Beyond Tokens: Distributed, De-Centralized, Local Authorization Framework for Beyond 5GC SBI
Bharath Kumar R, R Rajavelsamy · 2024
The 3rd Generation Partnership Project (3GPP) has established the Service Based Architecture (SBA) as the frame-work for 5G Core Systems. This architecture relies on a set of Network Functions (NFs) that deliver services to authorized NFs through the interfaces of a unified framework called the Service Based Interface (SBI). Currently, the 5G Core SBI relies on Transport Layer Security (TLS) for authentication and OAuth2.0 for authorization. While OAuth2.0 is a robust framework for third-party access to HTTP services, its implementation in the 5G Core SBI raises security concerns such as the potential for masquerading as a different NF and forging access tokens. This paper addresses these concerns by advocating for a zero-trust architecture and proposing a distributed, decentralized, and local authorization framework for dynamic, granular access control in inter-NF communication within the 5G Core SBI. The proposed framework is built on Ciphertext-Policy Attribute Based Encryption (CP-ABE). NF producers incorporate a granular access policy as an input parameter for encrypting the messages. NF consumers receive a secret key derived from a set of attributes defining their authorization privileges. Only NF consumers with a valid secret key, where the attributes satisfy the policy in the ciphertext, can decrypt the received message. This approach enforces granular access control for each message. Experimental results demonstrate that the performance overhead of CP-ABE is comparable to that of OAuth2.0. Additionally, CP-ABE offers enhanced scalability and access granularity due to its distributed nature and expressive policy language.