Authorization in communication networks

    公开(公告)号:US12034733B2

    公开(公告)日:2024-07-09

    申请号:US17494930

    申请日:2021-10-06

    CPC classification number: H04L63/102 H04L63/083 H04W12/06 H04W12/08

    Abstract: According to an example aspect of the present invention, there is provided a method comprising, receiving, by an intermediary network function, a subscription request from a network function consumer requesting data of a network function producer, wherein the subscription request comprises a client credential assertion of the network function consumer and an access token, authorizing and authenticating, by the intermediary network function, the network function consumer upon successful validation of the access token and the client credential assertion validation and transmitting, by the intermediary network function, an access token request to an authorization server to get another access token, wherein said another access token is to be used to validate the network function consumer to access services of the network function producer, and the access token request comprises the client credential assertion of the network function consumer requesting data of the network function producer.

    Method, apparatus and computer program

    公开(公告)号:US11979937B2

    公开(公告)日:2024-05-07

    申请号:US17479867

    申请日:2021-09-20

    CPC classification number: H04W8/02 H04W8/18 H04W48/16 H04W84/042

    Abstract: There is provided an apparatus comprising at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to: receive, at a first network repository function in a first network from a security edge protection proxy in a second network, a request for discovering one or more roaming hubs and/or security edge protection proxies in the first network; and send, from the first network repository function to the security edge protection proxy in the second network, a response comprising information identifying the one or more roaming hubs and/or security edge protection proxies in the first network and information identifying one or more further networks which can be reached via a respective roaming hub and/or security edge protection proxy in the first network.

    Method and apparatus for tracking area topology

    公开(公告)号:US11943673B2

    公开(公告)日:2024-03-26

    申请号:US17237680

    申请日:2021-04-22

    CPC classification number: H04W36/00835 H04W36/0061

    Abstract: Techniques for determining a registration area are provided. A network entity may receive one or more indications of topology information from one or more radio access network nodes. Each indication of topology information is related to one or more tracking areas and each tracking area is associated with one or more cells in a radio access network served by each of the one or more radio access network nodes. The network entity may determine a registration area based at least in part on the received one or more indications of topology information related to the one or more tracking areas.

    NETWORK SECURITY
    8.
    发明公开
    NETWORK SECURITY 审中-公开

    公开(公告)号:US20230155832A1

    公开(公告)日:2023-05-18

    申请号:US18047434

    申请日:2022-10-18

    CPC classification number: H04L9/3213 H04L63/0884

    Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to process a request for an access token authorizing access for a network function consumer to a service provided by a network function producer, the request being received in the apparatus from a service communication proxy, wherein the processing comprises one or more of the following verification: verification that a credential data element comprised in the request, cryptographically signed by the network function consumer, identifies the request, the service or a type of the service, and verification with reference to a further node, or to a profile of the network function consumer, that the service communication proxy is authorized to act on behalf of the network function consumer, and transmit, responsive to at least one of the verifications being successful, the requested access token, the access token comprising an indication of the service communication proxy.

    Network Security
    9.
    发明申请

    公开(公告)号:US20230030315A1

    公开(公告)日:2023-02-02

    申请号:US17875438

    申请日:2022-07-28

    Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to function as a network function repository, and transmit to a network function consumer an access token authorizing access to a service provided by a network function producer, the access token comprising an at least one of: indication of a fully qualified domain name of the network function consumer, an indication of a domain from which access to the network function producer is allowed and an indication of a stand-alone non-public network from which access to the network function producer is allowed.

Patent Agency Ranking