Methods and apparatus for an identifier server, communication device, server, authorization server, external invoker device, and application programming interface provider server

An identifier server within the communication network generates and manages secure, internally bound identifiers to address privacy and security issues in identifying devices or connections, ensuring robust and flexible API integration.

WO2025189380A1PCT designated stage Publication Date: 2025-09-18TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) +1

Patent Information

Application Number
PCT/CN2024/081362
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-13
Publication Date
2025-09-18

AI Technical Summary

Technical Problem

Existing methods for identifying communication devices or connections through external APIs in communication networks face challenges such as privacy concerns and security vulnerabilities, particularly when Network Address Translators (NATs) are deployed, leading to unreliable external IP addresses and potential misuse of identifiers.

Method used

Implementing an identifier server within the communication network to generate and manage identifiers bound to internal network information, ensuring privacy protection and security by encrypting and constraining the use of these identifiers based on specific constraints.

Benefits of technology

The solution provides robust and secure identification of communication devices or connections, safeguarding privacy and preventing misuse, even in scenarios with network address changes, while enhancing deployment flexibility and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024081362_18092025_PF_FP_ABST
    Figure CN2024081362_18092025_PF_FP_ABST
Patent Text Reader

Abstract

An identifier server (22) is deployed in a communication network (10). The identifier server (22) receives a request (26) for an identifier (12-ID) that is to identify a communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10). The identifier server (22) determines, based on a payload (26P) of the request (26) and / or a source address (26A) of the request (26), internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10). The identifier server (22) generates an identifier (12-ID) that is bound to the internal identifying information (12-INT). The identifier server (22) transmits a response (28) that includes the generated identifier (12-ID).
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND APPARATUS FOR AN IDENTIFIER SERVER, COMMUNICATION DEVICE, SERVER, AUTHORIZATION SERVER, EXTERNAL INVOKER DEVICE, AND APPLICATION PROGRAMMING INTERFACE PROVIDER SERVERTECHNICAL FIELD

[0001] The present application relates generally to an identifier server, a communication device, a server, an authorization server, an external invoker device, and an application programming interface (API) provider server, as well as to corresponding methods, computer programs, computer-readable storage media, and carriers of the computer programs.BACKGROUND

[0002] In order to enable seamless integration of a communication network’s capabilities into third-party applications, platforms, and systems, a communication network may provide external parties with access to some of the network’s services and core functionalities. One way for the communication network to do this is to expose an application programming interface (API) to those services. An exposed API provides a set of standardized endpoints and protocols that allow an external party to interact programmatically with the network's services and infrastructure. The API may for example offer a range of functionalities such as sending text messages, making voice calls, managing user accounts, and accessing network data. By invoking such an API, a third-party aggregator may for instance provide value-added services such as bulk messaging, call routing, or data analytics, tailored to the specific needs of businesses or organizations. Integration with the communication network's API in these or other ways may empower developers to create custom solutions tailored to specific use cases or industries, facilitate partnerships and collaborations between the network and external parties, and foster a rich ecosystem of interconnected services and applications which enhance the user experience.

[0003] An external invoker of an API exposed by a communication network may need to identify to which communication device or connection its API call relates. For example, when invoking an Application Function (AF) Session With QoS API exposed by a 5G network, an API invoker heretofore must provide a user equipment (UE) Internet Protocol (IP) address as input along with a set of Service Data Flow Filters. The 5G network then uses the provided UE IP address to find which Policy Control Function (PCF) and User Plane Function (UPF) handles the UE’s traffic.

[0004] Challenges exist, however, with existing approaches for an external invoker of an exposed API to identify to which communication device or connection its API call relates. For example, some scenarios jeopardize the use of a communication device’s IP address as an external identifier for identifying to which communication device or connection an API call relates. One such scenario is when the communication network deploys a Network Address Translator (NAT) to expand its IP address space and increase user privacy. Indeed, in this case, the external IP address revealed to the external API invoker may no longer identify a communication device or connection from the perspective of the communication network, since  multiple communication devices or connections may re-use the same external IP address. One way to overcome this challenge would be for the application client on the communication device to send the external API invoker the ‘internal’ IP address that the communication network has internally assigned to the communication device or connection. But this workaround proves unworkable if the application client is sandboxed for security purposes and therefore lacks knowledge of the internal IP address, e.g., as may be the case where the application client executes in a web browser. Plus, revealing the internal IP address has drawbacks as the internal IP address may be considered privacy-sensitive information. This same privacy concern arises with use of a Generic Public Subscription Identifier (GPSI) as an external identifier. And although a so-called AF-specific UE identifier retrievable from an external AF overcomes privacy concerns, it proves vulnerable to re-use by a malicious party. Challenges therefore exist in identifying to which communication device or connection an API call relates in a way that accounts for different deployment scenarios (e.g., NAT deployment) , protects user privacy, and guards against identifier re-use.

[0005] WO 2022 / 233534 A1 discloses that a UE sends an application service request to an application function (AF) , where the application service request includes a second identifier specific to one or more applications that includes an application associated with the UE and the AF.SUMMARY

[0006] An object of the invention is to enable a communication network to expose an application programming interface (API) with improvement of at least one of deployment flexibility, privacy protection, and security.

[0007] Towards this end, some embodiments herein deploy an identifier server in a communication network for providing an identifier that is to identify a communication device, and / or a connection of the communication device, to an external invoker device of an API exposed by the communication network. That is, rather than an external server (e.g., associated with the external invoker) providing such an identifier, some embodiments exploit a server in the communication network itself for providing the identifier. With the identifier server located in the communication network, the identifier server binds the identifier to internal identifying information that identifies the communication device and / or the connection internally to the communication network. The internal identifying information may for example include a SUbscription Permanent Identifier (SUPI) , a Generic Public Subscription Identifier (GPSI) , and / or an internal network layer address (e.g., IP address) . By way of this binding, then, the identifier safeguards user privacy, improve robustness to network layer address changes, and / or proves effective even in deployment scenarios (e.g., NAT deployment) where the external network layer address of the communication device or connection is insufficient for identifying the communication device or connection. Furthermore, in some embodiments, the identifier may be changed from time to time, even while being bound to the same internal identifying information, e.g., so as to protect against long-term use of the same identifier and thereby enhance user privacy protection.

[0008] Moreover, in some embodiments, the identifier server determines the internal identifying information based on a payload of a request for the identifier and / or a source address of the request. In fact, in some embodiments, the payload of the request may indicate constraint (s) that are to constrain usability  of the identifier, e.g., in time, space, purpose, connectivity, etc. By way of the identifier’s binding to the internal identifying information and, in some embodiments, requestor-provided constraint (s) , some embodiments may advantageously improve security by guarding against re-use of the identifier, e.g., by an unintended bearer of the identifier, for an unintended use, etc.

[0009] More particularly, embodiments herein include a method performed by an identifier server in a communication network. The method comprises receiving a request for an identifier that is to identify a communication device to an external invoker device of an application programming interface, API, exposed by the communication network. The method also comprises determining, based on a payload of the request and / or a source address of the request, internal identifying information that identifies the communication device internally to the communication network. The method also comprises generating an identifier that is bound to the internal identifying information. The method also comprises transmitting a response that includes the generated identifier.

[0010] In some embodiments, generating the identifier comprises generating encrypted identifying information by encrypting at least some of the internal identifying information. In some embodiments, generating the identifier comprises including the encrypted identifying information in the identifier. In some embodiments, including the encrypted internal identifying information in the identifier comprises including the encrypted internal identifying information in an information element of the identifier, and the method further comprises cryptographically signing the information element.

[0011] In some embodiments, the generated identifier is a JavaScript Object Notation, JSON, Web Token.

[0012] In some embodiments, generating the identifier comprises generating the identifier in a format of a Network Access Identifier, NAI, or as an opaque string. In some embodiments, generating the identifier comprises binding the generated identifier to the internal identifying information and / or to the one or more constraints by storing the generated identifier at the identifier server in association with the internal identifying information and / or the one or more constraints.

[0013] In some embodiments, the request is received from an application executed on the communication device. In some embodiments, determining the internal identifying information comprises determining the internal identifying information based on the source address of the request by sending a query to a network node in the communication network for the internal identifying information. In some embodiments, the query includes the source address.

[0014] In some embodiments, the method further comprises, before receiving the request, receiving, from an authorization server, the internal identifying information and an access token associated with the internal identifying information. In some embodiments, the payload of the request includes the access token, and determining the internal identifying information comprises determining the internal identifying information based on the access token included in the payload of the request.

[0015] In some embodiments, the payload of the request includes an internal device identifier that identifies the communication device internally to the communication network, and determining the internal identifying information comprises determining the internal identifying information based on the internal device identifier included in the payload of the request.

[0016] In some embodiments, the internal identifying information identifies the communication device internally to the communication network and includes a SUbscription Permanent Identifier, SUPI, and / or a Generic Public Subscription Identifier, GPSI.

[0017] In some embodiments, the request is received from an application backend server that provides a service to an application executed on the communication device. In some embodiments, the payload of the request or a header of the request includes an access token that is bound to at least some of the internal identifying information. In other embodiments, the request is received from an external server of an enterprise that owns a subscription with which the communication device accesses the communication network or that owns a connectivity service provided to the communication device.

[0018] In some embodiments, the identifier also identifies a connection of the communication device, and the internal identifying information also identifies the connection internally to the communication network.

[0019] In some embodiments, the method comprises, after transmitting the response, receiving a resolve request that requests the identifier server to resolve the identifier. In some embodiments, the method comprises, after transmitting the response, resolving the identifier into the internal identifying information according to the request. In some embodiments, the method comprises, after transmitting the response, transmitting a response that includes at least some of the internal identifying information resolved from the identifier. In some embodiments, generating the identifier comprises encrypting the internal identifying information and including the encrypted internal identifying information in the identifier, and resolving the identifier comprises decrypting the internal identifying information included in the identifier. In some embodiments, generating the identifier comprises binding the generated identifier to the internal identifying information by storing the generated identifier at the identifier server in association with the internal identifying information, and resolving the identifier comprises retrieving the internal identifying information stored in association with the identifier. In some embodiments, the request indicates one or more constraints that are to constrain usability of the identifier. In some embodiments, the identifier is further bound to the one or more constraints. In some embodiments, the method further comprises checking whether the identifier is usable according to one or more of the one or more constraints bound to the identifier, and the identifier is resolved based on the identifier being usable according to said checking.

[0020] In some embodiments, the request indicates one or more constraints that are to constrain usability of the identifier. In some embodiments, the one or more constraints include at least one or more validity constraints that constrain a validity of the generated identifier. In other embodiments, the one or more constraints include alternatively or additionally at least one or more API invoker constraints that constrain API invokers that are allowed to present the generated identifier in a request for invocation of an API exposed by the communication network. In yet other embodiments, the one or more constraints include alternatively or additionally at least one or more API provider constraints that constrain API providers to which the generated identifier is allowed to be presented in a request for invocation of an API exposed by the communication network. In still yet other embodiments, the one or more constraints include alternatively or additionally at least one or more connectivity constraints that constrain with which connectivity services the generated identifier is valid, such that according to the one or more connectivity  constraints the generated identifier is valid for identifying a connection to any of one or more certain connectivity services. In some embodiments, the one or more validity constraints include a time constraint that constrains a validity of the generated identifier to a finite time period and / or a location constraint that constrains a validity of the generated identifier to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier to a certain roaming status of the communication device. In other embodiments, alternatively or additionally, the one or more API invoker constraints include an API invoker ID constraint that constrains API invokers that are allowed to present the generated identifier to a set of one or more API invokers that have one or more respective API invoker identifiers. In other embodiments, the one or more API invoker constraints include an application ID constraint that constrains API invokers that are allowed to present the generated identifier to a set of one or more API invokers that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints include an API provider ID constraint that constrains API providers to which the generated identifier is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints include a domain network name, DNN, constraint that constrains with which DNNs the generated identifier is usable and / or a network slice constraint that constrains with which network slices the generated identifier is usable. In some embodiments, generating the identifier comprises including the one or more constraints in the identifier.

[0021] In some embodiments, generating the identifier comprises generating the identifier to be different than a previously generated identifier that identifies the same communication device and that is bound to the same internal identifying information.

[0022] In some embodiments, the identifier identifies the communication device persistently across changes to an internal Internet Protocol, IP, address of the communication device that is assigned to the communication device to address the communication device internally in the communication network.

[0023] Other embodiments herein include a method performed by a node that is a communication device or a server. The method comprises transmitting, to an identifier server in a communication network, a request for an identifier that is to identify the communication device to an external invoker device of an application programming interface, API, exposed by the communication network. In some embodiments, the request has a payload that includes an internal device identifier or an access token, wherein the internal device identifier identifies the communication device internally to the communication network, wherein the access token is associated with internal identifying information which identifies the communication device internally to the communication network. In other embodiments, the request alternatively or additionally indicates one or more constraints that are to constrain usability of the identifier. The method also comprises receiving a response that includes the identifier.

[0024] In some embodiments, the one or more constraints are embedded or encoded into the identifier.

[0025] In some embodiments, the identifier is a JavaScript Object Notation, JSON, Web Token.

[0026] In some embodiments, the request indicates the one or more constraints. In some embodiments, the one or more constraints include at least one or more validity constraints that constrain a validity of the  identifier. In other embodiments, the one or more constraints include alternatively or additionally at least one or more API invoker constraints that constrain API invokers that are allowed to present the identifier in a request for invocation of an API exposed by the communication network. In yet other embodiments, the one or more constraints include alternatively or additionally at least one or more API provider constraints that constrain API providers to which the identifier is allowed to be presented in a request for invocation of an API exposed by the communication network. In still yet other embodiments, the one or more constraints include alternatively or additionally at least one or more connectivity constraints that constrain with which connectivity services the identifier is usable. In some embodiments, the one or more validity constraints include a time constraint that constrains a validity of the generated identifier to a finite time period and / or a location constraint that constrains a validity of the generated identifier to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier to a certain roaming status of the communication device. In other embodiments, alternatively or additionally, the one or more API invoker constraints include an API invoker ID constraint that constrains API invokers that are allowed to present the identifier to a set of one or more API invokers that have one or more respective API invoker identifiers. In other embodiments, alternatively or additionally, the one or more API invoker constraints include an application ID constraint that constrains API invokers that are allowed to present the identifier to a set of one or more API invokers that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints include an API provider ID constraint that constrains API providers to which the identifier is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints include a domain network name, DNN, constraint that constrains with which DNNs the identifier is usable and / or a network slice constraint that constrains with which network slices the identifier is usable.

[0027] In some embodiments, the method is performed by the communication device. In some embodiments, an application executed on the communication device is configured to send the request and receive the response.

[0028] In some embodiments, the method is performed by an application backend server that provides a service to an application executed on the communication device.

[0029] In some embodiments, the method further comprises transmitting, to the application executed on the communication device, an identifier request that requests the identifier. In some embodiments, the method further comprises receiving a response to the identifier request that redirects the application backend server to an authorization server and that includes an authorization code to which to present to the authorization server. In some embodiments, the method further comprises transmitting, to the authorization server, an access token request that requests an access token and that includes the authorization code. In some embodiments, the method further comprises receiving a response to the access token request that includes the access token. In some embodiments, the payload of the request includes the access token.

[0030] In some embodiments, the method is performed by an external server of an enterprise that owns a  subscription with which the communication device accesses the communication network or that owns a connectivity service provided to the communication device.

[0031] In some embodiments, the payload of the request includes the internal device identifier.

[0032] In some embodiments, the identifier also identifies a connection of the communication device, and the internal identifying information also identifies the connection internally to the communication network.

[0033] In some embodiments, the identifier is in the format of a Network Access Identifier, NAI, or an opaque string.

[0034] In some embodiments, the method further comprises transmitting the identifier to an application backend server that provides a service to an application executed on the communication device.

[0035] In some embodiments, the method further comprises transmitting, to an API provider of the API, a request to invoke the API, wherein the request to invoke the API includes the identifier.

[0036] Other embodiments herein include a method performed by an external invoker device of an application programming interface, API, exposed by a communication network, wherein the external invoker device is a communication device or a server. The method comprises obtaining an identifier that is to identify the communication device to the external invoker device of the API. In some embodiments, one or more constraints that constrain usability of the identifier are embedded or encoded into the identifier. The method also comprises transmitting, to an API provider of the API, a request to invoke the API. In some embodiments, the request to invoke the API includes or is associated with the identifier. In other embodiments, the request to invoke the API includes or is associated with internal identifying information that identifies the communication device internally to the communication network, as resolved from the identifier by an identifier server in the communication network.

[0037] In some embodiments, the identifier is a JavaScript Object Notation, JSON, Web Token.

[0038] In some embodiments, the one or more constraints include at least one or more validity constraints that constrain a validity of the identifier. In other embodiments, the one or more constraints include alternatively or additionally at least one or more API invoker constraints that constrain API invokers that are allowed to present the identifier in a request for invocation of an API exposed by the communication network. In yet other embodiments, the one or more constraints include alternatively or additionally at least one or more API provider constraints that constrain API providers to which the identifier is allowed to be presented in a request for invocation of an API exposed by the communication network. In still yet other embodiments, the one or more constraints include alternatively or additionally at least one or more connectivity constraints that constrain with which connectivity services the identifier is usable. In some embodiments, the one or more validity constraints include a time constraint that constrains a validity of the generated identifier to a finite time period and / or a location constraint that constrains a validity of the generated identifier to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier to a certain roaming status of the communication device. In other embodiments, alternatively or additionally, the one or more API invoker constraints include an API invoker ID constraint that constrains API invokers that are allowed to present the identifier to a set of one or more API invokers that have one or more respective API invoker identifiers. In other embodiments, alternatively or  additionally, the one or more API invoker constraints include an application ID constraint that constrains API invokers that are allowed to present the identifier to a set of one or more API invokers that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints include an API provider ID constraint that constrains API providers to which the identifier is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints include a domain network name, DNN, constraint that constrains with which DNNs the identifier is usable and / or a network slice constraint that constrains with which network slices the identifier is usable.

[0039] In some embodiments, the external invoker device is the communication device. In some embodiments, an application executed on the communication device is configured to send the request.

[0040] In some embodiments, the external invoker device is the server. In some embodiments, the server is an application backend server that provides a service to an application executed on the communication device.

[0041] In some embodiments, obtaining the identifier comprises receiving the identifier from an external server of an enterprise that owns a subscription with which the communication device accesses the communication network or that owns a connectivity service provided to the communication device.

[0042] In some embodiments, the request includes the identifier.

[0043] In some embodiments, the request includes the internal identifying information. In some embodiments, the method further comprises transmitting, to the identifier server, a resolve request that requests the identifier server to resolve the identifier. In some embodiments, the method further comprises receiving the internal identifying information in a response to the resolve request.

[0044] In some embodiments, said transmitting comprises transmitting the identifier or the internal identifying information to the API provider server separately from the request to invoke the API.

[0045] Other embodiments herein include a method performed by an application programming interface, API, provider server that provides an API exposed by a communication network. The method comprises receiving, from an external invoker device external to the communication network, a request to invoke the API. In some embodiments, the request to invoke the API includes or is associated with an identifier that identifies a communication device to the external invoker device. The method also comprises transmitting, to an identifier server in the communication network, a resolve request that requests the identifier server to resolve the identifier. The method also comprises receiving a response to the resolve request that includes internal identifying information that identifies the communication device internally to the communication network. The method also comprises processing the request to invoke the API using the internal identifying information.

[0046] In some embodiments, one or more constraints that constrain usability of the identifier are bound to the identifier.

[0047] In some embodiments, said processing comprises: (i) checking an extent to which the one or more constraints allow the identifier to be used for invoking the API as requested; (ii) if each of the one or more  constraints allow the identifier to be used for invoking the API to at least some extent requested, invoking the API according to the request; and (iii) if at least one of the one or more constraints does not allow the identifier to be used for invoking the API to any extent requested, rejecting the request to invoke the API.

[0048] In some embodiments, the one or more constraints are embedded or encoded into the identifier. In some embodiments, the one or more constraints include at least one or more validity constraints that constrain a validity of the identifier. In other embodiments, the one or more constraints include alternatively or additionally at least one or more API invoker constraints that constrain API invokers that are allowed to present the identifier in a request for invocation of an API exposed by the communication network. In yet other embodiments, the one or more constraints include alternatively or additionally at least one or more API provider constraints that constrain API providers to which the identifier is allowed to be presented in a request for invocation of an API exposed by the communication network. In still yet other embodiments, the one or more constraints include alternatively or additionally at least one or more connectivity constraints that constrain with which connectivity services the identifier is usable. In some embodiments, the one or more validity constraints include a time constraint that constrains a validity of the generated identifier to a finite time period and / or a location constraint that constrains a validity of the generated identifier to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier to a certain roaming status of the communication device. In other embodiments, alternatively or additionally, the one or more API invoker constraints include an API invoker ID constraint that constrains API invokers that are allowed to present the identifier to a set of one or more API invokers that have one or more respective API invoker identifiers. In other embodiments, alternatively or additionally, the one or more API invoker constraints include an application ID constraint that constrains API invokers that are allowed to present the identifier to a set of one or more API invokers that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints include an API provider ID constraint that constrains API providers to which the identifier is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints include a domain network name, DNN, constraint that constrains with which DNNs the identifier is usable and / or a network slice constraint that constrains with which network slices the identifier is usable.

[0049] In some embodiments, the identifier is a JavaScript Object Notation, JSON, Web Token.

[0050] In some embodiments, the external invoker device is the communication device.

[0051] In some embodiments, the external invoker device is an application backend server that provides a service to an application executed on the communication device.

[0052] Other embodiments herein include a method performed by an authorization server in a communication network. The method comprises obtaining internal identifying information that identifies a communication device internally to the communication network. The method also comprises generating an access token with which an identifier bound to the internal identifying information is retrievable. The method also comprises storing the internal identifying information at an identifier server in the  communication network in association with the access token.

[0053] In some embodiments, the method further comprises receiving, from the communication device, an authorization request that comprises a request to authorize retrieval of the identifier. In some embodiments, the internal identifying information is obtained responsive to receiving the authorization request. In some embodiments, the method further comprises, after obtaining the internal identifying information, storing the internal identifying information at the identifier server, generating an authorization code that is associated with the internal identifying information, and transmitting the authorization code in a response to the authorization request. In some embodiments, the method further comprises receiving an access token request that includes the authorization code, wherein the access token is generated responsive to the access token request. In some embodiments, the method further comprises, after generating the access token, transmitting signaling to the identifier server indicating that the identifier server is to associate the internal identifying information with the access token. In some embodiments, the method further comprises transmitting a response to the access token request including the access token.

[0054] In some embodiments, the internal identifying information identifies the communication device internally to the communication network and includes a SUbscription Permanent Identifier, SUPI, and / or a Generic Public Subscription Identifier, GPSI. In some embodiments, the identifier also identifies a connection of the communication device, and the internal identifying information also identifies the connection internally to the communication network.

[0055] Other embodiments herein include an identifier server of a communication network. The identifier server is configured to receive a request for an identifier that is to identify a communication device to an external invoker device of an application programming interface, API, exposed by the communication network. The identifier server is also configured to determine, based on a payload of the request and / or a source address of the request, internal identifying information that identifies the communication device internally to the communication network. The identifier server is also configured to generate an identifier that is bound to the internal identifying information. The identifier server is also configured to transmit a response that includes the generated identifier.

[0056] In some embodiments, the identifier server is configured to perform the steps described above for an identifier server in a communication network.

[0057] Other embodiments herein include a node that is a communication device or a server. The node is configured to transmit, to an identifier server in a communication network, a request for an identifier that is to identify the communication device to an external invoker device of an application programming interface, API, exposed by the communication network. In some embodiments, the request has a payload that includes an internal device identifier or an access token, wherein the internal device identifier identifies the communication device internally to the communication network, wherein the access token is associated with internal identifying information which identifies the communication device internally to the communication network. In other embodiments, the request alternatively or additionally indicates one or more constraints that are to constrain usability of the identifier. The node is also configured to receive a response that includes the identifier.

[0058] In some embodiments, the node is configured to perform the steps described above for a node in a communication network or a server.

[0059] Other embodiments herein include an external invoker device of an application programming interface, API, exposed by a communication network, wherein the external invoker device is a communication device or a server. The external invoker device is configured to obtain an identifier that is to identify the communication device, and / or a connection of the communication device, to the external invoker device of the API, wherein one or more constraints that constrain usability of the identifier are embedded or encoded into the identifier. The external invoker device is also configured to transmit, to an API provider of the API, a request to invoke the API. In some embodiments, the request to invoke the API includes or is associated with the identifier. In other embodiments, the request to invoke the API includes or is associated with internal identifying information that identifies the communication device internally to the communication network, as resolved from the identifier by an identifier server in the communication network.

[0060] In some embodiments, the external invoker device is configured to perform the steps described above for an external invoker device of an application programming interface, API, exposed by a communication network.

[0061] Other embodiments herein include an application programming interface, API, provider server that provides an API exposed by a communication network. The API provider server is configured to receive, from an external invoker device external to the communication network, a request to invoke the API, wherein the request to invoke the API includes or is associated with an identifier that identifies a communication device to the external invoker device. The API provider server is also configured to transmit, to an identifier server in the communication network, a resolve request that requests the identifier server to resolve the identifier. The API provider server is also configured to receive a response to the resolve request that includes internal identifying information that identifies the communication device internally to the communication network. The API provider server is also configured to process the request to invoke the API using the internal identifying information.

[0062] In some embodiments, the API provider server is configured to perform the steps described above for an API provider server that provides an API exposed by a communication network.

[0063] Other embodiments herein include an authorization server of a communication network. The authorization server is configured to obtain internal identifying information that identifies a communication device internally to the communication network. The authorization server is also configured to generate an access token with which an identifier bound to the internal identifying information is retrievable. The authorization server is also configured to store the internal identifying information at an identifier server in the communication network in association with the access token.

[0064] In some embodiments, the authorization server is configured to perform the steps described above for an authorization server in a communication network.

[0065] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of an identifier server of a communication network, causes the identifier server to  perform the steps described above for an identifier server in a communication network.

[0066] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of a node that is a communication device or a server, causes the node to perform the steps described above for a node in a communication network or a server.

[0067] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of an external invoker device of an application programming interface, API, exposed by a communication network, causes the external invoker device to perform the steps described above for an external invoker device of an application programming interface, API, exposed by a communication network.

[0068] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of an application programming interface, API, provider server that provides an API exposed by a communication network, causes the API provider server to perform the steps described above for an API provider server that provides an API exposed by a communication network.

[0069] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of an authorization server of a communication network, causes the authorization server to perform the steps described above for an authorization server in a communication network.

[0070] In some embodiments, a carrier containing the computer program is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.

[0071] Other embodiments herein include an identifier server of a communication network. The identifier server comprises communication circuitry and processing circuitry. The processing circuitry is configured to receive a request for an identifier that is to identify a communication device to an external invoker device of an application programming interface, API, exposed by the communication network. The processing circuitry is also configured to determine, based on a payload of the request and / or a source address of the request, internal identifying information that identifies the communication device internally to the communication network. The processing circuitry is also configured to generate an identifier that is bound to the internal identifying information. The processing circuitry is also configured to transmit a response that includes the generated identifier.

[0072] In some embodiments, the processing circuitry is configured to perform the steps described above for an identifier server in a communication network.

[0073] Other embodiments herein include a node that is a communication device or a server. The node comprises communication circuitry and processing circuitry. The processing circuitry is configured to transmit, to an identifier server in a communication network, a request for an identifier that is to identify the communication device to an external invoker device of an application programming interface, API, exposed by the communication network. In some embodiments, the request has a payload that includes an internal device identifier or an access token, wherein the internal device identifier identifies the communication device internally to the communication network, wherein the access token is associated with internal identifying information which identifies the communication device internally to the communication network. In other embodiments, the request alternatively or additionally indicates one or  more constraints that are to constrain usability of the identifier. The processing circuitry is also configured to receive a response that includes the identifier.

[0074] In some embodiments, the processing circuitry is configured to perform the steps described above for a node in a communication network or a server.

[0075] Other embodiments herein include an external invoker device of an application programming interface, API, exposed by a communication network, wherein the external invoker device is a communication device or a server. The external invoker device comprises communication circuitry and processing circuitry. The processing circuitry is configured to obtain an identifier that is to identify the communication device to the external invoker device of the API. In some embodiments, one or more constraints that constrain usability of the identifier are embedded or encoded into the identifier. The processing circuitry is also configured to transmit, to an API provider of the API, a request to invoke the API. In some embodiments, the request to invoke the API includes or is associated with the identifier. In other embodiments, the request to invoke the API includes or is associated with internal identifying information that identifies the communication device internally to the communication network, as resolved from the identifier by an identifier server in the communication network.

[0076] In some embodiments, the processing circuitry is configured to perform the steps described above for an external invoker device of an application programming interface, API, exposed by a communication network.

[0077] Other embodiments herein include an application programming interface, API, provider server that provides an API exposed by a communication network. The API provider server comprises communication circuitry and processing circuitry. The processing circuitry is configured to receive, from an external invoker device external to the communication network, a request to invoke the API, wherein the request to invoke the API includes or is associated with an identifier that identifies a communication device to the external invoker device. The processing circuitry is also configured to transmit, to an identifier server in the communication network, a resolve request that requests the identifier server to resolve the identifier. The processing circuitry is also configured to receive a response to the resolve request that includes internal identifying information that identifies the communication device internally to the communication network. The processing circuitry is also configured to process the request to invoke the API using the internal identifying information.

[0078] In some embodiments, the processing circuitry is configured to perform the steps described above for an API provider server that provides an API exposed by a communication network.

[0079] Other embodiments herein include an authorization server of a communication network. The authorization server comprises communication circuitry and processing circuitry. The processing circuitry is configured to obtain internal identifying information that identifies a communication device internally to the communication network. The processing circuitry is also configured to generate an access token with which an identifier bound to the internal identifying information is retrievable. The processing circuitry is also configured to store the internal identifying information at an identifier server in the communication network in association with the access token.

[0080] In some embodiments, the processing circuitry is configured to perform the steps described above for an authorization server in a communication network.

[0081] Other embodiments herein include a non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an identifier server of a communication network, cause the identifier server to receive a request for an identifier that is to identify a communication device to an external invoker device of an application programming interface, API, exposed by the communication network. The instructions, when executed by a processor of an identifier server of a communication network, also cause the identifier server to determine, based on a payload of the request and / or a source address of the request, internal identifying information that identifies the communication device internally to the communication network. The instructions, when executed by a processor of an identifier server of a communication network, also cause the identifier server to generate an identifier that is bound to the internal identifying information. The instructions, when executed by a processor of an identifier server of a communication network, also cause the identifier server to transmit a response that includes the generated identifier.

[0082] Other embodiments herein include a non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of a node that is a communication device or a server, cause the node to transmit, to an identifier server in a communication network, a request for an identifier that is to identify the communication device to an external invoker device of an application programming interface, API, exposed by the communication network. In some embodiments, the request has a payload that includes an internal device identifier or an access token. In some embodiments, the internal device identifier identifies the communication device internally to the communication network, wherein the access token is associated with internal identifying information which identifies the communication device internally to the communication network. In other embodiments, the request alternatively or additionally indicates one or more constraints that are to constrain usability of the identifier. The instructions, when executed by a processor of a node that is a communication device or a server, also cause the node to receive a response that includes the identifier.

[0083] Other embodiments herein include a non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an external invoker device of an application programming interface, API, exposed by a communication network, cause the external invoker device to obtain an identifier that is to identify the communication device to the external invoker device of the API, wherein one or more constraints that constrain usability of the identifier are embedded or encoded into the identifier. The instructions, when executed by a processor of an external invoker device of an application programming interface, API, exposed by a communication network, also cause the external invoker device to transmit, to an API provider of the API, a request to invoke the API. In some embodiments, the request to invoke the API includes or is associated with the identifier. In other embodiments, the request to invoke the API includes or is associated with internal identifying information that identifies the communication device internally to the communication network, as resolved from the identifier by an identifier server in the communication network.

[0084] Other embodiments herein include a non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an application programming interface, API, provider server that provides an API exposed by a communication network, cause the API provider server to receive, from an external invoker device external to the communication network, a request to invoke the API, wherein the request to invoke the API includes or is associated with an identifier that identifies a communication device to the external invoker device. The instructions, when executed by a processor of an application programming interface, API, provider server that provides an API exposed by a communication network, also cause the API provider server to transmit, to an identifier server in the communication network, a resolve request that requests the identifier server to resolve the identifier. The instructions, when executed by a processor of an application programming interface, API, provider server that provides an API exposed by a communication network, also cause the API provider server to receive a response to the resolve request that includes internal identifying information that identifies the communication device internally to the communication network. The instructions, when executed by a processor of an application programming interface, API, provider server that provides an API exposed by a communication network, also cause the API provider server to process the request to invoke the API using the internal identifying information.

[0085] Other embodiments herein include a non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an authorization server of a communication network, cause the authorization server to obtain internal identifying information that identifies a communication device internally to the communication network. The instructions, when executed by a processor of an authorization server of a communication network, also cause the authorization server to generate an access token with which an identifier bound to the internal identifying information is retrievable. The instructions, when executed by a processor of an authorization server of a communication network, also cause the authorization server to store the internal identifying information at an identifier server in the communication network in association with the access token.

[0086] Embodiments herein also include corresponding apparatus, computer programs, and carriers of those computer programs.

[0087] Of course, the present disclosure is not limited to the above features and advantages. Indeed, those skilled in the art will recognize additional features and advantages upon reading the following detailed description, and upon viewing the accompanying drawings.BRIEF DESCRIPTION OF THE DRAWINGS

[0088] Figure 1 is a block diagram of a communication network that exposes an API according to some embodiments.

[0089] Figure 2A is a block diagram of an identifier according to some embodiments.

[0090] Figure 2B is a block diagram of an identifier server and identifier according to some embodiments.

[0091] Figure 3A is a block diagram of a communication network that includes an API provider server which resolves an identifier received in an API invocation request, according to some embodiments.

[0092] Figure 3B is a block diagram of a communication network that includes an external invoker device  which resolves an identifier for including the corresponding internal identifying information in an API invocation request, according to some embodiments.

[0093] Figure 4 is a block diagram of an identifier server in a communication network according to some embodiments.

[0094] Figure 5 is a block diagram of a communication network that includes an authorization server for supporting an identifier server according to some embodiments.

[0095] Figure 6 is a block diagram of an identifier that embeds constraint (s) according to some embodiments.

[0096] Figure 7 is a sequence diagram of obtaining a token-like identifier from a communication network and using the identifier at Northbound APIs calls for accessing Network Capabilities, according to some embodiments.

[0097] Figure 8 is a call flow diagram of UE ID retrieval by a device application according to some embodiments.

[0098] Figure 9 is sequence diagram illustrating the retrieval of the UE identify by the UE and the usage of the UE Identity by the App Backend according to some embodiments.

[0099] Figure 10 is a call flow sequence diagram of the UE ID retrieval by the SUPI  / CS owner, according to some embodiments.

[0100] Figures 11A-11B are a block diagram of UE Connection ID retrieval by Device App according to some embodiments.

[0101] Figure 12 is a logic flow diagram of a method performed by an identifier server according to some embodiments.

[0102] Figure 13 is a logic flow diagram of a method performed by a node that is a communication device or a server according to some embodiments.

[0103] Figure 14 is a logic flow diagram of a method performed by an external invoker device according to some embodiments.

[0104] Figure 15 is a logic flow diagram of a method performed by an API provider server according to some embodiments.

[0105] Figure 16 is a logic flow diagram of a method performed by an authorization server according to some embodiments.

[0106] Figure 17 is a block diagram of a communication device according to some embodiments.

[0107] Figure 18 is a block diagram of an identifier server according to some embodiments.

[0108] Figure 19 is a block diagram of a node that is a communication device or a server according to some embodiments.

[0109] Figure 20 is a block diagram of an external invoker device according to some embodiments.

[0110] Figure 21 is a block diagram of an API provider server according to some embodiments.

[0111] Figure 22 is a block diagram of an authorization server according to some embodiments.DETAILED DESCRIPTION

[0112] Figure 1 shows a communication network 10 according to some embodiments, e.g., in the form of a 3GPP 4G, 5G or 6G network. The communication network 10 provides communication service to one or more communication devices, including communication device 12, e.g., a user equipment (UE) . Communication device 12 in this regard is shown as having a connection 12C to the communication network 10, e.g., in the form of a Protocol Data Unit (PDU) session. In embodiments where the connection 12C is at the network layer, for instance, the connection 12C may be an Internet Protocol (IP) connection.

[0113] The communication network 10 exposes an application programming interface (API) 16 to one or more services offered by the communication network 10, e.g., where such exposure may be via a Network Exposure Function (NEF) or a Services Capability Exposure Function (SCEF) . The communication network 10 as shown for example includes an API provider server 14 that provides this API 16. Regardless, the API 16 provides a set of standardized endpoints and protocols that allow an external invoker device 18 to invoke the API 16, in order to interact programmatically with the network's service (s) . The API 16 may for example offer one or more services such as sending text messages, making voice calls, managing user accounts, quality of service (QoS) services, location services, Subscriber Identity Module (SIM) swapping services, and / or accessing network data. By invoking such an API 16, the external invoker device 18 may for instance provide value-added services such as bulk messaging, call routing, or data analytics.

[0114] In some embodiments, the external invoker device 18 is a device that is outside the management or control of the communication network’s operator. For example, the external invoker device 18 may be an application backend server that provides a service to an application (e.g., a 3rd party application) executed on the communication device 12. Or, the external invoker device 18 may be an external server of an enterprise that owns a subscription with which the communication device 12 accesses the communication network 10 or that owns a connectivity service provided to the communication device 12. In other embodiments, by contrast, the external invoker device 18 is a device that executes an application which invokes the API 16 and which is outside the management or control of the communication network’s operator. That is, even if the external invoker 18 device itself is under the management or control of the communication network’s operator, the application that invokes the API 16 is nonetheless outside the management or control of the communication network’s operator. In fact, in some embodiments, the external invoker device 18 is the communication device 12 itself, in which case the communication device 12 executes the application that invokes the API 16. Generally, then, the external nature of the external invoker device 18 may mean that the device itself, or an application executed by the device, is outside the management or control of the communication network’s operator.

[0115] Irrespective of the particular form of the external invoker device 18, the external invoker device 18 as shown transmits an API invocation request 20 to the API provider server 14. The API invocation request 20 requests invocation of the API 16, e.g., by calling one or more functions exposed by the API 16. The API invocation request 20 according to embodiments herein, though, relates to a particular communication device, which in this example is communication device 12. As such, the API invocation request 20 must identify to which communication device 12 the API invocation request 20 relates, e.g., for which communication device 12 service (s) invoked by the API invocation request 20 are to be applied.

[0116] Embodiments herein notably deploy an identifier server 22 in the communication network 10 for this purpose. As such, it is a server in the communication network 10 itself that facilitates identification of the communication device 12, rather than some server external to the communication network 10. The deployment of the identifier server 22 in the communication network 10 puts the identifier server 22 in an advantageous position for facilitating identification of the communication device 12 in the API invocation request 20.

[0117] In this role, the identifier server 22 generates an identifier 12-ID that is to identify the communication device 12 to the API provider server 14 or the external invoker device 18. In some embodiments, the identifier 12-ID also identifies the connection 12C of the communication device 12. The identifier 12-ID may for example take the form of a JavaScript Object Notation (JSON) Web Token (JWT) , be in the form of a Network Access Identifier (NAI) , or even be an opaque string, as elaborated more fully later. No matter its particular form, though, from the perspective of the API provider server 14 or the external invoker device 18, the identifier 12-ID functions as the means by which to identify the communication device 12, as distinguishable from one or more other communication devices. In fact, in some embodiments, the identifier 12-ID uniquely identifies the communication device 12 within a defined scope, e.g., in the sense that no other communication device, at least for the same communication network 10, the same API provider server 14, and / or the same external invoker device 18, is identified by the same identifier 12-ID at the same time. In fact, in some embodiments, the identifier 12-ID is globally unique in the sense that only one communication service provider is able to make use of the identifier 12-ID.

[0118] Even though the identifier 12-ID identifies the communication device 12 to the external invoker device 18, as needed by the external invoker device 18 for identifying the communication device 12 as the target of the API invocation request 20, the identifier 12-ID effectively obfuscates information 12-INT that identifies the communication device 12 internally to the communication network 10. Indeed, such internal identifying information 12-INT may include privacy-sensitive information that, if revealed externally and / or to untrusted nodes, would jeopardize the privacy of the communication device’s user. For example, the internal identifying information 12-INT may include a SUbscription Permanent Identifier (SUPI) or Generic Public Subscription Identifier (GPSI) of the communication device 12. In embodiments where the identifier 12-ID also identifies the connection 12C, the internal identifying information 12-INT may further include an internal network layer address (e.g., IP address) of the connection 12C as well as a domain network name (DNN) , a network slice identifier, and / or an internal network domain of the connection 12C. In still other embodiments, the internal identifying information 12-INT may include a GPSI in the form of a Mobile Station International Subscriber Directory Number (MSISDN) . In these or other embodiments, then, the internal identifying information 12-INT may identify the communication device 12 (and possibly also the connection 12C) on a relatively long-term basis. The identifier 12-ID may obfuscate the internal identifying information 12-INT in these and other cases, then, in order to protect the privacy of the communication device’s user.

[0119] Even though the identifier 12-ID obfuscates the internal identifying information 12-INT, at least to the external invoker device 18, the identifier server 22 creates a binding 12B between the identifier 12-ID  and the internal identifying information 12-INT. As such, the identifier 12-ID is bound to the internal identifying information 12-INT.

[0120] For example, Figure 2A shows one example where the identifier server 22 binds the identifier 12-ID to the internal identifying information 12-INT by including the internal identifying information 12-INT, in encrypted form, within the identifier 12-ID itself. That is, the identifier server 22 encrypts the internal identifying information 12-INT to obtain encrypted internal identifying information 12-INT (E) and then includes the encrypted internal identifying information 12-INT (E) in the identifier 12-ID, e.g., by embedding or encoding the encrypted internal identifying information 12-INT (E) in the identifier 12-ID. Such embodiments may be realizable where the identifier 12-ID takes the form of a data object or structure, such as a JWT or other security token, capable of containing the encrypted internal identifying information 12-INT (E) . The encrypted nature of the encrypted internal identifying information 12-INT (E) protects the internal identifying information 12-INT from being revealed to the external invoker device 18 in decrypted form. Yet the inclusion of the encrypted internal identifying information 12-INT (E) in the identifier 12-ID enables the internal identifying information 12-INT to be obtained from the identifier 12-ID by any node capable of decrypting the encrypted internal identifying information 12-INT (E) . In some embodiments, the identifier server 22 also may cryptographically sign the identifier 12-ID, e.g., to enable the identifier 12-ID (or at least a portion thereof) to be cryptographically authenticated as having been issued by the identifier server 22. In one embodiment, for example, the identifier server 22 includes the encrypted internal identifying information 12-INT (E) in an information element (IE) of the identifier 12-ID and cryptographically signs that information element.

[0121] Figure 2B illustrates a different example where the identifier server 22 binds the identifier 12-ID to the internal identifying information 12-INT by storing the identifier 12-ID at the identifier server 22 in association with the internal identifying information 12-INT. As shown, for instance, the identifier server 22 maintains a mapping 22M at the identifier server 22 which maps the identifier 12-ID to the internal identifying information 12-INT. This enables the identifier server 22 to later resolve the identifier 12-ID into the internal identifying information 12-INT, yet the identifier 12-ID itself does not reveal the internal identifying information 12-INT to any other node that lacks this mapping 22M. These embodiments may thereby permit the identifier 12-ID to be a Network Access Identifier (NAI) , an opaque string, or any other pointer to an ephemeral state at the identifier server 22. Such an NAI or opaque string may be an unstructured or undecipherable sequence of characters or symbols that cannot be easily understood or interpreted without additional context or information.

[0122] No matter how bound, though, the binding 12B in some embodiments persists even across changes to the internal network layer address (e.g., IP address) of the communication device 12. For example, where the internal identifying information 12-INT includes the SUPI or GPSI of the communication device 12, the identifier 12-ID by way of being bound to such information 12-INT persistently identifies the communication device 12 even after the external network layer address of the communication device 12 changes. As such, some embodiments improve robustness to external network layer address changes.

[0123] Note, though, that the identifier server 22 in some embodiments generates a new identifier on each  request to retrieve an identifier, e.g., meaning that at any one time there may be multiple such identifiers identifying the same device 12. For example, in some embodiments, the identifier server 22 generates the identifier 12-ID to be different than a previously generated identifier that identifies the same communication device 12 and that is bound to the same internal identifying information 12-INT. The identifier server 22 may for instance include one or more pseudorandom components, counter (s) , or a timestamp in the generation of the identifier 12-ID to facilitate this. Note though that in some embodiments the identifier server 22 generates identifiers in a way so that it is not possible to determine that multiple identifiers identify the same device 12., e.g., so as to enhance user privacy protection.

[0124] Furthermore, the binding of the identifier 12-ID to internal identifying information 12-INT enables embodiments herein to be effective even in deployment scenarios (e.g., Network Address Translation, NAT, deployment) where the external network layer address of the communication device 12 would be insufficient for identifying the communication device 12. Some embodiments thereby improve flexibility of API invocation to different deployment scenarios of the communication network 10. According to some embodiments, then, the communication network 10 deploys a Network Address Translator (NAT) or firewall (not shown) , e.g., in-between the device connection 12C and the external network where the external invoker device 18 resides. In such a case, the external invoker device 18 is outside the NAT or firewall, and there is no NAT or firewall between the communication device 12, its connection 12C, and the identifier server 22.

[0125] In any event, returning back to Figure 1, the identifier 12-ID as such enables the external invoker device 18 to identify the communication device 12 as the target of its API invocation request 20, without revealing the internal identifying information 12-INT to the external invoker device 18. The external invoker device 18 in this regard obtains the identifier 12-ID from the identifier server 22, either directly or indirectly. In some embodiments, for example, the external invoker device 18 directly requests and retrieves the identifier 12-ID from the identifier server 22. In such a case, the external invoker device 18 is itself an identifier requesting device 24. This may be the case for instance where an application client running on the communication device 12 both invokes the API 16 and requests the identifier 12-ID. In other embodiments shown in Figure 1, though, the identifier requesting device 24 that directly requests and retrieves the identifier 12-ID from the identifier server 22 is different than and separate from the external invoker device 18. In this case, the external invoker device 18 retrieves the identifier 12-ID from the identifier server 22 only indirectly, via a separate identifier requesting device 24 that directly retrieves and requests the identifier 12-ID from the identifier server 22.

[0126] In one or more of these latter embodiments, for example, the identifier requesting device 24 may be an external server of an enterprise that owns a subscription with which the communication device 12 accesses the communication network 10. As another example, the identifier requesting device 24 may be an external server of an enterprise that owns a connectivity service provided to the communication device 12.

[0127] No matter how the external invoker device 18 obtains the identifier 12-ID, the external invoker device 18 uses that identifier 12-ID to identify the communication device 12 as the target of the API  invocation request 20. In some embodiments, such as where the external invoker device 18 is untrusted, the external invoker device 18 does so by including the identifier 12-ID in the API invocation request 20. In this case, the API provider server 14 may employ the identifier server 22 to resolve the identifier 12-ID into the internal identifying information 12-INT, in order to determine which communication device the API invocation request 20 targets. In other embodiments where the external invoker device 22 is trusted, though, the external invoker device 22 may itself employ the identifier server 22 to resolve the identifier 12-ID into the internal identifying information 12-INT and then just include the internal identifying information 12-INT in the API invocation request 20. Figures 3A and 3B illustrate these embodiments in more detail.

[0128] As shown in Figure 3A, the external invoker device 18 includes the identifier 12-ID in the API invocation request 20. In receipt of the API invocation request 20, the API provider server 14 sends a resolve request 25 to the identifier server 22. The resolve request 25 includes the identifier 12-ID and requests the identifier server 22 to resolve the identifier 12-ID into the internal identifying information 12-INT. Per the resolve request 25, the identifier server 22 resolves the identifier 12-ID, e.g., by decrypting encrypted internal identifying information 12-INT (E) included in the identifier 12-ID or by retrieving the internal identifying information 12-INT stored in association with the identifier 12-ID. The identifier server 22 then responds to the resolve request 25 by transmitting at least some of the internal identifying information 12-INT to the API provider server 14. The API provider server 14 uses this internal identifying information 12-INT to process the API invocation request 20, e.g., to identify the communication device 12 to which the API invocation request 20 relates.

[0129] In Figure 3B, by contrast, the external invoker device 18 itself transmits the resolve request 25 to the identifier server 22. As in Figure 3A, the resolve request 25 includes the identifier 12-ID and requests the identifier server 22 to resolve the identifier 12-ID into the internal identifying information 12-INT. Per the resolve request 25, the identifier server 22 resolves the identifier 12-ID and responds to the resolve request 25 by transmitting at least some of the internal identifying information 12-INT to the external invoker device 18. The external invoker device 18 includes this internal identifying information 12-INT in the API invocation request 20, alternatively to or in addition to the identifier 12-ID. The API provider server 14 uses the internal identifying information 12-INT included in the API invocation request 20 in order to process the API invocation request 20, e.g., to identify the communication device 12 to which the API invocation request 20 relates.

[0130] Although some embodiments are shown as including the identifier 12-ID or the internal identifying information 12-INT in the API invocation request 20, in other embodiments the identifier 12-ID or internal identifying information 12-INT are transmitted to the API provider server 14 separately from, but in association with, the API invocation request 20. For example, the identifier 12-ID or internal identifying information 12-INT may be transmitted in a separate message to the API provider server 14, in advance of the API invocation request 20. The API invocation request 20 may then reference the previously sent message as a way to indicate that the API invocation request 20 targets whatever communication device 12 is identified by the identifier 12-ID or internal identifying information 12-INT which was included in that  message.

[0131] Consider now additional details shown in Figure 4 for how the identifier server 22 fields a request for the identifier 12-ID from the identifier requesting device 24, which may be the same as or different than the external invoker device 18. In Figure 4, the identifier requesting device 24 transmits an identifier request 26 to the identifier server 22. The identifier request 26 requests the identifier 12-ID that is to identify the communication device 12.

[0132] In some embodiments, the identifier requesting device 24 is preconfigured with an address of the identifier server 22 to which to send the identifier request 26. For example, the address of the identifier server 22 may be predefined as a well-known address which resolves to the identifier server 22. In other embodiments, the identifier requesting device 24 receives the address of the identifier server 22 from the communication network 10 or from another server, e.g., an application server (AS) .

[0133] Regardless, the identifier server 22 in some embodiments exploits a source address 26A of the identifier request 26, in order to determine the internal identifying information 12-INT for the communication device 12 to be identified by the requested identifier 12-ID. For example, in one or more embodiments, the identifier requesting device 24 is the communication device 12 itself, e.g., where the API invocation request 20 is sent by an application executed on the communication device 12. In this case, the source address 26A of the identifier request 26 is an address of the communication device 12. In fact, in some embodiments, the source address 26A of the identifier request 26 is an address of the connection 12C over which the request is sent. For example, in some embodiments, the communication device 12 as the identifier requesting device 24 sends the identifier request 26 over the connection 12C, e.g., the same connection 12C as that used for application traffic. The identifier request 26 may for instance utilize the same traffic category or application identifier as the application traffic. In these and other embodiments, then, the identifier server 22 may lookup the internal identifying information 12-INT based on the source address 26A of the identifier request 26. For example, the identifier server 22 may send a query for the internal identifying information 12-INT to another network node 30, e.g., implementing a Binding Support Function (BSF) . The query in this case includes the source address 26A. The network node 30 resolves the internal identifying information 12-INT from the source address 26A and returns the internal identifying information 12-INT to the identifier server 22.

[0134] In other embodiments, the identifier server 22 alternatively or additionally exploits a payload 26P of the identifier request 26 in order to determine the internal identifying information 12-INT. For example, in some embodiments, the payload 26P includes an internal device identifier (ID) 27 that identifies the communication device 12 internally to the communication network 10. The internal device ID 27 may for example be a SUPI, GPSI, or another identifier 12-ID for the same communication device 12. The identifier server 22 may lookup the internal identifying information 12-INT using such an internal device ID 27, potentially with assistance from another network node 30, e.g., implementing a Unified Data Management (UDM) function.

[0135] In still other embodiments, the payload 26P of the identifier request 26 alternatively or additionally includes an access token 28 that the identifier server 22 uses to determine the internal identifying  information 12-INT. The access token 287 may for example have been previously associated with the internal identifying information 12-INT. Figure 5 illustrates one or more such embodiments.

[0136] As shown in Figure 5, the communication network 10 also includes an authorization (auth) server 40.The authorization server 40 receives authorization request 42 from the communication device 12, e.g., from an application executed on the communication device 12. The authorization request 42 requests the authorization server 40 to authorize retrieval of the identifier 12-ID. Responsive to receiving this authorization request 42, the authorization server 40 obtains the internal identifying information 12-INT. After obtaining the internal identifying information 12-ID, the authorization server 40 stores the internal identifying information 12-ID at the identifier server 22, as shown. The authorization server 40 also generates an authorization code 44 to be associated with the internal identifying information 12-ID. The association between the authorization code 44 and the internal identifying information 12-INT may for instance be maintained by the authorization server 40. Regardless, the authorization server 40 transmits that authorization code 44 to the communication device 12 in a response 46 to the authorization request 42.

[0137] The communication device 12 thereafter passes the authorization code 44 to a separate identifier requesting device 24, e.g., an application backend server for an application executing on the communication device 12. In some embodiments, for example, the identifier requesting device 24 transmits a request (not shown) for the identifier 12-ID to an application executed on the communication device 12. In response to this request, the application on the communication device 12 may send a response that redirects the identifier requesting device 12 to the authorization server 40 and that includes the authorization code 44 to which to present to the authorization server 40.

[0138] The identifier requesting device 24 correspondingly transmits an access token request 47 to the authorization server 40. The access token request 47 includes the authorization code 44. Responsive to this access token request 47, the authorization server 40 generates an access token 28 and transmits signaling to the identifier server 22 indicating that the identifier server 22 is to associate the internal identifying information 12-INT with this access token 28. Based on this signaling, the identifier server 22 stores the internal identifying information 12-INT in association with the access token 28. The authorization server 40 then transmits a response 48 to the access token request 47. This response 48 includes the access token 28.As a result, then, the identifier requesting device 24 is equipped with an access token 28 that the identifier server 22 has associated with the internal identifying information 12-INT and that therefore is usable by the identifier requesting device 24 to retrieve an identifier 12-ID bound to that internal identifying information 12-INT. Figure 4 shows in this regard that the identifier requesting device 24 may include the access token 28 in the payload of its identifier request 26 to the identifier server 22.

[0139] Alternatively or additionally, Figure 4 shows that the identifier requesting device 24 may include one or more constraints 29 in the payload 26P of the identifier request 26 to the identifier server 22. The constraint (s) 29 are to constrain usability of the identifier 12-ID, e.g., in time, space, purpose, connectivity, or some other extent. Enabling the identifier requesting device 24 to specify constraint (s) 29 for constraining usability of the identifier 12-ID advantageously expands the ways in which usability of the identifier 12-ID can be constrained. For example, rather than the identifier 12-ID just being constrained to  being usable for a specific application or application function (AF) , the identifier 12-ID by way of the requester-provided constraint (s) 29 may be constrained to being usable by a specified external invoker device 18, for a specified time duration, within a specified geographic area, for a specified purpose, or the like. Some embodiments may thereby advantageously improve security by better guarding against re-use of the identifier 12-ID, e.g., by an unintended bearer of the identifier 12-ID, for an unintended use, etc.

[0140] More particularly in this regard, the constraint (s) 29 in some embodiments may include one or more validity constraints that constrain a validity of the identifier 12-ID. For example, the validity constraint (s) may include a time constraint that constrains a validity of the identifier 12-ID to a finite time period. Alternatively or additionally, the validity constraint (s) may include a location constraint that constrains a validity of the identifier 12-ID to a finite geographical location. The validity constraint (s) may alternatively or additionally include a roaming constraint that constraints a validity of the identifier 12-ID to a certain roaming status of the communication device 12, e.g., to where the identifier 12-ID is valid only when the communication device 12 is roaming or valid only when the communication device 12 is not roaming.

[0141] The constraint (s) 29 may alternatively or additionally include one or more API invoker constraints. The API invoker constraint (s) may constrain API invokers that are allowed to present the identifier 12-ID in a request for invocation of the API 16. The API invoker constraint (s) may for instance include an API invoker ID constraint that constrains API invokers that are allowed to present the identifier 12-ID to a set of one or more API invokers that have one or more respective API invoker identifiers. Or, the API invoker constraint (s) may include an application ID constraint that constrains API invokers that are allowed to present the identifier 12-ID to a set of one or more API invokers that execute an application with a specified application identifier.

[0142] Furthermore, the constraint (s) 29 may include constraints on the API endpoint (s) and / or the API operations for which the identifier 12-ID is allowed to be used. For example, the constraint (s) 29 may restrict use of the identifier 12-ID to READ-only operations or only to being "used for Location APIs, but not for other APIs" .

[0143] As still another option, the constraint (s) 29 may include API provider constraint (s) that constrain API providers to which the identifier 12-ID is allowed to be presented in a request for invocation of the API 16. For example, the API provider constraint (s) may include an API provider ID constraint that constrains API providers to which the identifier 12-ID is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers.

[0144] As yet another option, the constraint (s) 29 may include connectivity constraint (s) 29 that constrain with which connectivity services the identifier 12-ID is valid. According to the connectivity constraint (s) 29, for example, the identifier 12-ID may be valid for identifying a connection to any of one or more certain connectivity services. For example, the connectivity constraint (s) may include a domain network name (DNN) constraint that constrains with which DNNs the identifier 12-ID is usable and / or a network slice constraint that constrains with which network slices the identifier 12-ID is usable.

[0145] In any event, the identifier server 22 in some embodiments binds the constraint (s) 29 to the  identifier 12-ID. Figure 6 for example shows that in some embodiments the identifier server 22 includes the constraint (s) 29 in the identifier 12-ID, e.g., by embedding or encoding the constraint (s) 29 in the identifier 12-ID along with encrypted internal identifying information 12-INT (E) . In some embodiments, the constraint (s) 29 may also be encrypted, e.g., either separately from or together with the encrypted internal identifying information 12-INT (E) .

[0146] One or more of the constraint (s) 29 may be checked before the identifier 12-ID is able to be used. In some embodiments, for example, the API provider server 14 receives the identifier 12-ID in the API invocation request 20, as shown in Figure 3A, but checks whether the identifier 12-ID is usable according to the constraint (s) 29. The API provider server 14 in this regard may only process, accept, or allow the API invocation request 20 if the identifier 12-ID is usable according to that check. Generally, then, the API provider server 14 may: (i) check an extent to which the one or more constraints 29 allow the identifier 12-ID to be used for invoking the API 16 as requested; (ii) if each of the one or more constraints 29 allow the identifier 12-ID to be used for invoking the API 16 to at least some extent requested, invoke the API 16 according to the API invocation request 20; and (iii) if at least one of the one or more constraints 29 does not allow the identifier 12-ID to be used for invoking the API 16 to any extent requested, rejecting the API invocation request 20.

[0147] In other embodiments, the identifier server 22 receives the identifier 12-ID in a resolve request 25, as shown in Figure 3B, and checks whether the identifier 12-ID is usable according to one or more of the constraint (s) 29 bound to the identifier 12-ID. The identifier server 22 may accordingly resolve the identifier 12-ID based on the identifier 12-ID being usable according to that check, e.g., the identifier server 22 may reject the resolve request 25 if the identifier 12-ID is not usable according to the constraint (s) 29.

[0148] In still other embodiments (not shown) , the identifier server 22 returns the constraint (s) 29 in response to resolve request 25. So, in Figures 3A and 3B the constraint (s) would be returned in addition to the internal identifying information 12-INT in response to the resolve request 25.

[0149] Note that different ones of the constraint (s) 29 may be checkable by different nodes. For example, some of the constraint (s) 29 may be checked by the identifier server 22 whereas other (s) of the constraint (s) 29 may be checked by the API provider server 14 and / or the external invoker device 18.

[0150] Note also that, in some embodiments, the constraint (s) 29 may be applied by the communication network 10, e.g., based on a policy or service logic, regardless of whether or not the constraint (s) 29 were included in the identifier request 26.

[0151] Consider now specific examples of some embodiments herein in a context where the communication network 10 is a 5G network or another network specified by the 3rd Generation Partnership Project (3GPP) . As such, the communication device 12 is exemplified as a user equipment (UE) and the identifier 12-ID is exemplified as a UE identifier (ID) . In these examples, the following terms are used, e.g., consistent with 3GPP TS 23.222 v19.0.0.

[0152] API: The means by which an API invoker can access the service. The API in the below examples exemplify the API 16 in Figure 1.

[0153] API invoker: The entity which invokes a Common API Framework (CAPIF) or service APIs. The  API invoker in the examples below exemplify the external invoker device 18 in Figure 1.

[0154] API exposing function: The entity which provides the service communication entry point for the service APIs.

[0155] Common API framework (CAPIF) : A framework comprising common API aspects that are required to support service APIs.

[0156] Northbound API: A service API exposed to higher-layer API invokers.

[0157] Resource: The object or component of the API on which the operations are acted upon, e.g., as requested by the API invocation request 20 in Figure 1.

[0158] Resource owner: An entity (either a UE user or a mobile network operator subscriber) capable of granting access to a protected resource related to the invoked API.

[0159] Service API: The interface through which a component of the system exposes its services to API invokers by abstracting the services from the underlying mechanisms.

[0160] Some embodiments herein enable communication service providers (CSPs) to expose network capabilities to external consumers. This for example enables different external entities like aggregators to get access to network capabilities. Some embodiments in particular address a common issue across multiple APIs (Network Exposure Function) , namely, the identification of the targeted user or device.

[0161] Some embodiments are operable in a communication network 10 where there are a number of identifiers available, depending on usage.

[0162] One identifier is a Subscription Permanent Identifier (SUPI) . The SUPI is a globally unique identifier, which shall be used only inside of the 5G System, i.e., it is never exposed externally by the CSP.

[0163] Another identifier is a Generic Public Subscription Identifier (GPSI) . The Generic Public Subscription Identifier (GPSI) is needed for addressing a 3GPP subscription in different data networks outside of the 3GPP system. The 3GPP system stores within the subscription data the association between the GPSI and the corresponding SUPI. The GPSI is either an MSISDN or an External Identifier. The External Identifier may also be used as an AF-specific UE Identifier (see TS 23.501 V18.4.0 Cl 5.20) . 3GPP uses a plain string format for both identifiers. Multiple different GPSIs may be associated to the same SUPI.

[0164] Yet another identifier is the 5G assigned IP address. This may be either an IPv4 address or an IPv6 network prefix. Formally, this 5G Assigned IP address is not considered as a UE identifier. However, each established PDU Session of a single UE is assigned an IP address. The 5G Assigned IP address may not be unique within the 5G System. It only becomes unique when combining with the DNN of the Data Network (DN) . In some deployments, also an IP Domain and / or the S-NSSAI is needed.

[0165] Some embodiments herein accommodate for a CSP to use Network Address Translators (NAT, RFC 2663) to separate the mobile network from the Public Internet. The high-performance NATs deployed by CSPs are often also called Carrier Grade NATs (CG-NAT) due to high scalability and performance.

[0166] One reason for the CSP to deploy a CG-NAT is that it “expands” the IPv4 address range of the  CSP. The CSP can assign internal and private IPv4 addresses to UEs in the mobile network. Towards the outside, the CSP needs to allocate only some (public) IPv4 addresses. The number of externally needed (public) IPv4 addresses is much lower than the number of assigned IP addresses by the system. Note that a single UE may use several external IP addresses at the same time, since the CG-NAT is assigning Public IP Address  / Source Port for each Layer 4 connection (i.e. TCP or UDP connection) .

[0167] Another reason for the CSP to deploy a CG-NAT is that it increases privacy, since UEs and users cannot be tracked by external entities based on their IP address. When using a NAT, many UEs use the same public IP address and the external provider cannot easily differentiate between UEs anymore.

[0168] In some embodiments, network exposure functions (like a NEF) in the communication network 10 have public IP addresses, e.g., to enable an Application Function (AF) in the external Data Network (DN) to access the Functions. A NEF may expose APIs using Hypertext Transfer Protocol Secure (HTTPS) . An external API invoker may need to register to get access to a NEF. This may be accomplished in some embodiments using registration, authorization and security procedures.

[0169] Some embodiments herein account for the possibility that an application client executed by the UE may not be able to read its own IP address from the local IP stack. Some embodiments for example account for a single device having multiple IP addresses assigned, like localhost, Wi-Fi access IP, cellular access IP. Alternatively or additionally, some embodiments account for the possibility that the cellular system (5G System) may support multiple PDU Sessions, e.g. through usage of UE Route Selection Policy (URSP) rules. Each PDU Session is assigned with an own IP address. Other embodiments may account for the possibility that the application client may be prevented from reading the local IP address, e.g. due to security sandboxing like in a browser. Still other embodiments account for the possibility that some CSPs allocate overlapping IP address pools, e.g., using the “IP domain” or DNNs, in which case an additional identifier would be needed to make the IP address unique.

[0170] In this context, some embodiments address a need that occurs when an application invokes a network API, namely, that information may be required in the API request to identify the target UE. An external API invoker therefore needs to identify the device (or a specific PDU Session of the device, when multiple PDU Sessions are established) in some shape or form. For example, when requesting the establishment of a QoS flow using the AF Session With QOS API (also called AS Session With QOS API) exposed by the NEF, the API invoker need to provide a UE IP address as input along with a set of IP flow filters or Service Data Flow Filter (s) or Service Data Flow Template (s) which can be an SDF filter or an Application Id (also known as PFD) . The 5G System uses the UE IP address to find the correct PCF and UPF, which are handling the traffic. In another example, when using the MonitoringEvent API, the API invoker can either provide an MSISDN, an external identifier or an IP address (v4 or v6) as input.

[0171] Some embodiments in this regard address situations where, at least for 3GPP NEF APIs, existing identifiers prove problematic. For example, the application server provider may not be able to obtain the GPSI in some scenarios (due to permission or privacy setting) . Moreover, deployment of a NAT between the API invoker and the UE of interest proves problematic.

[0172] The UE IP address can be in some cases be obtained from the UE, when authorized to read the  local IP address. However, many applications are browser-based applications and the browser sandbox prohibit access to local network resources. Further, the UE IP address may not be unique within the 5G System, since it is re-used in different DNNs. CSPs are reluctant to expose the UE assigned IP address since they consider it “privacy sensitive” . Thus, it is not a generic solution to obtain the UE IP address (as UE identifier) from the local IP stack.

[0173] Specific problems with existing solutions include (i) the UE IP address is often not visible and cannot be used, and the UE cannot determine whether it is unique within 5GC; (ii) the MSISDN (GPSI) is considered privacy related, since it is often a rather static / long term identifier; (iii) there are no usage limitations associated with 3GPP defined existing identifier, thus, whoever is in the possession of the identifier can use the identifier without limits.

[0174] Also problematic, the API provider function (e.g. NEF as API Provider or PCF as API provider) heretofore has no means to validate whether the API invoker is authorized to use the provided parameters, unless parameters are provisioned API invoker specific. However, this is often impractical (e.g. with additional API layers like NEF API Provider in front of PCF API provider) and not scalable (stateful persistence of many parameters)

[0175] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. Some embodiments introduce a new UE identifier which can be used externally to uniquely identify a UE when invoking a network API without exposing sensitive information related to the UE. This UE identifier is an example of the identifier 12-ID in Figure 1. The UE identifier may have a set of constraints associated with it, where the constraints can limit the UE identifier’s validity and therefore usability, e.g., in time, space, purpose, connectivity, etc.

[0176] The UE identifier can be represented in different forms. In one embodiment, the UE identifier takes the form of a Network Access Identifier (NAI) , e.g., as per RFC 7542. In another embodiment, the UE identifier is a JWT (or similar) token (similar but not the same as an OpenID Connect, OIDC, User ID token) . In yet another embodiment, the UE identifier may be an opaque string. In still another embodiment, the UE identifier may be a serialized JWT included in the NAI.

[0177] In one or more embodiments, the network API or the underlying CSP system can use the UE identifier to determine information about the UE such as a SUPI, GPSIs, or a Connectivity identifier (e.g. IP address with additional parameters) . The UE identifier as a JWT token can be validated, e.g. based on a signature or an encryption method. An alternative embodiment (e.g. when the token becomes too long) is to store the data in a database and use the UE identifier (e.g. as NAI) as key for the database lookup.

[0178] In some embodiments, the UE identifier has one or more of the following characteristics, realizable as a list of one or more constraints which exemplify the constraint (s) 29 herein.

[0179] In some embodiments when the UE identifier (ID) is realized as a token, the API provider (like a NEF) can be traced back to the token issuer and self-determine modification of the token. Thus, the UE ID is not only “AF specific” , but also specific to the entity which obtained the token, including additional provided constrains or hints.

[0180] In some embodiments, the UE identifier may be time limited, e.g. contain a creation timestamp and a validity time.

[0181] Alternatively or additionally, the UE identifier may contain a list of “permitted”  /  “eligible” API Invoker IDs, e.g., AF IDs, Service Capability Server (SCS) IDs, or Application Server (AS) IDs. The UE may have provided this information when requesting its UE identifier.

[0182] In other embodiments, the UE identifier may contain a list of “permitted”  /  “eligible” Application IDs, e.g., exterAppId property within AF Session With QoS API invoker constraint. The UE may have provided this information when requesting its UE identifier.

[0183] In one or more embodiments, the UE identifier may contain some new “usage identifiers” , which limit the usage of the token identifiers, e.g., to specific API endpoints (Network Services or Network Service Groups) (Application  / Usage constrain) . As a result, the UE identifier may be used for a AF Session with QOS API call (also called an AS Session With QOS API call) , but not for a MONTE (NEF MonitoringEvent) API call. The requester of the UE identifier may have provided this information when requesting its UE identifier.

[0184] Alternatively or additionally, the UE identifier may include a list of authorized DNNs  / S-NSSAIs. Here, S-NSSAI stands for Single Network Slice Selection Assistant Information. When the subscription is eligible for multiple DNNs  / S-NSSAIs (e.g. Mobile Broadband and an enterprise owned network slice) , the token can limit its validity to a subset of eligible connectivity services. This amounts to a Connectivity Constraint.

[0185] In some embodiments, the UE identifier may be a composition of encrypted information, which cannot be interpreted by externals, and unencrypted information. For example, the UE identifier may contain an issuer identification or a domain name which is not encrypted, allowing an external entity to identify the target network.

[0186] Encoding information like the Connection Identifier, GPSI or SUPI into the token simplifies the usage of the UE identifier in subsequent procedures. This is because the 5G system in this case does not need to execute database lookups, but rather need simply perform decryption operations to obtain the stored parameters.

[0187] Note that the UE identifier differs from the AF specific UE identifier as specified by 3GPP in TS 23.502 V18.4.0 in a number of respects. For example, the AF specific UE identifier lacks a time limited validity. The AF specific UE identifier is also not specific to the entity which requests the UE identifier.

[0188] The UE identifier can be seen as a new form of a GPSI, since it identifies the targeted 3GPP subscription in a more secure way. The identifier may be carried within the existing “external identifier” or as new GPSI subtype.

[0189] Examples of GPSI string are, assuming a <type>-<value> format, preventing the creation of a JSON object

[0190] ● msisdn-4917312345 (existing standard way)

[0191] ● extid-exampleuser@examplecsp. se

[0192] ● extid-#randomtoken@examplecsp. se (Note, the leading hash identifies the token)

[0193] ● ueid-randomtoken@examplecsp. se

[0194] Alternatively, the UE identifier may replace the GPSI on API calls.

[0195] There are different procedures usable to obtain the UE identifier in some embodiments.

[0196] In another procedure, the subscription owner (e.g. enterprise customer) or the Network Slice owner (CS Owner  / Connectivity Service Owner) or an application authorized by the subscription owner may request the UE identifier from the 5G System, in order to pass it as token on to e.g. an external API invoker.

[0197] In yet another procedure, an application (app) , executed on the UE, may request the UE identifier from a new CSP-operated “UE ID Server” . This UE ID Server exemplifies the identifier server 22 in Figure 1.

[0198] With regard to this latter procedure, the UE identifier can be requested by a UE based Application Client (App) from a Network Function (called “UE ID Server” ) , which resides at the N6 interface within a trusted Data Network of the CSP. In other words, the UE ID server is operated by the CSP and has access to other trusted network functions.

[0199] When accessing the UE ID Server, the App may optionally provide some input parameters (e.g. in the form of query parameters) to the UE ID server. The UE ID Server uses the parameters for (i) determining validity constraints; (ii) requesting the token in a specific form, e.g. a QR code (i.e. a UE ID Server generates a PNG image) ; (iii) the API Invoker information or an Application Identifier (scope) , where the App may be deployed in association with some application server backend; (iv) a usage identifier (e.g., scope) ; and / or (v) Application identifier, e.g. identifying the distributed application like MS TEAMS.

[0200] The Application Client can access the UE ID Server from within the 5G System. The UE ID Server obtains the IP address of the requesting UE, optionally evaluates inserted enrichment headers and finds associated information like the SUPI, GPSI and IP domain identifiers for the PDU Session by executing lookup queries to e.g. a UDM function. As result, the UE ID server can identify the PDU Session and SUPI.

[0201] Depending on the deployment location of the UE ID Server, the UE ID Server may also obtain the DNN and the S-NSSAI. Alternatively or in addition, the intermediate User Plane Function (UPF) had inserted some additional information into the communication (header enrichment) such as the DNN or a 4G  / 5G indicator, which are read by the UE ID Server.

[0202] The Application Client may optionally provide an identifier of the parent Application Provider, like an AF ID, so that the UE ID Server can make the token AF specific.

[0203] Some embodiments thereby introduce a new type of identifier which can be used externally to uniquely identify a UE and PDU session when invoking a network API. The identifier can identify the UE even if the UE IP address is changed, can be used to identify the DNN for the case that the IP address is released in the meantime, can be used by an AF to address the UE in service and API invocation context, and / or can be limited in time, user and usage (new constrains) .

[0204] Some embodiments herein further include mechanisms to generate, obtain, and retire the identifier.

[0205] In addition, some embodiments include a new way of obtaining the parameters from a UE application. When the UE application is obtaining the new token-like identifier from the network, the UE application client is passing the new token like identifier to the Application backend, which then uses it for API invocation.

[0206] Certain embodiments may provide one or more of the following technical advantage (s) . The new UE identifier (especially represented as a new token) has several advantages compared to existing identifiers. For example, the owner of the identifier can limit the usage in various different ways. Further, the origin (issuer) of the UE identifier can be validated, at least when using a token representation. Another benefit is that the usage of the new UE identifier may be simplified, e.g., in embodiments where important information is encrypted in the token. This speeds up the usage of the identifier, since time demanding database lookup and search operations are prevented.

[0207] Figure 7 shows some embodiments of a sequence of obtaining the token-like identifier from the network and then using the identifier at Northbound APIs calls for accessing Network Capabilities. Here, the NBI API exemplifies the API providing server 14 in Figure 1, the APP exemplifies the external invoker device 18, and the UE ID server exemplifies the identifier server 22 in Figure 1.

[0208] In Steps 1 and 2, the UE application obtains the UE identifier from the UE ID server. The UE ID Server is deployed at the CSPs N6 reference point, within the trusted part of the N6 Data Network (i.e. south of the NAT / Firewall) . The Get UE ID call in Step 1 exemplifies the identifier request 26 in Figure 4, with the response in Step 2 exemplifying the response 28 in Figure 4.

[0209] In step 3, the UE Identifier is used for API invocation in order to access a network capability. Here, the App is invoking the Northbound Interface (NBI) API. The APP can be an application running in the device or the application backend system. The device Application may also pass the UE identifier to the backend system of the application, which is using the identifier for the API call. In some cases, API aggregators are in the path between the original API invoker and the NBI API server, i.e. the token may traverse multiple intermediate functions. The API Request in Step 3 exemplifies the API invocation request 20 in Figure 1.

[0210] Step 4 and 5 illustrate the decoding and verification of the token. Here, the NBI API server contains the UE ID server for the decoding. Alternatively, the decoding key may be distributed within trusted network functions and the NBI API server may decode the token on its own. Steps 4 and 5 exemplify the resolve request 25 and response in Figure 3A.

[0211] Figure 8 shows UE ID retrieval by a device application according to some embodiments that exemplify those shown in Figure 5. In these embodiments, the App Backend exemplifies the identifier requesting device 24, the Device App exemplifies the communication device 12, and the UE ID server exemplifies the identifier server 22.

[0212] 1: The App Backend requests the Device App to assist with the UE ID retrieval.

[0213] 2: The Device App triggers an OAuth 2.0 procedure with an Authorization request towards the Auth Server, where the Auth Server exemplifies the Auth server 40 and the Authorization request exemplifies the auth request 42 in Figure 5. In the Authorization request, client ID and redirect URI are specified, where the redirect URI points to the App Backend.

[0214] 3: The Auth Server authenticates the device where the Device App is installed.

[0215] 4: The Auth Server obtains unique UE information (e.g., GPSI) after the authentication, where the unique UE information exemplifies the internal identifying information 12-INT in Figure 5. And it generates the Authorization Code, which exemplifies the auth code 44 in Figure 5.

[0216] 5: The Auth Server stores the UE information to the UE ID Server and associates it with the Authorization Code.

[0217] 6: The Auth Server sends back an Authorization Code to the Device App and asks the Device App to redirect to the App Backend. This Authorization Code exemplifies the auth code 44 in Figure 5.

[0218] 7: The Device App redirects the Authorization Code to the App Backend.

[0219] 8: The App Backend sends a Token request towards the token endpoint of the Auth Server, where  the request includes the Authorization Code. The Token request exemplifies the access token request 47 in Figure 5.

[0220] 9: The Auth Server generates an Access Token, which exemplifies the access token 28 in Figure 5.

[0221] 10: The Auth Server sends the Access Token to the UE ID Server to associate with the UE information.

[0222] 11: The Auth Server returns the Access Token to the App Backend, exemplifying the response 48 in Figure 5.

[0223] 12: The App Backend sends a get UE ID request to the UE ID Server with the Access Token and the constraints. The get UE ID request exemplifies the identifier request 26 in Figure 4, with the access token 28 included therein.

[0224] 13: The UE ID Server looks up the UE information based on the Access Token and generates UE ID based on the UE information and constraints.

[0225] 14: The UE ID Server returns the UE ID to the App Backend. Here, the UE ID exemplifies the identifier 12-ID returned in the response 28 in Figure 4.

[0226] 15: When the App Backend invokes an NBI API, it puts the UE ID inside the request to identify the target device. The UE ID in the request exemplifies the identifier 12-ID included in the API invocation request 20 in Figure 1 and Figure 3A.

[0227] 16: The NBI API resolves the UE ID towards the UE ID Server. This exemplifies the resolve request 25 in Figure 3A.

[0228] 17: The UE ID Server returns the unique UE information (e.g., GPSI) . The NBI API then uses the unique UE information in the API processing. This exemplifies the internal identifying information 12-INT plus some constraints.

[0229] 18. The NBI API sends a response back to the App Backend when it completes the processing.

[0230] Figure 9 is a sequence diagram illustrating the retrieval of the UE identify by the UE and the usage of the UE Identity by the App Backend according to some embodiments. This sequence diagram exemplifies Figure 3A where the UE is the identifier requesting device 24 and the App Backend is the external invoker device 18.

[0231] It is assumed that the UE ID Server is controlled by the CSP and deployed within the trusted part of the CSP data network (also called N6-Lan or SGi-LAN) . Thus, the UE ID Server is deployed here before the NAT  / Firewall and the UE ID server can observe the 5G Assigned IP address. Further, due to the specific deployment, the UE ID server is aware of used DNN  / S-NSSAI. The UE ID Server can lookup the SUPI and GPSIs, using the 5G Assigned IP from other Network Functions like the BSF or the UDM.

[0232] 1: The Device App logic or the App Backend triggers the UE ID retrieval procedure. For example, the App backend desires to obtain device location information.

[0233] This step 1 may be realized as a response containing a redirection instruction, such as a HTTP 302 redirection.

[0234] 2: The Device App connects to the UE ID Server, which is deployed in the CSP network. The UE ID Server may allow anonymous access of the UE Id, assuming that all installed Applications may obtain  its UE Id. The Device App may provide additional information (App specific hints, such as constraints or permissions) to be stored with the UE ID either within the token or in a database. The request in Step 2 exemplifies the identifier request 26 in Figure 4, with the UE exemplifying the identifier requesting device 24.

[0235] 3: The UE ID Server obtains the UE ID information, based on the visible IP address of the UE. The UE ID Server leverages different network functions (like the BSF) for collecting the information. This step exemplifies the identifier server 22 in Figure 4 exploiting the source address 26A of the identifier request 26 to retrieve the internal identifying information 12-INT.

[0236] 4: When the UE Id information is not stored within the token, the UE Id Server may store the UE Id on a Server. The UE ID is then used as reference to find the stored information.

[0237] 5: The UE ID server provides the UE ID to the Device App.

[0238] 6: The Device App provides the UE ID to the App Backend.

[0239] 7: The App Backend issues the API request to the NBI Server of the CSP. The API request contains information about Network Service (like QOS) , the UE ID, an API invoker identification (AF ID) , and other information. Note The App Backend is authorized and has authenticated itself as API invoker in a previous step. Step 7 may only contain the resulting authentication token. The API Request in Step 7 exemplifies the API invocation request 20 in Figure 3A, with the App Backend employing the external invoker device 18.

[0240] 8 / 9: The NBI Server obtains information from the UE ID Server. When information is embedded in the token, then the UE ID server decodes and / or decrypts the information piece or provides the key to the NBI Server. When information is not embedded in the token, the UE ID server uses the UE ID as key for a database lookup. The Resolve / decode UE ID call in Step 8 exemplifies the resolve request 25 in Figure 3A.

[0241] The NBI Server authorizes and authenticates the API invoker, based on the presented information, like the UE ID, etc.

[0242] 10: After successful authentication and authorization, the NBI Server triggers the requested Network Service.

[0243] 11: The NBI Server provides the results or information about the result of the network service to the App Backend.

[0244] Note, one or more of the transactions are secured using HTTPS. The client is validating the Server Certificates to ensure that it is connected to the correct server.

[0245] Figure 10 shows a sequence focused on the UE ID retrieval by the SUPI  / CS owner. The SUPI  / CS owner is then passing the UE ID to an Application Service Provider (represented as App Backend) , who then uses this UE ID in its processes of providing a specific service to the authorized devices by the enterprise (as SUPI  / CS owner) . Figure 10 therefore exemplifies the case where the identifier requesting device 24 is the SIM / CS Owner, and the App Backend is the external invoker device 18 in Figure 3A.

[0246] When an enterprise purchases subscriptions (SUPIs) for its employees, the Enterprise as subscription owner is aware about the SUPI (or a unique alternative external SUPI) and can also authenticate  / authorize itself as subscription owner towards the CSP. See step 1.

[0247] When an enterprise owns a Connectivity Service (CS) , which can be realized by a Network Slice or a DNN, the CS Owner is also aware about the devices, which are permitted to the enterprise owner Connectivity service. When the enterprise does not know the SUPI of these (onboarded) subscriptions, the enterprise has another mean to identify these subscriptions. This scenario focuses on realizations where individuals may use their own Subscription for accessing the connectivity service of the enterprise (bring your own device, BYOD) . Also in this case, the enterprise can authenticate and authorize itself as Connectivity Service owner to the CSP (see step 1) .

[0248] This sequence assumes that the SUPI  / CS Owner is an enterprise, who is also contracting an Application Service from an ASP. The intention is that employees of that enterprise (as SUPI  / CS Owner) are allowed to use network resource when the App of the ASP is used. The enterprise manages the logging credentials of its employees to the Application Service separately. An example setup is MS TEAMS, where an enterprise is using the application service by an ASP for video conferencing. The enterprise is controlling that only employees of the enterprise get access.

[0249] Steps 1 to 5: This is the UE ID creation and retrieval by the SUPI  / CS owner. The SUPI  / CS Owner needs to first authenticate and authorize itself as SUPI  / CS owner to the CSP’s operated UE ID Server. When requesting the UE ID, the SUPI  / CS Owner may provide “app specific hints” to the UE ID Server, which should be stored together with the UE ID. These App specific hints may be constraints, usage limitations or scopes.

[0250] Step 6 &7: The SUPI  / CS Owner acts as a “as a service consumer” towards the ASP. For example, the ASP is a video conferencing platform provider like MS TEAMS, which is used by the SUPI / CS Owner for offering additional services leveraging the connectivity. The SUPI  / CS Owner passes the UE ID, which should be presented by Device Applications, when activating a video conferencing session.

[0251] User login to App: A user of the Application service signs-in the App.

[0252] Steps 8 to 11: The App is authenticating and authorizing the user as an employee of the enterprise. The enterprise is the same entity, which also acts as SUPI  / CS owner towards the CSP.

[0253] When using the App (e.g. at time of a video conferencing sessions)

[0254] Steps 12 to 19: The (authenticated) App is starting a video conferencing session (requests a feature like QOS, step 12) , the App Backend looks-up the UE ID, associated with this user account. The App Backend is authenticating and authorizing itself towards the aggregator, using its own API Invoker credentials. When requesting the CSP feature (Step 14) , the App Backend provides its own AF ID (API Invoker identification) together with the UE ID towards the aggregator. The Aggregator uses the UE ID to find the correct CSP and issues the NBI API access for the feature. The CSP determines, based on the UE ID, the device, which should be targeted and leverages the app specific hints to identify the Aggregator as an authorized entity for accessing the feature.

[0255] Figures 11A-11B show UE Connection ID retrieval by Device App according to other embodiments. This sequence illustrates the case when the UE has multiple PDU sessions established with the communication network while the Device APP uses one of these PDU sessions to send and receive application traffic IP packets. The UE Connection ID Server exemplifies, implements, or contains the  identifier server 22 and the UE Connection ID exemplifies the identifier 12-ID in figures 3A and 3B. The device exemplifies communication device 12, the Device App exemplifies the identifier requesting device 24, the PDU session used by the application client for its traffic exemplifies connection 12C, and the Application Server (AS) exemplifies the external invoker device in figures 3A and 3B.

[0256] The address of the UE Connection ID Server must be known to the application client prior to requesting the UE Connection ID. This can be achieved in a number of ways: a predefined, well-known address which will always be resolved to the local UE Connection ID Server is preconfigured in the application client, or the address of the local UE Connection ID Server is provided by other means to the application client by the CSP, e.g. via UE or AS in some earlier configuration and / or signaling step. E. g. the AS may redirect the application client to the UE Connection ID Server.

[0257] The UE Connection ID Server is deployed on the N6 interface and is reachable from the application client. It is also a trusted application function (AF) by the core network (CN) and can therefore use the core network services.

[0258] Step 1: Device App sends a request to the UE Connection ID Server to obtain the UE Connection ID.It ensures that the request is sent in the PDU session it is using for the application traffic. How the Device App can ensure it depends on the operating system and the mechanisms used for sending the traffic, e.g. the Device App can use the same application identifier and / or application traffic category and associates it with the identifier request.

[0259] Upon receiving the request, the UE Connection ID Server uses the source address of the request and the information from the core network related to the source address to generate a UE Connection ID that uniquely identifies the PDU session in the 3GPP network. The generated UE Connection ID can take any of the form described earlier, e.g. it can be an encrypted token containing SUPI, GPSI, S-NSSAI, DNN, UE address, or it can be a network access identifier (NAI) serving as a reference / pointer to an ephemeral state (stored) containing this information.

[0260] Step 2: The UE Connection ID Server returns the UE Connection ID to the Device App.

[0261] Step 3: The Device App sends the UE Connection ID to the Application Server in conjunction with some application logic that requires the AS to invoke a network service by calling a network API. Here, the UE Connection ID exemplifies the identifier 12-ID returned to the external invoker device 18 by identifier requesting device 24 in Figures 3A and 3B.

[0262] Steps 4-6 show an alternative where the AS invokes an NBI API (e.g. AsSessionWithQoS API) and puts the UE Connection ID inside the request to identify the target device and the PDU session. The UE Connection ID in the request exemplifies the identifier 12-ID included in the API invocation request 20 in Figure 1 and Figure 3A.

[0263] Steps 7-9 show an alternative where the AS resolves the UE Connection ID before it invokes the NBI API. The UE Connection ID in the request exemplifies the internal identifying information 12-INT included in the API invocation request 20 in Figure 1 and Figure 3B.

[0264] Step 10: Execution of logic in the 3GPP NW in reaction to the NBI API invocation, e.g. creation / update of the policy control charging (PCC) rules for the identified PDU session.

[0265] In view of the modifications and variations herein, Figure 12 depicts a method performed by an identifier server 22 in a communication network 10 in accordance with particular embodiments. The method includes receiving a request 26 for an identifier 12-ID that is to identify a communication device 12 to an external invoker device 18 of an application programming interface, API, 16 exposed by the communication network 10 (Block 1200) . The method also comprises determining, based on a payload 26P of the request 26 and / or a source address 26A of the request 26, internal identifying information 12-INT that identifies the communication device 12 internally to the communication network 10 (Block 1210) . The method also comprises generating an identifier 12-ID that is bound to the internal identifying information 12-INT (Block 1220) . The method also comprises transmitting a response 28 that includes the generated identifier 12-ID (Block 1230) .

[0266] In some embodiments, generating the identifier 12-ID comprises generating encrypted internal identifying information 12-INT (E) by encrypting at least some of the internal identifying information 12-INT. In some embodiments, generating the identifier 12-ID comprises including the encrypted internal identifying information 12-INT (E) in the identifier 12-ID. In some embodiments, including the encrypted internal identifying information 12-INT (E) in the identifier 12-ID comprises including the encrypted internal identifying information 12-INT (E) in an information element of the identifier 12-ID, and the method further comprises cryptographically signing the information element.

[0267] In some embodiments, the generated identifier 12-ID is a JavaScript Object Notation, JSON, Web Token.

[0268] In some embodiments, generating the identifier 12-ID comprises generating the identifier 12-ID as a Network Access Identifier, NAI, or as an opaque string. In some embodiments, generating the identifier 12-ID comprises binding the generated identifier 12-ID to the internal identifying information 12-INT and / or to the one or more constraints 29 by storing the generated identifier 12-ID at the identifier server 22 in association with the internal identifying information 12-INT and / or the one or more constraints 29.

[0269] In some embodiments, the request 26 is received from an application executed on the communication device 12. In some embodiments, determining the internal identifying information 12-INT comprises determining the internal identifying information 12-INT based on the source address 26A of the request 26 by sending a query to a network node 30 in the communication network 10 for the internal identifying information 12-INT. In some embodiments, the query includes the source address 26A.

[0270] In some embodiments, the method further comprises, before receiving the request 26, receiving, from an authorization server 40, the internal identifying information 12-INT and an access token 28 associated with the internal identifying information 12-INT. In some embodiments, the payload 26P of the request 26 includes the access token 28, and determining the internal identifying information 12-INT comprises determining the internal identifying information 12-INT based on the access token 28 included in the payload 26P of the request 26.

[0271] In some embodiments, the payload 26P of the request 26 includes an internal device identifier 27 that identifies the communication device 12 internally to the communication network 10, and determining the internal identifying information 12-INT comprises determining the internal identifying information 12- INT based on the internal device identifier 27 included in the payload 26P of the request 26.

[0272] In some embodiments, the internal identifying information 12-INT identifies the communication device 12 internally to the communication network 10 and includes a SUbscription Permanent Identifier, SUPI, and / or a Generic Public Subscription Identifier, GPSI.

[0273] In some embodiments, the request 26 is received from an application backend server that provides a service to an application executed on the communication device 12. In some embodiments, the payload 26P of the request 26 or a header of the request 26 includes an access token 28 that is bound to at least some of the internal identifying information 12-INT. In other embodiments, the request 26 is received from an external server of an enterprise that owns a subscription with which the communication device 12 accesses the communication network 10 or that owns a connectivity service provided to the communication device 12.

[0274] In some embodiments, the identifier 12-ID also identifies a connection 12C of the communication device 12, and the internal identifying information 12-INT also identifies the connection 12C internally to the communication network 10.

[0275] In some embodiments, the method comprises, after transmitting the response 28, receiving a resolve request 25 that requests the identifier server 22 to resolve the identifier 12-ID (Block 1240) . In some embodiments, the method comprises, after transmitting the response 28, resolving the identifier 12-ID into the internal identifying information 12-INT according to the request 25 (Block 1250) . In some embodiments, the method comprises, after transmitting the response 28, transmitting a response that includes at least some of the internal identifying information 12-INT resolved from the identifier 12-ID (Block 1260) . In some embodiments, generating the identifier 12-ID comprises encrypting the internal identifying information 12-INT and including the encrypted internal identifying information 12-INT (E) in the identifier 12-ID, and resolving the identifier 12-ID comprises decrypting the internal identifying information 12-INT included in the identifier 12-ID. In some embodiments, generating the identifier 12-ID comprises binding the generated identifier 12-ID to the internal identifying information 12-INT by storing the generated identifier 12-ID at the identifier server 22 in association with the internal identifying information 12-INT, and resolving the identifier 12-ID comprises retrieving the internal identifying information 12-INT stored in association with the identifier 12-ID. In some embodiments, the request 26 indicates one or more constraints 29 that are to constrain usability of the identifier 12-ID. In some embodiments, the identifier 12-ID is further bound to the one or more constraints 29. In some embodiments, the method further comprises checking whether the identifier 12-ID is usable according to one or more of the one or more constraints 29 bound to the identifier 12-ID, and the identifier 12-ID is resolved based on the identifier 12-ID being usable according to said checking.

[0276] In some embodiments, the request 26 indicates one or more constraints 29 that are to constrain usability of the identifier 12-ID, and the identifier 12-ID is further bound to the one or more constraints 29. In some embodiments, the one or more constraints 29 include at least one or more validity constraints 29 that constrain a validity of the generated identifier 12-ID. In other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API invoker constraints 29 that constrain API  invokers 18 that are allowed to present the generated identifier 12-ID in a request 20 for invocation of an API 16 exposed by the communication network 10. In yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API provider constraints 29 that constrain API providers to which the generated identifier 12-ID is allowed to be presented in a request 20 for invocation of an API 16 exposed by the communication network 10. In still yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more connectivity constraints 29 that constrain with which connectivity services the generated identifier 12-ID is valid, such that according to the one or more connectivity constraints 29 the generated identifier 12-ID is valid for identifying a connection to any of one or more certain connectivity services. In some embodiments, the one or more validity constraints 29 include a time constraint that constrains a validity of the generated identifier 12-ID to a finite time period and / or a location constraint that constrains a validity of the generated identifier 12-ID to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier 12-ID to a certain roaming status of the communication device 12. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an API invoker ID constraint 29 that constrains API invokers 18 that are allowed to present the generated identifier 12-ID to a set of one or more API invokers 18 that have one or more respective API invoker identifiers. In other embodiments, the one or more API invoker constraints 29 include an application ID constraint that constrains API invokers 18 that are allowed to present the generated identifier 12-ID to a set of one or more API invokers 18 that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints 29 include an API provider ID constraint 29 that constrains API providers to which the generated identifier 12-ID is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints 29 include a domain network name, DNN, constraint that constrains with which DNNs the generated identifier 12-ID is usable and / or a network slice constraint that constrains with which network slices the generated identifier 12-ID is usable. In some embodiments, generating the identifier 12-ID comprises including the one or more constraints 29 in the identifier 12-ID.

[0277] In some embodiments, generating the identifier 12-ID comprises generating the identifier 12-ID to be different than a previously generated identifier 12-ID that identifies the same communication device 12 and that is bound to the same internal identifying information 12-INT.

[0278] In some embodiments, the identifier 12-ID identifies the communication device 12 persistently across changes to an internal Internet Protocol, IP, address of the communication device 12 that is assigned to the communication device 12 to address the communication device 12 internally in the communication network 10.

[0279] Figure 13 depicts a method performed by a node that is a communication device 12 or a server in accordance with other particular embodiments. The method includes transmitting, to an identifier server 22 in a communication network 10, a request 26 for an identifier 12-ID that is to identify the communication device 12 to an external invoker device 18 of an application programming interface, API, 16 exposed by  the communication network 10 (Block 1300) . In some embodiments, the request 26 has a payload 26P that includes an internal device identifier 27 or an access token 28, wherein the internal device identifier 27 identifies the communication device 12 internally to the communication network 10, wherein the access token 28 is associated with internal identifying information 12-INT which identifies the communication device 12 internally to the communication network 10. In other embodiments, the request 26 alternatively or additionally indicates one or more constraints 29 that are to constrain usability of the identifier 12-ID. The method also comprises receiving a response 28 that includes the identifier 12-ID (Block 1330) .

[0280] In some embodiments, the one or more constraints 29 are embedded or encoded into the identifier 12-ID.

[0281] In some embodiments, the identifier 12-ID is a JavaScript Object Notation, JSON, Web Token.

[0282] In some embodiments, the request 26 indicates the one or more constraints 29. In some embodiments, the one or more constraints 29 include at least one or more validity constraints that constrain a validity of the identifier 12-ID. In other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API invoker constraints 29 that constrain API invokers 18 that are allowed to present the identifier 12-ID in a request 20 for invocation of an API 16 exposed by the communication network 10. In yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API provider constraints 29 that constrain API providers to which the identifier 12-ID is allowed to be presented in a request 20 for invocation of an API 16 exposed by the communication network 10. In still yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more connectivity constraints 29 that constrain with which connectivity services the identifier 12-ID is usable. In some embodiments, the one or more validity constraints 29 include a time constraint that constrains a validity of the generated identifier 12-ID to a finite time period and / or a location constraint that constrains a validity of the generated identifier 12-ID to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier 12-ID to a certain roaming status of the communication device 12. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an API invoker ID constraint 29 that constrains API invokers 18 that are allowed to present the identifier 12-ID to a set of one or more API invokers 18 that have one or more respective API invoker identifiers. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an application ID constraint that constrains API invokers 18 that are allowed to present the identifier 12-ID to a set of one or more API invokers 18 that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints 29 include an API provider ID constraint 29 that constrains API providers to which the identifier 12-ID is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints 29 include a domain network name, DNN, constraint that constrains with which DNNs the identifier 12-ID is usable and / or a network slice constraint that constrains with which network slices the identifier 12-ID is usable.

[0283] In some embodiments, the method is performed by the communication device 12. In some  embodiments, an application executed on the communication device 12 is configured to send the request 26 and receive the response 28.

[0284] In some embodiments, the method is performed by an application backend server that provides a service to an application executed on the communication device 12.

[0285] In some embodiments, the method further comprises transmitting, to the application executed on the communication device 12, an identifier request 26 that requests the identifier 12-ID. In some embodiments, the method further comprises receiving a response 28 to the identifier request 26 that redirects the application backend server to an authorization server 40 and that includes an authorization code 44 to which to present to the authorization server 40. In some embodiments, the method further comprises transmitting, to the authorization server 40, an access token request 47 that requests an access token 28 and that includes the authorization code 44. In some embodiments, the method further comprises receiving a response 48 to the access token request 47 that includes the access token 28. In some embodiments, the payload 26P of the request 26 includes the access token 28.

[0286] In some embodiments, the method is performed by an external server of an enterprise that owns a subscription with which the communication device 12 accesses the communication network 10 or that owns a connectivity service provided to the communication device 12.

[0287] In some embodiments, the payload 26P of the request 26 includes the internal device identifier 27.

[0288] In some embodiments, the identifier 12-ID also identifies a connection 12C of the communication device 12, and the internal identifying information 12-INT also identifies the connection 12C internally to the communication network 10.

[0289] In some embodiments, wherein the identifier 12-ID is a Network Access Identifier, NAI, or an opaque string.

[0290] In some embodiments, the method further comprises transmitting the identifier 12-ID to an application backend server that provides a service to an application executed on the communication device 12 (Block 1340) .

[0291] In some embodiments, the method further comprises transmitting, to an API provider of the API 16, a request 20 to invoke the API 16. In some embodiments, the request 20 to invoke the API 16 includes the identifier 12-ID (Block 1350) .

[0292] Figure 14 depicts a method performed by an external invoker device 18 of an application programming interface, API, 16 exposed by a communication network 10 in accordance with other particular embodiments. The method includes obtaining an identifier 12-ID that is to identify the communication device 12 to the external invoker device 18 of the API 16 (Block 1400) . In some embodiments, one or more constraints 29 that constrain usability of the identifier 12-ID are embedded or encoded into the identifier 12-ID. The method also comprises transmitting, to an API provider of the API 16, a request 20 to invoke the API 16 (Block 1410) . In some embodiments, the request 20 to invoke the API 16 includes or is associated with the identifier 12-ID. In other embodiments, the request 20 to invoke the API 16 includes or is associated with internal identifying information 12-INT that identifies the communication device 12 internally to the communication network 10, as resolved from the identifier 12- ID by an identifier server 22 in the communication network 10.

[0293] In some embodiments, the identifier 12-ID is a JavaScript Object Notation, JSON, Web Token.

[0294] In some embodiments, the one or more constraints 29 include at least one or more validity constraints that constrain a validity of the identifier 12-ID. In other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API invoker constraints 29 that constrain API invokers 18 that are allowed to present the identifier 12-ID in a request 20 for invocation of an API 16 exposed by the communication network 10. In yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API provider constraints 29 that constrain API providers to which the identifier 12-ID is allowed to be presented in a request 20 for invocation of an API 16 exposed by the communication network 10. In still yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more connectivity constraints that constrain with which connectivity services the identifier 12-ID is usable. In some embodiments, the one or more validity constraints include a time constraint that constrains a validity of the generated identifier 12-ID to a finite time period and / or a location constraint that constrains a validity of the generated identifier 12-ID to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier 12-ID to a certain roaming status of the communication device 12. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an API invoker ID constraint 29 that constrains API invokers 18 that are allowed to present the identifier 12-ID to a set of one or more API invokers 18 that have one or more respective API invoker identifiers. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an application ID constraint that constrains API invokers 18 that are allowed to present the identifier 12-ID to a set of one or more API invokers 18 that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints 29 include an API provider ID constraint 29 that constrains API providers to which the identifier 12-ID is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints include a domain network name, DNN, constraint that constrains with which DNNs the identifier 12-ID is usable and / or a network slice constraint that constrains with which network slices the identifier 12-ID is usable.

[0295] In some embodiments, the external invoker device 18 is the communication device 12, wherein an application executed on the communication device 12 is configured to send the request.

[0296] In some embodiments, the external invoker device 18 is the server, wherein the server is an application backend server that provides a service to an application executed on the communication device 12.

[0297] In some embodiments, obtaining the identifier 12-ID comprises receiving the identifier 12-ID from an external server of an enterprise that owns a subscription with which the communication device 12 accesses the communication network 10 or that owns a connectivity service provided to the communication device 12.

[0298] In some embodiments, the request 26 includes the identifier 12-ID.

[0299] In some embodiments, the request 26 includes the internal identifying information 12-INT. In some embodiments, the method further comprises transmitting, to the identifier server 22, a resolve request 25 that requests the identifier server 22 to resolve the identifier 12-ID (Block 1450) . In some embodiments, the method further comprises receiving the internal identifying information 12-INT in a response to the resolve request 25 (Block 1460) .

[0300] In some embodiments, said transmitting comprises transmitting the identifier 12-ID or the internal identifying information 12-INT to the API provider server separately from the request 20 to invoke the API 16.

[0301] Other embodiments herein include a method performed by an application programming interface, API, provider server that provides an API 16 exposed by a communication network 10. The method comprises receiving, from an external invoker device 18 external to the communication network 10, a request 20 to invoke the API 16. In some embodiments, the request 20 to invoke the API 16 includes or is associated with an identifier 12-ID that identifies a communication device 12 to the external invoker device 18 (Block 1500) . The method also comprises transmitting, to an identifier server 22 in the communication network 10, a resolve request 25 that requests the identifier server 22 to resolve the identifier 12-ID (Block 1510) . The method also comprises receiving a response to the resolve request 25 that includes internal identifying information 12-INT that identifies the communication device 12 internally to the communication network 10 (Block 1520) . The method also comprises processing the request 20 to invoke the API 16 using the internal identifying information 12-INT (Block 1530) .

[0302] In some embodiments, one or more constraints 29 that constrain usability of the identifier 12-ID are bound to the identifier 12-ID.

[0303] In some embodiments, said processing comprises: (i) checking an extent to which the one or more constraints 29 allow the identifier 12-ID to be used for invoking the API 16 as requested; (ii) if each of the one or more constraints 29 allow the identifier 12-ID to be used for invoking the API 16 to at least some extent requested, invoking the API 16 according to the API invocation request 20; and (iii) if at least one of the one or more constraints 29 does not allow the identifier 12-ID to be used for invoking the API 16 to any extent requested, rejecting the API invocation request 20.

[0304] In some embodiments, the one or more constraints 29 are embedded or encoded into the identifier 12-ID. In some embodiments, the one or more constraints 29 include at least one or more validity constraints that constrain a validity of the identifier 12-ID. In other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API invoker constraints 29 that constrain API invokers 18 that are allowed to present the identifier 12-ID in a request 20 for invocation of an API 16 exposed by the communication network 10. In yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more API provider constraints 29 that constrain API providers to which the identifier 12-ID is allowed to be presented in a request 20 for invocation of an API 16 exposed by the communication network 10. In still yet other embodiments, the one or more constraints 29 include alternatively or additionally at least one or more connectivity constraints  that constrain with which connectivity services the identifier 12-ID is usable. In some embodiments, the one or more validity constraints 29 include a time constraint that constrains a validity of the generated identifier 12-ID to a finite time period and / or a location constraint that constrains a validity of the generated identifier 12-ID to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier 12-ID to a certain roaming status of the communication device 12. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an API invoker ID constraint 29 that constrains API invokers 18 that are allowed to present the identifier 12-ID to a set of one or more API invokers 18 that have one or more respective API invoker identifiers. In other embodiments, alternatively or additionally, the one or more API invoker constraints 29 include an application ID constraint that constrains API invokers 18 that are allowed to present the identifier 12-ID to a set of one or more API invokers 18 that execute an application with a specified application identifier. In yet other embodiments, alternatively or additionally, the one or more API provider constraints 29 include an API provider ID constraint 29 that constrains API providers to which the identifier 12-ID is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers. In still yet other embodiments, alternatively or additionally, the one or more connectivity constraints 29 include a domain network name, DNN, constraint that constrains with which DNNs the identifier 12-ID is usable and / or a network slice constraint that constrains with which network slices the identifier 12-ID is usable.

[0305] In some embodiments, the identifier 12-ID is a JavaScript Object Notation, JSON, Web Token.

[0306] In some embodiments, the external invoker device 18 is the communication device 12.

[0307] In some embodiments, the external invoker device 18 is an application backend server that provides a service to an application executed on the communication device 12.

[0308] Other embodiments herein include a method performed by an authorization server 40 in a communication network 10. The method comprises obtaining internal identifying information 12-INT that identifies a communication device 12 internally to the communication network 10 (Block 1600) . The method also comprises generating an access token 28 with which an identifier 12-ID bound to the internal identifying information 12-INT is retrievable (Block 1610) . The method also comprises storing the internal identifying information 12-INT at an identifier server 22 in the communication network 10 in association with the access token 28 (Block 1620) .

[0309] In some embodiments, the method further comprises receiving, from the communication device 12, an authorization request 42 that comprises a request to authorize retrieval of the identifier 12-ID (Block 1630) . In some embodiments, the internal identifying information 12-INT is obtained responsive to receiving the authorization request 42. In some embodiments, the method further comprises, after obtaining the internal identifying information 12-INT, storing the internal identifying information 12-INT at the identifier server 22, generating an authorization code 44 that is associated with the internal identifying information 12-INT, and transmitting the authorization code 44 in a response 46 to the authorization request 42 (Block 1640) . In some embodiments, the method further comprises receiving an access token request 47 that includes the authorization code 44, wherein the access token 28 is generated responsive to the access  token request 47 (Block 1650) . In some embodiments, the method further comprises, after generating the access token 28, transmitting signaling to the identifier server 22 indicating that the identifier server 22 is to associate the internal identifying information 12-INT with the access token 28 (Block 1660) . In some embodiments, the method further comprises transmitting a response 48 to the access token request 47 including the access token 28 (Block 1670) .

[0310] In some embodiments, the internal identifying information 12-INT identifies the communication device 12 internally to the communication network 10 and includes a SUbscription Permanent Identifier, SUPI, and / or a Generic Public Subscription Identifier, GPSI. In some embodiments, the identifier 12-ID also identifies a connection 12C of the communication device 12, and the internal identifying information 12-INT also identifies the connection 12C internally to the communication network 10.

[0311] Embodiments herein also include corresponding apparatuses. Embodiments herein for instance include a communication device 12 configured to perform any of the steps of any of the embodiments described above for the communication device 12.

[0312] Embodiments also include a communication device 12 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the communication device 12. The power supply circuitry is configured to supply power to the communication device 12.

[0313] Embodiments further include a communication device 12 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the communication device 12. In some embodiments, the communication device 12 further comprises communication circuitry.

[0314] Embodiments further include a communication device 12 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the communication device 12 is configured to perform any of the steps of any of the embodiments described above for the communication device 12.

[0315] Embodiments moreover include a user equipment (UE) . The UE comprises an antenna configured to send and receive wireless signals. The UE also comprises radio front-end circuitry connected to the antenna and to processing circuitry, and configured to condition signals communicated between the antenna and the processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the communication device 12. In some embodiments, the UE also comprises an input interface connected to the processing circuitry and configured to allow input of information into the UE to be processed by the processing circuitry. The UE may comprise an output interface connected to the processing circuitry and configured to output information from the UE that has been processed by the processing circuitry. The UE may also comprise a battery connected to the processing circuitry and configured to supply power to the UE.

[0316] Embodiments herein also include an identifier server 22 configured to perform any of the steps of any of the embodiments described above for the identifier server 22

[0317] Embodiments also include an identifier server 22 comprising processing circuitry and power supply  circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the identifier server 22. The power supply circuitry is configured to supply power to the identifier server 22.

[0318] Embodiments further include an identifier server 22 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the identifier server 22. In some embodiments, the identifier server 22 further comprises communication circuitry.

[0319] Embodiments further include an identifier server 22 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the identifier server 22 is configured to perform any of the steps of any of the embodiments described above for the identifier server 22.

[0320] Embodiments herein also include a server 1900 configured to perform any of the steps of any of the embodiments described above for the server 1900.

[0321] Embodiments also include a server 1900 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the server 1900. The power supply circuitry is configured to supply power to the server 1900.

[0322] Embodiments further include a server 1900 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the server 1900. In some embodiments, the server 1900 further comprises communication circuitry.

[0323] Embodiments further include a server 1900 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the server 1900 is configured to perform any of the steps of any of the embodiments described above for the server 1900.

[0324] Embodiments herein also include an external invoker device 18 configured to perform any of the steps of any of the embodiments described above for the external invoker device 18.

[0325] Embodiments also include an external invoker device 18 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the external invoker device 18. The power supply circuitry is configured to supply power to the external invoker device 18.

[0326] Embodiments further include an external invoker device 18 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the external invoker device 18. In some embodiments, the external invoker device 18 further comprises communication circuitry.

[0327] Embodiments further include an external invoker device 18 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the external invoker device 18 is configured to perform any of the steps of any of the embodiments described above for the external invoker device 18.

[0328] Embodiments herein also include an API provider server 14 configured to perform any of the steps  of any of the embodiments described above for the API provider server 14.

[0329] Embodiments also include an API provider server 14 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the API provider server 14. The power supply circuitry is configured to supply power to the API provider server 14.

[0330] Embodiments further include an API provider server 14 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the API provider server 14. In some embodiments, the API provider server 14 further comprises communication circuitry.

[0331] Embodiments further include an API provider server 14 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the API provider server 14 is configured to perform any of the steps of any of the embodiments described above for the API provider server 14.

[0332] Embodiments herein also include an authorization server 40 configured to perform any of the steps of any of the embodiments described above for the authorization server 40.

[0333] Embodiments also include an authorization server 40 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the authorization server 40. The power supply circuitry is configured to supply power to the authorization server 40.

[0334] Embodiments further include an authorization server 40 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the authorization server 40. In some embodiments, the authorization server 40 further comprises communication circuitry.

[0335] Embodiments further include an authorization server 40 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the authorization server 40 is configured to perform any of the steps of any of the embodiments described above for the authorization server 40.

[0336] More particularly, the apparatuses described above may perform the methods herein and any other processing by implementing any functional means, modules, units, or circuitry. In one embodiment, for example, the apparatuses comprise respective circuits or circuitry configured to perform the steps shown in the method figures. The circuits or circuitry in this regard may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. For instance, the circuitry may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs) , special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as read-only memory (ROM) , random-access memory, cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well  as instructions for carrying out one or more of the techniques described herein, in several embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the one or more processors, carries out the techniques described herein.

[0337] Figure 17 for example illustrates a communication device 12 as implemented in accordance with one or more embodiments. As shown, the communication device 12 includes processing circuitry 1710 and communication circuitry 1720. The communication circuitry 1720 (e.g., radio circuitry) is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. Such communication may occur via one or more antennas that are either internal or external to the communication device 1700. The processing circuitry 1710 is configured to perform processing described above, e.g., in Figure 12, such as by executing instructions of a computer program 1735 stored in a computer-readable storage medium 1730. The processing circuitry 1710 in this regard may implement certain functional means, units, or modules.

[0338] Figure 18 illustrates an identifier server 22 as implemented in accordance with one or more embodiments. As shown, the identifier server 22 includes processing circuitry 1810 and communication circuitry 1820. The communication circuitry 1820 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 1810 is configured to perform processing described above, e.g., in Figure 13, such as by executing instructions of a computer program 1835 stored in a computer-readable storage medium 1830. The processing circuitry 1810 in this regard may implement certain functional means, units, or modules.

[0339] Figure 19 illustrates a server 1900 as implemented in accordance with one or more embodiments. As shown, the server 1900 includes processing circuitry 1910 and communication circuitry 1920. The communication circuitry 1920 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 1910 is configured to perform processing described above, e.g., in Figure 12, such as by executing instructions of a computer program 1935 stored in a computer-readable storage medium 1930. The processing circuitry 1910 in this regard may implement certain functional means, units, or modules.

[0340] Figure 20 illustrates an external invoker device 18 as implemented in accordance with one or more embodiments. As shown, the external invoker device 18 includes processing circuitry 2010 and communication circuitry 2020. The communication circuitry 2020 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 2010 is configured to perform processing described above, e.g., in Figure 14, such as by executing instructions of a computer program 2035 stored in a computer-readable storage medium 2030. The processing circuitry 2010 in this regard may implement certain functional means, units, or modules.

[0341] Figure 21 illustrates an API provider server 14 as implemented in accordance with one or more embodiments. As shown, the API provider server 14 includes processing circuitry 2110 and communication circuitry 2120. The communication circuitry 2120 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 2110 is configured to perform processing described above, e.g., in Figure 16, such as  by executing instructions of a computer program 2135 stored in a computer-readable storage medium 2130. The processing circuitry 2110 in this regard may implement certain functional means, units, or modules.

[0342] Figure 22 illustrates an authorization server 40 as implemented in accordance with one or more embodiments. As shown, the authorization server 40 includes processing circuitry 2210 and communication circuitry 2220. The communication circuitry 2220 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 2210 is configured to perform processing described above, e.g., in Figure 17, such as by executing instructions of a computer program 2235 stored in a computer-readable storage medium 2230. The processing circuitry 2210 in this regard may implement certain functional means, units, or modules.

[0343] Those skilled in the art will also appreciate that embodiments herein further include corresponding computer programs.

[0344] A computer program comprises instructions which, when executed on at least one processor of an apparatus, cause the apparatus to carry out any of the respective processing described above. A computer program in this regard may comprise one or more code modules corresponding to the means or units described above.

[0345] Embodiments further include a carrier containing such a computer program. This carrier may comprise one of an electronic signal, optical signal, radio signal, or computer readable storage medium.

[0346] In this regard, embodiments herein also include a computer program product stored on a non-transitory computer readable (storage or recording) medium and comprising instructions that, when executed by a processor of an apparatus, cause the apparatus to perform as described above.

[0347] Embodiments further include a computer program product comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device. This computer program product may be stored on a computer readable recording medium.

[0348] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the  processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0349] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0350] Notably, modifications and other embodiments of the present disclosure will come to mind to one skilled in the art having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the present disclosure is not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of this disclosure. Although specific terms may be employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

1.A method performed by an identifier server (22) in a communication network (10) , the method comprising:receiving (1200) a request (26) for an identifier (12-ID) that is to identify a communication device (12) to an application programming interface, API, provider server (14) or an external invoker device (18) of an API (16) exposed by the communication network (10) ;determining (1210) , based on a payload (26P) of the request (26) and / or a source address (26A) of the request (26) , internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ;generating (1220) an identifier (12-ID) that is bound to the internal identifying information (12-INT) ; andtransmitting (1230) a response (28) that includes the generated identifier (12-ID) .2.The method of claim 1, wherein generating the identifier (12-ID) comprises:generating encrypted internal identifying information (12-INT (E) ) by encrypting at least some of the internal identifying information (12-INT) ; andincluding the encrypted internal identifying information (12-INT (E) ) in the identifier (12-ID) .3.The method of claim 2, wherein including the encrypted internal identifying information (12-INT (E) ) in the identifier (12-ID) comprises including the encrypted internal identifying information (12-INT (E) ) in an information element of the identifier (12-ID) , and wherein the method further comprises cryptographically signing the information element.4.The method of any one of claims 1-3, wherein the generated identifier (12-ID) is a JavaScript Object Notation, JSON, Web Token.5.The method of any one of claims 1-4, wherein generating the identifier (12-ID) comprises:generating the identifier (12-ID) in a format of a Network Access Identifier, NAI, or as an opaque string; andbinding the generated identifier (12-ID) to the internal identifying information (12-INT) and / or to one or more constraints (29) by storing the generated identifier (12-ID) at the identifier server (22) in association with the internal identifying information (12-INT) and / or the one or more constraints (29) .6.The method of any of claims 1-5, wherein the request (26) is received from an application executed on the communication device (12) .7.The method of claim 6, wherein determining the internal identifying information (12-INT)  comprises determining the internal identifying information (12-INT) based on the source address (26A) of the request (26) by sending a query to a network node (30) in the communication network (10) for the internal identifying information (12-INT) , wherein the query includes the source address (26A) .8.The method of any one of claims 1-6, further comprising, before receiving the request (26) , receiving, from an authorization server (40) , the internal identifying information (12-INT) and an access token (28) associated with the internal identifying information (12-INT) , wherein the payload (26P) of the request (26) includes the access token (28) , and wherein determining the internal identifying information (12-INT) comprises determining the internal identifying information (12-INT) based on the access token (28) included in the payload (26P) of the request (26) .9.The method of any one of claims 1-6, wherein the payload (26P) of the request (26) includes an internal device identifier (27) that identifies the communication device (12) internally to the communication network (10) , and wherein determining the internal identifying information (12-INT) comprises determining the internal identifying information (12-INT) based on the internal device identifier (27) included in the payload (26P) of the request (26) .10.The method of any one of claims 1-9, wherein the internal identifying information (12-INT) identifies the communication device (12) internally to the communication network (10) and includes a SUbscription Permanent Identifier, SUPI, and / or a Generic Public Subscription Identifier, GPSI.11.The method of any of claims 1-5 and 8-10, wherein the request (26) is received from:an application backend server that provides a service to an application executed on the communication device (12) , wherein the payload (26P) of the request (26) or a header of the request (26) includes an access token (28) that is bound to at least some of the internal identifying information (12-INT) ; oran external server of an enterprise that owns a subscription with which the communication device (12) accesses the communication network (10) or that owns a connectivity service provided to the communication device (12) .12.The method of any one of claims 1-11, wherein the identifier (12-ID) also identifies a connection (12C) of the communication device (12) , and wherein the internal identifying information (12-INT) also identifies the connection (12C) internally to the communication network (10) .13.The method of any one of claims 1-12, comprising, after transmitting the response (28) :receiving a resolve request (25) that requests the identifier server (22) to resolve the identifier (12-ID) ;resolving the identifier (12-ID) into the internal identifying information (12-INT) according to the request (25) ; andtransmitting a response (28) that includes at least some of the internal identifying information (12-INT) resolved from the identifier (12-ID) .14.The method of claim 13, wherein generating the identifier (12-ID) comprises encrypting the internal identifying information (12-INT) and including the encrypted internal identifying information (12-INT (E) ) in the identifier (12-ID) , and wherein resolving the identifier (12-ID) comprises decrypting the internal identifying information (12-INT) included in the identifier (12-ID) .15.The method of claim 13, wherein generating the identifier (12-ID) comprises binding the generated identifier (12-ID) to the internal identifying information (12-INT) by storing the generated identifier (12-ID) at the identifier server (22) in association with the internal identifying information (12-INT) , and wherein resolving the identifier (12-ID) comprises retrieving the internal identifying information (12-INT) stored in association with the identifier (12-ID) .16.The method of any of claims 13-15, wherein the request (26) indicates one or more constraints (29) that are to constrain usability of the identifier (12-ID) , wherein the identifier (12-ID) is further bound to the one or more constraints (29) , wherein the method further comprises checking whether the identifier (12-ID) is usable according to one or more of the one or more constraints (29) bound to the identifier (12-ID) , and wherein the identifier (12-ID) is resolved based on the identifier (12-ID) being usable according to said checking.17.The method of any one of claims 1-15, wherein the request (26) indicates one or more constraints (29) that are to constrain usability of the identifier (12-ID) .18.The method of any one of claims 4, 16, and 17, wherein the one or more constraints (29) include one or more of:one or more validity constraints (29) that constrain a validity of the generated identifier (12-ID) ;one or more API invoker constraints (29) that constrain API invokers (18) that are allowed to present the generated identifier (12-ID) in a request (20) for invocation of an API (16) exposed by the communication network (10) ;one or more API provider constraints (29) that constrain API providers to which the generated identifier (12-ID) is allowed to be presented in a request (20) for invocation of an API (16) exposed by the communication network (10) ; and / orone or more connectivity constraints (29) that constrain with which connectivity services the generated identifier (12-ID) is valid, such that according to the one or more connectivity constraints (29) the generated identifier (12-ID) is valid for identifying a connection to any of one or more certain connectivity services.19.The method of claim 18, wherein:the one or more validity constraints (29) include a time constraint that constrains a validity of the generated identifier (12-ID) to a finite time period and / or a location constraint that constrains a validity of the generated identifier (12-ID) to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier (12-ID) to a certain roaming status of the communication device (12) ;the one or more API invoker constraints (29) include:an API invoker ID constraint that constrains API invokers (18) that are allowed to present the generated identifier (12-ID) to a set of one or more API invokers (18) that have one or more respective API invoker identifiers; oran application ID constraint that constrains API invokers (18) that are allowed to present the generated identifier (12-ID) to a set of one or more API invokers (18) that execute an application with a specified application identifier;the one or more API provider constraints (29) include an API provider ID constraint that constrains API providers to which the generated identifier (12-ID) is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers; and / orthe one or more connectivity constraints (29) include a domain network name, DNN, constraint that constrains with which DNNs the generated identifier (12-ID) is usable and / or a network slice constraint that constrains with which network slices the generated identifier (12-ID) is usable.20.The method of any one of claims 17-19, wherein generating the identifier (12-ID) comprises including the one or more constraints (29) in the identifier (12-ID) .21.The method of any one of claims 1-20, wherein generating the identifier (12-ID) comprises generating the identifier (12-ID) to be different than a previously generated identifier (12-ID) that identifies the same communication device (12) and that is bound to the same internal identifying information (12-INT) .22.The method of any one of claims 1-21, wherein the identifier (12-ID) identifies the communication device (12) persistently across changes to an internal Internet Protocol, IP, address of the communication device (12) that is assigned to the communication device (12) to address the communication device (12) internally in the communication network (10) .23.A method performed by a node that is a communication device (12) or a server, the method comprising:transmitting (1300) , to an identifier server (22) in a communication network (10) , a request (26) for an identifier (12-ID) that is to identify the communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) , wherein the request (26) :has a payload (26P) that includes an internal device identifier (27) or an access token (28) , wherein the internal device identifier (27) identifies the communication device (12) internally to the communication network (10) , wherein the access token (28) is associated with internal identifying information (12-INT) which identifies the communication device (12) internally to the communication network (10) ; and / orindicates one or more constraints (29) that are to constrain usability of the identifier (12-ID) ; andreceiving (1330) a response (28) that includes the identifier (12-ID) .24.The method of claim 23, wherein the one or more constraints (29) are embedded or encoded into the identifier (12-ID) .25.The method of any one of claims 23-24, wherein the identifier (12-ID) is a JavaScript Object Notation, JSON, Web Token.26.The method of any one of claims 23-25, wherein the request (26) indicates the one or more constraints (29) , wherein the one or more constraints (29) include one or more of:one or more validity constraints (29) that constrain a validity of the identifier (12-ID) ;one or more API invoker constraints (29) that constrain API invokers (18) that are allowed to present the identifier (12-ID) in a request (20) for invocation of an API (16) exposed by the communication network (10) ;one or more API provider constraints (29) that constrain API providers to which the identifier (12-ID) is allowed to be presented in a request (20) for invocation of an API (16) exposed by the communication network (10) ; and / orone or more connectivity constraints (29) that constrain with which connectivity services the identifier (12-ID) is usable.27.The method of claim 26, wherein:the one or more validity constraints (29) include a time constraint that constrains a validity of the generated identifier (12-ID) to a finite time period and / or a location constraint that constrains a validity of the generated identifier (12-ID) to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier (12-ID) to a certain roaming status of the communication device (12) ;the one or more API invoker constraints (29) include:an API invoker ID constraint that constrains API invokers (18) that are allowed to present the identifier (12-ID) to a set of one or more API invokers (18) that have one or more respective API invoker identifiers; oran application ID constraint that constrains API invokers (18) that are allowed to present the identifier (12-ID) to a set of one or more API invokers (18) that execute an application with a specified application identifier;the one or more API provider constraints (29) include an API provider ID constraint that constrains API providers to which the identifier (12-ID) is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers; and / orthe one or more connectivity constraints (29) include a domain network name, DNN, constraint that constrains with which DNNs the identifier (12-ID) is usable and / or a network slice constraint that constrains with which network slices the identifier (12-ID) is usable.28.The method of any one of claims 23-27, wherein the method is performed by the communication device (12) , wherein an application executed on the communication device (12) is configured to send the request (26) and receive the response (28) .29.The method of any one of claims 23-27, wherein the method is performed by an application backend server that provides a service to an application executed on the communication device (12) .30.The method of claim 29, further comprising:transmitting, to the application executed on the communication device (12) , an identifier request (26) that requests the identifier (12-ID) ;receiving a response (28) to the identifier request (26) that redirects the application backend server to an authorization server (40) and that includes an authorization code (44) to which to present to the authorization server (40) ;transmitting, to the authorization server (40) , an access token request (47) that requests an access token (28) and that includes the authorization code (44) ;receiving a response (48) to the access token request (47) that includes the access token (28) ;wherein the payload (26P) of the request (26) includes the access token (28) .31.The method of any one of claims 23-27, wherein the method is performed by an external server of an enterprise that owns a subscription with which the communication device (12) accesses the communication network (10) or that owns a connectivity service provided to the communication device (12) .32.The method of any of claims 23-31, wherein the payload (26P) of the request (26) includes the internal device identifier (27) .33.The method of any one of claims 23-32, wherein the identifier (12-ID) also identifies a connection (12C) of the communication device (12) , and wherein the internal identifying information (12-INT) also identifies the connection (12C) internally to the communication network (10) .34.The method of any one of claims 23 and 25-33, wherein the identifier (12-ID) is a Network Access Identifier, NAI, or an opaque string.35.The method of any one of claims 23-28 and 31-34, further comprising transmitting the identifier (12-ID) to an application backend server that provides a service to an application executed on the communication device (12) .36.The method of any one of claims 23-34, further comprising transmitting, to an API provider of the API (16) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes the identifier (12-ID) .37.A method performed by an external invoker device (18) of an application programming interface, API, (16) exposed by a communication network (10) , wherein the external invoker device (18) is a communication device (12) or a server, wherein the method comprises:obtaining (1400) an identifier (12-ID) that is to identify the communication device (12) to the external invoker device (18) of the API (16) , wherein one or more constraints (29) that constrain usability of the identifier (12-ID) are embedded or encoded into the identifier (12-ID) ; andtransmitting (1410) , to an API provider of the API (16) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with:the identifier (12-ID) ; orinternal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) , as resolved from the identifier (12-ID) by an identifier server (22) in the communication network (10) .38.The method of claim 37, wherein the identifier (12-ID) is a JavaScript Object Notation, JSON, Web Token.39.The method of any one of claims 37-38, wherein the one or more constraints (29) include one or more of:one or more validity constraints (29) that constrain a validity of the identifier (12-ID) ;one or more API invoker constraints (29) that constrain API invokers (18) that are allowed to present the identifier (12-ID) in a request (20) for invocation of an API (16) exposed by the communication network (10) ;one or more API provider constraints (29) that constrain API providers to which the identifier (12-ID) is allowed to be presented in a request (20) for invocation of an API (16) exposed by the communication network (10) ; and / orone or more connectivity constraints (29) that constrain with which connectivity services the identifier (12-ID) is usable.40.The method of claim 39, wherein:the one or more validity constraints (29) include a time constraint that constrains a validity of the generated identifier (12-ID) to a finite time period and / or a location constraint that constrains a validity of the generated identifier (12-ID) to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier (12-ID) to a certain roaming status of the communication device (12) ;the one or more API invoker constraints (29) include:an API invoker ID constraint that constrains API invokers (18) that are allowed to present the identifier (12-ID) to a set of one or more API invokers (18) that have one or more respective API invoker identifiers; oran application ID constraint that constrains API invokers (18) that are allowed to present the identifier (12-ID) to a set of one or more API invokers (18) that execute an application with a specified application identifier;the one or more API provider constraints (29) include an API provider ID constraint that constrains API providers to which the identifier (12-ID) is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers; and / orthe one or more connectivity constraints (29) include a domain network name, DNN, constraint that constrains with which DNNs the identifier (12-ID) is usable and / or a network slice constraint that constrains with which network slices the identifier (12-ID) is usable.41.The method of any one of claims 37-40, wherein the external invoker device (18) is the communication device (12) , wherein an application executed on the communication device (12) is configured to send the request.42.The method of any one of claims 37-40, wherein the external invoker device (18) is the server, wherein the server is an application backend server that provides a service to an application executed on the communication device (12) .43.The method of any one of claims 37-40 and 42, wherein obtaining the identifier (12-ID) comprises receiving the identifier (12-ID) from an external server of an enterprise that owns a subscription with which the communication device (12) accesses the communication network (10) or that owns a connectivity  service provided to the communication device (12) .44.The method of any one of claims 37-43, wherein the request (26) includes the identifier (12-ID) .45.The method of any one of claims 37-44, wherein the request (26) includes the internal identifying information (12-INT) , and wherein the method further comprises:transmitting, to the identifier server (22) , a resolve request (25) that requests the identifier server (22) to resolve the identifier (12-ID) ; andreceiving the internal identifying information (12-INT) in a response to the resolve request (25) .46.The method of any one of claims 37-45, wherein said transmitting comprises transmitting the identifier (12-ID) or the internal identifying information (12-INT) to the API provider server (14) separately from the request (20) to invoke the API (16) .47.A method performed by an application programming interface, API, provider server (14) that provides an API (16) exposed by a communication network (10) , wherein the method comprises:receiving (1500) , from an external invoker device (18) external to the communication network (10) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with an identifier (12-ID) that identifies a communication device (12) to the external invoker device (18) ;transmitting (1510) , to an identifier server (22) in the communication network (10) , a resolve request (25) that requests the identifier server (22) to resolve the identifier (12-ID) ;receiving (1520) a response to the resolve request (25) that includes internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ; andprocessing (1530) the request (20) to invoke the API (16) using the internal identifying information (12-INT) .48.The method of claim 47, wherein one or more constraints (29) that constrain usability of the identifier (12-ID) are bound to the identifier (12-ID) .49.The method of claim 48, wherein said processing comprises:checking an extent to which the one or more constraints (29) allow the identifier (12-ID) to be used for invoking the API (16) as requested;if each of the one or more constraints (29) allow the identifier (12-ID) to be used for invoking the API (16) to at least some extent requested, invoking the API (16) according to the request (20) ; andif at least one of the one or more constraints (29) does not allow the identifier (12-ID) to be used for invoking the API (16) to any extent requested, rejecting the request (20) to invoke the API.50.The method of any one of claims 48-49, wherein the one or more constraints (29) are embedded or encoded into the identifier (12-ID) .51.The method of any one of claims 48-50, wherein the one or more constraints (29) include one or more of:one or more validity constraints (29) that constrain a validity of the identifier (12-ID) ;one or more API invoker constraints (29) that constrain API invokers (18) that are allowed to present the identifier (12-ID) in a request (20) for invocation of an API (16) exposed by the communication network (10) ;one or more API provider constraints (29) that constrain API providers to which the identifier (12-ID) is allowed to be presented in a request (20) for invocation of an API (16) exposed by the communication network (10) ; and / orone or more connectivity constraints (29) that constrain with which connectivity services the identifier (12-ID) is usable.52.The method of claim 51, wherein:the one or more validity constraints (29) include a time constraint that constrains a validity of the generated identifier (12-ID) to a finite time period and / or a location constraint that constrains a validity of the generated identifier (12-ID) to a finite geographical location and / or a roaming constraint that constrains a validity of the generated identifier (12-ID) to a certain roaming status of the communication device (12) ;the one or more API invoker constraints (29) include:an API invoker ID constraint that constrains API invokers (18) that are allowed to present the identifier (12-ID) to a set of one or more API invokers (18) that have one or more respective API invoker identifiers; oran application ID constraint that constrains API invokers (18) that are allowed to present the identifier (12-ID) to a set of one or more API invokers (18) that execute an application with a specified application identifier;the one or more API provider constraints (29) include an API provider ID constraint that constrains API providers to which the identifier (12-ID) is allowed to be presented to a set of one or more API providers that have one or more respective API provider identifiers; and / orthe one or more connectivity constraints (29) include a domain network name, DNN, constraint that constrains with which DNNs the identifier (12-ID) is usable and / or a network slice constraint that constrains with which network slices the identifier (12-ID) is usable.53.The method of any one of claims 47-52, wherein the identifier (12-ID) is a JavaScript Object Notation, JSON, Web Token.54.The method of any one of claims 47-53, wherein the external invoker device (18) is the communication device (12) .55.The method of any one of claims 47-53, wherein the external invoker device (18) is an application backend server that provides a service to an application executed on the communication device (12) .56.A method performed by an authorization server (40) in a communication network (10) , the method comprising:obtaining (1600) internal identifying information (12-INT) that identifies a communication device (12) internally to the communication network (10) ;generating (1610) an access token (28) with which an identifier (12-ID) bound to the internal identifying information (12-INT) is retrievable; andstoring (1620) the internal identifying information (12-INT) at an identifier server (22) in the communication network (10) in association with the access token (28) .57.The method of claim 56, further comprising:receiving, from the communication device (12) , an authorization request (42) that comprises a request to authorize retrieval of the identifier (12-ID) , wherein the internal identifying information (12-INT) is obtained responsive to receiving the authorization request (42) ;after obtaining the internal identifying information (12-INT) , storing the internal identifying information (12-INT) at the identifier server (22) , generating an authorization code (44) that is associated with the internal identifying information (12-INT) , and transmitting the authorization code (44) in a response (46) to the authorization request (42) ;receiving an access token request (47) that includes the authorization code (44) , wherein the access token (28) is generated responsive to the access token request (47) ;after generating the access token (28) , transmitting signaling to the identifier server (22) indicating that the identifier server (22) is to associate the internal identifying information (12-INT) with the access token (28) ; andtransmitting a response (48) to the access token request (47) including the access token (28) .58.The method of any one of claims 56-57, wherein the internal identifying information (12-INT) identifies the communication device (12) internally to the communication network (10) and includes a SUbscription Permanent Identifier, SUPI, and / or a Generic Public Subscription Identifier, GPSI.59.The method of claim 58, wherein the identifier (12-ID) also identifies a connection (12C) of the  communication device (12) , and wherein the internal identifying information (12-INT) also identifies the connection (12C) internally to the communication network (10) .60.An identifier server (22) of a communication network (10) , the identifier server (22) configured to:receive a request (26) for an identifier (12-ID) that is to identify a communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) ;determine, based on a payload (26P) of the request (26) and / or a source address (26A) of the request (26) , internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ;generate an identifier (12-ID) that is bound to the internal identifying information (12-INT) ; andtransmit a response (28) that includes the generated identifier (12-ID) .61.The identifier server (22) of claim 60, configured to perform the method of any one of claims 2-22.62.A node that is a communication device (12) or a server, the node configured to:transmit, to an identifier server (22) in a communication network (10) , a request (26) for an identifier (12-ID) that is to identify the communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) , wherein the request (26) :has a payload (26P) that includes an internal device identifier (27) or an access token (28) , wherein the internal device identifier (27) identifies the communication device (12) internally to the communication network (10) , wherein the access token (28) is associated with internal identifying information (12-INT) which identifies the communication device (12) internally to the communication network (10) ; and / orindicates one or more constraints (29) that are to constrain usability of the identifier (12-ID) ; andreceive a response (28) that includes the identifier (12-ID) .63.The node of claim 62, configured to perform the method of any one of claims 24-36.64.An external invoker device (18) of an application programming interface, API, (16) exposed by a communication network (10) , wherein the external invoker device (18) is a communication device (12) or a server, wherein the external invoker device (18) is configured to:obtain an identifier (12-ID) that is to identify the communication device (12) to the external invoker device (18) of the API (16) , wherein one or more constraints (29) that constrain usability of the identifier (12-ID) are embedded or encoded into the identifier (12-ID) ; andtransmit, to an API provider of the API (16) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with:the identifier (12-ID) ; orinternal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) , as resolved from the identifier (12-ID) by an identifier server (22) in the communication network (10) .65.The external invoker device (18) of claim 64, configured to perform the method of any one of claims 38-46.66.An application programming interface, API, provider server (14) that provides an API (16) exposed by a communication network (10) , wherein the API provider server (14) is configured to:receive, from an external invoker device (18) external to the communication network (10) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with an identifier (12-ID) that identifies a communication device (12) to the external invoker device (18) ;transmit, to an identifier server (22) in the communication network (10) , a resolve request (25) that requests the identifier server (22) to resolve the identifier (12-ID) ;receive a response to the resolve request (25) that includes internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ; andprocess the request (20) to invoke the API (16) using the internal identifying information (12-INT) .67.The API provider server (14) of claim 66, configured to perform the method of any one of claims 48-55.68.An authorization server (40) of a communication network (10) , the authorization server (40) configured to:obtain internal identifying information (12-INT) that identifies a communication device (12) internally to the communication network (10) ;generate an access token (28) with which an identifier (12-ID) bound to the internal identifying information (12-INT) is retrievable; andstore the internal identifying information (12-INT) at an identifier server (22) in the communication network (10) in association with the access token (28) .69.The authorization server (40) of claim 68, configured to perform the method of any one of claims 57-59.70.A computer program comprising instructions which, when executed by at least one processor of an  identifier server (22) of a communication network (10) , causes the identifier server (22) to perform the method of any one of claims 1-22.71.A computer program comprising instructions which, when executed by at least one processor of a node that is a communication device (12) or a server, causes the node to perform the method of any one of claims 23-36.72.A computer program comprising instructions which, when executed by at least one processor of an external invoker device (18) of an application programming interface, API, (16) exposed by a communication network (10) , causes the external invoker device (18) to perform the method of any one of claims 37-46.73.A computer program comprising instructions which, when executed by at least one processor of an application programming interface, API, provider server (14) that provides an API (16) exposed by a communication network (10) , causes the API provider server (14) to perform the method of any one of claims 47-55.74.A computer program comprising instructions which, when executed by at least one processor of an authorization server (40) of a communication network (10) , causes the authorization server (40) to perform the method of any one of claims 56-59.75.A carrier containing the computer program of any one of claims 70-74, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.76.An identifier server (22) of a communication network (10) , the identifier server (22) comprising:communication circuitry; andprocessing circuitry configured to:receive a request (26) for an identifier (12-ID) that is to identify a communication device (12) an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) ;determine, based on a payload (26P) of the request (26) and / or a source address (26A) of the request (26) , internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ;generate an identifier (12-ID) that is bound to the internal identifying information (12-INT) ; andtransmit a response (28) that includes the generated identifier (12-ID) .77.The identifier server (22) of claim 76, the processing circuitry configured to perform the method  of any one of claims 2-22.78.A node that is a communication device (12) or a server, the node comprising:communication circuitry; andprocessing circuitry configured to:transmit, to an identifier server (22) in a communication network (10) , a request (26) for an identifier (12-ID) that is to identify the communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) , wherein the request (26) :has a payload (26P) that includes an internal device identifier (27) or an access token (28) , wherein the internal device identifier (27) identifies the communication device (12) internally to the communication network (10) , wherein the access token (28) is associated with internal identifying information (12-INT) which identifies the communication device (12) internally to the communication network (10) ; and / orindicates one or more constraints (29) that are to constrain usability of the identifier (12-ID) ; andreceive a response (28) that includes the identifier (12-ID) .79.The node of claim 78, the processing circuitry configured to perform the method of any one of claims 24-36.80.An external invoker device (18) of an application programming interface, API, (16) exposed by a communication network (10) , wherein the external invoker device (18) is a communication device (12) or a server, wherein the external invoker device (18) comprises:communication circuitry; andprocessing circuitry configured to:obtain an identifier (12-ID) that is to identify the communication device (12) to the external invoker device (18) of the API (16) , wherein one or more constraints (29) that constrain usability of the identifier (12-ID) are embedded or encoded into the identifier (12-ID) ; andtransmit, to an API provider of the API (16) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with:the identifier (12-ID) ; orinternal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) , as resolved from the identifier (12-ID) by an identifier server (22) in the communication network (10) .81.The external invoker device (18) of claim 80, the processing circuitry configured to perform the method of any one of claims 38-46.82.An application programming interface, API, provider server (14) that provides an API (16) exposed by a communication network (10) , the API provider server (14) comprising:communication circuitry; andprocessing circuitry configured to:receive, from an external invoker device (18) external to the communication network (10) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with an identifier (12-ID) that identifies a communication device (12) to the external invoker device (18) ;transmit, to an identifier server (22) in the communication network (10) , a resolve request (25) that requests the identifier server (22) to resolve the identifier (12-ID) ;receive a response to the resolve request (25) that includes internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ; andprocess the request (20) to invoke the API (16) using the internal identifying information (12-INT) .83.The API provider server (14) of claim 82, the processing circuitry configured to perform the method of any one of claims 48-55.84.An authorization server (40) of a communication network (10) , the authorization server (40) comprising:communication circuitry; andprocessing circuitry configured to:obtain internal identifying information (12-INT) that identifies a communication device (12) internally to the communication network (10) ;generate an access token (28) with which an identifier (12-ID) bound to the internal identifying information (12-INT) is retrievable; andstore the internal identifying information (12-INT) at an identifier server (22) in the communication network (10) in association with the access token (28) .85.The authorization server (40) of claim 84, the processing circuitry configured to perform the method of any one of claims 57-59.86.A non-transitory computer-readable storage medium on which is stored instructions that, when  executed by a processor of an identifier server (22) of a communication network (10) , cause the identifier server (22) to:receive a request (26) for an identifier (12-ID) that is to identify a communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) ;determine, based on a payload (26P) of the request (26) and / or a source address (26A) of the request (26) , internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ;generate an identifier (12-ID) that is bound to the internal identifying information (12-INT) ; andtransmit a response (28) that includes the generated identifier (12-ID) .87.A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of a node that is a communication device (12) or a server, cause the node to:transmit, to an identifier server (22) in a communication network (10) , a request (26) for an identifier (12-ID) that is to identify the communication device (12) to an external invoker device (18) of an application programming interface, API, (16) exposed by the communication network (10) , wherein the request (26) :has a payload (26P) that includes an internal device identifier (27) or an access token (28) , wherein the internal device identifier (27) identifies the communication device (12) internally to the communication network (10) , wherein the access token (28) is associated with internal identifying information (12-INT) which identifies the communication device (12) internally to the communication network (10) ; and / orindicates one or more constraints (29) that are to constrain usability of the identifier (12-ID) ; andreceive a response (28) that includes the identifier (12-ID) .88.A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an external invoker device (18) of an application programming interface, API, (16) exposed by a communication network (10) , cause the external invoker device (18) to:obtain an identifier (12-ID) that is to identify the communication device (12) to the external invoker device (18) of the API (16) , wherein one or more constraints (29) that constrain usability of the identifier (12-ID) are embedded or encoded into the identifier (12-ID) ; andtransmit, to an API provider of the API (16) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with:the identifier (12-ID) ; orinternal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) , as resolved from the identifier (12-ID) by an identifier server (22) in the communication network (10) .89.A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an application programming interface, API, provider server (14) that provides an API (16) exposed by a communication network (10) , cause the API provider server (14) to:receive, from an external invoker device (18) external to the communication network (10) , a request (20) to invoke the API (16) , wherein the request (20) to invoke the API (16) includes or is associated with an identifier (12-ID) that identifies a communication device (12) to the external invoker device (18) ;transmit, to an identifier server (22) in the communication network (10) , a resolve request (25) that requests the identifier server (22) to resolve the identifier (12-ID) ;receive a response to the resolve request (25) that includes internal identifying information (12-INT) that identifies the communication device (12) internally to the communication network (10) ; andprocess the request (20) to invoke the API (16) using the internal identifying information (12-INT) .90.A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an authorization server (40) of a communication network (10) , cause the authorization server (40) to:obtain internal identifying information (12-INT) that identifies a communication device (12) internally to the communication network (10) ;generate an access token (28) with which an identifier (12-ID) bound to the internal identifying information (12-INT) is retrievable; andstore the internal identifying information (12-INT) at an identifier server (22) in the communication network (10) in association with the access token (28).

Citation Information

Patent Citations

  • Application-specific GPSI retrieval

    WO2022233534A1

  • Methods of and systems of service capabilities exposure function (SCEF) based internet-of-things (IOT) communications

    US20180324671A1

  • Seamlessly securing access to application programming interface gateways

    US20220394039A1

  • Method and device for managing identifier of UE in edge computing service

    US20240073798A1

Cited By

  • Methods, intermediary device, identifier server, and node

    WO2026084627A1