Description
The Resource Owner Function (ROF) is a logical function defined in 3GPP Release 18 within the broader architecture for enhanced network sharing and multi-operator core networks. It is a policy and authorization control entity that represents the owner of a physical or virtual network resource. These resources can include radio spectrum, radio access network (RAN) infrastructure (like gNBs), or even specific network slices. The ROF exposes the capabilities and usage conditions of its owned resources and can grant, modify, or revoke usage rights to other authorized entities, known as Resource User Functions (RUF). The interaction is governed by policies and service level agreements (SLAs).
Architecturally, the ROF is part of the management and orchestration plane, often associated with the Network Resource Model (NRM) and Service Management and Orchestration (SMO) framework. It interfaces with the RUF, typically via standardized APIs (like the Northbound APIs of the SMO), to facilitate resource discovery, negotiation, and leasing. The ROF's key role is to make authorization decisions. For example, in a neutral host scenario where a building owner operates a private 5G network, the building owner's ROF could authorize multiple mobile network operators (MNOs) to use that RAN, with each MNO's management system acting as a RUF. The ROF enforces policies on resource isolation, quality of service, and security for each user.
How it works involves a multi-step process. First, a RUF discovers available resources by querying a ROF or a discovery service. The RUF then sends a resource usage request, specifying requirements. The ROF evaluates this request against its internal policies, SLAs, and current resource utilization. If authorized, the ROF provisions the resource for the RUF, which may involve configuring the RAN, allocating spectrum, or activating a network slice. The ROF continues to monitor the usage for compliance and can trigger re-negotiation or termination based on policy violations or contract end. Specifications such as TS 23.222 (architecture for network sharing) and TS 33.122 (security aspects) define the procedures and security requirements for these interactions, ensuring that authorization is secure and auditable.
Purpose & Motivation
The ROF was created to address the growing complexity and demand for flexible network sharing models in 5G and beyond. Traditional network sharing (like MORAN or MOCN) was relatively static and required complex, pre-negotiated contracts between a limited number of operators. The rise of neutral hosts, private networks, and dynamic spectrum sharing scenarios required a more agile, automated, and standardized way to manage resource ownership and access rights. The ROF provides a standardized logical function to enable these dynamic marketplaces for network resources.
It solves the problem of operational silos and manual processes in multi-operator environments. By having a clear ROF-RUF interface, different business entities can automatically negotiate and utilize shared infrastructure, lowering barriers to entry and fostering innovation. For instance, it enables an airport authority (ROF) to dynamically grant capacity on its private network to an airline (RUF) during peak hours. From a security perspective, TS 33.122 defines how to secure these delegation interactions, preventing unauthorized access and ensuring that the resource owner maintains control. The ROF is a key enabler for 5G-Advanced business models, moving beyond simple roaming to true resource-as-a-service paradigms.
Classification
Release Timeline
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (5 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 18, the Resource Owner Function (ROF) was newly introduced as an entity responsible for enabling authorization, management, and revocation of resource owner authorization for API access. This function interacts with the CAPIF core function via the newly defined CAPIF-8 reference point to support resource owner-aware northbound API access scenarios. Specific procedures were defined for the ROF to obtain collective authorization information and to initiate the revocation of resource owner authorization.
- Resource owner function TS 33.122CR0072
In Release 19, the Resource Owner Function (ROF) was enhanced with new capabilities for mutual authentication with the CAPIF Core Function over the CAPIF-8 reference point, which was previously not specified. The release also clarified the responsibilities between the ROF and the Authorization Function and added missing functions to the ROF, formally defining its role in enabling, managing, and revoking resource owner authorization as part of procedures like obtaining service API authorization.
- Authentication of ROF and CCF for CAPIF-8 reference point TS 33.122CR0098
- Clarification of the ROF and Authorization Function responsibilities TS 23.222CR0256
- Clarification of the ROF and Authorization Function responsibilities TS 23.222CR0260
- Add missing function to resource owner function TS 23.222CR0169
Explore further
Broader topics and technologies where ROF plays a role.
Defining Specifications
3GPP specifications that define or reference ROF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.222 vj80 | Common API Framework for 3GPP Northbound APIs | Rel-19 |
| TS 23.700 vk00 | XR Services Application Enablement Layer | Rel-20 |
| TS 33.122 vj20 | Security Architecture for CAPIF | Rel-19 |