Network node and authentication method
By starting the browser as the RP on the UCRF and using the OIDC-CIBA authentication process, the problem of the browser being unable to access the AF service in the 5G system is solved, and the ID collaborative authentication between the browser and the AF is realized.
Patent Information
- Application Number
- CN202380096138.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2025-10-24
AI Technical Summary
In the 5G system, the browser cannot achieve ID collaboration with the AF without direct user management, resulting in the inability to access application function services.
By launching the browser as the RP on the UCRF, executing the OIDC-CIBA authentication process, and using the CAPIF core functions and authorization functions for identifier verification and authentication, the browser can access the AF service.
It is realized that in the 5G system, the browser can perform the authentication process as the RP, successfully access the AF service and perform ID collaboration.
Smart Images

Figure CN120836029A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a network node in a communication system and an authentication method. BACKGROUND
[0002] In 3GPP (registered trademark) (3rd Generation Partnership Project), in order to achieve further large capacity of system capacity, further high speed of data transmission speed, further low delay in a wireless section, and the like, research on a wireless communication system (hereinafter, referred to as "5G" or "NR") called 5G or NR is being conducted. In 5G, in order to satisfy a requirement condition of achieving a throughput of 10 Gbps or more and making a delay in a wireless section 1 ms or less, research on various wireless technologies is being conducted.
[0003] In NR, a network architecture including 5GC (5G Core Network) corresponding to an EPC (Evolved Packet Core) which is a core network in a network architecture of LTE (Long Term Evolution) and NG-RAN (Next Generation-Radio Access Network) corresponding to an E-UTRAN (Evolved Universal Terrestrial Radio Access Network) which is a RAN (Radio Access Network) in a network architecture of LTE is being researched (for example, Non-Patent Literature 1 and Non-Patent Literature 2).
[0004] In addition, for example, an architecture of a Northbound interface between an NEF (Network Exposure Function) and an AF (Application Function) in a 5G system constituted by a CAPIF (Common API Framework) is being researched (for example, Non-Patent Literature 3 and Non-Patent Literature 4).
[0005] PRIOR ART DOCUMENTS
[0006] NON-PATENT LITERATURE
[0007] Non-Patent Literature 1: 3GPP TS 23.501 V18.0.0 (2022-12)
[0008] Non-Patent Literature 2: 3GPP TS 23.502 V18.0.0 (2022-12)
[0009] Non-Patent Literature 3: 3GPP TS 29.522 V17.8.0 (2022-12)
[0010] Non-Patent Literature 4: 3GPP TS 23.222 V18.0.0 (2022-12)
[0011] Non-Patent Literature 5: OpenID Specification “OpenID Connect Client-Initiated Backchannel Authentication Flow-Core 1.0”, September 1, 2021 SUMMARY
[0012] PROBLEMS TO BE SOLVED BY THE INVENTION
[0013] It is assumed that a communication carrier provides a service that lends a computing resource within a network and an execution environment on the computing resource to a subscriber. As one of use cases, there is a case where a browser started in an execution environment of 5GS that is not under the management or operation of a direct user wants to access a service of an AF (Application Function) and perform ID federation. However, this ID federation cannot be achieved in the existing 5GS.
[0014] The present invention was made in view of the above problems, and aims to perform an authentication process with an execution environment on a network as an RP (Relying party).
[0015] MEANS FOR SOLVING THE PROBLEMS
[0016] According to the disclosed technology, a network node is provided, which has a reception section that receives a back channel authentication request from a network node having a function related to a computing resource, and a transmission section that performs an inquiry to a User Data Repository (UDR) for determining a user based on an identifier included in the back channel authentication request, the transmission section transmitting a web push authentication request to a terminal of the determined user, the reception section receiving a response of the web push authentication request from the terminal, and the transmission section transmitting success of the back channel authentication request to the network node.
[0017] EFFECTS OF THE INVENTION
[0018] According to the disclosed technology, an execution environment on a network is able to perform an authentication process as a RP (Relying party). BRIEF DESCRIPTION OF DRAWINGS
[0019] Figure 1 is a diagram for explaining an example of a communication system.
[0020] Figure 2 is a diagram for explaining an example of a communication system in a roaming environment.
[0021] Figure 3 is a timing chart for explaining an example of a CRMF session establishment process in an embodiment of the present application.
[0022] Figure 4 is a timing chart for explaining an example of a CRMF session change process in an embodiment of the present application.
[0023] Figure 5 is a timing chart for explaining an example of a service request process in an embodiment of the present application.
[0024] Figure 6 is a timing chart for explaining an example of a CRMF session release process in an embodiment of the present application.
[0025] Figure 7 is a diagram for explaining an example of an API call in an embodiment of the present application.
[0026] Figure 8 is a diagram showing an example of an authentication process in an embodiment of the present application.
[0027] Figure 9 is a timing chart for explaining an example of an authentication process in an embodiment of the present application.
[0028] Figure 10 is a diagram showing an example of a functional structure of a base station 10 in an embodiment of the present application.
[0029] Figure 11 is a diagram showing an example of a functional structure of a terminal 20 in an embodiment of the present application.
[0030] Figure 12 is a diagram showing an example of a hardware structure of the base station 10 and the terminal 20 in an embodiment of the present application.
[0031] Figure 13 is a diagram showing an example of a structure of a vehicle 2001 in an embodiment of the present application. DETAILED DESCRIPTION
[0032] Hereinafter, an embodiment of the present application will be described with reference to the drawings. In addition, the embodiment described below is only an example, and the embodiment to which the present application is applied is not limited to the embodiment below.
[0033] In the operation of the wireless communication system in the embodiment of the present application, a prior art is appropriately used. The prior art is, for example, the existing LTE, but is not limited to the existing LTE. In addition, unless otherwise specified, the term "LTE" used in this specification has a broad meaning including LTE-Advanced and LTE-Advanced and later (for example, NR) or a wireless LAN (Local Area Network: LAN) in addition to the existing LTE.
[0034] In addition, in the embodiment of the present application, the wireless parameters and the like are "configured" to be "pre-configured" to a predetermined value, or are configured to be configured from the wireless parameters notified from the network node 30 or the terminal 20.
[0035] Figure 1 is a diagram for explaining an example of a communication system. As shown in Figure 1 , the communication system is configured of a UE as the terminal 20, and a plurality of network nodes 30. Hereinafter, one network node 30 is assumed to correspond to each function, but a plurality of functions can be implemented by one network node 30, and one function can be implemented by a plurality of network nodes 30. In addition, the "connection" described below can be a logical connection, or a physical connection.
[0036] The RAN (Radio Access Network) is a network node 30 having a radio access function, and can include a base station 10, and is connected to a UE, an AMF (Access and Mobility Management Function), and a UPF (User plane function). The AMF is a network node 30 having a function of terminating a RAN interface, a function of terminating a NAS (Non-Access Stratum), a function of registration management, a function of connection management, a function of reachability management, a function of mobility management, and the like. The UPF is a network node 30 having a function of a PDU (Protocol Data Unit) session point to the outside, a function of packet routing and forwarding, a function of QoS (Quality of Service) processing of a user plane, and the like, and is connected to a DN (Data Network). The UPF and the DN constitute a network slice. In the wireless communication network in the embodiment of the present application, a plurality of network slices can be constructed.
[0037] The AMF is connected with the UE, the RAN, the SMF (Session Management function), the NSSF (Network Slice Selection Function), the NEF (Network Exposure Function), the NRF (Network Repository Function), the UDM (Unified Data Management), the AUSF (Authentication Server Function), the PCF (Policy Control Function), and the AF (Application Function). The AMF, the SMF, the NSSF, the NEF, the NRF, the UDM, the AUSF, the PCF, and the AF are network nodes 30 that are connected with each other via interfaces based on respective services, that is, Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.
[0038] The SMF is a network node 30 that has functions of session management, IP (Internet Protocol) address allocation and management of the UE, a DHCP (Dynamic Host Configuration Protocol) function, an ARP (Address Resolution Protocol) proxy, a roaming function, and the like. The NEF is a network node 30 that has a function of notifying capabilities and events to other NFs (Network Functions). The NSSF is a network node 30 that has functions of selection of a network slice to which the UE is connected, decision of permitted NSSAI (Network Slice Selection Assistance Information), decision of set NSSAI, decision of a set of AMFs to which the UE is connected, and the like. The PCF is a network node 30 that has a function of performing policy control of a network. The AF is a network node 30 that has a function of controlling an application server. The NRF is a network node 30 that has a function of discovering NF instances that provide services. The UDM is a network node 30 that manages subscriber data and authentication data. The UDM is connected with a UDR (User Data Repository) that holds the data.
[0039] Figure 2is a diagram for explaining an example of a communication system in a roaming environment. As shown in Figure 2 The network is composed of a UE that is a terminal 20, and a plurality of network nodes 30. Hereinafter, one network node 30 corresponds to each function, but one network node 30 can implement a plurality of functions, and a plurality of network nodes 30 can implement one function. In addition, the "connection" described below can be a logical connection, or a physical connection.
[0040] The RAN is a network node 30 having a radio access function, and is connected to the UE, the AMF, and the UPF. The AMF is a network node 30 having a function of terminating a RAN interface, terminating a NAS, registration management, connection management, reachability management, mobility management, and the like. The UPF is a network node 30 having a function of being a PDU session point to the outside, routing and forwarding of packets, QoS handling of a user plane, and the like, and is interconnected with a DN. The UPF and the DN constitute a network slice. In the wireless communication network of the embodiment of the present application, a plurality of network slices are constructed.
[0041] The AMF is connected to the UE, the RAN, the SMF, the NSSF, the NEF, the NRF, the UDM, the AUSF, the PCF, the AF, and the SEPP (Security Edge Protection Proxy). The AMF, the SMF, the NSSF, the NEF, the NRF, the UDM, the AUSF, the PCF, and the AF are network nodes 30 that are connected to each other via interfaces Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf based on respective services.
[0042] The SMF is a network node 30 having a function of session management, IP address allocation and management of the UE, DHCP function, ARP proxy, roaming function, and the like. The NEF is a network node 30 having a function of notifying capabilities and events to other NFs. The NSSF is a network node 30 having a function of selecting a network slice to which the UE is connected, deciding allowed NSSAI, deciding set NSSAI, deciding a set of AMFs to which the UE is connected, and the like. The PCF is a network node 30 having a function of performing policy control of a network. The AF is a network node 30 having a function of controlling an application server. The NRF is a network node 30 having a function of discovering a service-providing NF instance. The SEPP is a non-transparent proxy that filters control plane messages between PLMNs (Public Land Mobile Networks). Figure 2 The vSEPP shown is a SEPP in a visited network, and the hSEPP is a SEPP in a home network.
[0043] As shown inFigure 2 As illustrated, the UE is in a roaming environment connected with a RAN and an AMF in a VPLMN (Visited PLMN: Visited Public Land Mobile Network). The VPLMN and the HPLMN (Home PLMN: Home Public Land Mobile Network) are connected via a vSEPP and a hSEPP. The UE can communicate with a UDM of the HPLMN via the AMF of the VPLMN, for example.
[0044] Here, in several use cases of 5G Advanced / 6G, there are common requirements conditions illustrated in 1) and 2) below.
[0045] 1) A communication operator provides a service that lends a computing resource within a network and an execution environment on the computing resource to a subscriber. In a case where a cloud environment is presupposed, it can be equivalent to the communication operator preparing a container (Container) for the subscriber. However, it is not presupposed to a specific technology related to the container.
[0046] 2) The subscriber uses the computing resource and the execution environment as a termination point of initiation / termination of communication related to the subscriber.
[0047] However, in the existing technology, it is difficult to achieve the above requirements conditions.
[0048] Therefore, a new function called UCRF (User Computing Resource Function) can also be introduced, in which the above container can be set per subscriber. Further, a new function called CRMF (Computing Resource Management Function) that controls the UCRF can also be introduced. In addition, the names of the UCRF and the CRMF are an example, and the function can also be called other names.
[0049] Regarding the procedures related to the session, the CRMF can be regarded as the SMF, and the UCRF can be regarded as the UPF. For example, 1) to 3) illustrated below can also be defined.
[0050] 1) A CRMF session establishment procedure, a CRMF session change procedure, and a CRMF session release procedure similar to the procedures related to the PDU session can be defined between the UE-CRMF.
[0051] 2) A UCRF session establishment procedure, a UCRF session change procedure, and a UCRF session release procedure similar to the procedures related to the PFCP (Packet Forwarding Control Protocol) session can be defined between the CRMF-UCRF.
[0052] 3) A service request procedure for activating a deactivation container can be defined.
[0053] Figure 3 is a timing chart for explaining an example of a CRMF session establishment procedure in the embodiment of the present application. In step S101, the UE 20 transmits a CRMF session establishment request to the AMF 30A. The UE 20 can set a requested resource capability capacity in the CRMF session establishment request, the requested resource capability capacity indicating a CRMF session ID of the terminal in the AMF and a capacity of a computing resource requested. Further, the "capacity of a computing resource" described below can include, in addition to the capacity of the computing resource, an execution environment, capability, and the like.
[0054] In next step S102, the AMF 30A transmits a CRMF session establishment request to the CRMF 30B. The AMF 30A can include the CRMF session ID set by the UE 20 and the requested resource capability capacity set by the UE 20 in the CRMF session establishment request.
[0055] In next step S103, the CRMF 30B transmits a subscriber information confirmation to the UDM 30E in order to acquire subscriber information. In next step S104, the UDM 30E transmits a subscriber information response to the CRMF 30B. The CRMF 30B determines whether to permit the CRMF session establishment request from the UE 20 based on the acquired subscriber information. In a case where the CRMF session establishment request from the UE 20 is permitted through the determination, step S105 can be entered. On the other hand, in a case where the CRMF session establishment request from the UE 20 is not permitted through the determination, the CRMF 30B can transmit a response indicating that the CRMF session establishment request is rejected to the AMF 30A. The AMF 30A can transmit the response to the UE 20.
[0056] In next step S105, the CRMF 30B transmits the requested resource capability capacity acquired through the CRMF session establishment request to the PCF 30D. In next step S106, the PCF 30D decides a capacity of a computing resource to be provided to the UE 20 according to information included in the acquired requested resource capability capacity and a policy of a communication carrier, and transmits information including the decided capacity as a requested resource capability response to the CRMF 30B.
[0057] For example, the PCF 30D can decide to provide the UE 20 with a computing resource of the same capacity as the requested resource capability capacity, can decide to provide the UE 20 with a computing resource of a capacity smaller than the requested resource capability capacity, or can decide to provide the UE 20 with a computing resource of a capacity exceeding the requested resource capability capacity.
[0058] In the next step S107, the CRMF 30B selects the UCRF 30C. For example, the CRMF 30B can select the UCRF 30C close to the UE 20 based on the location information of the UE 20. In the next step S108, the CRMF 30B transmits a UCRF session establishment request to the UCRF 30C. The CRMF 30B sets a computing resource generation request in the UCRF session establishment request. The computing resource generation request can be set based on the requested resource capability capacity, or can contain information indicating the capacity of the computing resource based on the requested resource capability response obtained from the PCF 30D.
[0059] In the next step S109, the UCRF 30C sets a container. The container can also be set in accordance with the capacity of the computing resource obtained from the CRMF 30B. In the next step S110, the UCRF 30C transmits a UCRF session establishment response to the CRMF 30B.
[0060] In the next step S111, the CRMF 30B transmits a CRMF session establishment response to the AMF 30A. In the next step S112, the AMF 30A transmits a CRMF session establishment response to the UE 20.
[0061] In addition, in step S113, the UCRF 30C can also obtain an external communication IP address from an interface with a DN, for example. In step S114, the UCRF 30C can start an application within the container. The application can be a communication application that uses the obtained external communication IP address.
[0062] After step S114, the UE 20 can accept the service of the communication carrier using the container set in the UCRF 30C.
[0063] Figure 4 is a timing chart for explaining an example of a CRMF session change procedure in the embodiment of the present application. In step S200, it is assumed that the CRMF session is in an established state.
[0064] In step S201, the UE 20 specifies a CRMF session ID and transmits a CRMF session change request to the AMF 30A. The UE 20 can set a change resource capability capacity in the CRMF session change request, which is information requesting a change of the capacity, capability, execution environment, and the like of the computing resource of the container to be changed.
[0065] In the next step S202, the AMF 30A transmits a CRMF session change request to the CRMF 30B. The AMF 30A can include the CRMF session ID set by the UE 20 and the change resource capability capacity set by the UE 20 in the CRMF session change request.
[0066] In the next step S203, the CRMF 30B determines whether to allow the CRMF session change request from the UE 20, based on the subscriber information that the node has acquired. In a case where the CRMF session change request from the UE 20 is allowed through the determination, it is possible to proceed to step S204.
[0067] In the next step S204, the CRMF 30B transmits the change resource capability capacity acquired through the CRMF session change request to the PCF 30D. In the next step S205, the PCF 30D decides the capacity of the computing resource to be provided to the UE 20, based on the information included in the acquired change resource capability capacity and the policy of the communication carrier, and transmits information including the decided capacity to the CRMF 30B as a change resource capability response.
[0068] For example, the PCF 30D can decide to provide the UE 20 with the computing resource of the same capacity as the change resource capability capacity, can decide to provide the UE 20 with the computing resource of a capacity smaller than the change resource capability capacity, or can decide to provide the UE 20 with the computing resource of a capacity exceeding the change resource capability capacity.
[0069] In the next step S206, the CRMF 30B transmits a UCRF session change request to the UCRF 30C. The CRMF 30B sets a computing resource change request in the UCRF session change request. The computing resource change request can be set based on the change resource capability capacity, or can include information indicating the capacity of the computing resource based on the change resource capability response acquired from the PCF 30D.
[0070] In the next step S207, the UCRF 30C changes the container based on the UCRF session change request. The container can also be changed according to the capacity of the computing resource acquired from the CRMF 30B. In the next step S208, the UCRF 30C transmits a UCRF session change response to the CRMF 30B.
[0071] In the next step S209, the CRMF 30B transmits a CRMF session change response to the AMF 30A. In the next step S210, the AMF 30A transmits the CRMF session change response to the UE 20.
[0072] Figure 5 is a timing chart for explaining an example of a service request procedure in the embodiment of the present application. In step S300, it is assumed that the CRMF session is in an established state.
[0073] In step S301, the UCRF 30C detects container non-use. In next step S302, the UCRF 30C deactivates the container. The UCRF 30C can also deactivate the container based on a policy of the communication carrier when the container is not used for a certain period.
[0074] In step S303, the UE 20 specifies the CRMF session ID in the list of containers to be activated and transmits a service request to the AMF 30A. In next step S304, the AMF 30A transmits a context update request including an information element (IE) indicating the container state set to "activating" to the CRMF 30B. In addition, the value of the information element indicating the container state can be set to "activating", "activated", or "deactivated".
[0075] In next step S305, the CRMF 30B transmits a UCRF session change request to the UCRF 30C. The CRMF 30B sets a computing resource change request in the UCRF session change request. The CRMF 30B can set an information element indicating the container state acquired from the context update request in the computing resource change request.
[0076] In next step S306, the UCRF 30C activates the container based on the UCRF session change request. In next step S307, the UCRF 30C transmits a UCRF session change response to the CRMF 30B.
[0077] In next step S308, the CRMF 30B transmits a context update response to the AMF 30A. In next step S309, the AMF 30A transmits a service response to the UE 20.
[0078] Figure 6 is a timing chart for explaining an example of a CRMF session release procedure in the embodiment of the present application. In step S400, it is assumed that the CRMF session is in an established state.
[0079] In step S401, the UE 20 specifies the CRMF session ID and transmits a CRMF session release request to the AMF 30A. In next step S402, the AMF 30A transmits a CRMF session release request to the CRMF 30B.
[0080] In the next step S403, the CRMF 30B transmits a UCRF session release request to release the UCRF session corresponding to the CRMF session specified by the received CRMF session release request to the UCRF 30C. In the next step S404, the UCRF 30C releases the corresponding container based on the received UCRF session release request. In the next step S405, the UCRF 30C transmits a UCRF session release response to the CRMF 30B.
[0081] In the next step S406, the CRMF 30B transmits a CRMF session release response to the AMF 30A. In the next step S407, the AMF 30A transmits a CRMF session release response to the UE 20.
[0082] Figure 7 is a diagram for explaining an example of an API (Application Programming Interface) call in the embodiment of the present application. As shown in Figure 7 , the CAPIF core function 30F receives pre-registration of an application transmitted from an API invoker 20A, authenticates and authorizes a third-party application. The API exposing function 30G receives an API call of a core network transmitted from the API invoker, and exposes the API to an external application that is authenticated and authorized.
[0083] Further, as shown in Figure 7 , a resource owner client 20B can authorize an API call based on a core network via an authorization function 30J. The authorization function 30J is registered in the API exposing function 30G. After the registration, at necessary timing, the API exposing function 30G can access the authorization function 30J to confirm whether or not the API call is possible.
[0084] Further, the API invoker 20A is, for example, an application on a terminal, and can have a capability to support authentication by providing an identifier of the API invoker, a capability to support mutual authentication with the CAPIF core function 30F, a capability to acquire authentication at the time of accessing a service API, a capability to discover information related to a service API, and a capability to call a service API.
[0085] Further, the CAPIF core function 30F can also have, for example, a capability to support mutual authentication with the API invocation source 20A, a capability to authenticate the API invocation source 20A at the time of access to the service API, a capability to disclose and accumulate information about the service API, a capability to perform access control of the service API based on a policy set by the PLMN operator, a capability to perform recording of a log of invocation of the service API and to provide the log of invocation of the service API to an approving authority, a capability to perform charging based on the log of invocation of the service API, a capability to monitor invocation of the service API, a capability to perform addition and deletion of the API invocation source 20A, a capability to support access to a log for monitoring of illegal use, for example, a capability to disclose information about the service API together with other CAPIF core functions based on connection between CAPIFs.
[0086] Further, the API providing function 30G, the API publishing function 30H, and the API management function 30I can also be functions or nodes belonging to a certain API provider.
[0087] Further, the API providing function 30G is a provider that provides the service API and can have a capability to authenticate the API invocation source 20A based on information provided from the CAPIF core function 30F, a capability to verify authentication provided from the CAPIF core function 30F, and a capability to record a log of invocation of the service API in the CAPIF core function 30F.
[0088] Further, the API publishing function 30H can also have a capability to disclose information about the service API possessed by the API provider to the CAPIF core function 30F.
[0089] Further, the API management function 30I is a function that causes the API provider to perform management of the service API and can have a capability to monitor a log of invocation of the service API received from the CAPIF core function 30F, a capability to monitor events reported from the CAPIF core function 30F, a capability to set a policy of the API provider to the CAPIF core function 30F, a capability to monitor a state of the service API, a capability to add and delete the API invocation source 20A, and a capability to register and maintain registration information of the API provider to the CAPIF core function 30F.
[0090] Furthermore, the CAPIF core function 30F, the API providing function 30G, the API public function 30H, and the API management function 30I can each be configured as a network node 30. For example, the API providing function 30G, the API public function 30H, and the API management function 30I can also be configured as one network node 30. Furthermore, the API call source 20A, the resource holder client 20B, and the authorization function 30J can be, for example, a communication device such as a terminal or a server, or other communication devices.
[0091] Imagine a service where a telecommunications carrier, like the aforementioned UCRF and CRMF, provides subscribers with computing resources within their network and the execution environment running on those resources. One use case involves a browser launched within a 5GS execution environment not under the direct management or operation of the user, attempting to access AF (Application Function) services and perform ID collaboration. However, this ID collaboration is not possible with existing 5GS.
[0092] Therefore, it's possible to use a browser launched on the UCRF as an RP (Relying Party) and perform the following extensions to enable the OIDC-CIBA (Open ID Connect Client-Initiated Backchannel Authentication) sequence (see Non-Patent Document 5) within the CAPIF core and authorization functions. An identifier is defined in the UCRF or a container within the UCRF. The browser within the UCRF includes this identifier in the login_hint parameter of the OIDC-CIBA and sends it to the CAPIF authorization function.
[0093] Figure 8 This is a diagram showing an example of an authentication process in an embodiment of the present invention. Figure 8 An example of the OIDC-CIBA process with UCRF as the RP is shown. Figure 8 The process can also be the process of CIBA polling mode (Poll mode). Figure 8The browser inside the UCRF 30C includes a client notification EP (End point). The CAPIF authorization function 30J includes a backchannel authentication EP. The CAPIF core function 30F includes a token EP and an introspection EP. The user terminal 20 can be an Authentication Device. The browser inside the UCRF 30C can be a Consumption Device, a Client, and / or a Relying Party.
[0094] The browser inside the UCRF 30C sends a backchannel authentication request (HTTP POST) including an identifier of the UCRF to the backchannel authentication EP of the CAPIF authorization function 30J. Next, the CAPIF authorization function 30J authenticates the client and determines the user from the identifier. Next, the CAPIF authorization function 30J sends a request for authentication and authorization of the user to the user terminal 20. Next, the user sends a response to the request for authentication and authorization from the user terminal 20 to the CAPIF authorization function 30J.
[0095] Next, the backchannel authentication EP of the CAPIF authorization function 30J sends an ACK (auth_req_id, etc.) of success of the authentication request to the browser inside the UCRF 30C. Subsequently, the browser inside the UCRF 30C sends a token request including the auth_req_id to the token EP of the CAPIF core function 30F. Next, the CAPIF core function 30F acquires the authentication time and the authentication method from the CAPIF authorization function 30J based on the auth_req_id. Next, the token EP of the CAPIF core function 30F sends a token response to the browser inside the UCRF 30C.
[0096] Next, the browser inside the UCRF 30C sends the token and calls an API to the third-party service server 30K. Next, the third-party service server 30K performs signature and token verification with the introspection EP of the CAPIF core function 30F. Next, the third-party service server 30K provides a resource to the browser inside the UCRF 30C. The browser inside the UCRF 30C acquires the resource from the third-party service server 30K. The third-party service server can also be referred to as an external service server.
[0097] Figure 9is a timing chart for explaining an example of an authentication procedure in the embodiment of the present application. In step S501, a browser inside the UCRF 30C transmits a back channel authentication request to the CAPIF authorization function 30J. This back channel authentication request contains an identifier of the UCRF or the container in use as a login_hint parameter. In the next step S502, the CAPIF authorization function 30J inquires the UDR 30E based on the received identifier, determines the SUPI (Subscription Permanent Identifier) of the user terminal 20.
[0098] In the next step S503, the CAPIF authorization function 30J transmits a Web push authentication request to the user's terminal 20 determined. In the next step S504, the user responds to the authentication request, and the CAPIF authorization function 30J receives the response. In the next step S505, the CAPIF authorization function 30J transmits a success ACK of the back channel authentication request containing the auth_req_id to the browser inside the UCRF 30C.
[0099] In the next step S506, the browser inside the UCRF 30C transmits a token request containing the auth_req_id to the CAPIF core function 30F. In the next step S507, the CAPIF core function 30F accesses the CAPIF authorization function 30J using the auth_req_id, and acquires the authentication enforcement time and the authentication method. The authentication enforcement time and the authentication method can also be the authentication enforcement time and the authentication method related to the back channel authentication request.
[0100] In the next step S508, the CAPIF core function 30F generates an ID token and an access token based on the acquired authentication enforcement time and authentication method, and transmits them to the browser inside the UCRF 30C. In the next step S509, the browser inside the UCRF 30C transmits the ID token and the access token to the third party service server 30K, and invokes an API.
[0101] In the next step S510, the third party service server 30K and the CAPIF core function 30F verify the tokens. The verification can also be a verification of whether they correspond to the ID token and the access token generated in step S508. The CAPIF core function 30F can also transmit the verification result of the tokens to the third party service server 30K.
[0102] In the next step S511, the third-party service server 30K provides the resource to the browser inside the UCRF 30C. The browser inside the UCRF 30C acquires the resource from the third-party service server 30K.
[0103] Here, the CAPIF core function 30F acts as an IdP (Identify Provider) with respect to the third-party service server 30K outside the 5GS.
[0104] According to the above-described embodiments, the browser launched in the execution environment of the 5GS not under the management or operation of the direct user can access the service of the AF (Application Function) and perform the ID collaboration.
[0105] That is, it is possible to perform the authentication process with the execution environment on the network as the RP (Relying party).
[0106] (Structure of apparatus)
[0107] Next, a functional structure example of the base station 10, the network node 30, and the terminal 20 that execute the processes and actions described above will be described. The base station 10, the network node 30, and the terminal 20 include the functions of the above-described embodiments. However, the base station 10, the network node 30, and the terminal 20 can also have only a part of the functions of the embodiments, respectively.
[0108] <Base station 10 and network node 30>
[0109] Figure 10 is a diagram showing an example of the functional structure of the base station 10. As shown in Figure 10 , the base station 10 has a transmission section 110, a reception section 120, a setting section 130, and a control section 140. Figure 10 The functional structure shown in the drawing is only an example. As long as the actions of the embodiments of the present application can be implemented, the functional division and the names of the functional sections can be arbitrary. The network node 30 can have the same functional structure as the base station 10. In addition, the network node 30 having a plurality of different functions in the system architecture can also be composed of a plurality of network nodes 30 separated by functions.
[0110] The transmission section 110 includes a function of generating a signal to be transmitted to the terminal 20 or another network node 30 and transmitting the signal through a wire or wirelessly. The reception section 120 includes a function of receiving various signals transmitted from the terminal 20 or another network node 30 and acquiring, for example, higher layer information from the received signals.
[0111] The setting section 130 stores setting information set in advance and various setting information transmitted to the terminal 20 in a storage device, and reads out from the storage device as necessary. The content of the setting information is, for example, settings relating to the computing resource and the authentication procedure, and the like.
[0112] As explained in the embodiments, the control section 140 performs processing relating to the computing resource and the authentication procedure in the network. In addition, the control section 140 performs processing relating to communication with the terminal 20. The functional section relating to signal transmission in the control section 140 can be included in the transmission section 110, and the functional section relating to signal reception in the control section 140 can be included in the reception section 120.
[0113] <terminal 20>
[0114] Figure 11 is a diagram showing an example of the functional structure of the terminal 20. As shown in Figure 11 , the terminal 20 has a transmission section 210, a reception section 220, a setting section 230, and a control section 240. Figure 11 The functional structure shown in the diagram is merely an example. The functional division and the names of the functional sections can be arbitrary as long as the actions of the embodiments of the present application can be implemented.
[0115] The transmission section 210 generates a transmission signal from transmission data, and transmits the transmission signal in a wireless manner. The reception section 220 receives various signals in a wireless manner, and acquires signals of higher layers from the received physical layer signals. In addition, the reception section 220 has a function of receiving an NR-PSS, an NR-SSS, an NR-PBCH, a DL / UL control signal, or a reference signal, and the like transmitted from the network node 30.
[0116] The setting section 230 stores various setting information received by the reception section 220 from the network node 30 in a storage device, and reads out from the storage device as necessary. In addition, the setting section 230 also stores setting information set in advance. The content of the setting information is, for example, settings relating to the computing resource and the authentication procedure, and the like.
[0117] As explained in the embodiments, the control section 240 performs processing relating to connection control to the network and the network slice. In addition, the control section 240 performs processing relating to the authentication procedure. The transmission section 210 can include a functional section relating to signal transmission in the authentication control section 240, and the reception section 220 can include a functional section relating to signal reception in the control section 240.
[0118] (hardware structure)
[0119] The block diagrams used in the explanation of the above embodiments Figure 10 and Figure 11) show blocks in units of functions. These functional blocks (structural units) are realized by any combination of at least one of hardware and software. Further, the method of realizing each functional block is not particularly limited. That is, each functional block can be realized by one device which is physically or logically integrated, or can be realized by two or more devices which are physically or logically separated and connected directly or indirectly (for example, using wire, wireless, or the like). Each functional block can also be realized by combining software in one device or in the plurality of devices.
[0120] The function has judgment, decision, determination, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, solution, selection, election, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, assigning, and the like, but is not limited to these. For example, a functional block (structural unit) which functions as a transmission function is called a transmitting unit or a transmitter. In any case, as described above, the method of realization is not particularly limited.
[0121] For example, the network node 30, the terminal 20, and the like in one embodiment of the present disclosure can also function as a computer which performs processing of the wireless communication method of the present disclosure. Figure 12 is a diagram showing an example of a hardware structure of the base station 10 and the terminal 20 in one embodiment of the present disclosure. The network node 30 can have the same hardware structure as the base station 10. The above-described base station 10 and terminal 20 can also be configured as a computer device which physically includes the processor 1001, the storage 1002, the auxiliary storage 1003, the communication device 1004, the input device 1005, the output device 1006, the bus 1007, and the like.
[0122] In addition, in the following description, the expression "device" can be replaced with "circuit", "device", "unit", and the like. The hardware structure of the base station 10 and the terminal 20 can be configured to include one or more of each device illustrated, or can be configured not to include a part of the device.
[0123] Each function in the base station 10 and the terminal 20 is realized by reading a predetermined software (program) into a hardware such as the processor 1001, the storage 1002, and causing the processor 1001 to perform an operation, and controlling at least one of communication of the communication device 1004 or reading and writing of data in the storage 1002 and the auxiliary storage 1003.
[0124] The processor 1001 controls the entire computer by, for example, causing an operating system to operate. The processor 1001 can also be constituted by a central processing device (CPU: Central Processing Unit) including an interface with a peripheral device, a control device, an arithmetic device, a register, and the like. For example, the control section 140, the control section 240, and the like described above can also be realized by the processor 1001.
[0125] Further, the processor 1001 reads a program (program code), a software module, or data, and the like from at least one of the auxiliary storage 1003 and the communication device 1004 to the storage 1002, and performs various processes based on the same. As the program, a program that causes a computer to perform at least a part of the operations described in the above-described embodiments is used. For example, Figure 10 The control section 140 of the base station 10 illustrated can also be realized by a control program stored in the storage 1002 and operating in the processor 1001. Also, for example, Figure 11 The control section 240 of the terminal 20 illustrated can also be realized by a control program stored in the storage 1002 and operating in the processor 1001. Although it is described that the above-described various processes are performed by one processor 1001, the above-described various processes can also be performed simultaneously or sequentially by two or more processors 1001. The processor 1001 can also be realized by one or more chips. In addition, the program can also be transmitted from a network via a telecommunication line.
[0126] The storage 1002 is a computer-readable recording medium, and can also be constituted by at least one of a ROM (Read Only Memory), an EPROM (Erasable Programmable ROM), an EEPROM (Electrically Erasable Programmable ROM), a RAM (Random Access Memory), and the like. The storage 1002 can also be referred to as a register, a cache, a main storage (main storage device), and the like. The storage 1002 can hold a program (program code), a software module, and the like that can be executed in order to implement a communication method related to one embodiment of the present disclosure.
[0127] The auxiliary storage device 1003 is a computer-readable recording medium, and can be constituted by at least one of, for example, an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (for example, a compact disk, a digital versatile disk, a Blu-ray (registered trademark) disk, a smart media, a flash memory (for example, a card, a stick, a Key drive), a Floppy (registered trademark) disk, a magnetic stripe, and the like. The above-described storage medium can be, for example, a database, a server, and other appropriate medium including at least one of the storage device 1002 and the auxiliary storage device 1003.
[0128] The communication device 1004 is hardware (a transceiver device) for performing communication between computers via at least one of a wired network and a wireless network, and can also be referred to as a network device, a network controller, a network card, a communication module, and the like. The communication device 1004 can also be constituted to include, for example, a high-frequency switch, a duplexer, a filter, a frequency synthesizer, and the like, to realize at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, a transceiving antenna, an amplification section, a transceiving section, a transmission path interface, and the like can also be realized by the communication device 1004. The transceiving section can also be realized by a transmission section and a reception section, which are physically or logically separated.
[0129] The input device 1005 is an input device (for example, a keyboard, a mouse, a microphone, a switch, a button, a sensor, and the like) that receives input from the outside. The output device 1006 is an output device (for example, a display, a speaker, an LED lamp, and the like) that performs output to the outside. In addition, the input device 1005 and the output device 1006 can also be integrally constituted (for example, a touch panel).
[0130] Furthermore, the processor 1001 and each of the devices such as the storage device 1002 are connected by a bus 1007 for communicating information. The bus 1007 can be constituted by a single bus, or can be constituted by different buses between the devices.
[0131] Furthermore, the base station 10 and the terminal 20 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA). Part or all of each functional block may be implemented using this hardware. For example, the processor 1001 may be implemented using at least one of these hardware components.
[0132] Figure 13 2001 shows a structural example of a vehicle. Figure 13 As shown, vehicle 2001 includes a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a shift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021 to 2029, an information service unit 2012, and a communication module 2013. The various forms and embodiments described in this disclosure may also be applied to a communication device mounted on vehicle 2001, such as communication module 2013.
[0133] The driving unit 2002 is composed of, for example, an engine, a motor, or a hybrid of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also referred to as a steering wheel) and is configured to steer at least one of the front wheels and the rear wheels based on the user's operation of the steering wheel.
[0134] Electronic control unit 2010 is composed of a microprocessor 2031, memory (ROM, RAM) 2032, and a communication port (IO port) 2033. Signals from various sensors 2021 to 2029 included in vehicle 2001 are input to electronic control unit 2010. Electronic control unit 2010 may also be referred to as an ECU (Electronic Control Unit).
[0135] As signals from various sensors 2021 to 2029, there are a current signal from a current sensor 2021 that monitors a current of a motor, a rotational speed signal of a front wheel and a rear wheel acquired by a rotational speed sensor 2022, a pneumatic pressure signal of the front wheel and the rear wheel acquired by a pneumatic pressure sensor 2023, a vehicle speed signal acquired by a vehicle speed sensor 2024, an acceleration signal acquired by an acceleration sensor 2025, a depression amount signal of an accelerator pedal acquired by an accelerator pedal sensor 2029, a depression amount signal of a brake pedal acquired by a brake pedal sensor 2026, an operation signal of a shift lever acquired by a shift lever sensor 2027, a detection signal for detecting an obstacle, a vehicle, a pedestrian, and the like acquired by an object detection sensor 2028, and the like.
[0136] The information service section 2012 is constituted by various devices for providing various information such as driving information, traffic information, entertainment information, and the like, and one or more ECUs that control these devices, such as a car navigation system, an audio system, a speaker, a television, a radio, and the like. The information service section 2012 provides various multimedia information and multimedia services to an occupant of the vehicle 2001 using information acquired from an external device via the communication module 2013 or the like.
[0137] The drive assist system section 2030 is constituted by various devices for providing a function of preventing an accident from occurring or reducing a driving load on a driver, such as a millimeter wave radar, a LiDAR (Light Detection and Ranging), a camera, a positioner for positioning (for example, a GNSS or the like), map information (for example, a high-definition (HD) map, an autonomous vehicle (AV) map, or the like), a gyro system (for example, an IMU (Inertial Measurement Unit), an INS (Inertial Navigation System), or the like), an AI (Artificial Intelligence) chip, an AI processor, and one or more ECUs that control these devices. In addition, the drive assist system section 2030 transmits and receives various information via the communication module 2013, and realizes a drive assist function or an autonomous driving function.
[0138] The communication module 2013 is capable of communicating with the microprocessor 2031 and the constituent elements of the vehicle 2001 via a communication port. For example, the communication module 2013 transmits and receives data between the microprocessor 2031 and the memory (ROM, RAM) 2032, the sensors 2021 to 2029, and the like in the drive section 2002, the steering section 2003, the accelerator pedal 2004, the brake pedal 2005, the shift lever 2006, the front wheel 2007, the rear wheel 2008, the axle 2009, the electronic control section 2010 possessed by the vehicle 2001 via the communication port 2033.
[0139] The communication module 2013, which can be controlled by the microprocessor 2031 of the electronic control section 2010, is a communication device that can communicate with an external device. For example, various information is transmitted and received between the external device via wireless communication. The communication module 2013 can be located inside or outside the electronic control section 2010. The external device can also be a base station, a mobile station, or the like, for example.
[0140] The communication module 2013 transmits the current signal from the current sensor input to the electronic control section 2010 to the external device via wireless communication. In addition, the communication module 2013 transmits the rotational speed signal of the front wheels and the rear wheels acquired by the rotational speed sensor 2022, the air pressure signal of the front wheels and the rear wheels acquired by the air pressure sensor 2023, the vehicle speed signal acquired by the vehicle speed sensor 2024, the acceleration signal acquired by the acceleration sensor 2025, the amount of depression signal of the accelerator pedal acquired by the accelerator pedal sensor 2029, the amount of depression signal of the brake pedal acquired by the brake pedal sensor 2026, the operation signal of the shift lever acquired by the shift lever sensor 2027, the detection signal for detecting obstacles, vehicles, pedestrians, and the like acquired by the object detection sensor 2028, and the like, which are input to the electronic control section 2010, to the external device via wireless communication.
[0141] The communication module 2013 receives various information (traffic information, signal information, inter-vehicle information, and the like) transmitted from the external device and displays it on the information service section 2012 provided in the vehicle 2001. In addition, the communication module 2013 stores various information received from the external device in the memory 2032 that can be used by the microprocessor 2031. The microprocessor 2031 can also control the drive section 2002, the steering section 2003, the accelerator pedal 2004, the brake pedal 2005, the shift lever 2006, the front wheels 2007, the rear wheels 2008, the axle 2009, the sensors 2021 to 2029, and the like provided in the vehicle 2001 on the basis of the information stored in the memory 2032.
[0142] (Summary of Embodiments)
[0143] As described above, according to the embodiment of the present application, there is provided a network node having a reception section that receives a backend channel authentication request from a network node having a function related to a computing resource, and a transmission section that performs an inquiry to a user data repository (UDR) for determining a user on the basis of an identifier included in the backend channel authentication request, the transmission section transmitting a web push authentication request to a terminal of the determined user, the reception section receiving a response of the web push authentication request from the terminal, and the transmission section transmitting a success of the backend channel authentication request to the network node.
[0144] According to the above structure, a browser launched in an execution environment of a 5GS not under the management or operation of a direct user can access a service of an AF (Application Function) and perform ID federation. That is, an authentication process can be performed with the execution environment on a network as an RP (Relying party).
[0145] The transmission section can also transmit the authentication enforcement time and the authentication method of the backend channel authentication request to a CAPIF (Common API Framework) core function. According to this structure, a browser launched in an execution environment of a 5GS not under the management or operation of a direct user can access a service of an AF (Application Function) and perform ID federation.
[0146] In addition, according to an embodiment of the present application, a network node is provided, which has a reception section that receives a token request from a network node having a function related to a computing resource, a control section that acquires an authentication enforcement time and an authentication method from a CAPIF (Common API Framework) authorization function and generates a token based on the authentication enforcement time and the authentication method, and a transmission section that transmits the token to the network node, the transmission section transmitting a verification result related to the token to an external service server.
[0147] According to the above structure, a browser launched in an execution environment of a 5GS not under the management or operation of a direct user can access a service of an AF (Application Function) and perform ID federation. That is, an authentication process can be performed with the execution environment on a network as an RP (Relying party).
[0148] In addition, according to an embodiment of the present application, a network node is provided, which has a transmission section that transmits a backend channel authentication request to a CAPIF (Common API Framework) authorization function, and a reception section that receives success of the backend channel authentication request from the CAPIF authorization function, the transmission section transmitting a token request to a CAPIF core function, the reception section receiving a token from the CAPIF core function, the transmission section transmitting the token to an external service server to invoke an API (Application Programming Interface), and the reception section acquiring a resource from the external service server.
[0149] According to the above structure, a browser launched in an execution environment of the 5GS that is not under the management or operation of a direct user can access a service of an AF (Application Function) and perform ID collaboration. That is, an authentication process can be performed with the execution environment on the network as an RP (Relying party).
[0150] Further, according to an embodiment of the present application, there is provided an authentication method, performed by a network node, comprising the steps of: receiving, from a network node having a function related to a computing resource, a backend channel authentication request; performing, based on an identifier included in the backend channel authentication request, a query of a user data repository (UDR) for a determined user; sending, to a terminal of the determined user, a web push authentication request; receiving, from the terminal, a response to the web push authentication request; and sending, to the network node, a success of the backend channel authentication request.
[0151] According to the above structure, a browser launched in an execution environment of the 5GS that is not under the management or operation of a direct user can access a service of an AF (Application Function) and perform ID collaboration. That is, an authentication process can be performed with the execution environment on the network as an RP (Relying party).
[0152] (Supplement to Embodiments)
[0153] The above describes embodiments of the present application, but the disclosed application is not limited to such embodiments, and those skilled in the art will understand various modifications, changes, alternatives, substitutions, and the like. Specific numerical examples are used to facilitate understanding of the application, but these numerical examples are only examples, and appropriate arbitrary values can be used unless otherwise specified. The items in the above description are not essential to the present application, and two or more of the items described in the items can be combined as needed, or the item can be applied to the item described in another item (as long as there is no contradiction). The boundaries of the functional blocks or processing blocks in the functional block diagram do not necessarily correspond to the boundaries of physical components. The actions of multiple functional blocks can be performed by one physical component, or the actions of one functional block can be performed by multiple physical components. The order of the processes described in the embodiments can be changed as long as there is no contradiction. The network node 30 and the terminal 20 are described using a functional block diagram for convenience of explanation of the processes, but such devices can also be implemented by hardware, software, or a combination thereof. Software that causes the processor of the network node 30 to act in accordance with the embodiments of the present application and software that causes the processor of the terminal 20 to act in accordance with the embodiments of the present application can each be stored in a random access memory (RAM), a flash memory, a read only memory (ROM), an EPROM, an EEPROM, a register, a hard disk (HDD), a removable disk, a CD-ROM, a database, a server, and other appropriate arbitrary storage media.
[0154] Further, the notification of the information is not limited to the forms / embodiments described in the present disclosure, and other methods can be used. For example, the notification of the information can be implemented by physical layer signaling (e.g., DCI (Downlink Control Information), UCI (Uplink Control Information)), higher layer signaling (e.g., RRC (Radio Resource Control) signaling, MAC (Medium Access Control) signaling, broadcast information (MIB (Master Information Block), SIB (System Information Block)), other signals, or a combination thereof. Further, the RRC signaling can also be referred to as an RRC message, and for example, can be an RRC Connection Setup message, an RRC Connection Reconfiguration message, or the like.
[0155] The forms / embodiments described in the present disclosure can also be applied to at least one of systems utilizing LTE (Long Term Evolution), LTE-A (LTE-Advanced), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), FRA (Future Radio Access), NR (New Radio), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, UWB (Ultra-WideBand), Bluetooth (registered trademark), other appropriate systems, and next-generation systems extended therefrom. Furthermore, a plurality of systems (for example, a combination of at least one of LTE and LTE-A and 5G, and the like) can also be applied in combination.
[0156] The forms / embodiments described in this disclosure can also be applied to at least one of systems using LTE (Long Term Evolution), LTE-A (LTE-Advanced), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), 6th generation mobile communication system (6G), xth generation mobile communication system (xG) (xG (x is an integer, a fraction, etc.), FRA (Future Radio Access), NR (new Radio), new radio access (NX), future generation radio access (FX), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, UWB (Ultra-WideBand), Bluetooth (registered trademark), other appropriate systems, and next-generation systems extended, modified, created, and specified based on these systems. In addition, a plurality of systems (for example, at least one of LTE and LTE-A and 5G, etc.) can be combined and applied.
[0157] For the processes, timing, flow, etc. of the forms / embodiments described in this specification, the order can be changed without contradiction. For example, for the methods described in this disclosure, the elements of various steps are prompted using the order of the examples, but are not limited to the specific order prompted.
[0158] In the present specification, a certain action performed by the network node 30 is sometimes also performed by an upper node thereof, as appropriate. In a network constituted by one or a plurality of network nodes (network nodes) including the network node 30, it is obvious that various actions performed for communication with the terminal 20 can be performed by at least one of the network node 30 and other network nodes (for example, consider an MME or an S-GW or the like, but not limited to these) other than the network node 30. In the above, a case where the other network node than the network node 30 is one is exemplified, but the other network node can also be a combination of a plurality of other network nodes (for example, an MME and an S-GW).
[0159] Information or a signal and the like explained in the present disclosure can be output from a higher layer (or a lower layer) to a lower layer (or a higher layer). It can also be input or output via a plurality of network nodes.
[0160] Information and the like input or output can be saved in a certain location (for example, a memory), and can be managed using a management table. Information and the like input or output can be rewritten, updated, or appended. Information and the like output can also be deleted. Information and the like input can also be transmitted to other apparatuses.
[0161] Determination in the present disclosure can be performed by a value (0 or 1) represented by 1 bit, by a Boolean value (true or false), or by comparison of numerical values (for example, comparison with a predetermined value).
[0162] As for software, regardless of being called software, firmware, middleware, microcode, hardware description language, or by another name, it should be broadly interpreted as meaning a command, a command set, code, a code segment, program code, a program, a subprogram, a software module, an application, a software application, a software package, a routine, a sub routine, an object, an executable file, an execution thread, a procedure, a function, and the like.
[0163] In addition, software, commands, information, and the like can also be transmitted and received via a transmission medium. For example, in a case where software is transmitted from a web page, a server, or another remote source using at least one of wired technology (coaxial cable, optical fiber cable, twisted pair cable, digital subscriber line (DSL), and the like) and wireless technology (infrared rays, microwaves, and the like), at least one of these wired technology and wireless technology is included in the definition of the transmission medium.
[0164] The information, signals, and / or the like described in the present disclosure can be represented using various different technologies and / or techniques. For example, data, commands, instructions, information, signals, bits, symbols, chips, and / or the like that can be referenced throughout the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0165] In addition, the terms described in the present disclosure and the terms required for understanding the present disclosure can be replaced with terms having the same or similar meanings. For example, at least one of a channel and a symbol can also be a signal (signaling). Also, a signal can be a message. Also, a component carrier (CC) can be referred to as a carrier frequency, a cell, a frequency carrier, or the like.
[0166] The terms "system" and "network" used in the present disclosure can be used interchangeably.
[0167] In addition, the information, parameters, and / or the like described in the present disclosure can be represented using absolute values, relative values with respect to predetermined values, or corresponding other information. For example, a radio resource can be indicated using an index.
[0168] The names used for the above-described parameters are non-limiting names in any respect. Furthermore, the formulas and / or the like using these parameters are sometimes different from those explicitly disclosed in the present disclosure. Various channels (e.g., PUCCH, PDCCH, and / or the like) and information elements can be identified by all appropriate names, and thus various names assigned to the various channels and information elements are non-limiting names in any respect.
[0169] In the present disclosure, the terms "base station (BS)", "wireless base station", "base station device", "fixed station", "NodeB", "eNodeB (eNB)", "gNodeB (gNB)", "access point", "transmission point", "reception point", "transmission / reception point", "cell", "sector", "cell group", "carrier", "component carrier", and / or the like can be used interchangeably. The base station is sometimes referred to as a macro cell, a small cell, a femto cell, a pico cell, and / or the like.
[0170] A base station can accommodate one or plural (for example, 3) cells. In a case where a base station accommodates plural cells, the coverage area of the base station as a whole can be divided into plural smaller areas, and each of the smaller areas can also be provided with a communication service by a base station subsystem (for example, a small-sized base station RRH: Remote Radio Head for indoor use). The term "cell" or "sector" refers to a part or the whole of the coverage area of at least one of the base station and the base station subsystem that provides a communication service in the coverage.
[0171] In the present disclosure, the terms "mobile station (MS)", "user terminal (user terminal)", "user equipment (UE)", "terminal", and the like can be used interchangeably.
[0172] For a mobile station, the following terms are also used by those skilled in the art: subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other suitable terminology.
[0173] At least one of the base station and the mobile station can also be referred to as a transmission device, a reception device, a communication device, and the like. In addition, at least one of the base station and the mobile station can be a device mounted on a moving body, the moving body itself, and the like. The moving body can be a vehicle (for example, an automobile, an airplane, and the like), a moving body that moves in an unmanned manner (for example, a drone, an autonomous vehicle, and the like), and a robot (manned or unmanned). In addition, at least one of the base station and the mobile station also includes a device that does not necessarily move when performing communication. For example, at least one of the base station and the mobile station can be an IoT (Internet of Things) device such as a sensor.
[0174] Further, the base station in the present disclosure can also be replaced with a user terminal. For example, a structure in which communication between the base station and the user terminal is replaced with communication between a plurality of terminals 20 (for example, also referred to as D2D (Device-to-Device), V2X (Vehicle-to-Everything), or the like) can also apply the forms / embodiments of the present disclosure. In this case, the terminal 20 can also be provided with the functions of the network node 30 described above. Further, the expressions "uplink" and "downlink" and the like can be replaced with expressions corresponding to the inter-terminal communication (for example, "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with a side channel.
[0175] Likewise, the user terminal in the present disclosure can also be replaced with a base station. In this case, the base station can also be formed in a structure in which the base station has the functions of the user terminal described above.
[0176] The expressions "determining", "determining" and the like used in the present disclosure sometimes also include a variety of actions. The "determining", "determining" can include, for example, an action in which a matter in which a determination, calculation, computation, processing, derivation, investigation, search (for example, search in a table, a database, or other data structure), ascertainment, and the like are performed is regarded as a matter in which "determining", "determining" is performed. Further, the "determining", "determining" can include an action in which a matter in which receiving (for example, receiving information), transmitting (for example, transmitting information), input, output, accessing (for example, accessing data in a memory), and the like are performed is regarded as a matter in which "determining", "determining" is performed. Further, the "determining", "determining" can include an action in which a matter in which resolving, selecting, choosing, establishing, comparing, and the like are performed is regarded as a matter in which "determining", "determining" is performed. That is, the "determining", "determining" can include an action in which certain actions are regarded as a matter in which "determining", "determining" is performed. Further, the "determining" can also be replaced with "assuming", "expecting", "considering", and the like.
[0177] The terms "connected," "coupled," and "coupling," or all modifications thereof, mean any direct or indirect connection or coupling between two or more elements, which can include the use of one or more intermediate elements having one or more wires, cables, and printed or printed electrical connections between them. The coupling or connection between the elements can be a physical coupling or connection, a logical coupling or connection, or a combination thereof. For example, "access" can be used instead of "connect." In the present disclosure, it can be considered that two elements are "connected" or "coupled" to each other using at least one of a wire, a cable, and a printed electrical connection, and as some non-limiting and non-inclusive examples, electromagnetic energy having a wavelength in the radio frequency domain, the microwave region, and the light region (including both visible and invisible) is used to "connect" or "couple" to each other.
[0178] The reference signal can be referred to as RS (Reference Signal), and can be referred to as a pilot according to the applied standard.
[0179] The description "based on" used in the present disclosure does not mean "only based on" unless otherwise explicitly described. In other words, the description "based on" means both "only based on" and "at least based on."
[0180] Any reference to the elements using the terms "1st", "2nd", and the like used in the present disclosure does not limit the number or order of the elements. These terms can be used in the present disclosure as a convenient method of distinguishing between two or more elements. Therefore, a reference to a 1st element and a 2nd element does not mean that only two elements are taken or that the 1st element must precede the 2nd element in any form.
[0181] The "unit" in the structure of each of the above-described devices can be replaced with "part", "circuit", "device", and the like.
[0182] When "include", "including", and their modifications are used in the present disclosure, these terms mean the same as the term "comprising" and are inclusive. Also, the term "or" used in the present disclosure does not mean exclusive or.
[0183] In the present disclosure, for example, in the case where an article is added by translation, such as a, an, and the in English, the present disclosure also includes the case where the article following these articles is plural.
[0184] In the present disclosure, the expression "A and B are different" can mean "A and B are mutually different". In addition, the expression can also mean "A and B are each different from C". The expressions "separate", "combine", and the like can also be interpreted in the same way as "different".
[0185] The forms / embodiments described in the present disclosure can be used alone or in combination, and can also be used in switching along with execution. In addition, the notification of predetermined information (for example, the notification of "X is") is not limited to be performed explicitly, but can also be performed implicitly (for example, the notification of the predetermined information is not performed).
[0186] The above has been described in detail for the present disclosure, but it should be clear to those skilled in the art that the present disclosure is not limited to the embodiments described in the present disclosure. The present disclosure can be implemented as modifications and changes without departing from the spirit and scope of the present disclosure determined by the claims. Therefore, the purpose of the description of the present disclosure is to illustrate, and the present disclosure does not have any limiting meaning.
[0187] Label Explanation
[0188] 10 base station
[0189] 110 transmission unit
[0190] 120 reception unit
[0191] 130 setting unit
[0192] 140 control unit
[0193] 20 terminal
[0194] 210 transmission unit
[0195] 220 reception unit
[0196] 230 setting unit
[0197] 240 control unit
[0198] 30 network node
[0199] 1001 processor
[0200] 1002 storage device
[0201] 1003 auxiliary storage device
[0202] 1004 communication device
[0203] 1005 input device
[0204] 1006 output device
[0205] 2001 vehicle
[0206] 2002 drive section
[0207] 2003 steering section
[0208] 2004 accelerator pedal
[0209] 2005 brake pedal
[0210] 2006 gearshift lever
[0211] 2007 front wheel
[0212] 2008 rear wheel
[0213] 2009 axle
[0214] 2010 electronic control section
[0215] 2012 information service section
[0216] 2013 communication module
[0217] 2021 current sensor
[0218] 2022 rotation speed sensor
[0219] 2023 air pressure sensor
[0220] 2024 vehicle speed sensor
[0221] 2025 acceleration sensor
[0222] 2026 brake pedal sensor
[0223] 2027 gearshift lever sensor
[0224] 2028 object detection sensor
[0225] 2029 accelerator pedal sensor
[0226] 2030 driving assistance system section
[0227] 2031 microprocessor
[0228] 2032 memory (ROM, RAM)
[0229] 2033 communication port (I / O port)
Claims
1. A network node having: a receiving section that receives a backend channel authentication request from a network node having a function related to a computing resource; and a transmitting section that performs an inquiry of determining a user on a user data repository (UDR) based on an identifier included in the backend channel authentication request, the transmitting section transmits a web push authentication request to a terminal of the determined user, the receiving section receives a response of the web push authentication request from the terminal, and the transmitting section transmits success of the backend channel authentication request to the network node.
2. The network node according to claim 1, wherein the transmitting section transmits an authentication enforcement time and an authentication method of the backend channel authentication request to a CAPIF core function, the CAPIF referring to a Common API Framework.
3. A network node having: a receiving section that receives a token request from a network node having a function related to a computing resource; a control section that acquires an authentication enforcement time and an authentication method from a CAPIF authorization function and generates a token based on the authentication enforcement time and the authentication method, the CAPIF referring to a Common API Framework; and a transmitting section that transmits the token to the network node, the transmitting section transmits a verification result related to the token to an external service server.
4. A network node having: a transmitting section that transmits a backend channel authentication request to a CAPIF authorization function, the CAPIF referring to a Common API Framework; and a receiving section that receives success of the backend channel authentication request from the CAPIF authorization function, the transmitting section transmits a token request to a CAPIF core function, the receiving section receives a token from the CAPIF core function, the transmitting section transmits the token to an external service server to invoke an application program interface (API), and the receiving section acquires a resource from the external service server.
5. An authentication method performed by a network node, comprising: receiving a backend channel authentication request from a network node having a function related to a computing resource; performing an inquiry of determining a user on a user data repository (UDR) based on an identifier included in the backend channel authentication request; transmitting a web push authentication request to a terminal of the determined user; receiving a response of the web push authentication request from the terminal; and transmitting success of the backend channel authentication request to the network node.