An API Topology Hiding Method, Device and System
By introducing topology hidden methods in CAPIF through CCF, the API calling entity indirectly calls the API by hiding the entry point, solving the security problem caused by the API calling entity directly accessing the AEF that provides the API, achieving higher system security.
Patent Information
- Application Number
- CN202210339744.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-04-08
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2038-04-08
AI Technical Summary
In CAPIF, when the API call entity directly accesses the AEF that provides the API, it is susceptible to malicious attacks and resource exhaustion from criminals, resulting in reduced system security.
The AEF that provides API is hidden through CCF, and the topological hiding method is adopted. The API calling entity indirectly calls the API through the topological hiding entry point to avoid direct access to the AEF that provides API.
Improve the security of the CAPIF system, prevent malicious attacks and resource exhaustion, and enhance the system's protection capabilities.
Smart Images

Figure CN114880657B_ABST
Abstract
Description
[0001] This is a divisional application. The application number of the original application is 201810308313.1, and the filing date of the original application is April 8, 2018. The entire content of the original application is incorporated herein by reference. Technical Field
[0002] Embodiments of the present application relate to the field of communication technologies, and in particular, to an Application Programming Interface (API) topology hiding method, device, and system. Background Art
[0003] The 3rd Generation Partnership Project (3GPP) defines a Common Application Programming Interface Framework (CAPIF), which may include an API call entity, a Common API Framework Core Function (CCF), an API Exposing Function (AEF), an API Management Function entity, etc. Among them, the AEF can provide one or more APIs. To achieve load balancing and access control, in CAPIF, the AEF can be deployed in a cascaded manner, a star topology manner, or other deployment manners.
[0004] Currently, in CAPIF, the API call entity usually obtains information about the AEF that provides the API from the CCF and directly accesses the AEF that provides the API. During this process, if the information of the AEF that provides the API is exploited by lawbreakers, the AEF that provides the API is likely to be maliciously attacked by lawbreakers. The API call entity usually obtains information about the AEF that provides the API from the CCF and directly accesses the AEF that provides the API. During this process, if the information of the AEF that provides the API is exploited by lawbreakers, the AEF that provides the API is likely to be maliciously attacked by lawbreakers. A large number of illegal requests will be sent to the AEF that provides the API, resulting in the exhaustion of the software and hardware resources of the AEF and the inability to provide normal API call services, etc. In this way, the system security of CAPIF will be greatly reduced. Summary of the Invention
[0005] The embodiments of the present application provide an API topology hiding method, device, and system to hide the AEF that provides the API for the API calling entity and improve the system security of CAPIF.
[0006] To achieve the above object, the embodiments of the present application adopt the following technical solutions.
[0007] In a first aspect, the embodiments of the present application provide an API topology hiding method. The CCF receives a request message including information about the API from a topology hiding request entity, requesting to hide the AEF that provides the API. The CCF determines a topology hiding entry point for the API calling entity to call the API based on the request message. Based on the method provided by the embodiments of the present application, when the API calling entity requests the CCF to discover an API that meets the discovery conditions, the CCF can send information about the topology hiding entry point of the API that meets the discovery conditions to the API calling entity according to the determined topology hiding entry point for the API calling entity to call the API, so that the API calling entity can send an API call request to the topology hiding entry point according to the information about the topology hiding entry point to request to call the API, instead of directly sending an API call request to the AEF that provides the API to request to call the API, realizing the topology hiding of the API and improving the system security of CAPIF.
[0008] In a first possible design of the first aspect, in combination with the first aspect, the information about the API includes: the identifier of the API; or the identifier of the API and the identifier of the AEF that provides the API. In this way, the CCF can know the API that needs to be hidden according to the identifier of the API, or know the API that needs to be hidden and the AEF that provides the API according to the identifier of the API and the identifier of the AEF that provides the API.
[0009] In a second possible design of the first aspect, in combination with the first aspect or any one of the possible designs of the first aspect, after the CCF determines the information about the topology hiding entry point, the CCF sends the identifier of the API and the identifier of the AEF that provides the API to the topology hiding entry point. For example, the CCF can carry the identifier of the API and the identifier of the AEF that provides the API in a notification message and send it to the topology hiding entry point to notify the topology hiding entry point to hide the AEF that provides the API. In this way, the topology hiding entry point can save the corresponding relationship between the API and the AEF that provides the API according to the received identifier of the API and the identifier of the AEF that provides the API. When the topology hiding entry point receives an API call request sent by the API calling entity carrying the identifier of the API to be called, it sends an API call request to the AEF corresponding to the API to be called according to this corresponding relationship to realize API call.
[0010] Second aspect, embodiments of the present application provide an API topology hiding method. The CCF receives a request message including information of an AEF providing at least one API from a topology hiding request entity, and requests to hide the AEF. The CCF determines a topology hiding entry point for an API calling entity to call at least one API according to the request message. Based on the method provided by the embodiments of the present application, one or more APIs can be hidden. When an API calling entity requests the CCF to discover APIs that meet the discovery conditions, the CCF can send information of the topology hiding entry point of the APIs that meet the discovery conditions to the API calling entity according to the determined topology hiding entry point for the API calling entity to call the APIs, so that the API calling entity can send an API call request to the topology hiding entry point according to the information of the topology hiding entry point to request to call the API, instead of directly sending an API call request to the AEF providing one or more APIs to request to call the API, realizing the topology hiding of multiple APIs and improving the system security of CAPIF.
[0011] In a first possible design, in combination with the first aspect or the second aspect or any possible design of the first aspect, the request message received by the CCF further includes information of the topology hiding entry point. The CCF determines the topology hiding entry point of the API according to the information of the topology hiding entry point, that is, the topology hiding request entity designates the topology hiding entry point of the API and informs the CCF of the information of the topology hiding entry point, reducing the difficulty for the CCF to determine the topology hiding entry point.
[0012] In a second possible design, in combination with the first aspect or the second aspect or any possible design of the first aspect, after receiving the request message, the CCF takes an AEF other than the AEF providing the API as the topology hiding entry point according to the request message. For example, any AEF among multiple AEFs (excluding the AEF providing the API) is taken as the topology hiding entry point, or the AEF with the least load is selected from multiple AEFs as the topology hiding entry point, or the AEF closest to the AEF providing the API is selected from multiple AEFs as the topology hiding entry point, etc. In this way, the CCF can designate the topology hiding entry point by itself, and the CCF has absolute control over the determination of the topology hiding entry point.
[0013] In a third possible design, in combination with the second possible design, after the CCF determines the topology hiding entry point of the API, the CCF sends the information of the topology hiding entry point to the topology hiding request entity, so that the topology hiding request entity saves the information of the topology hiding entry point and carries the information of the topology hiding entry point when initiating a new request message to the CCF.
[0014] In a fourth possible design, in combination with any possible design of the first aspect or the first aspect or the second aspect or the first aspect or any possible design of the second aspect, after determining the topology hiding entry point of the API, the CCF sends a response message to the topology hiding request entity, and the response message is used to indicate that the topology hiding setting of the API is successful. In this way, the topology hiding request entity can learn that the topology hiding of the API has been successfully set.
[0015] In a fifth possible design, in combination with any possible design of the first aspect or the first aspect or the second aspect or the first aspect or any possible design of the second aspect, the method further includes: the CCF receives an API discovery request carrying discovery conditions from an API calling entity, obtains the APIs that meet the discovery conditions according to the API discovery request, obtains the topology hiding entry points corresponding to the APIs that meet the discovery conditions according to the correspondence between the APIs and the topology hiding entry points, and the CCF sends a discovery response including the identifiers of the APIs that meet the discovery conditions and the identifiers of the topology hiding entry points corresponding to the APIs that meet the discovery conditions to the API calling entity. Among them, the correspondence between the APIs and the topology hiding entry points can be saved on the CCF by the CCF according to the information of the APIs and the information of the topology hiding entry points of the APIs. In this way, when the API calling entity discovers an API, the CCF can provide the information of the topology hiding entry point of the API to the API calling entity, so that the API calling entity sends an API call request to the topology hiding entry point instead of directly sending a call request to the AEF providing the API, realizing the topology hiding of the API.
[0016] In a sixth possible design, in combination with any possible design of the first aspect or the first aspect or the second aspect or the first aspect or any possible design of the second aspect, the topology hiding request entity is an API publishing function APF or an API management function entity. In this way, different functional entities can initiate a request message for instructing the CCF to perform topology hiding on the API, improving the flexibility of API topology hiding.
[0017] In a third aspect, an embodiment of the present application provides an API topology hiding method. The topology hiding request entity sends a request message including the information of the API to the CCF, requesting to hide the AEF providing the API, and receives a response message to the request message from the CCF. Based on the method provided by the embodiment of the present application, when the topology hiding request entity needs to hide the topology structure of a certain API, it can send a request message to the CCF, so that the CCF determines the topology hiding entry point of the API, realizing the topology hiding of the API.
[0018] In the first possible design of the third aspect, in combination with the third aspect, the information of the API includes: the identifier of the API; or the identifier of the API and the identifier of the AEF that provides the API. In this way, the CCF can learn the API to be hidden based on the identifier of the API, or learn the API to be hidden and the AEF that provides the API based on the identifier of the API and the identifier of the AEF that provides the API.
[0019] In a fourth aspect, an embodiment of the present application provides an API topology hiding method. The topology hiding request entity sends a request message including information of an AEF that provides at least one API to the CCF, requests to hide the AEF, and receives a response message to the request message from the CCF. Based on the method provided by the embodiment of the present application, when the topology hiding request entity needs to hide certain APIs, it can send a request message including information of the AEF to the CCF, so that the CCF determines to perform topology hiding on the AEF or all the APIs on the AEF.
[0020] In a possible design, in combination with the third aspect or the fourth aspect or any possible design of the third aspect, the response message is used to indicate that the API topology hiding setting is successful. In this way, the topology hiding request entity can learn that the topology hiding of the API has been successfully set.
[0021] In another possible design, in combination with the third aspect or the fourth aspect or any possible design of the third aspect or any possible design of the fourth aspect, the request message further includes information of the API topology hiding entry point. In this way, the topology hiding request entity specifies the API topology hiding entry point and informs the CCF of the information of the topology hiding entry point, reducing the difficulty for the CCF to determine the topology hiding entry point.
[0022] In another possible design, in combination with the third aspect or the fourth aspect or any possible design of the third aspect or any possible design of the fourth aspect, the method further includes: the topology hiding request entity receives information of the API topology hiding entry point from the CCF. In this way, the CCF can specify the topology hiding entry point and send the information of the topology hiding entry point to the topology hiding request entity, so that the topology hiding request entity saves the information of the topology hiding entry point and carries the information of the topology hiding entry point when initiating a new request message to the CCF.
[0023] In yet another possible design, in combination with any possible design of the third aspect or the fourth aspect or the third aspect or the fourth aspect, the method further includes: the topology hiding request entity sends the identifier of the API and the identifier of the AEF providing the API to the topology hiding entry point of the API. For example, the topology hiding request entity can carry the identifier of the API and the identifier of the AEF providing the API in a notification message and send it to the topology hiding entry point to notify the topology hiding entry point to hide the AEF providing the API. In this way, the topology hiding entry point can save the correspondence between the API and the AEF providing the API according to the received identifier of the API and the identifier of the AEF providing the API. When the topology hiding entry point receives an API call request carrying the identifier of the API to be requested for call sent by the API call entity, it sends the API call request to the AEF corresponding to the API to be requested for call according to this correspondence to implement the API call.
[0024] It should be noted that in this possible design, if the request message includes the information of the AEF providing at least one API, the topology hiding request entity sends the identifiers of at least one API and the AEF providing at least one API to the topology hiding entry point of the API.
[0025] In yet another possible design, in combination with any possible design of the third aspect or the fourth aspect or the third aspect or the fourth aspect, the topology hiding request entity is an API publishing function APF or an API management function entity. In this way, different functional entities can initiate request messages to the CCF, improving the flexibility of API topology hiding.
[0026] Fifth aspect, an embodiment of the present application provides an API topology hiding method. The topology hiding entry point receives an API call request carrying the identifier of the API to be requested for call from the API call entity and sends the API call request to the AEF providing the API to be requested for call. Based on the method provided by the embodiment of the present application, the API call entity can call the API on a certain AEF through the topology hiding entry point of the API without directly sending the API call request to the AEF providing the API, hiding the information of the AEF providing the API and improving the security of the CAPIF system.
[0027] In the first possible design of the fifth aspect, in combination with the fifth aspect, the topology hiding entry point sends an API call request to the AEF that provides the API for which the request is made, including: the topology hiding entry point sends an API call request to the AEF that provides the API for which the request is made according to the correspondence between the API and the AEF that provides the API. In this way, the AEF that provides the API can be found according to the correspondence between the API and the AEF that provides the API, and the API call request sent can be sent to this AEF.
[0028] In the second possible design of the fifth aspect, in combination with the first possible design of the fifth aspect, the topology hiding entry point receives the identifier of the API and the identifier of the AEF that provides the API, and saves the correspondence between the API and the AEF that provides the API according to the identifier of the API and the identifier of the AEF that provides the API; or, the topology hiding entry point receives the correspondence. That is, the topology hiding entry point can obtain the correspondence between the API and the AEF that provides the API in different ways, increasing the flexibility of obtaining this correspondence.
[0029] In the third possible design of the fifth aspect, in combination with the second possible design of the fifth aspect, the topology hiding entry point receives the identifier of the API and the identifier of the AEF that provides the API, including: the topology hiding entry point receives the identifier of the API and the identifier of the AEF that provides the API from the general API framework core function CCF; or, the topology hiding entry point receives the identifier of the API and the identifier of the AEF that provides the API from the API publishing function APF or the API management function entity. Among them, the identifier of the API and the identifier of the AEF that provides the API can be carried in the notification message used to notify the topology hiding entry point to hide the AEF that provides the API. In this way, the topology hiding entry point can obtain the identifier of the API and the identifier of the AEF that provides the API from the CCF or the APF or the API management function entity.
[0030] It should be noted that in the fifth aspect or any possible design of the fifth aspect, the topology hiding entry point can also receive the identifiers of at least one API and the AEF that provides at least one API to achieve batch hiding of multiple APIs.
[0031] Sixth aspect, the embodiment of the present application provides a CCF, and this CCF can implement the functions performed by the CCF in the above aspects or various possible designs. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example: this CCF can include: a receiving unit, a determining unit.
[0032] In a possible design, a receiving unit is configured to receive a request message including information of an API from a topology hiding request entity, and a determining unit is configured to determine a topology hiding entry point of the API according to the request message received by the receiving unit.
[0033] In another possible design, the request message including information of an API received by the receiving unit may be replaced with a request message including information of an AEF. A sending unit is further configured to send an identifier of at least one API provided by the AEF and an identifier of the AEF to the topology hiding entry point.
[0034] Wherein, the specific implementation manner of the CCF may refer to the behavior function of the CCF in the API topology hiding method provided in the first aspect or the second aspect or any possible design of the above aspects, and will not be repeated here. Therefore, the provided CCF can achieve the same beneficial effects as those in the first aspect or the second aspect or any possible design of the above aspects.
[0035] In a seventh aspect, a CCF is provided, including: a processor and a memory; the memory is configured to store computer execution instructions, and when the CCF runs, the processor executes the computer execution instructions stored in the memory, so that the CCF executes the API topology hiding method described in the first aspect or the second aspect or any possible design of the above aspects.
[0036] In an eighth aspect, a computer-readable storage medium is provided, in which instructions are stored, and when the instructions run on a computer, the computer can execute the API topology hiding method described in the first aspect or the second aspect or any possible design of the above aspects.
[0037] In a ninth aspect, a computer program product including instructions is provided, and when the computer program product runs on a computer, the computer can execute the API topology hiding method described in the first aspect or the second aspect or any possible design of the above aspects.
[0038] In a tenth aspect, a chip system is provided, the chip system includes a processor and a communication interface, and is configured to support the CCF to implement the functions involved in the above aspects, for example, support the processor to receive a request message including information of an API from a topology hiding request entity through the communication interface, and determine a topology hiding entry point of the API according to the request message. In a possible design, the chip system further includes a memory, and the memory is configured to store necessary program instructions and data of the CCF. The chip system may be composed of chips or may include chips and other discrete devices.
[0039] Among them, for the technical effects brought by any one of the design methods in the sixth to tenth aspects, reference can be made to the technical effects brought by the first aspect or the second aspect above, or any possible design of the above aspects, and details will not be repeated.
[0040] In the eleventh aspect, an embodiment of the present application provides a topology hiding request entity. This topology hiding request entity can implement the functions executed by the topology hiding request entity in the above aspects or any possible design. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example, the topology hiding request entity may include: a sending unit and a receiving unit;
[0041] The sending unit is used to send a request message including information of the API to the CCF, and the receiving unit is used to receive a response message of the request message from the CCF.
[0042] Among them, the specific implementation manner of the topology hiding request entity can refer to the behavior functions of the topology hiding request entity in the API topology hiding method provided in the third aspect or the fourth aspect, or any possible design of the above aspects, and will not be repeated here. Therefore, the provided topology hiding request entity can achieve the same beneficial effects as the third aspect or the fourth aspect, or any possible design of the above aspects.
[0043] In the twelfth aspect, a topology hiding request entity is provided, including: a processor and a memory; the memory is used to store computer execution instructions. When the topology hiding request entity runs, the processor executes the computer execution instructions stored in the memory, so that the topology hiding request entity executes the API topology hiding method described in the third aspect or the fourth aspect, or any possible design of the above aspects.
[0044] In the thirteenth aspect, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When it runs on a computer, it enables the computer to execute the API topology hiding method described in the third aspect or the fourth aspect, or any possible design of the above aspects.
[0045] In the fourteenth aspect, a computer program product including instructions is provided. When it runs on a computer, it enables the computer to execute the API topology hiding method described in the third aspect or the fourth aspect, or any possible design of the above aspects.
[0046] In a fifteenth aspect, a chip system is provided. The chip system includes a processor and a communication interface, which are used to support a topology hiding request entity to implement the functions involved in the above aspects. For example, it supports the processor to receive information about the topology hiding entry point of the API from the CCF through the communication interface, send the identifier of the API to the topology hiding entry point of the API, and provide the identifier of the AEF of the API. In a possible design, the chip system further includes a memory, which is used to store the necessary program instructions and data of the topology hiding request entity. The chip system can be composed of chips or can include chips and other discrete devices.
[0047] Among them, the technical effects brought by any one of the design methods in the eleventh to fifteenth aspects can be referred to the technical effects brought by the third aspect or the fourth aspect or any possible design of the above aspects, and will not be elaborated here.
[0048] In a sixteenth aspect, an embodiment of the present application provides a topology hiding entry point, which can implement the functions performed by the topology hiding entry point in the above aspects or any possible design. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example, the topology hiding entry point can include a receiving unit and a sending unit;
[0049] Among them, the receiving unit is used to receive an API call request carrying the identifier of the requested API from an API call entity, and the sending unit is used to send the API call request to the AEF that provides the requested API.
[0050] Among them, the specific implementation method of the topology hiding entry point can refer to the behavior functions of the topology hiding entry point in the API topology hiding method provided in the fifth aspect or any possible design of the above aspects, and will not be repeated here. Therefore, the provided topology hiding entry point can achieve the same beneficial effects as the first aspect or the second aspect or any possible design of the above aspects.
[0051] In a seventeenth aspect, a topology hiding entry point is provided, including: a processor and a memory; the memory is used to store computer execution instructions. When the topology hiding entry point runs, the processor executes the computer execution instructions stored in the memory, so that the topology hiding entry point executes the API topology hiding method as described in the fifth aspect or any possible design of the above aspects.
[0052] In an eighteenth aspect, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When it runs on a computer, it enables the computer to execute the API topology hiding method as described in the fifth aspect or any possible design of the above aspects.
[0053] In a nineteenth aspect, a computer program product including instructions is provided. When it runs on a computer, it enables the computer to execute the API topology hiding method described in the above fifth aspect or any possible design of the above aspects.
[0054] In a twentieth aspect, a chip system is provided. The chip system includes a processor and a communication interface, which are used to support the topology hiding entry point to implement the functions involved in the above aspects. For example, it supports the processor to receive a request message including information of the API from the topology hiding request entity through the communication interface, and determine the topology hiding entry point of the API according to the request message. In a possible design, the chip system further includes a memory, which is used to store the program instructions and data necessary for the topology hiding entry point. The chip system can be composed of chips or can include chips and other discrete devices.
[0055] Among them, for the technical effects brought by any design method in the sixteenth aspect to the twentieth aspect, reference can be made to the technical effects brought by the above fifth aspect or any possible design of the above aspects, and details will not be repeated.
[0056] In a twenty - first aspect, an API topology hiding system is provided, including a CCF as described in any design method in the sixth aspect to the tenth aspect, a topology hiding request entity as described in any design method in the eleventh aspect to the fifteenth aspect, and a topology hiding entry point as described in any design method in the sixteenth aspect to the twentieth aspect.
[0057] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 It is a schematic diagram of CAPIF provided by an embodiment of the present application;
[0059] Figure 2 It is a structural diagram of a communication device provided by an embodiment of the present application;
[0060] Figure 3 It is a flowchart of an API topology hiding method provided by an embodiment of the present application;
[0061] Figure 4 It is a flowchart of another API topology hiding method provided by an embodiment of the present application;
[0062] Figure 5 It is a flowchart of yet another API topology hiding method provided by an embodiment of the present application;
[0063] Figure 6 It is a structural diagram of a CCF provided by an embodiment of the present application;
[0064] Figure 7 This is a structural diagram of an entity for a topology hiding request provided by an embodiment of the present application;
[0065] Figure 8 This is a structural diagram of an entry point for a topology hiding provided by an embodiment of the present application;
[0066] Figure 9 This is a structural diagram of an API topology hiding system provided by an embodiment of the present application. Detailed implementation manners
[0067] The following describes in detail the implementation manners of the embodiments of the present application with reference to the accompanying drawings.
[0068] The API topology hiding method provided by the embodiments of the present application can be used to hide Figure 1 the AEF that provides services in the CAPIF shown, such as Figure 1 shown. The CAPIF may include: an API call entity (also referred to as an API invoker), a CCF, an AEF, an API Publish Function (APF), and an API management function entity. The AEF, APF, and API management function entity belong to the API provider domain. Different functional entities can be connected through the CAPIF-x interface. For example, the API call entity can be connected to the CCF through the CAPIF-1 interface, etc. In Figure 1 the CAPIF shown, the API call entity can be in the same Public Land Mobile Network (PLMN) trust domain as other functional entities in the CAPIF, or can be in different PLMNs from other functional entities in the CAPIF. Different AEFs can be connected in a cascaded manner or through other means. When an AEF is cascaded with other AEFs, the AEF can be connected to the CCF through the CAPIF-4 interface or may not be connected to the CCF. It should be noted that Figure 1 this is only an exemplary framework diagram. In addition to Figure 1 the functional entities shown, the CAPIF may also include other functional entities, which are not limited.
[0069] Generally, Figure 1 the CAPIF shown can be deployed in a fourth-generation (4 th Generation, 4G) or fifth-generation (5 th Generation, 5G) mobile communication system.
[0070] When the CAPIF is deployed in a 4G mobile communication system, Figure 1 the API call entity in can be an Application Function (AF), or a third-party application (such as a machine-to-machine (M2M) application, an Internet of Things (IoT) application, a Vehicle-to-everything (V2X) application), or a Mobile Management Entity (MME), or a Radio Access Network (RAN), or a Policy and Charging Rules Function (PCRF), or a Home Subscriber Server (HSS), or a Serving Call Session Control Function (S-CSCF), etc. It should be noted that Figure 1 the AEF in can be deployed in a Service Capability Exposure Function (SCEF); the CCF can be independently deployed in a network entity in the 4G mobile communication system; or, the CCF, the AEF, the APF, and the API management function entity can be centrally deployed in the SCEF together.
[0071] When the CAPIF is deployed in a 5G mobile communication system, Figure 1 the API call entity in can be a third-party application, or an Access and Mobility Management Function (AMF), or a Session Management Function (SMF), or a User Plane Function (UPF), or a Policy Control Function (PCF), or an AF, etc. It should be noted that Figure 1 the CCF, the AEF, the APF, and the API management function entity in can be independently deployed in the CAPIF, or can be merged and deployed in the same physical device with other core network elements in the mobile communication system. For example, the CCF can be independently deployed in a network entity in the 5G mobile communication system, and can also be deployed in the NEF together with the function entity in the API provider domain, without limitation.
[0072] Combined with Figure 1, the network elements involved in Figure 1 are introduced as follows.
[0073] The API call entity has functions such as supporting mutual authentication with the CCF, discovering APIs, or calling APIs.
[0074] The CCF has functions such as authenticating the API call entity based on the identity and other information of the API call entity, providing authorization to the API call entity before the API call entity accesses the API, publishing, storing, and supporting the discovery of APIs, being responsible for API access control based on the policies of the PLMN operator, or detecting API calls.
[0075] The AEF, as the entry for the API call entity to call the API, can provide APIs, authenticate the API call entity based on the identity of the API call entity and other information provided by the CCF, confirm the authorization provided by the CCF, and synchronize API logs to the CCF, etc.
[0076] The APF is used to publish APIs, etc.
[0077] The API management function entity is used to provide management of APIs, such as auditing API call logs provided by the CCF, monitoring events reported by the CCF, configuring policies for API providers for APIs, detecting the status of APIs, registering API call entities, etc.
[0078] To implement the technical solution provided by the embodiments of the present application, Figure 1 each functional entity in Figure 2 may include Figure 2 the components shown. As
[0079] shown, it is a structural diagram of a communication device provided by an embodiment of the present application. The communication device 200 includes at least one processor 201, a communication line 202, a memory 203, and at least one communication interface 204. Among them, the processor 201, the memory 203, and the communication interface 204 can be connected through the communication line 202.
[0080] The communication line 202 may include a path for transmitting information between the above components.
[0081] The communication interface 204, which is used to communicate with other devices or communication networks, can use any device such as a transceiver, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Networks (WLAN), etc.
[0082] The memory 203 can be a Read-Only Memory (ROM) or other types of static storage devices that can store static information and instructions, a Random Access Memory (RAM) or other types of dynamic storage devices that can store information and instructions, or it can also be an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Compact Disc Read-Only Memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited to this. The memory 203 can exist independently and be connected to the processor 201 through the communication line 202. The memory 203 can also be integrated with the processor 201. Among them, the memory 203 is used to store execution instructions or application program codes, and is controlled by the processor 201 to execute, implementing the API topology hiding method provided in the following embodiments of the present application.
[0083] In a possible design, the processor in the APF or API management functional entity sends a request message including API information to the CCF through its own communication interface, requesting the CCF to hide the AEF that provides the API; the communication interface of the CCF receives the request message, and the processor of the CCF determines the topology hiding entry point of the API according to the request message. When the communication interface of the CCF receives an API discovery request from the API calling entity, it sends the information of the topology hiding entry point of the API that meets the discovery conditions to the API discovery request, so that the API calling entity can send an API call request carrying the identifier of the API to be called to the topology hiding entry point; after receiving the API call request from the API calling entity, the topology hiding entry point finds the AEF that provides the API to be called and sends an API call request to the AEF. In this way, the API on a certain AEF is indirectly called through the topology hiding entry point, realizing the topology hiding of the API. Specifically, this possible implementation method can refer to Figures 3 - 5 as shown.
[0084] As an implementable way, the processor 201 may include one or more CPUs, such as Figure 2 CPU0 and CPU1 in. As another implementable way, the communication device 200 may include multiple processors, such as Figure 2 processor 201 and processor 207 in. As yet another implementable way, the communication device 200 may further include an output device 205 and an input device 206.
[0085] It should be noted that the above communication device 200 may be a general device or a dedicated device. For example, the communication device 200 may be a desktop computer, a portable computer, a network server, a PDA, a mobile phone, a tablet computer, a wireless terminal, an embedded device or a device with a Figure 2 similar structure in. The embodiments of the present application do not limit the type of the communication device 200.
[0086] The API topology hiding method provided by the embodiments of the present application can be applied to the Figure 1 system shown below, and will be described in conjunction with the Figure 1 system shown.
[0087] Figure 3 The flowchart of an API topology hiding method provided by the embodiments of the present application, the method may include:
[0088] Step 301: The topology hiding request entity sends a request message to the CCF.
[0089] Wherein, the topology hiding request entity may be Figure 1 the APF or API management functional entity in. The CCF may beFigure 1 CCF in it.
[0090] This request message can be used to request the CCF to hide the AEF that provides the API. This request message can include information about the API. It should be noted that the API can be one or more, without limitation.
[0091] Among them, this request message can indicate the topology hiding of the AEF that provides the API in a display way. For example, this request message includes a topology hiding indication for instructing the CCF to hide the AEF that provides the API, so as to explicitly instruct the CCF to hide the AEF that provides the API.
[0092] In addition, this request message can also indicate the topology hiding of the AEF that provides the API in an implicit way. For example, this request message includes information about the topology hiding entry point of the API, so as to implicitly instruct the CCF to hide the AEF that provides the API. Among them, the information about the topology hiding entry point of the API can also be used to use the AEF corresponding to the information about the topology hiding entry point as the hiding entry point of the API.
[0093] For example, this request message can be an API Topology Hiding Request message, or other types of messages. For example, when the topology hiding request entity is an APF, this request message can be an API publishing request, and this API publishing request can also be used to request the CCF to publish this API externally.
[0094] Among them, the information about the API can be the identifier of the API; the information about the API can also be the identifier of the API and the identifier of the AEF that provides the API. The identifier of the API can be used to identify the API. For example, it can be the number of the API (such as: a free combination of letters, numbers, special symbols, etc.), and it can also be the name of the API, the index of the API, or the Uniform Resource Locator (URL) of the API, etc.
[0095] Among them, the AEF that provides the API can refer to the AEF on which the API is deployed, or it can also be understood that the AEF owns the API, that is, the logical implementation of this API is completed by the AEF.
[0096] Among them, the identifier of the AEF that provides the API can be used to identify the AEF that provides the API. For example, it can be the Internet Protocol (IP) address of the AEF that provides the API, or the URL, or the device identifier, or the tunnel identifier, or the Fully Qualified Domain Name (FQDN), etc.
[0097] Step 302: The CCF receives a request message from the topology hiding request entity and determines the topology hiding entry point of the API according to the request message.
[0098] Wherein, the topology hiding entry point can be used by the API calling entity to call the API. For example, the API calling entity can call an API that is not provided by the topology hiding entry point through the topology hiding entry point, that is, the information of the topology hiding entry point presented to the API calling entity is not the device information of the device providing the API. The topology hiding entry point can be an AEF, generally an AEF different from the AEF providing the API.
[0099] In a possible design, the request message received by the CCF further includes the information of the topology hiding entry point, and the CCF determines the topology hiding entry point of the API according to the information of the topology hiding entry point. In this way, the CCF can use the AEF identified by the information of the topology hiding entry point as the topology hiding entry point of the API. Further, in this possible design, the request message may further include a topology hiding indication for instructing the CCF to hide the AEF providing the API, or may not include this topology hiding indication, without limitation. For example, the request message includes the information of the API and a cell specifically used to carry the information of the hiding entry point. Once the CCF receives the request message including this cell, it means that the CCF is requested to hide the AEF providing the API. In this way, the CCF is instructed to hide the AEF providing the API in an implicit manner.
[0100] Wherein, the information of the topology hiding entry point can be used to identify the topology hiding entry point of the API, and can be the identifier of the topology hiding entry point of the API, or the address, or the number of the topology hiding entry point in the CAPIF, etc., without limitation.
[0101] Exemplarily, the topology hiding request entity (such as: the APF or the API management function entity) can randomly select an AEF from multiple AEFs (excluding the AEF providing the API), or select the AEF with the least load, or select the AEF closest to the AEF providing the API as the topology hiding entry point, and carry the information of the topology hiding entry point in the request message and send it to the CCF.
[0102] In another possible design, after the CCF receives the request message, the CCF is triggered to select the topology hiding entry point, and the topology hiding entry point can be an AEF other than the AEF providing the API. For example, the CCF can randomly select an AEF from multiple AEFs (excluding the AEF providing the API), or select the AEF with the least load, or select the AEF closest to the AEF providing the API as the topology hiding entry point.
[0103] Furthermore, the CCF can also send the information of the topology hiding entry point to the topology hiding request entity (such as: APF or API management function entity), so that the topology hiding request entity can send the identifier of the API and the identifier of the AEF providing the API to the topology hiding entry point according to the information of the topology hiding entry point, or perform other actions.
[0104] Based on the above method, when the API calling entity requests the CCF to discover an API, the CCF can send the information of the API that meets the discovery conditions and its corresponding topology hiding entry point to the API calling entity according to the determined topology hiding entry point for the API calling entity to call the API, instead of sending the information of the AEF providing the API to the API calling entity. In this way, the AEF providing the API is hidden, and the topology hiding of the API is achieved.
[0105] Optionally, after step 302, the above method further includes:
[0106] The CCF receives an API discovery request carrying discovery conditions from the API calling entity. This API discovery request is used to request an API that meets the discovery conditions. The CCF obtains the API that meets the discovery conditions according to the API discovery request, and obtains the topology hiding entry point corresponding to the API that meets the discovery conditions according to the correspondence between the API and the topology hiding entry point, and sends an API discovery response to the API calling entity. This API discovery response may include the identifier of the API that meets the discovery conditions and the identifier of the topology hiding entry point corresponding to the API that meets the discovery conditions.
[0107] In this way, the API calling entity can obtain the information of the API that meets the discovery conditions and the topology hiding entry point corresponding to the API during the API discovery phase, so that in the subsequent API call phase, the API calling entity can send an API call request to the topology hiding entry point according to the information of the topology hiding entry point, and call the API provided by other AEFs through the topology hiding entry. Correspondingly, the topology hiding entry point can execute the following step 304 to step 305 to achieve the call of the API.
[0108] Among them, the above discovery conditions may include: keywords of the name of the API, type of the API, communication type of the API, description of the API, AEF information providing the API (such as: IP address of the AEF, port number of the AEF, URL of the AEF, etc.), data type of the API, and one or more of such information. The keywords of the name of the API may refer to the words or phrases in the name of the API that can be used to characterize the API. For example, assuming that QoS_Provisioning is the name of the API, both QoS_Provisioning and QoS can be used as the keywords of the name of the API. The type of the API may refer to the type of operation on the resource, and may include: get (GET), create (POST), full update (PUT), partial update (PATCH), delete (DELETE), and other operation types. The communication type of the API may refer to the communication method supported by the API, and the communication type of the API may include the immediate feedback type, subscription type, etc. The description of the API may refer to the introduction of the usage method of the API. The data type of the API may characterize the types of data supported by the API, and may include integer type, floating-point type, string type, and so on.
[0109] Among them, for the CCF to obtain the APIs that meet the discovery conditions according to the discovery conditions of the API may include: the CCF matches the information of the saved API with the discovery conditions, and uses the API that matches the discovery conditions as the API that meets the discovery conditions. Among them, the information of the API may also include one or more of the following: keywords of the name of the API, type of the API, communication type of the API, descriptor of the API (such as usage method), AEF information providing the API (such as: IP address, port number, URL, etc.), data type, etc.
[0110] In addition, the corresponding relationship between the above API and the topology hiding entry point may be stored on the CCF in the form of a list. After the CCF obtains the API that meets the discovery conditions, the CCF may, by looking up the table, find the topology hiding entry point corresponding to the API that meets the discovery conditions.
[0111] As shown in Table 1, assuming that the AEF of the API providing service x is AEF-2, the AEF of the API providing service y is AEF-3, and the topology hiding entry points of the APIs of service x and service y are AEF-1, then the CCF may store the corresponding relationship between the API and the topology hiding entry point in the manner shown in Table 1. Among them, the information stored in the API column in Table 1 may be the identifier of the API, and the information stored in the topology hiding entry point column may be the identifier of the topology hiding entry point, without limitation.
[0112] If the CCF determines that the API of service x is the API required by the API calling entity after receiving the API discovery request sent by the API calling entity, it determines, by looking up Table 1, that the AEF corresponding to the API of service x is AEF-1, and returns the information of AEF-1 to the API calling entity.
[0113] Table 1
[0114]
[0115]
[0116] Optionally, in Figure 3 the first implementation scenario of the embodiment shown, the method further includes:
[0117] Step 303: The CCF sends a response message to the topology hiding request entity for the request message.
[0118] Wherein, the response message is used to respond to the request message in Step 301, and can be used to confirm that the CCF has received the request message, or can be used to indicate or notify that the topology hiding setting of the API is successful. In this way, the topology hiding request entity can learn that the CCF has successfully hidden the AEF providing the API.
[0119] For example, the response message can be 200OK corresponding to the request message, or can also be an API Publish Response, or an API Topology Hiding Response, or other types of messages, without limitation. Among them, 200OK corresponding to the request message can indicate that the API topology hiding setting is successful.
[0120] Based on Figure 3 the first implementation scenario of the embodiment shown, the topology hiding request entity can learn that it has successfully sent the request message to the CCF. Further, in the case where the response message is used to indicate or notify that the topology hiding setting of the API is successful, the topology hiding request entity can also learn that the CCF has successfully hidden the AEF providing the API.
[0121] Optionally, in Figure 3 the second implementation scenario of the embodiment shown, after the API calling entity obtains the information of the topology hiding entry point of the API from the CCF through the above API discovery process, the API calling entity sends an API call request to the topology hiding entry point according to the information of the topology hiding entry point, and calls the API on a certain AEF through the topology hiding entry point. Specifically, the method further includes:
[0122] Step 304: The topology hiding entry point receives an API call request from the API calling entity.
[0123] Among them, the API call request can be used to request to call an API. The API call request can carry the identifier of the API to be called, and the API to be called can be any API that meets the discovery conditions.
[0124] Step 305: The topology hiding entry point sends an API call request to the AEF that provides the API to be called.
[0125] Among them, the API call request received by the topology hiding entry point from the API call entity and the API call request sent by the topology hiding entry point to the AEF that provides the API to be called can be the same or different, without limitation.
[0126] Exemplarily, the topology hiding entry point sending an API call request to the AEF that provides the API to be called in step 305 may include:
[0127] The topology hiding entry point sends an API call request to the AEF of the API to be called according to the correspondence between the API and the AEF that provides the API.
[0128] Among them, the correspondence between the API and the AEF that provides the API can be determined by the topology hiding entry point according to the identifier of the API and the identifier of the AEF that provides the API, or obtained by the topology hiding entry point from other functional entities, without limitation.
[0129] For example: The topology hiding entry point can receive the identifier of the API and the identifier of the AEF that provides the API, and save the correspondence between the API and the AEF that provides the API according to the identifier of the API and the identifier of the AEF that provides the API. Among them, the correspondence between the API and the AEF that provides the API can be saved in the form of a list. In this way, when the topology hiding entry point receives an API call request sent by the API call entity carrying the identifier of the API to be called, it determines the AEF that provides the API to be called through a table lookup method, and forwards the API call request to this AEF.
[0130] For example, as shown in Table 2, assume that the AEF providing the API for service x is AEF-2, the AEF providing the API for service y is AEF-3, and both need to be hidden. If the CCF determines that the topology hiding entry point for the API of service x and the API of service y is AEF-1, then the CCF can send the identifier of the API of service x and the identifier of AEF-2, as well as the identifier of the API of service y and the identifier of AEF-3 to AEF-1. After receiving this information, AEF-1 stores the correspondence between the API and the AEF providing the API in the manner shown in Table 2. If the CCF receives an API call request carrying the identifier of the API of service x sent by an API call entity, then the CCF determines that the AEF providing the API of service x is AEF-2 by looking up Table 2 and forwards the API call request to AEF-2.
[0131] Table 2
[0132] API AEF that provides the API API for Service x AEF - 2 API for Service y AEF - 3
[0133] Among them, the topology hiding entry point receiving the identifier of the API and the identifier of the AEF providing the API may include: the topology hiding entry point receives the identifier of the API and the identifier of the AEF providing the API from the CCF, or receives the identifier of the API and the identifier of the AEF providing the API from the APF or the API management function entity. For example, the identifier of the API and the identifier of the AEF providing the API may be carried in a notification message, and this notification message can be used to notify the topology hiding entry point to hide the AEF providing the API. This notification message can be an API topology hiding notification, without limitation.
[0134] Furthermore, after the AEF providing the requested API receives the API call request sent by the topology hiding entry point and executes the API logic, the AEF providing the requested API can send the execution result to the topology hiding entry point, and the topology hiding entry point forwards the execution result to the API call entity. Among them, when forwarding this execution result, the information of the topology hiding entry point can be carried, and the information of the AEF providing the requested API is not carried to avoid exposing the information of the AEF actually providing the API.
[0135] Based on Figure 3 In the second implementation scenario of the illustrated embodiment, during the API call phase, the API call request sent by the API call entity is sent to the AEF providing the API through the topology hiding entry point of the API, triggering the execution of the API logic (such as executing a piece of code for the called API, etc.). In this way, the API call can be realized while hiding the information of the AEF providing the API.
[0136] Optionally, in Figure 3 the third implementation scenario of the illustrated embodiment, when the topology hiding request entity sends a request message carrying information about the topology hiding entry point of the API to the CCF, the above method further includes:
[0137] If the CCF detects that the topology hiding entry point is unavailable (e.g., overloaded or down), it sends a response message to the topology hiding request entity indicating that the request has failed or been rejected.
[0138] Wherein, the response message may carry a reason value for the request failure or rejection, and the reason value may include that the topology hiding entry point is overloaded or down, etc., without limitation.
[0139] In addition, the response message may also carry information about one or more available topology hiding entry points provided by the CCF, so that the topology hiding request entity selects a topology hiding entry point according to the information about one or more topology hiding entry points carried in the response message (e.g., selects a topology hiding entry point with the lowest load), and sends a request message carrying the information about the selected topology hiding entry point to the CCF, avoiding the inability to determine the topology hiding entry point of the API due to the unavailability of the topology hiding entry point indicated by the topology hiding request entity, and thus ensuring the normal invocation of the API.
[0140] Optionally, in Figure 3 the fourth implementation scenario of the illustrated embodiment, when the topology hiding request entity sends a request message carrying information about the topology hiding entry point of the API to the CCF, the above method further includes:
[0141] The CCF selects other AEFs other than the topology hiding entry point requested by the topology hiding request entity as the topology hiding entry point of the API, and sends a response message carrying the information about the topology hiding entry point of the API selected by the CCF to the topology hiding request entity.
[0142] Furthermore, the topology hiding request entity receives the topology hiding entry point of the API selected by the CCF and saves the information about the topology hiding entry point.
[0143] Wherein, the response message corresponds to the request message and can be used to indicate that the CCF has successfully received the request message sent by the topology hiding request entity, but has not accepted the topology hiding entry point specified by the topology hiding request entity, but selects a new topology hiding entry point.
[0144] Based on Figure 3In the fourth implementation scenario of the illustrated embodiment, the CCF may not accept the designation of the topology hiding entry point by the topology hiding request entity, but instead actively designate the topology hiding entry point, which gives the CCF absolute control over the selection of the topology hiding entry point.
[0145] The following describes Figure 4 the illustrated embodiment by taking the topology hiding request entity as the APF as an example. Figure 3 It should be noted that when the topology hiding request entity is the API management function entity, the execution process can refer to Figure 4 the illustrated solution. For example, the APF in Figure 4 the illustrated embodiment can be replaced with the API management function entity.
[0146] Figure 4 FIG. is a flowchart of another API topology hiding method provided by an embodiment of the present application. The method includes:
[0147] Step 401: The APF sends a request message to the CCF.
[0148] Among them, the APF may be the APF in Figure 1 , and the request message may be an API publishing request.
[0149] Specifically, the relevant description of the request message and the execution process of step 401 can be referred to step 301, and will not be elaborated here.
[0150] Step 402: The CCF receives the request message from the APF and determines the topology hiding entry point of the API according to the request message.
[0151] Among them, step 402 can be referred to step 302, and will not be elaborated here.
[0152] Step 403: The CCF saves the correspondence between the API and the topology hiding entry point.
[0153] Among them, step 403 can be referred to the description in Figure 3 , and will not be elaborated here.
[0154] Step 404: The CCF sends a response message to the APF.
[0155] Among them, the response message is used to indicate that the topology hiding setting of the API is successful.
[0156] Step 405: The CCF sends a notification message to the topology hiding entry point. The notification message includes the identifier of the API and the identifier of the AEF providing the API. The notification message is used to notify the topology hiding entry point to hide the AEF providing the API.
[0157] It should be noted that steps 404 and 405 can be executed in the order Figure 4 shown, or step 405 can be executed first and then step 404, without any restrictions.
[0158] Step 406: The topology hiding entry point receives a notification message from the CCF, and saves the correspondence between the API and the AEF providing the API according to the identifier of the API and the identifier of the AEF providing the API.
[0159] Step 407: The CCF receives an API discovery request from the API calling entity.
[0160] Among them, the API discovery request is used to request an API that meets the discovery conditions, and the API discovery request may include discovery conditions.
[0161] Step 408: The CCF obtains an API that meets the discovery conditions according to the API discovery request.
[0162] Step 409: The CCF obtains the topology hiding entry point corresponding to the API that meets the discovery conditions according to the correspondence between the API and the topology hiding entry point saved in step 403.
[0163] Step 410: The CCF sends an API discovery response including the identifier of the API that meets the discovery conditions and the identifier of the topology hiding entry point corresponding to the API that meets the discovery conditions to the API calling entity.
[0164] Step 411: The topology hiding entry point receives an API call request from the API calling entity.
[0165] Among them, step 411 can be referred to as described in step 304 and will not be elaborated here.
[0166] Step 412: The topology hiding entry point determines the AEF providing the API requested to be called according to the correspondence between the API and the AEF providing the API saved in step 406, and sends an API call request to the AEF providing the API requested to be called.
[0167] Among them, step 412 can be referred to as step 305 and will not be elaborated here.
[0168] It should be noted that Figure 4 in the embodiment shown, step 405 can be replaced by the APF sending a notification message to the topology hiding entry point.
[0169] In addition, Figure 3 and Figure 4In the illustrated embodiment, the request message sent by the topology hiding request entity to the CCF can be used to request hiding the information of one API or the information of multiple APIs, that is, hiding the AEFs corresponding to the multiple APIs, so as to implement topology hiding for one or more APIs.
[0170] Based on Figure 4 the method shown, the APF can request the CCF to hide the AEF providing the API. The CCF determines the topology hiding entry point of the API. When the API call entity requests the CCF to discover the API, the CCF sends the information of the API that meets the discovery conditions and its corresponding topology hiding entry point to the API call entity, instead of sending the information of the AEF providing the API to the API call entity, thus hiding the AEF providing the API. Further, in the API call phase, the API call entity can send an API call request to the topology hiding entry point of the API, and the API call request is sent to the AEF providing the API through the topology hiding entry point. Throughout the process, the information of the AEF providing the API is hidden from the API call entity, making the information of the AEF providing the API unknown to the API call entity, and improving the system security of CAPIF.
[0171] Figure 5 Another API topology hiding entry point provided by the embodiment of the present application is described by taking the topology hiding request entity as the API management function entity in this embodiment. As Figure 5 shown, the method includes:
[0172] Step 501: The API management function entity sends a request message to the CCF.
[0173] Among them, the API management function entity can be the Figure 1 API management function entity in
[0174] The request message may include the identifier of the AEF. The request message is used to request topology hiding of the AEF. One or more APIs can be provided on the AEF, that is, the request message can also be understood as being used for topology hiding all the APIs provided by the AEF. The request message can be an API topology hiding request.
[0175] Step 502: The CCF receives the request message from the API management function entity and determines the topology hiding entry point of the AEF according to the request message.
[0176] Among them, step 502 can refer to step 302 described above and will not be elaborated here.
[0177] Step 503: The CCF saves the correspondence between the AEF and the topology hiding entry point.
[0178] Specifically, the CCF's preservation of the correspondence between the AEF and the topology hiding entry point may include:
[0179] The CCF preserves the correspondence between the AEF and the topology hiding entry point. At the same time, the CCF may also preserve the AEF and at least one API corresponding thereto during the API release phase; or, the CCF may preserve at least one API provided by the AEF during the API release phase, and preserve the correspondence between at least one API and the topology hiding entry point according to at least one AEF provided by the AEF.
[0180] Step 504: The CCF sends a response message to the API management functional entity.
[0181] Wherein, the response message is used to indicate that the topology hiding setting of the API is successful. The response message may be an API topology hiding response. Optionally, the response message may also include information about the topology hiding entry point.
[0182] Step 505: The CCF sends a notification message to the topology hiding entry point, wherein the notification message includes the identifier of the AEF and at least one API identifier provided by the AEF, and the notification message is used to notify the topology hiding entry point to hide the AEF providing the API.
[0183] It should be noted that Step 504 and Step 505 may be executed Figure 5 in the order shown, or Step 505 may be executed first, and then Step 504, without limitation.
[0184] Step 506: The topology hiding entry point receives the identifier of the AEF and at least one API identifier provided by the AEF from the CCF, and preserves the correspondence between the AEF and at least one API provided by the AEF.
[0185] Step 507: The CCF receives an API discovery request from the API calling entity.
[0186] Wherein, the API discovery request is used to request an API that meets the discovery conditions, and the API discovery request may include discovery conditions.
[0187] Step 508: The CCF obtains an API that meets the discovery conditions according to the API discovery request.
[0188] Step 509: The CCF obtains the topology hiding entry point corresponding to the API that meets the discovery conditions according to the correspondence between the AEF and the topology hiding entry point saved in Step 503.
[0189] Step 510: The CCF sends an API discovery response to the API calling entity, including the identifier of the API that meets the discovery condition and the identifier of the topology hiding entry point corresponding to the API that meets the discovery condition.
[0190] Among them, Steps 507 to 510 can refer to Figure 3 the API discovery process described in
[0191] Step 511: The topology hiding entry point receives an API call request from the API calling entity, carrying the identifier of the API to be called.
[0192] Among them, Step 511 can refer to Step 304 and will not be elaborated here.
[0193] Step 512: The topology hiding entry point determines the AEF that provides the API to be called according to the correspondence between the AEF saved in Step 506 and at least one API that the AEF can provide, and sends an API call request to the AEF that provides the API to be called.
[0194] Among them, Step 512 can refer to Step 305 and will not be elaborated here.
[0195] It should be noted that Figure 5 Step 405 in the illustrated embodiment can also be replaced by the API management function entity sending a notification message to the topology hiding entry point.
[0196] Based on Figure 5 the method shown, the APF can request the CCF to hide a certain AEF (that is, hide the AEF that provides one or more APIs), and the CCF determines the topology hiding entry point of the AEF to achieve topology hiding of one or more APIs. When the API calling entity requests the CCF to discover an API, the CCF sends information about the API that meets the discovery condition and its corresponding topology hiding entry point to the API calling entity, rather than sending information about the AEF that provides the API to the API calling entity, hiding the AEF that provides the API. Further, in the API call phase, when the API calling entity calls one or more APIs on the AEF, it can send an API call request to the topology hiding entry point of the AEF, and the API call request is sent to the AEF that provides the API through the topology hiding entry point to achieve the call of one or more APIs. At the same time, throughout the process, the information of the AEF is hidden from the API calling entity, making the information of the AEF unknown to the API calling entity, ensuring the security of the AEF and thus enhancing the system security of CAPIF.
[0197] The above mainly introduces the method provided by the embodiments of the present application from the perspective of the interaction between various nodes. It can be understood that in order to implement the above functions, each node, such as communication devices like CCF, topology hiding request entity, topology hiding entry point, etc., includes corresponding hardware structures and / or software modules for executing various functions. Those skilled in the art should easily realize that in combination with the algorithm steps of the examples described in the embodiments disclosed in this article, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0198] The embodiments of the present application can perform functional module partitioning on CCF, topology hiding request entity, and topology hiding entry point according to the above method examples. For example, corresponding functional modules can be partitioned for each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. It should be noted that the partitioning of modules in the embodiments of the present application is illustrative, only a logical functional partitioning, and there can be other partitioning methods in actual implementation.
[0199] Figure 6 The structure diagram of a communication device is shown. This communication device can be CCF, or a chip in CCF, or a system-on-chip, and this communication device can be used to execute the functions of CCF involved in the above embodiments.
[0200] As an implementable manner, Figure 6 The shown communication device includes: a receiving unit 60 and a determining unit 61.
[0201] The receiving unit 60 is used to receive a request message including information of API from the topology hiding request entity, for example, it supports the communication device to execute the above step 301 and step 401.
[0202] The determining unit 61 is used to determine the topology hiding entry point of the API according to the request message received by the receiving unit 60. For example, it supports the communication device to execute the above step 302 and step 402.
[0203] Furthermore, in this possible design, Figure 6 The shown communication device may further include:
[0204] A sending unit 62, which is used to send the information of the topology hiding entry point to the topology hiding request entity.
[0205] Furthermore, Figure 6The sending unit 62 shown is further configured to send the identifier of the API and the identifier of the AEF providing the API to the topology hiding entry point. For example, it supports the communication device to execute step 405 described above.
[0206] Furthermore, Figure 6 The sending unit 62 shown is further configured to send a response message to the topology hiding request entity. For example, it supports the communication device to execute step 303 and step 404 described above.
[0207] Furthermore, Figure 6 The receiving unit 60 shown is further configured to receive an API discovery request carrying discovery conditions from the API calling entity. For example, it supports the communication device to execute step 407 described above. Figure 6 The communication device shown may further include: an obtaining unit 63, configured to obtain APIs that meet the discovery conditions according to the API discovery request received by the receiving unit; and obtain the topology hiding entry points corresponding to the APIs that meet the discovery conditions according to the correspondence between the APIs and the topology hiding entry points. For example, it supports the communication device to execute step 408 and step 409 described above.
[0208] Figure 6 The sending unit 62 shown is further configured to send an API discovery response to the API calling entity, where the API discovery response includes the identifier of the API that meets the discovery conditions and the identifier of the topology hiding entry point corresponding to the API that meets the discovery conditions. For example, it supports the communication device to execute step 410 described above.
[0209] It should be noted that all relevant contents of the steps involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here. The communication device provided in the embodiments of the present application is used to execute the function of the CCF in the above API topology hiding method, and thus can achieve the same effect as the above API topology hiding method.
[0210] As another implementable manner, Figure 6 The communication device shown may include: a processing module and a communication module. The processing module is configured to control and manage the actions of the communication device. For example, the processing module is used to support the communication device to execute step 302, step 402, step 403, step 408, step 409, step 502, step 503, step 508, step 509, and other processes of the technologies described herein. The communication module is used to support the communication of the communication device with other network entities, such as the communication with Figure 1 the functional modules or network entities shown. Furthermore, the communication device may further include a storage module, configured to store the program code and data of the communication device.
[0211] Among them, the processing module can be a processor or a controller. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on. The communication module can be a transceiver circuit or a communication interface, etc. The storage module can be a memory. When the processing module is a processor, the communication module is a communication interface, and the storage module is a memory, Figure 6 The communication device shown can be Figure 2 the communication device shown.
[0212] Figure 7 The structure diagram of a communication device is shown. The communication device can be a topology hiding request entity, or a chip in the topology hiding request entity, or a system-on-chip. The communication device can be used to execute the functions of the APF or API management function entity involved in the above embodiments.
[0213] As an implementable manner, Figure 7 The communication device shown includes: a sending unit 70 and a receiving unit 71.
[0214] The sending unit 70 is used to send a request message including information of the API to the CCF, such as: supporting the communication device to execute the above steps 301 and 401.
[0215] The receiving unit 71 is used to receive a response message of the request message from the CCF. Such as: supporting the communication device to execute the above steps 303 and 404.
[0216] Further, the receiving unit 71 is also used to receive information of the topology hiding entry point of the API from the CCF.
[0217] Further, the sending unit 70 is also used to send the identifier of the API and the identifier of the AEF providing the API to the topology hiding entry point of the API.
[0218] It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be elaborated here. The communication device provided in the embodiment of this application is used to execute the functions of the APF or API management function entity in the above API topology hiding method, so the same effect as the above API topology hiding method can be achieved.
[0219] As another implementable manner, Figure 7 The communication device shown includes: a processing module and a communication module. The processing module is used to control and manage the actions of the communication device. For example, the processing module is used to support the communication device to execute other processes of the technology described herein. The communication module is used to support the communication of the communication device with other network entities, such as withFigure 1 Communication between the shown functional modules or network entities. The communication device may further include a storage module for storing program code and data of the communication device.
[0220] Among them, the processing module may be a processor or a controller. It may implement or execute various exemplary logic blocks, modules, and circuits described in connection with the disclosure of the present application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on. The communication module may be a transceiver circuit or a communication interface, etc. The storage module may be a memory. When the processing module is a processor, the communication module is a communication interface, and the storage module is a memory, the communication device involved in the embodiments of the present application may be Figure 2 the shown communication device.
[0221] Figure 8 The structure diagram of a communication device is shown. The communication device may be a topology hiding entry point, or a chip in the topology hiding entry point, or a system-on-chip. The communication system may be used to execute the functions of the topology hiding entry point involved in the above embodiments.
[0222] As an implementable manner, Figure 8 the shown communication device includes: a receiving unit 80 and a transmitting unit 81.
[0223] The receiving unit 80 is configured to receive an API call request carrying an identifier of the API to be requested for call from an API call entity, such as: supporting the communication device to execute the above steps 411 and 511.
[0224] The transmitting unit 81 is configured to send an API call request to an AEF that provides the API to be requested for call. Such as: supporting the communication device to execute the above steps 412 and 512.
[0225] Further, the receiving unit 80 is further configured to receive the identifier of the API and the identifier of the AEF that provides the API; Figure 8 The shown communication device further includes: a saving unit 82, configured to save the correspondence between the API and the AEF that provides the API according to the identifier of the API received by the receiving unit 80 and the identifier of the AEF that provides the API, such as: supporting the communication device to execute the above steps 405, 406, 505, and 506; or, the receiving unit 80 is further configured to receive the correspondence.
[0226] It should be noted that all relevant content of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here. The communication device provided in the embodiments of the present application is used to execute the function of the topology hiding entry point in the above API topology hiding method, so the same effect as the above API topology hiding method can be achieved.
[0227] As another implementable manner, Figure 8 The shown communication device includes: a processing module and a communication module. The processing module is used to control and manage the actions of the communication device. For example, the processing module is used to support the communication device to execute step 305, step 406, step 412, step 506, step 512, and other processes of the technologies described herein. The communication module is used to support the communication of the communication device with other network entities, such as the communication with Figure 1 the shown functional modules or network entities. The communication device may further include a storage module for storing the program code and data of the communication device.
[0228] Among them, the processing module may be a processor or a controller. It can implement or execute various exemplary logical blocks, modules, and circuits described in combination with the disclosure of the present application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc. The communication module may be a transceiver circuit or a communication interface, etc. The storage module may be a memory. When the processing module is a processor, the communication module is a communication interface, and the storage module is a memory, the communication device involved in the embodiments of the present application may be Figure 2 the shown communication device.
[0229] Figure 9 This is a structural diagram of an API topology hiding system provided by an embodiment of the present application. As Figure 9 shown, the API topology hiding system may include: CCF90, a topology hiding request entity 91, a topology hiding entry point 92, and an API call entity.
[0230] Among them, CCF90 may be Figure 6 the shown communication device, and is used to execute the function of CCF involved in the above method embodiments; the topology hiding request entity 91 may be Figure 7 the shown communication device, and is used to execute the function of APF or API management functional entity involved in the above method embodiments; the topology hiding entry point 92 may be Figure 8 the shown communication device, and is used to execute the function of the topology hiding entry point involved in the above method embodiments, and will not be elaborated.
[0231] It should be noted that all relevant content of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional entities, and will not be elaborated here. For example, each functional entity in the API topology hiding system provided by the embodiments of the present application can interact with each other to execute the following process: the topology hiding request entity 91 requests the CCF 90 to hide the AEF providing the API, the CCF 90 determines the topology hiding entry point 92 of the API. When the API calling entity requests the CCF 90 to discover one or more APIs, the CCF 90 sends the information of the APIs that meet the discovery conditions and their corresponding topology hiding entry points 92 to the API calling entity, rather than sending the information of the AEF providing the API to the API calling entity, thus hiding the AEF providing the API. In this way, in the API calling phase, the API calling entity sends an API calling request to the topology hiding entry point 92 of the API, and the API calling request is sent to the AEF providing the API through the topology hiding entry point 92, so as to hide the information of the AEF providing the API from the API calling entity, making the information of the AEF providing the API unknown to the API calling entity and improving the system security of CAPIF.
[0232] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0233] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0234] The unit described as a separated component may or may not be physically separated, and the component displayed as a unit may be a physical unit or multiple physical units, that is, it can be located in one place or distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0235] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0236] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0237] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claimed rights.
Claims
1. An Application Programming Interface (API) topology hiding method, characterized in that The method includes: The API call entity sends an API discovery request to the core function CCF of the general API framework, and the API discovery request carries discovery conditions; the API discovery request is used to request an API that meets the discovery conditions. The API call entity receives an API discovery response from the CCF, and the API discovery response includes the identifier of the API that meets the discovery conditions and information about the topology hidden entry point corresponding to the API that meets the discovery conditions. The API call entity sends an API call request to the API open function AEF through the topology hidden entry point, and the API call request carries the identifier of the API to be called, and the API to be called is any one of the APIs that meet the discovery conditions, and the AEF is used to provide the API to be called.
2. The API topology hiding method according to claim 1, wherein The API call entity sending an API call request to the AEF that provides the API to be called through the topology hidden entry point includes: The API call entity sends the API call request to the topology hidden entry point. The topology hidden entry point sends the API call request to the AEF that provides the API to be called.
3. The API topology hiding method according to claim 1 or 2, characterized in that The information about the topology hidden entry point includes the identifier of the topology hidden entry point or the address of the topology hidden entry point.
4. The API topology hiding method according to any one of claims 1-3, characterized in that, The method further includes: The API call entity receives an execution result from the AEF that provides the API to be called through the topology hidden entry point, and the execution result does not carry information about the AEF that provides the API to be called.
5. A method for hiding the topology of an Application Programming Interface (API), characterized in that, The method includes: The topology hidden entry point receives an API call request from the API call entity, and the API call request carries the identifier of the API to be called, and the API to be called is any one of the APIs that meet the discovery conditions. The topology hidden entry point sends the API call request to the API open function AEF, and the AEF is used to provide the API to be called.
6. The method according to claim 5, wherein The topology hidden entry point sending the API call request to the AEF that provides the API to be called includes: The topology hidden entry point sends the API call request to the AEF that provides the API to be called according to the correspondence between the API and the AEF that provides the API.
7. The method according to claim 6, characterized in that, The method further includes: The topology hidden entry point receives the identifier of the API and the identifier of the AEF that provides the API, and determines the correspondence according to the identifier of the API and the identifier of the AEF that provides the API; or The topology hidden entry point receives the correspondence.
8. The method according to claim 7, wherein The topology hidden entry point receiving the identifier of the API and the identifier of the AEF that provides the API includes: The topology hidden entry point receives the identifier of the API and the identifier of the AEF that provides the API from the core function CCF of the general API framework; or The topology hiding entry point receives the identifier of the API and the identifier of the AEF that provides the API from a topology hiding request entity, where the topology hiding request entity is an API publishing function (APF) or an API management function.
9. An API topology hiding system, characterized in that, The API topology hiding system includes: an API calling entity, a general API framework core function (CCF), and a topology hiding entry point; The API calling entity is configured to send an API discovery request to the CCF, where the API discovery request carries discovery conditions; the API discovery request is used to request an API that meets the discovery conditions; The CCF is configured to send an API discovery response to the API calling entity, where the API discovery response includes the identifier of the API that meets the discovery conditions and information about the topology hiding entry point corresponding to the API that meets the discovery conditions; The API calling entity is further configured to send an API call request to an API exposure function (AEF) through the topology hiding entry point, where the API call request carries the identifier of the API to be called, and the API to be called is any one of the APIs that meet the discovery conditions, and the AEF is used to provide the API to be called; The topology hiding entry point is configured to send the API call request to the AEF.
10. The API topology hiding system according to claim 9, wherein Specifically, the topology hiding entry point is configured to: send the API call request to the AEF that provides the API to be called according to the correspondence between the API and the AEF that provides the API.
11. The API topology hiding system according to claim 10, characterized in that, The topology hiding entry point is further configured to receive the identifier of the API and the identifier of the AEF that provides the API, and determine the correspondence according to the identifier of the API and the identifier of the AEF that provides the API; or, The topology hiding entry point is further configured to receive the correspondence.
12. The API topology hiding system according to claim 11, wherein, The CCF is further configured to send the identifier of the API and the identifier of the AEF that provides the API to the topology hiding entry point.
13. The API topology hiding system according to any one of claims 9-12, characterized in that, The topology hiding entry point is further configured to forward the execution result from the AEF that provides the API to be called to the API calling entity, and the execution result does not carry information about the AEF that provides the API.
14. A communication device, characterized in that, The communication device includes one or more processors and a communication interface, and the one or more processors and the communication interface are used to support the communication device to execute the application programming interface (API) topology hiding method according to any one of claims 1 - 4.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer instructions, and when the computer instructions run on a computer, the computer is caused to execute the application programming interface (API) topology hiding method according to any one of claims 1 - 4.
16. A communication device, characterized in that, The communication device includes one or more processors and a communication interface, and the one or more processors and the communication interface are used to support the communication device to execute the application programming interface (API) topology hiding method according to any one of claims 5 - 8.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer instructions that, when run on a computer, cause the computer to execute the application programming interface (API) topology hiding method according to any one of claims 5-8.