or more permitted services; or
a number of times the NFc is allowed to access the at least one or more permitted services.
6 . The apparatus according to claim 1 , wherein the apparatus comprises the NFc, is the NFc, or is comprised in the NFc.
7 . An apparatus for a network function producer, NFp, comprising:
at least one processor; and
at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to perform:
obtaining a network function service request, NF service request, from an NFc indicative of at least one desired service provided by the NFp via a mutual transport layer security protocol, the mutual transport layer security protocol based upon at least one information element of authorization information indicative of a service authorization of an NF certificate to be validated, wherein the NF certificate to be validated is comprised by the NF service request;
validating a network function certificate, NF certificate, wherein
the NF certificate is indicative of an identity of a network function consumer, NFc, for authentication of the NFc by least one NFp; and
the NF certificate comprises the at least one information element of authorization information indicative of the service authorization specifying that the NFc is permitted to access at least one permitted service provided by at least one permitted NFp, wherein the NF certificate comprises an X.509 certificate and/or a transport layer security certificate, TLS certificate, comprising and/or being embedded with the at least one information element of authorization information; and
transmitting a service response to the NFc, wherein at least a part of the service response depends on the at least one information element of authorization information.
8 . The apparatus according to claim 7 , wherein the validating comprises at least one of:
authenticating the NFc based on the NF certificate; or
evaluating if the NFc is permitted to access at least one of the at least one desired services of the NFp.
9 . The apparatus according to claim 7 , wherein at least a part of the service response depends on a result of the validating.
10 . The apparatus according to claim 7 , wherein the apparatus comprises the NFp, is the NFp, or is comprised in the NFp.
11 . An apparatus for a network manager, comprising:
at least one processor; and
at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to perform:
transmitting a network function certificate request, NF certificate request, to at least one of a certification authority server, CA server, or a network function consumer, NFc; wherein
the NF certificate request is indicative of a service authorization specifying that the NFc is permitted to access at least one permitted service provided by at least one permitted network function producer, NFp;
obtaining a network function certificate, NF certificate, from the CA server, wherein
the NF certificate is indicative of an identity of the NFc for authentication of the NFc by at least one NFp; and
the NF certificate comprises at least one information element of authorization information indicative of the service authorization and is configured for a mutual transport layer security protocol between the NFc and NFp, wherein the at least one information element of authorization information is configured to be included in a service response to the NFc, wherein
the NF certificate comprises an X.509 certificate and/or a transport layer security certificate, TLS certificate, comprising and/or being embedded with the at least one information element of authorization information; and
transmitting the NF certificate to the NFc.
12 . The apparatus according to claim 11 , wherein the apparatus comprises the network manager, is the network manager, or is comprised in the network manager.