Information processing method, communication device, communication system and storage medium

By using identification and indication information transmission in the communication system, combined with token verification and local authorization information, the problem of CAPIF in authorized access to metaverse services is solved, achieving more secure and accurate authorized access.

CN121844602APending Publication Date: 2026-04-10BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

The existing Common API Framework (CAPIF) is difficult to effectively implement authorized access when supporting metaverse business.

Method used

By defining information processing methods in the communication system, using identification and indication information to transmit between devices, clarifying the requester, object, and operation permissions, and combining token verification and local authorization information, authorized access based on the CAPIF framework is achieved.

Benefits of technology

It improves the security and accuracy of authorized access to metaverse application services, adapts to more operating scenarios, and meets diverse user needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121844602A_ABST
    Figure CN121844602A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information processing method, communication equipment, a communication system and a storage medium. The information processing method is executed by a first device and comprises the steps that first information is sent to a second device, and the first information is used for requesting to authorize the first device to execute a first operation on an object; the first information comprises at least one of a first identifier, a second identifier and a first indication; the first identifier is used for indicating first equipment; the second identifier is used for indicating the object; the first indication is used for indicating the first operation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to an information processing method, a communication device, a communication system and a storage medium. BACKGROUND

[0002] In the field of communication technology, some objects can be used between various applications and / or platforms, and the use of the objects can benefit users in various industries. SUMMARY

[0003] Embodiments of the present disclosure need to solve the problem of authorized access when a Common Application Program Interface (API) Framework (CAPIF) is used to support a meta-universe service in a communication system.

[0004] According to a first aspect of embodiments of the present disclosure, an information processing method is provided, executed by a first device, comprising: sending first information to a second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information comprises at least one of the following: a first identifier, a second identifier and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0005] According to a second aspect of embodiments of the present disclosure, an information processing method is provided, executed by a second device, comprising: receiving first information sent by a first device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information comprises at least one of the following: a first identifier, a second identifier and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0006] According to a third aspect of embodiments of the present disclosure, an information processing method is provided, executed by a third device, comprising: receiving third information sent by a second device, wherein the third information is used to request to obtain second authorization information; the second authorization information is used by the second device to determine whether to authorize the first device to perform an operation on an object; and sending the second authorization information to the second device.

[0007] According to a fourth aspect of embodiments of the present disclosure, an information processing method is provided, executed by a communication system comprising a first device and a second device; the method comprises: the first device sends first information to the second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information comprises at least one of the following: a first identifier, a second identifier and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0008] According to a fifth aspect of the embodiments of the present disclosure, a first device is provided, including: a first transceiver configured to send first information to a second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; and the first information includes at least one of: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0009] According to a sixth aspect of the embodiments of the present disclosure, a second device is provided, including: a second transceiver configured to receive first information sent by a first device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; and the first information includes at least one of: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0010] According to a seventh aspect of the embodiments of the present disclosure, a third device is provided, including: a third transceiver configured to receive third information sent by a second device, wherein the third information is used to request second authorization information; the second authorization information is used by the second device to determine whether to authorize the first device to perform an operation on an object; and the second transceiver is configured to send the second authorization information to the second device.

[0011] According to an eighth aspect of the embodiments of the present disclosure, a communication device is provided, and the communication device is configured to perform the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect, and the third aspect.

[0012] According to a ninth aspect of the embodiments of the present disclosure, a communication system is provided, including: a first device, a second device, and a third device; wherein the first device is configured to perform the method described in the optional implementation of the first aspect, the second device is configured to perform the method described in the optional implementation of the second aspect, and the third device is configured to perform the method described in the optional implementation of the third aspect.

[0013] According to a tenth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, and when the instructions run on a communication device, the communication device performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect, and the third aspect.

[0014] According to an eleventh aspect of the embodiments of the present disclosure, a program product is provided, and the program product includes at least one of a program and instructions, and when the at least one of the program and the instructions is executed by a communication device, the communication device performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect, and the third aspect.

[0015] The embodiment of the disclosure can enable CAPIF internal authorized access to support meta-universe application services. BRIEF DESCRIPTION OF DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the disclosure, which do not specifically limit the protection scope of the disclosure.

[0017] Figure 1 is an architecture schematic diagram of a communication system according to an embodiment of the disclosure.

[0018] Figure 2A is an interaction schematic diagram of an information processing method according to an embodiment of the disclosure.

[0019] Figure 2B is an interaction schematic diagram of an information processing method according to an embodiment of the disclosure.

[0020] Figure 3 is an interaction schematic diagram of an information processing method according to an embodiment of the disclosure.

[0021] Figure 4A is a schematic diagram of a support meta-universe application digital asset service architecture according to an embodiment of the disclosure.

[0022] Figure 4B is a schematic diagram of a space anchor function model using a SEAL architecture according to an embodiment of the disclosure.

[0023] Figure 4C is a schematic diagram of a space map function model using a SEAL architecture according to an embodiment of the disclosure.

[0024] Figure 4D is a schematic diagram of a function model of CAPIF according to an embodiment of the disclosure.

[0025] Figure 4E is a flow schematic diagram of an information processing method according to an embodiment of the disclosure.

[0026] Figure 4F is a flow schematic diagram of an information processing method according to an embodiment of the disclosure.

[0027] Figure 5A is a structural schematic diagram of a first device according to an embodiment of the disclosure.

[0028] Figure 5B is a structural schematic diagram of a second device according to an embodiment of the disclosure.

[0029] Figure 5C FIG. 3 is a structural schematic diagram of a third device according to an embodiment of the present disclosure.

[0030] Figure 6A FIG. 4 is a structural schematic diagram of a communication device according to an embodiment of the present disclosure.

[0031] Figure 6B FIG. 5 is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0032] The embodiments of the present disclosure provide an information processing method, a communication device, a communication system and a storage medium.

[0033] In a first aspect, the embodiments of the present disclosure provide an information processing method, executed by a first device, comprising: sending first information to a second device, wherein the first information is used to request authorization of the first device to perform a first operation on an object; and the first information comprises at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0034] In the above-mentioned embodiments, by sending the first information to the second device by the first device, the second device can be triggered to authorize the first device to request to perform the first operation on the object; thus, it is beneficial to explicitly authorize the service to perform the operation on the object, so as to improve the security of performing the operation on the object, and reduce the unauthorized operation of the object by the imposter (i.e., the first device).

[0035] Further, when the second device is an API exposure function mapped to CAPIF, it can be achieved to authorize the operation on the object based on the CAPIF framework (i.e., it can be achieved to authorize the access to the service supporting the meta-universe application in the CAPIF).

[0036] In some embodiments of the first aspect, the first information further comprises at least one of the following: a third identifier, wherein the third identifier is used to indicate a user requesting authorization; a fourth identifier, wherein the fourth identifier is used to indicate an application requesting authorization; and location information, wherein the location information is used to indicate a location of the first device.

[0037] In the above-mentioned embodiments, by including the third identifier in the first information, it is convenient to verify whether the user requesting is an authorized user; by including the fourth identifier in the first information, it is convenient to verify whether the application requesting is an authorized application; and by including the location information in the first information, it is convenient to verify whether the location where the requester is located is an allowed location (i.e., to verify whether the requester is an allowed requester); thus, it can further improve the security of performing the operation on the object.

[0038] In conjunction with some embodiments of the first aspect, in some embodiments, the first operation includes at least one of the following: creating an object; retrieving an object; invoking an object; updating an object; deleting an object.

[0039] In the above embodiments, object creation, retrieval, retrieval, updating and / or deletion operations can be performed, which can adapt to more application scenarios and meet various user needs.

[0040] In conjunction with some embodiments of the first aspect, in some embodiments, the second identifier includes at least one of the following: a digital asset identifier, wherein the digital asset identifier is used to indicate that the object is a digital asset; a spatial anchor identifier, wherein the spatial anchor identifier is used to indicate that the object is a spatial anchor; and a spatial map identifier, wherein the spatial map identifier is used to indicate that the object is a spatial map.

[0041] In the above embodiments, it is clarified that the object can be at least one of digital assets, spatial anchors, and spatial maps, which can be applied to more scenarios of performing operations on objects and meet user needs.

[0042] In conjunction with some embodiments of the first aspect, in some embodiments, the first information further includes a token; the token includes at least one of the following: an expiration time, wherein the expiration time is set as an expiration time declaration of the token; a fifth identifier, wherein the fifth identifier is used to indicate a first device, and the fifth identifier is set as a calling client declaration of the token; a sixth identifier, wherein the sixth identifier is used to indicate a service supported by a second device, and the sixth identifier is set as a scope declaration of the token; a seventh identifier, wherein the seventh identifier is used to indicate an object; a list of owner identifiers, wherein the list of owner identifiers is used to indicate the owner of the object; a list of user identifiers, wherein the list of user identifiers is used to indicate allowed users; a second indication, wherein the second indication is used to indicate allowed operations; and an application identifier list, wherein the list of application identifiers is used to indicate allowed applications.

[0043] In the above embodiments, by carrying a token in the first information, the second device can first verify the request of the first device based on the token's claim. If the token's claim cannot meet the authorization verification requirements, further authorization verification can be performed based on local authorization information, etc. This can ensure that the authorization verification of the request of the first device can be completed and improve the accuracy of authorization verification.

[0044] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: sending second information to a third device, wherein the second information is used to request a token; and receiving a token sent by the third device.

[0045] In the above embodiments, a token can be obtained from a third device to accommodate authorization verification based on a token-based secure transport layer.

[0046] In conjunction with some embodiments of the first aspect, in some embodiments, the second information further includes at least one of the following: a first identifier; a second identifier; a first indication; a third identifier, wherein the third identifier is used to indicate a user requesting authorization; a fourth identifier, wherein the fourth identifier is used to indicate an application requesting authorization; and location information, wherein the location information is used to indicate the location of the first device.

[0047] In a second aspect, embodiments of this disclosure propose an information processing method executed by a second device, comprising: receiving first information sent by a first device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0048] In conjunction with some embodiments of the second aspect, in some embodiments, the first information further includes at least one of the following: a third identifier, wherein the third identifier is used to indicate a user requesting authorization; a fourth identifier, wherein the fourth identifier is used to indicate an application requesting authorization; and location information, wherein the location information is used to indicate the location of the first device.

[0049] In conjunction with some embodiments of the second aspect, in some embodiments, the first operation includes at least one of the following: creating an object; retrieving an object; calling an object; updating an object; deleting an object.

[0050] In conjunction with some embodiments of the second aspect, in some embodiments, the second identifier includes at least one of the following: a digital asset identifier, wherein the digital asset identifier is used to indicate that the object is a digital asset; a spatial anchor identifier, wherein the spatial anchor identifier is used to indicate that the object is a spatial anchor; and a spatial map identifier, wherein the spatial map identifier is used to indicate that the object is a spatial map.

[0051] In conjunction with some embodiments of the second aspect, in some embodiments, the first information further includes a token; the token includes at least one of the following: an expiration time, wherein the expiration time is set as an expiration time declaration of the token; a fifth identifier, wherein the fifth identifier is used to indicate a first device, and the fifth identifier is set as a calling client declaration of the token; a sixth identifier, wherein the sixth identifier is used to indicate a service supported by the second device, and the sixth identifier is set as a scope declaration of the token; a seventh identifier, wherein the seventh identifier is used to indicate an object; a list of owner identifiers, wherein the list of owner identifiers is used to indicate the owner of the object; a list of user identifiers, wherein the list of user identifiers is used to indicate allowed users; a second indication, wherein the second indication is used to indicate allowed operations; and a list of application identifiers, wherein the list of application identifiers is used to indicate allowed metaverse applications.

[0052] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: determining, based on authorization information, whether the first device is allowed to call the service API of the second device; and, if the first device is allowed to call the service API, determining, based on the authorization information, whether to authorize the first device to perform a first operation on the object.

[0053] In the above embodiments, the request of the first device can be verified based on the authorization information, thereby enabling authorization verification; if the authorization information is obtained from CAPIF or the second device is an API open function mapped to CAPIF, then the operation of authorizing access to the object based on the CAPIF framework can be realized.

[0054] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes one of the following: determining whether to authorize a first operation performed on an object by a first device based on a statement in a token; and determining whether to authorize the first device to perform the first operation on an object based on authorization information if the token does not contain sufficient statements for authorization.

[0055] In conjunction with some embodiments of the second aspect, in some embodiments, determining whether to authorize a first operation performed by a first device on an object based on a statement in the token includes: determining that the first operation to be authorized to be performed by the first device on an object is based on at least one of the following: a third identifier included in the first information is an identifier in the owner identifier list in the token; a third identifier included in the first information is an identifier in the user identifier list in the token; a first operation indicated by a first instruction included in the first information is an operation in the operation indicated by a second instruction in the token; a fourth identifier included in the first information is an identifier in the application identifier list in the token.

[0056] In conjunction with some embodiments of the second aspect, in some embodiments, the authorization information includes at least one of the following: first authorization information; wherein the first authorization information is stored in a second device; second authorization information; wherein the second authorization information is obtained from a third device.

[0057] In the above embodiments, the second device can perform authorization verification based on local authorization information (i.e., first authorization information) and / or second authorization information obtained from the third device, thereby increasing the probability of authorization verification completion.

[0058] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: sending third information to a third device, wherein the third information is used to request obtaining second authorization information; and receiving the second authorization information sent by the third device.

[0059] Thirdly, this disclosure provides an information processing method executed by a third device, comprising: receiving third information sent by a second device, wherein the third information is used to request second authorization information; the second authorization information is used by the second device to determine whether to authorize the first device to perform an operation on an object; and sending the second authorization information to the second device.

[0060] In conjunction with some embodiments of the third aspect, in some embodiments, the method includes: receiving second information sent by a first device, wherein the second information is used to request a token; generating a token based on the second information; and sending the token to the first device.

[0061] In conjunction with some embodiments of the third aspect, in some embodiments, a token is generated based on the second information, including one of the following: generating a token based on the fact that a third identifier included in the second information is an identifier in the owner identifier list in the second authorization information; wherein the owner identifier list is used to indicate the owner of the object; generating a token based on the fact that the third identifier included in the second information is an identifier in the user identifier list in the second authorization information; wherein the user identifier list is used to indicate the user authorized to use the object; requesting the owner to authorize the third identifier based on the fact that the user identifier list in the second authorization information is unavailable; generating a token if the owner authorizes the third identifier.

[0062] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes one of the following: obtaining an owner identifier list from a second device if the owner identifier list is not present in the second authorization information; obtaining a user identifier list from the second device if the user identifier list is not present in the second authorization information; and obtaining an operation list from the second device if the second authorization information is not present in the second instruction, the operation list including at least one permitted operation.

[0063] In conjunction with some embodiments of the third aspect, in some embodiments, the token includes at least one of the following: an expiration time, wherein the expiration time is set as an expiration time declaration of the token; a fifth identifier, wherein the fifth identifier is used to indicate a first device, and the fifth identifier is set as an invoking client declaration of the token; a sixth identifier, wherein the sixth identifier is used to indicate a service supported by a second device, and the sixth identifier is set as a scope declaration of the token; a seventh identifier, wherein the seventh identifier is used to indicate an object; an owner identifier list, wherein the owner identifier list is used to indicate the owner of the object; a user identifier list, wherein the user identifier list is used to indicate allowed users; a second indicator, wherein the second indicator is used to indicate allowed operations; and an application identifier list, wherein the application identifier list is used to indicate allowed applications.

[0064] Fourthly, embodiments of this disclosure propose an information processing method executed by a communication system, the communication system including a first device and a second device; the method includes: the first device sending first information to the second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; the first indication is used to indicate the first operation.

[0065] Fifthly, embodiments of this disclosure provide a first device, comprising: a first transceiver module configured to send first information to a second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0066] In a sixth aspect, embodiments of this disclosure provide a second device, comprising: a second transceiver module configured to receive first information sent by a first device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0067] In a seventh aspect, embodiments of this disclosure provide a third device, comprising: a third transceiver module configured to receive third information sent by a second device, wherein the third information is used to request second authorization information; the second authorization information is used by the second device to determine whether to authorize the first device to perform an operation on an object; and the second authorization information is sent to the second device.

[0068] Eighthly, embodiments of this disclosure provide a communication device for performing an alternative implementation of the first aspect, the second aspect, the third aspect, or the first aspect, the second aspect, and the third aspect.

[0069] In a ninth aspect, embodiments of this disclosure provide a communication system comprising: a first device, a second device, and a third device; wherein the first device is configured to perform the method described in the optional implementation of the first aspect, the second device is configured to perform the method described in the optional implementation of the second aspect, and the third device is configured to perform the method described in the optional implementation of the third aspect.

[0070] In a tenth aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect, the second aspect, the third aspect, or an optional implementation of the first aspect, the second aspect, and the third aspect.

[0071] In one aspect, embodiments of this disclosure provide a program product including at least one of a program and instructions, wherein the program and instructions, when executed by a communication device, implement the method described in the first aspect, the second aspect, the third aspect, or an optional implementation of the first aspect, the second aspect, and the third aspect.

[0072] In a twelfth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the information processing method as described in the first aspect, the second aspect, the third aspect, or an optional implementation of the first aspect, the second aspect, and the third aspect.

[0073] In a thirteenth aspect, embodiments of this disclosure provide a chip or chip system including processing circuitry configured to perform the methods described in accordance with the first, second, third, or alternative implementations of the first, second, and third aspects described above.

[0074] It is understood that the aforementioned devices (such as the first device, the second device, the third device, etc.), communication systems, storage media, program products, etc., are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0075] This disclosure provides an information processing method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "information processing method" and "information processing method" may be used interchangeably.

[0076] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments. In all embodiments of this disclosure, unless otherwise specified or logically conflicting, the terminology and / or descriptions between the embodiments are consistent and can be mutually utilized. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0077] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0078] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0079] In the embodiments disclosed herein, "multiple" refers to two or more.

[0080] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0081] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.

[0082] In some embodiments, the notation "A or B" may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.

[0083] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0084] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0085] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.

[0086] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.

[0087] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0088] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.

[0089] In some embodiments, "network" can be interpreted as devices included in the network (e.g., access network devices, core network devices, etc.).

[0090] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.

[0091] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriberstation, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, and client can be used interchangeably.

[0092] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0093] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0094] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0095] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0096] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0097] Figure 1 This is a schematic diagram illustrating the architecture of a communication system 100 according to an embodiment of this disclosure. Figure 1 As shown, the communication system 100 includes: terminal 101, access network device 102, and core network device 103.

[0098] In some embodiments, terminal 101 includes, for example, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home, but is not limited thereto.

[0099] In some embodiments, the access network device 102 may be a node or device that connects a terminal to a wireless network. The access network device may include at least one of the following in a 5G communication system: an evolved Node B (eNB), a next-generation eNB (ng-eNB), a next-generation Node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open RAN, a cloud RAN, a base station in other communication systems, and an access node in a Wi-Fi system, but is not limited thereto.

[0100] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0101] In some embodiments, the technical solutions of this disclosure can be applied to a service-based RAN architecture. In this case, the interfaces between access network devices or between access network devices and core network devices involved in the embodiments of this disclosure can be service-based interfaces. The processes and information interactions between these interfaces can be implemented by software or programs that call one or more corresponding services.

[0102] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0103] In some embodiments, terminal 101 may include a first device 1031 or other devices.

[0104] In some embodiments, the core network device 103 may be a single device, including a second device 1032 or a third device 1033, or it may be multiple devices or a group of devices, including all or some of the aforementioned second device 1032, third device 1033, etc. The device may be virtual or physical. The core network may include, for example, at least one of the following: Evolved Packet Core (EPC), 5G Core Network (5GCN), Next Generation Core (NGC), and 6G Core Network (6GCN).

[0105] In some embodiments, the first device 1031 refers to, for example, an API invoker or an API requester.

[0106] In some embodiments, the first device 1031 is used to request or invoke a service API to perform a corresponding operation, and the name is not limited thereto.

[0107] For example, the first device 1031 may be a caller or requester in a Vertical Application Layer (VAL) client, and / or a caller or requester in a VAL server, etc.

[0108] Exemplary API callers can be terminals or user interfaces (UEs), or applications (such as browsers) running on terminals or UEs, or public accounts or mini-programs, or application functions, or application servers, or servers belonging to third parties (such as Company A, operator B, or platform C).

[0109] In some embodiments, the second device 1032 is, for example, a Service Enabler Architecture Layer (SEAL) server.

[0110] In some embodiments, the second device 1032 is used for API opening functions or for services, and the name is not limited thereto.

[0111] For example, the second device 1032 may be at least one of the following: a server related to digital assets (DA), a server related to spatial anchors (SAn), and a server related to spatial maps (SM).

[0112] For example, the second device 1032 can be at least one of the following: a DA server, a SAn server, and an SM server. The second device 1032 can also be any server related to metaverse applications.

[0113] For example, the second device can be mapped to an API Exposing Function (AEF) within the CAPIF architecture.

[0114] In some embodiments, the third device 1033 may be a Universal Application Programming Interface Framework core function (CAPIF core function, CCF) or a licensing function, etc.

[0115] In some embodiments, the third device 1033 is any network element, function, or entity in the core network of the CAPIF system, or it may be any network element, function, or entity in the core network used for functions such as authorization, etc., and the name is not limited thereto.

[0116] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions provided in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in this disclosure are also applicable to similar technical problems.

[0117] The following embodiments of this disclosure can be applied to Figure 1 The communication system 100 shown, or a part thereof, but not limited to it. Figure 1 The entities shown are illustrative; a communication system may include... Figure 1 All or part of the main body, or may include Figure 1 Other entities besides the main body, the number and form of each entity are arbitrary, each entity can be physical or virtual, the connection relationship between the entities is illustrative, the entities can be unconnected or connected, and the connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0118] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Futuregeneration Radio Access (FX), Global System for Mobile Communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0119] Digital assets used in mobile metaverse services can be at least one of the following: digital representations (avatars), software licenses, gift certificates, tokens, etc.; these digital assets are uniquely identifiable. Users can associate with one or more digital assets, such as avatars, software licenses, and / or gift certificates. Mobile metaverse applications can leverage user-associated digital assets, and users can benefit from using their digital assets in an interoperable manner across various metaverse applications or platforms. For example, digital asset services enable users to create, discover, and manage (e.g., read, retrieve, update, delete) digital assets and digital asset profiles to offload applications and enable core network functions across services and vertical industries. Most metaverse applications require digital assets (e.g., avatars) for users to interact with the application. Furthermore, users can seamlessly move between metaverse applications using the same digital assets (e.g., avatars) while taking into account the constraints of the applications accessed.

[0120] Currently, metaverse enabling services (i.e., digital asset services, spatial anchor management services, and spatial map management services) require authorization. Since metaverse enabling services can be provided based on the Service Enabler Architecture Layer (SEAL) service, it can be assumed that authorization for accessing metaverse enabling services can be based on the SEAL service authorization mechanism. Here, a spatial anchor can refer to an anchor point in space.

[0121] The Common API Framework (CAPIF) system defined in the communication system can also be used to support SEAL services. This means that CAPIF can be used to support metaverse-enabled services, such as digital asset services, spatial anchor management services, and / or spatial map management services. However, when CAPIF is used to support metaverse-enabled services, service access based on SEAL service authorization is no longer applicable. Therefore, in addition to the SEAL service authorization mechanism, a method for authorization to access metaverse-enabled services based on the CAPIF framework needs to be studied.

[0122] In some embodiments, the UE can be a terminal, or the terminal can be a UE.

[0123] like Figure 2A This is an interactive schematic diagram illustrating an information processing method according to an embodiment of this disclosure. For example... Figure 2AAs shown, this disclosure relates to an information processing method for a communication system 100, the method comprising:

[0124] Step S2101: The first device sends the second information to the third device.

[0125] In some embodiments, the third device receives second information sent by the first device.

[0126] In some embodiments, the second information is used to request a token.

[0127] Optionally, the token can be used to access an object. For example, the token can be used to access a service API opened by a second device. For example, the token can be used to access an object and / or perform operations on that object, etc.

[0128] For example, an object is an object related to metaverse applications. For instance, an object may include, but is not limited to, at least one of the following: digital assets, spatial anchors, and spatial maps. Here, metaverse enablement services can be introduced into the communication system, allowing users to benefit from using user-related digital assets in various metaverse applications and / or platforms, and from building spatial anchors or spatial maps using location information related to metaverse enablement services. In short, applications supported by metaverse enablement services can facilitate users across various industries.

[0129] For example, in this embodiment of the disclosure, the object may be the object corresponding to the execution of the first operation.

[0130] For example, the name of the object is not limited; it may be, for example, the first object or the target object.

[0131] Optionally, the token may include at least one of the following: expiration time, fifth identifier, sixth identifier, seventh identifier, owner identifier, list of user identifiers, second instruction, and list of application identifiers.

[0132] For example, the expiration time is set to the token's expiration time declaration or first declaration. Here, by setting the expiration period of the token, the validity period of the token can be determined; once the expiration time has expired, the token can be invalidated.

[0133] For example, the fifth identifier is used to indicate the first device; the fifth identifier is set as the calling client declaration of the token. Here, the calling client can refer to the client of the caller or requester; the calling client declaration refers to the caller or requester that issues the first message (or API request), allowing these calling clients to invoke the API request, etc. There can be one or more fifth identifiers, and one fifth identifier indicates one or more calling clients. Here, the calling client declaration can be replaced by a client identifier (e.g., client_id) declaration or a second declaration.

[0134] For example, the sixth identifier is used to indicate the services supported by the second device; the sixth identifier is set to a scope (e.g.) claim or a third claim of the token.

[0135] For example, the sixth identifier can be for different services supported by different servers. For instance, for a DA server, the supported services may include DA configuration file management, etc.; for a SAn server, the supported services may include at least one of the following: SAn management, SAn discovery, and SAn usage information, etc.; for an SM server, the supported services may include at least one of the following: SM management, SM discovery, SMF localization, SM data source registration, and SMF data source discovery, etc.

[0136] For example, the seventh identifier is used to indicate an object.

[0137] For example, the seventh identifier is set to the token's object declaration or object identifier (e.g., targetObject_id) declaration or the fourth declaration, etc.

[0138] For example, the seventh identifier may include at least one of the following: a digital asset identifier, a spatial anchor identifier, and a spatial map identifier; the digital asset identifier is used to indicate that the object is a digital asset; the spatial anchor identifier is used to indicate that the object is a spatial anchor; and the spatial map identifier is used to indicate that the object is a spatial map.

[0139] For example, the seventh identifier is a digital asset identifier, which is set as the digital asset statement of the token; the seventh identifier is a spatial anchor identifier, which is set as the spatial anchor statement of the token; the seventh identifier is a spatial map identifier, which is set as the spatial map statement of the token. Here, the seventh identifier, the data asset identifier, the spatial anchor identifier, and the spatial map identifier can all be one or more; for example, a seventh identifier can indicate one or more objects; for example, a digital asset identifier can be used to indicate a data asset; for example, a spatial anchor identifier can indicate a spatial anchor; for example, a spatial map identifier can be used to indicate a spatial map.

[0140] For example, a list of owner identifiers is used to indicate the owner of an object.

[0141] For example, the list of owner identifiers is set to the token's owner list statement or owner identifier list (e.g., ownerID_list) statement or fifth statement, etc.

[0142] For example, the list of owner identifiers may include one or more owner identifiers; an owner identifier can be used to indicate an owner. The owner refers to the owner of the object.

[0143] For example, a list of user identifiers is used to indicate allowed users.

[0144] For example, the list of user identifiers is set to a token's user list statement or a user identifier list (e.g., userID_list) statement or a sixth statement, etc.

[0145] For example, the list of user identifiers may include one or more user identifiers; a user identifier can be used to indicate a user. This user refers to the user who is authorized to perform operations on the object. Optionally, the user and the owner can be the same, or the user and the owner can be different.

[0146] For example, the second instruction is used to indicate the permitted operation.

[0147] For example, the second instruction is set to a token's operation list (e.g., operation_list) declaration, an operation declaration, or a seventh declaration.

[0148] For example, the second instruction may include one or more operation instructions, one operation instruction indicating an operation. Here, the operation may include at least one of the following: creation, discovery, reading, updating, deleting, retrieving, and invoking. For example, a user may be allowed to perform at least one of the following operations on an object: creation, discovery, reading, updating, deleting, retrieving, and invoking.

[0149] For example, the application identifier list is used to indicate allowed applications.

[0150] For example, the application ID list is set to the token's application ID list (appID_list) declaration, application declaration, or eighth declaration.

[0151] For example, the list of application identifiers may include one or more application identifiers; an application identifier can be used to indicate an application. For example, the application may be a metaverse application, or an application other than a metaverse application.

[0152] For example, the fifth identifier, sixth identifier, seventh identifier, owner identifier list, user identifier list, second instruction, and application identifier list can each be one or more bits. The fifth identifier, sixth identifier, seventh identifier, owner identifier list, user identifier list, second instruction, and application identifier list can each be a string; the string can include one or more letters, numbers, and / or symbols, etc.

[0153] For example, the names of the fifth identifier, sixth identifier, seventh identifier, owner identifier list, user identifier list, second instruction, and application identifier list are not limited; for example, the fifth identifier can be a client identifier, requester identifier, or caller identifier, etc.; the sixth identifier can be a service identifier, etc.; the seventh identifier can be an object identifier, etc.; the owner identifier list can be a first list, etc.; the user identifier list can be a second list, etc.; the second instruction can be an operation list or operation type, etc.; and the application identifier list can be a third list or a metaverse application list, etc.

[0154] Optionally, the token may contain a statement as shown in Table 1.

[0155]

[0156] Table 1

[0157] Optionally, the second information includes at least one of the following: a first identifier, a second identifier, a first indication, a third identifier, a fourth identifier, and location information.

[0158] For example, the first identifier is used to indicate a first device. The first device can be a client of a requester or a caller; for example, the first identifier can be used to indicate a client of a requester or a caller. For instance, the first identifier is used to indicate a first device requesting authorization, or a requester client, or a caller client.

[0159] For example, the second identifier is used to indicate an object. For instance, the second identifier is used to indicate an object requesting authorization.

[0160] For example, the first instruction is used for the first operation of requesting authorization.

[0161] For example, the first operation may include, but is not limited to, at least one of the following: creating an object, retrieving an object, discovering an object, reading an object, calling an object, updating an object, and deleting an object.

[0162] For example, the second identifier may include, but is not limited to, at least one of the following: a digital asset identifier, a spatial anchor identifier, and a spatial map identifier; the digital asset identifier indicates that the object is a digital asset; the spatial anchor identifier indicates that the object is a spatial anchor; and the spatial map identifier indicates that the object is a spatial map. Here, when the second identifier is a digital asset identifier, it can be used to indicate a digital asset requesting authorization; when the second identifier is a spatial anchor identifier, it can be used to indicate a spatial anchor requesting authorization; and when the second identifier is a spatial map identifier, it can be used to indicate a spatial map requesting authorization. Here, the second identifier, the digital asset identifier, the spatial anchor identifier, and the spatial map identifier can each be one or more.

[0163] For example, a third identifier is used to indicate the user requesting authorization. The third identifier can be one or more, or a list of user identifiers; a third identifier can be used to indicate a user.

[0164] For example, the fourth identifier is used to indicate the application requesting authorization. The fourth identifier can be one or more, or a list of application identifiers; a fourth identifier can be used to indicate an application. For example, the application can be a metaverse application, or an application other than a metaverse application.

[0165] For example, location information is used to indicate the location of a first device. For instance, location information can be used to indicate the location of a first device requesting authorization; if the location indicated by the location information is authorized, the first device is permitted to perform a first operation on an object while at the location indicated by the location information.

[0166] For example, the first identifier, second identifier, first indication, third identifier, and fourth identifier can each be one or more bits. The first identifier, second identifier, first indication, third identifier, and fourth identifier can be a string; the string can include one or more letters, numbers, and / or symbols, etc.

[0167] For example, the names of the first identifier, the second identifier, the first instruction, the third identifier, and the fourth identifier are not limited; for example, the first identifier can be a client identifier, a requester identifier, or a caller identifier, etc.; the second identifier can be an object identifier, etc.; the first instruction can be an operation list or an operation type, etc.; the third identifier can be a user identifier or a list of user identifiers, etc.; and the fourth identifier can be an application identifier or a list of application identifiers, etc.

[0168] Optionally, the second information may be an Access Token Request message or a token request message, etc.

[0169] Optionally, the name of the second information is not limited, and it may be, for example, access token request information or token request information.

[0170] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transfer,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.

[0171] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "bit", and "data" can be used interchangeably.

[0172] In some embodiments, terms such as "certain", "preset", "specified", "default", "set", "indicated", "a certain", "any", and "first" can be used interchangeably. "Certain A", "preset A", "specified A", "default A", "set A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, specified A, a certain A, any A, or first A, but are not limited thereto.

[0173] Step S2102: The third device generates a token.

[0174] In some embodiments, the third device generates a token based on the second information.

[0175] In some embodiments, the third device generates a token based on the second information and the second authorization information.

[0176] Optionally, the second authorization information may be authorization information stored in a third device.

[0177] Optionally, the second authorization information may be a portion of the information declared in Table 1.

[0178] In some optional implementations, the third device generates a token based on the second information and the authorization information. Optionally, the authorization information may include at least one of the following: first authorization information and second authorization information; the first authorization information is obtained from the second device.

[0179] Optionally, the third device generates a token based on the third identifier included in the second information being an identifier in the owner identifier list in the second authorization information; wherein the owner identifier list is used to indicate the owner of the object.

[0180] For example, the third device receives second information sent by the first device, the second information including a third identifier and a second identifier; if the third device determines that the second identifier is any identifier in the seventh identifier in the second authorization information, and determines that the third identifier is any identifier in the owner identifier list in the second authorization information (i.e. the user indicated by the third identifier is any identifier in the owner of the object), it determines to generate a token.

[0181] Optionally, the third device generates a token based on the fact that the third identifier included in the second information is an identifier in the user identifier list in the second authorization information; wherein the user identifier list is used to indicate the user who is allowed to use the object.

[0182] For example, the third device receives second information sent by the first device, the second information including a third identifier and a second identifier; if the third device determines that the second identifier is any identifier in the seventh identifier in the second authorization information, and determines that the third identifier is any identifier in the user identifier list in the second authorization information (i.e., the user indicated by the third identifier is any identifier among the users of the target), it determines to generate a token.

[0183] Optionally, the third device requests authorization from the owner for a third identifier based on the unavailability of the user identifier list in the second authorization information; if the owner authorizes the third identifier, a token is generated.

[0184] For example, if the user identifier list in the second authorization information is unavailable, the third device sends a fourth message to the owner, which requests authorization of the third identifier. If the third device receives confirmation of authorization of the third identifier from the owner, it generates a token. Here, the fourth message may include the third identifier.

[0185] In some embodiments, generating a token may include at least one of the following: a calling client declaration that sets a fifth identifier as the token, a scope declaration that sets a sixth identifier as the token, an object declaration that sets a seventh identifier as the token, a list of owner identifiers that sets a list of owner identifiers as the token, a list of user identifiers that sets a list of user identifiers as the token, an operation list declaration that sets a second indicator as the token, and an application list declaration that sets an application identifier list as the token.

[0186] In some embodiments, if the third device does not have an owner list in the second authorization information, it obtains an owner identifier list from the second device.

[0187] For example, if the owner list is not present in the second authorization information, the third device sends fifth information to the second device, which is used to request the owner identifier list; the third device receives the owner identifier list sent by the second device. Here, the fifth information may include the second identifier; the fifth information can be used to request the owner identifier list corresponding to the second identifier.

[0188] In some embodiments, the third device obtains the user identifier list from the second device if the user identifier list is not present in the second authorization information.

[0189] For example, if the second authorization information does not contain a list of user identifiers, the third device sends a sixth message to the second device, which requests a list of user identifiers; the third device receives the list of user identifiers sent by the second device. Here, the sixth message may include the second identifier; the sixth message can be used to request a list of user identifiers corresponding to the second identifier.

[0190] In some embodiments, if the second instruction is not present in the second authorization information, the third device obtains an operation list from the second device, the operation list including at least one permitted operation.

[0191] For example, if the second instruction is not present in the second authorization information, the third device sends a seventh message to the second device, the seventh message being used to request the second instruction; the third device receives the second instruction sent by the second device. Here, the seventh message may include a second identifier; the seventh message can be used to request the second instruction corresponding to the second identifier.

[0192] In some embodiments, the third device obtaining at least one of the owner identifier list, user identifier list, and second instruction from the second device can be considered as obtaining the first authorization information from the second device; in this embodiment of the disclosure, when the information included in the second authorization information in the third device is insufficient to determine whether to generate a token, at least a portion of the first authorization information can be obtained from the second device so that it can be used together with the first authorization information to determine whether to generate a token.

[0193] In some embodiments, the names of the fourth, fifth, sixth, and seventh information are not limited; for example, the fourth information may be user authorization request information, the fifth information may be owner request information, the sixth information may be user request information, and the seventh information may be operation request information.

[0194] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomously implementing, among other meanings.

[0195] In step S2103, the third device sends a token to the first device.

[0196] In some embodiments, the first device receives a token sent by the third device.

[0197] In some embodiments, the third device sends a token response message to the first device, the token response information including a token. Here, the token response message can be replaced with an access token response message.

[0198] In some embodiments, the first device receives a token response message sent by the third device, the token response message including a token.

[0199] Step S2104: The first device sends the first information to the second device.

[0200] In some embodiments, the second device receives the first information sent by the first device.

[0201] Optionally, the first information is used to request authorization from the first device to perform a first operation on the object. For example, the first information is used to request authorization from the second device to perform the first operation on the object.

[0202] Optionally, the first information may include a first identifier, a second identifier, and a first instruction; the first information is used to request authorization: the first device corresponding to the first identifier performs the first operation corresponding to the first instruction on the object corresponding to the second identifier.

[0203] Optionally, the first information may also include at least one of the following: a third identifier, a fourth identifier, and location information.

[0204] For example, if the first information includes a third identifier, the first information can be used to request authorization for the user corresponding to the third identifier to perform a first operation on the object.

[0205] For example, if the first information includes a fourth identifier, the first information can be used to request authorization for the application corresponding to the fourth identifier; for example, authorizing the execution of a first operation on an object through the application corresponding to the fourth identifier.

[0206] For example, if the first information includes location information, the first information can be used to request a first device at the location indicated by the location information to perform a first operation on the object.

[0207] Optionally, the first information also includes a token. This token can be a token as described in previous embodiments (e.g., the token shown in Table 1). For example, the token may include at least one of the following: an expiration time, a fifth identifier, a sixth identifier, a seventh identifier, an owner identifier, a list of user identifiers, a second instruction, and a list of application identifiers. Here, by including the token in the first information, the second device can perform token verification, and authorization verification can be performed only if the token verification is successful.

[0208] Optionally, the first piece of information may be a call request message or a service API call request message, etc.

[0209] Optionally, the name of the first piece of information is not limited; it may be, for example, service API call request information or authorization request information.

[0210] Step S2105: The second device sends third information to the third device.

[0211] In some embodiments, the third device receives third information sent by the second device.

[0212] Optionally, the third information is used to request the second authorization information.

[0213] Optionally, the name of the third information is not limited, and it may be, for example, authorization information request information or authorization information acquisition information.

[0214] In some embodiments, if the second device can determine whether it authorizes the first device to perform the first operation on the object based on the first authorization information, then it is not necessary to send third information to the third device to request the second authorization information, that is, it is not necessary to execute steps S2105 and S2106; or, if the second device cannot determine whether it authorizes the first device to perform the first operation on the object based on the first authorization information, it is necessary to send third information to the third device to request the second authorization information.

[0215] In some embodiments, if the first information does not include a token, the second device may send third information to the third device to request the second authorization information if authorization cannot be determined based on the first authorization information.

[0216] In some embodiments, if the first information also includes a token, the second device, after successfully verifying the token and unable to determine authorization based on the first authorization information, sends third information to the third device to request the second authorization information.

[0217] In step S2106, the third device sends the second authorization information to the second device.

[0218] In some embodiments, the second device receives second authorization information sent by the third device.

[0219] In some embodiments, the third device sends an authorization information response message to the second device, the authorization information response message including second authorization information.

[0220] In some embodiments, the third device receives an authorization information response message sent by the second device, the authorization information response message including second authorization information.

[0221] In step S2107, the second device determines whether to authorize the first device to perform the first operation on the object.

[0222] Optionally, determining whether to authorize the first device to perform the first operation on the object includes: determining whether to authorize the first device to perform the first operation on the object, or determining whether to authorize the first device to perform the first operation on the object.

[0223] In some embodiments, the first information does not include a token; the second device determines whether to authorize the first device to perform an operation on the object based on the authorization information. Here, when the first information does not include a token, the second device can directly perform authorization verification based on the authorization information.

[0224] Optionally, the authorization information may include at least one of the following: first authorization information and second authorization information; the first authorization information is stored in the second device; the second authorization information is obtained from the third device. That is, the first authorization information may be local authorization information of the second device; the second authorization information may be local authorization information of the third device.

[0225] Optionally, the authorization information, the first authorization information, and the second authorization information may each include some of the information declared in Table 1. For example, the authorization information, the first authorization information, and the second authorization information may each include at least one of the following: a fifth identifier, a sixth identifier, a seventh identifier, a list of owner identifiers, a list of user identifiers, a second instruction, and a list of application identifiers. Of course, in other embodiments, the authorization information, the first authorization information, and the second authorization information may also include any information related to authorization.

[0226] Optionally, the second device determines whether the first device is allowed to call the service API based on the authorization information; if the first device is allowed to call the service API, it determines whether to authorize the first device to perform the first operation on the object based on the authorization information.

[0227] For example, the second device determines whether the first device is allowed to call the service API based on the first authorization information; if it is determined that the first device is allowed to call the service API based on the first authorization information, it determines whether to authorize the first device to perform the first operation on the object. In this embodiment, if the second device cannot determine whether to authorize the first device to perform the first operation on the object based on the first authorization information, it obtains the second authorization information from the third device (i.e., steps S2105 and S2106 are executed); the second device determines whether to authorize the first device to perform the first operation on the object based on the first authorization information and / or the second authorization information.

[0228] For example, the second device determines whether the first device is allowed to call the service API based on the first authorization information; if it cannot be determined whether the first device is allowed to call the service API based on the first authorization information, the second device obtains the second authorization information from the third device (i.e., steps S2105 and S2106 are executed); the second device determines whether the first device is allowed to call the service API based on the second authorization information; if it is determined that the first device is allowed to call the service API based on the second authorization information, the second device determines whether to authorize the first device to perform the first operation on the object based on the first authorization information and / or the second authorization information.

[0229] For example, the second device determines whether to authorize the first device to perform the first operation on the object based on the first authorization information and / or the second authorization information, which may include, but is not limited to, one of the following methods:

[0230] In method one, if the second device can determine whether to authorize the first device to perform the first operation on the object based on the first authorization information, then the second authorization information does not need to be considered.

[0231] Method 2: If the second device cannot determine whether to authorize the first device to perform the first operation on the object based on the first authorization information, then the second authorization information needs to be considered; the second device determines whether to authorize the first device to perform the first operation on the object based on the second authorization information.

[0232] Method 3: If the second device cannot determine whether to authorize the first device to perform the first operation on the object based on the first authorization information, then the second authorization information needs to be considered; the second device determines whether to authorize the first device to perform the first operation on the object based on the combination of the first authorization information and the second authorization information.

[0233] In some embodiments, the second device determines whether to authorize the first device to perform the first operation on the object based on the first information and the authorization information.

[0234] For example, the second device determines that it authorizes the first device to perform a first operation on an object based on at least one of the following: the first identifier included in the first information is an identifier in the fifth identifier in the authorization information; the second identifier included in the first information is an identifier in the seventh identifier in the authorization information; the third identifier included in the first information is an identifier in the owner identifier list in the authorization information; the third identifier included in the first information is an identifier in the user identifier list in the authorization information; the first operation indicated by the first instruction included in the first information is an operation in the operation indicated by the second instruction in the authorization information; and the fourth identifier included in the first information is an identifier in the application identifier list in the authorization information. For example, the first operation indicated by the first instruction included in the first information is any (i.e., one or more) of the operations indicated by the second instruction in the authorization information. For example, the fourth identifier included in the first information is any (i.e., one or more) of the identifiers in the application identifier list in the authorization information.

[0235] For example, the second device determines that it does not authorize the first device to perform the first operation on the object based on at least one of the following: the first identifier included in the first information is not an identifier in the fifth identifier in the authorization information; the second identifier included in the first information is not an identifier in the seventh identifier in the authorization information; the third identifier included in the first information is not any identifier in the owner identifier list in the authorization information; the third identifier included in the first information is not any identifier in the user identifier list in the authorization information; the first operation indicated by the first instruction included in the first information is not any operation indicated by the second instruction in the authorization information; and the fourth identifier included in the first information is not any identifier in the application identifier list in the authorization information.

[0236] In some embodiments, the first information includes a token; the second device first verifies the token, and if the token is insufficient for authorization verification, then performs authorization verification based on the authorization information.

[0237] In some embodiments, the second device determines whether to authorize the first device to perform a first operation on the object based on the claims in the token; if the token does not contain sufficient claims for authorization, it determines whether to authorize the first device to perform the first operation on the object based on authorization information.

[0238] Optionally, if the token includes all or part of the statements shown in Table 1, it is determined whether the first device is authorized to perform the first operation on the object based on the statements in the token.

[0239] For example, the second device determines that it authorizes the first device to perform a first operation on an object based on at least one of the following: the third identifier included in the first information is any identifier in the list of owner identifiers in the token; the third identifier included in the first information is any identifier in the list of user identifiers in the token; the first operation indicated by the first instruction included in the first information is any operation indicated by the second instruction in the token; and the fourth identifier included in the first information is any identifier in the list of application identifiers in the token.

[0240] For example, the second device determines that it does not authorize the first device to perform the first operation on the object based on at least one of the following: the third identifier included in the first information is not any identifier in the owner identifier list in the token; the third identifier included in the first information is not any identifier in the user identifier list in the token; the first operation indicated by the first instruction included in the first information is not any operation indicated by the second instruction in the token; and the fourth identifier included in the first information is not any identifier in the application identifier list in the token.

[0241] Optionally, if the second device determines that the token does not include at least one of the following statements: owner identifier list, user identifier list, second instruction, and application identifier list, then the token is insufficient for authorization verification; and / or, if the second device determines that the latest expiration time in the token is earlier than the current time, the token is also insufficient for authorization verification. In the case where the token is insufficient for authorization verification, authorization verification based on authorization information is required. In this embodiment, when the first information includes a token, the second device performs authorization verification based on the authorization information (i.e., determines whether to authorize the first device to perform the first operation on the object), which is similar to the implementation method where the first information does not include a token and the second device performs verification based on the authorization information. For an embodiment of authorization verification where the first information includes a token, please refer to: Embodiment of Authorization Verification Where the First Information Does Not Include a Token, which will not be repeated here.

[0242] Optionally, the second device may also perform verification in conjunction with the claims included in the token and the authorization information; if a claim is not included in the token, it may be further verified using the information included in the authorization information.

[0243] In some alternative embodiments, the second device invokes the service API to perform the first operation.

[0244] In some alternative embodiments, if the authorization verification is successful, the second device calls the service API to perform the first operation on the object.

[0245] In some alternative embodiments, the second device sends the service API call result to the first device.

[0246] In some alternative embodiments, the second device sends an eighth message to the first device, which includes the result of a service API call.

[0247] Optionally, the eighth information may include a third instruction or a fourth instruction; the third instruction is used to indicate that the first operation was successfully performed; the fourth instruction may be used to indicate at least one of the following: the first operation was not successfully performed, and the reason for the failure to perform the first operation.

[0248] Optionally, the eighth information may also include the result of calling the service API to perform the first operation, such as a confirmation indication of at least one of the objects including digital assets, spatial maps, and spatial anchors.

[0249] Optionally, the name of the eighth message is not limited; it may be, for example, a service API call response message.

[0250] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values ​​(e.g., a comparison with a predetermined value), but is not limited thereto.

[0251] The information processing method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2107. For example, step S2101 can be implemented as an independent embodiment; step S2102 can be implemented as an independent embodiment; step S2103 can be implemented as an independent embodiment; step S2104 can be implemented as an independent embodiment; step S2105 can be implemented as an independent embodiment; step S2106 can be implemented as an independent embodiment; step S2107 can be implemented as an independent embodiment; a combination of steps S2101 and S2102 can be implemented as an independent embodiment; a combination of steps S2101, S2102, and S2103 can be implemented as... The following can be implemented as independent embodiments: the combination of steps S2104 and S2105 can be implemented as an independent embodiment; the combination of steps S2105 and S2106 can be implemented as an independent embodiment; the combination of steps S2104, S2105, and S2106 can be implemented as an independent embodiment; the combination of steps S2104 and S2107 can be implemented as an independent embodiment; the combination of steps S2104 to S2107 can be implemented as an independent embodiment; the combination of steps S2101 to S2107 can be implemented as an independent embodiment.

[0252] In some embodiments, steps S2105 and S2107 may be performed in an alternate order or simultaneously.

[0253] In some embodiments, steps S2101, S2102 and S2103 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0254] In some embodiments, steps S2101, S2102, S2103, S2105 and S2106 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0255] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0256] like Figure 2B This is an interactive schematic diagram illustrating an information processing method according to an embodiment of this disclosure. For example... Figure 2B As shown, this disclosure relates to an information processing method for a communication system 100, the method comprising:

[0257] Step S2201: The first device sends the first information to the second device.

[0258] For optional implementations of step S2201, please refer to [link / reference]. Figure 2A Optional implementation methods in step S2104, and Figure 2A Other related parts in the embodiments involved will not be described in detail here.

[0259] In step S2202, the second device sends third information to the third device.

[0260] For optional implementations of step S2202, please refer to [link / reference]. Figure 2A Optional implementation methods in step S2105, and Figure 2A Other related parts in the embodiments involved will not be described in detail here.

[0261] In step S2203, the third device sends the second authorization information to the second device.

[0262] For optional implementations of step S2203, please refer to [link / reference]. Figure 2A Optional implementation methods in step S2106, and Figure 2A Other related parts in the embodiments involved will not be described in detail here.

[0263] In step S2204, the second device determines whether to authorize the first device to perform the first operation on the object.

[0264] For optional implementations of step S2204, please refer to [link / reference]. Figure 3 Optional implementation methods in step S2107, andFigure 3 Other related parts in the embodiments involved will not be described in detail here.

[0265] The information processing method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2204. For example, step S2201 may be implemented as a standalone embodiment; step S2202 may be implemented as a standalone embodiment; step S2203 may be implemented as a standalone embodiment; step S2204 may be implemented as a standalone embodiment; a combination of steps S2201, S2202, and S2203 may be implemented as a standalone embodiment; a combination of steps S2201 and S2204 may be implemented as a standalone embodiment; a combination of steps S2201 to S2204 may be implemented as a standalone embodiment.

[0266] In some embodiments, steps S2202 and S2204 may be performed in an alternate order or simultaneously.

[0267] In some embodiments, steps S2202 and S2203 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0268] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0269] Figure 2A This is an interactive schematic diagram illustrating an information processing method according to an embodiment of this disclosure. For example... Figure 2A As shown, this disclosure relates to an information processing method for a communication system 100, the method comprising one of the following steps:

[0270] In step S3101, the first device sends first information to the second device. The first information is used to request authorization for the first device to perform a first operation on the object. Optionally, the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

[0271] For optional implementations of step S3101, please refer to [link / reference]. Figure 4A Optional implementation methods in step S2104, and Figure 4A Other related parts in the embodiments involved will not be described in detail here.

[0272] In some embodiments, the first information further includes at least one of the following: a third identifier, wherein the third identifier is used to indicate the user requesting authorization; a fourth identifier, wherein the fourth identifier is used to indicate the application requesting authorization; and location information, wherein the location information is used to indicate the location of the first device.

[0273] In some embodiments, the first operation includes at least one of the following: creating an object; retrieving an object; invoking an object; updating an object; deleting an object.

[0274] In some embodiments, the second identifier includes at least one of the following: a digital asset identifier, wherein the digital asset identifier is used to indicate that the object is a digital asset; a spatial anchor identifier, wherein the spatial anchor identifier is used to indicate that the object is a spatial anchor; and a spatial map identifier, wherein the spatial map identifier is used to indicate that the object is a spatial map.

[0275] In some embodiments, the first information further includes a token; the token includes at least one of the following: an expiration time, wherein the expiration time is set as an expiration time declaration of the token; a fifth identifier, wherein the fifth identifier is used to indicate a first device and is set as a calling client declaration of the token; a sixth identifier, wherein the sixth identifier is used to indicate a service supported by the second device and is set as a scope declaration of the token; a seventh identifier, wherein the seventh identifier is used to indicate an object; a list of owner identifiers, wherein the list of owner identifiers is used to indicate the owner of the object; a list of user identifiers, wherein the list of user identifiers is used to indicate allowed users; a second indicator, wherein the second indicator is used to indicate allowed operations; and a list of application identifiers, wherein the list of application identifiers is used to indicate allowed applications.

[0276] In some embodiments, the method further includes: a first device sending second information to a third device, wherein the second information is used to request a token; and receiving a token sent by the third device.

[0277] In some embodiments, the second information further includes at least one of the following: a first identifier; a second identifier; a first indication; a third identifier, wherein the third identifier is used to indicate the user requesting authorization; a fourth identifier, wherein the fourth identifier is used to indicate the application requesting authorization; and location information, wherein the location information is used to indicate the location of the first device.

[0278] In some embodiments, the method further includes: the second device determining, based on authorization information, whether the first device is allowed to call the service API; and if the first device is allowed to call the service API, determining, based on the authorization information, whether to authorize the first device to perform a first operation on the object.

[0279] In some embodiments, the method further includes one of the following: the second device determines whether to authorize the first device to perform a first operation on the object based on the claims in the token; the second device determines whether to authorize the first device to perform the first operation on the object based on authorization information if the token does not contain sufficient claims for authorization.

[0280] In some embodiments, the second device determines whether to authorize the first device to perform a first operation on the object based on a statement in the token, including: the second device determines to authorize the first device to perform the first operation on the object based on at least one of the following: a third identifier included in the first information is an identifier in the owner identifier list in the token; a third identifier included in the first information is an identifier in the user identifier list in the token; a first operation indicated by a first instruction included in the first information is any operation indicated by a second instruction in the token; a fourth identifier included in the first information is any identifier in the application identifier list in the token.

[0281] In some embodiments, the authorization information includes at least one of the following: first authorization information; wherein the first authorization information is stored in a second device; and second authorization information; wherein the second authorization information is obtained from a third device.

[0282] In some embodiments, the method further includes: the second device sending third information to the third device, wherein the third information is used to request second authorization information; and receiving the second authorization information sent by the third device.

[0283] In some embodiments, the method includes: a third device receiving second information sent by a first device, wherein the second information is used to request a token; generating a token based on the second information; and sending the token to the first device.

[0284] In some embodiments, the third device generates a token based on the second information, including one of the following: the third device generates a token based on the fact that the third identifier included in the second information is any identifier in the owner identifier list in the second authorization information; wherein the owner identifier list is used to indicate the owner of the object; the third device generates a token based on the fact that the third identifier included in the second information is any identifier in the user identifier list in the second authorization information; wherein the user identifier list is used to indicate the user authorized to use the object; the third device requests the owner's authorization for the third identifier based on the fact that the user identifier list in the second authorization information is unavailable; and generates a token if the owner authorizes the third identifier.

[0285] In some embodiments, the method further includes one of the following: the third device obtains an owner identifier list from the second device if the owner identifier list does not exist in the second authorization information; the third device obtains a user identifier list from the second device if the user identifier list does not exist in the second authorization information; the third device obtains an operation list from the second device if the second authorization information does not contain a second instruction, the operation list including at least one permitted operation.

[0286] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0287] This disclosure relates to an information processing method that can ensure authorized access to metaverse support services within the CAPIF framework.

[0288] Example 1

[0289] Figure 4B This is a schematic diagram illustrating a digital asset service architecture supporting metaverse applications according to an embodiment of this disclosure. Figure 4B As shown, this architecture may include a Vertical Application Layer (VAL) and a Service Enabler Architecture Layer (SEAL). The architecture includes a User Equipment (UE) and a server; the UE connects to the server through the network system. The UE includes a VAL client and a Digital Asset (DA) client; the server may include a VAL server and a DA server. The VAL client connects to the VAL server via the VAL-UU interface; the DA client connects to the DA server via the DA-UU interface; the network system connects to the DA server via the N33 interface; this N33 interface is a service-oriented interface. Here, the UE can refer to a DA client (DA-C); the server can refer to a DA server (DA-S).

[0290] Figure 4C This is a schematic diagram illustrating a spatial anchor (SAn) functional model using the SEAL architecture according to an embodiment of this disclosure. Figure 4CAs shown, this model may include a UE and a server; the UE connects to the server through a network system. The UE includes a VAL client and a Space Anchor (SAn) client; the server may include a VAL server and a Space Anchor (SAn) server. The VAL client and VAL server connect via a VAL-UU interface; the SAn client and SAn server connect via a SAn-UU interface; the network system connects to the SAn server via a network interface. Here, the UE can refer to an SAn client (SAn-C); the server can refer to an SAn server (SAn-S).

[0291] Figure 4A This is a schematic diagram illustrating a spatial map (SM) functional model using the SEAL architecture according to an embodiment of this disclosure. Figure 4B As shown, the model may include a UE and a server; the UE connects to the server through a network system. The UE includes a VAL client and a Spatial Map (SM) client; the server may include a VAL server and a Spatial Map (SM) server. The VAL client and VAL server connect via a VAL-UU interface; the SM client and SM server connect via an SM-UU interface; the network system connects to the SM server via a network interface. Here, the UE can refer to an SM client (SM-C); the server can refer to an SM server (SM-S).

[0292] In the above Figure 4C , Figure 4D as well as Figure 4D In this framework, DA servers, SAn servers, and SM servers are all different types of SEAL servers. When a SEAL server is required to provide a CAPIF-compliant service API, it is recommended to map the SEAL server to the API Exposing Function (AEF) within the CAPIF framework. VAL servers (i.e., metaverse application servers), VAL clients built on top of DA clients, SAn clients, and SM clients can be mapped to API callers within the CAPIF framework. For example... Figure 4E As shown, a functional model of CAPIF is disclosed.

[0293] like Figure 4EAs shown, CAPIF is a framework for authorizing API callers (e.g., third-party application functions (AFs)) to access north-bound APIs of a communication system. The CAPIF framework may include CCF and AEF. API callers can send service APIs to AEFs via CCF; the CAPIF framework may also include API publishing functions (APFs) and / or API management functions. AEFs can use authorization information provided by CCFs (e.g., tokens, authorization policies) to authorize API callers' API call requests. CAPIF-1, CAPIF-2, CAPIF-3, CAPIF-4, and CAPIF-5 are interfaces between devices within the same domain. CAPIF-1e and CAPIF-2e are interfaces between devices in different domains.

[0294] In some embodiments, the authorization mechanism for accessing metaverse services, utilizing the mapping proposed in the CAPIF architecture above, may include the following authorization mechanisms: Scheme 1, using a Transport Layer Security Pre-Shared Key (TLS-PSK); Scheme 2, using a Transport Layer Security Public Key Infrastructure (TLS-PKI); Scheme 3, using TLS with an OAuth token.

[0295] Example 2

[0296] For both Scheme 1 and Scheme 2, it is proposed to configure the authorization information for enabling service access to the Metaverse locally in the AEF, i.e., the DA server or SAn server of the SM server. For example, for digital asset access, the authorization information can be included in the digital asset file (profile) stored in and managed by the DA server. The SM server will only obtain authorization information from the CCF if the DA server or SAn server of the SM server is missing any partial authorization information.

[0297] Figure 4F This is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. Figure 4F As shown, this disclosure relates to an information processing method, which includes:

[0298] Step S4101: The API caller sends a service API call request to the DA / SAn / SM server.

[0299] Optionally, the API caller sends a service API call request to the DA / SAn / SM server. This service API call request may include at least one of the following: a requester ID used as the caller ID, an object ID (e.g., a digital asset ID, spatial anchor ID, and / or spatial map ID), a user ID (indicating the user requesting the service operation), the requested operation (e.g., creation, retrieval, discovery, retrieval, reading, updating, and / or deletion of a digital asset), a metaverse application ID, and the requester's location. The object ID may be the target object ID.

[0300] Step S4102a: The DA / SAn / SM server obtains the CCF's authorization information.

[0301] Optionally, after receiving a service API request, the DA / SAn / SM server determines whether the API caller (i.e., the requester) is permitted to call the service API based on local authorization information (e.g., SS_DAProfileManagement). If the DA / SAn / SM server does not have the information required to authorize the service API proxy, it obtains the CCF's authorization information by sending at least one of the following to the CCF: requester ID, object ID, user ID, requested operation, metaverse application ID, and requester's location.

[0302] Step S4102: The DA / SAn / SM server performs authorization verification.

[0303] Optionally, the DA / SAn / SM server determines whether a requester is permitted to invoke the service API based on authorization information obtained from the CCF and locally stored authorization information. If the requester is permitted to invoke the service API, the server determines whether to authorize the requester to perform operations on the object based on authorization information (e.g., a DA file). For example, the DA file may include at least one of the following: a list of allowed users checked against the user ID; a list of allowed operations checked against the requested operation; a list of allowed applications checked against the metaverse application ID; and the current location checked against the requester's location.

[0304] Step S4103: The DA / SAn / SM server calls the service API to perform the operation.

[0305] Optionally, if the DA / SAn / SM server determines that the authorization is successful, it calls the service API to execute service logic (such as performing operations on objects).

[0306] In step S4104, the DA / SAn / SM server sends a service API call response to the API caller.

[0307] Optionally, the DA / SAn / SM server sends a service API call response (e.g., service API call result) to the API caller; the service API call result may be a successful operation (e.g., creating digital assets and / or spatial maps, etc.) or a reason for failure, or a confirmation indication of the object returned by the service API request (e.g., digital assets and / or spatial maps, etc.).

[0308] In some embodiments, the API caller may be an API caller in a VAL server or a VAL client; the API caller may be a first device in the previous embodiments; the DA / SAn / SM server may refer to at least one of a DA server, a SAn server, and an SM server; the DA / SAn / SM server may be a second device in the previous embodiments; and the CCF may be a third device in the previous embodiments.

[0309] The authorization information for the DA / SAn / SM server can be the first authorization information in the previous embodiments; the authorization information for the CCF can be the second authorization information. The service API call request can be the first information in the previous embodiments; the requester ID can be the first identifier in the previous embodiments; the object ID can be the second identifier in the previous embodiments; the user ID can be the third identifier in the previous embodiments; the requested operation can be the first operation in the previous embodiments; the metaverse application ID can be the fourth identifier in the previous embodiments; the requester's location can be the location indicated by the location information in the previous embodiments. The allowed user list can be the user identifier list in the previous embodiments; the allowed operation list can be the second indicator in the previous embodiments; the allowed application list can be the application identifier list in the previous embodiments.

[0310] The information processing method involved in the embodiments of this disclosure may include at least one of steps S4101 to S4104. For example, step S4101 may be implemented as an independent embodiment; step S4102a may be implemented as an independent embodiment; step S4102 may be implemented as an independent embodiment; step S4103 may be implemented as an independent embodiment; step S4104 may be implemented as an independent embodiment; a combination of steps S4101, S4102a, and S4102 may be implemented as an independent embodiment; a combination of steps S4101 to S4103 may be implemented as an independent embodiment; a combination of steps S4101 to S4104 may be implemented as an independent embodiment.

[0311] In some embodiments, steps S4102a and S4103 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0312] Example 3

[0313] For Option 3, it is recommended to configure the authorization information for service access in the Metaverse creation process locally within the CCF. The token (e.g., access) includes optional claims such as those in the standard declaration or attached based on the local authorization information.

[0314] Figure 5A This is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. Figure 5A As shown, this disclosure relates to an information processing method, which includes:

[0315] In step S4201, the API caller sends an access token request to the CCF.

[0316] Optionally, the API caller sends an access token request to the CCF, which includes the service API to be invoked (e.g., SS_DAProfileManagement); the access token request may also include at least one of the following: a requester ID used as the caller ID, an object ID (e.g., a digital asset ID, a spatial anchor ID, and / or a spatial map ID), a user ID (indicating the user requesting the service operation), the requested operation (e.g., creation, retrieval, discovery, invocation, reading, updating, and / or deletion of a digital asset), a metaverse application ID, and the requester's location, etc.

[0317] In step S4202, the CCF verifies the access token request. If the requesting user is not the object owner, RNAA is triggered; a token is generated.

[0318] Optionally, the CCF verifies the access token request; if the object ID and user ID are included in the access token request, it checks whether the user ID indicates that the user is the owner of the object based on local authorization information; if the user ID indicates that the user is not the owner of the object or the list of users allowed to request the object is unavailable, it triggers a Resource Owner Awareness North API Access (RNAA) process to obtain permission from the resource owner. If the CCF determines that there is no list of object owners, it can obtain the list of object owners from the DA / SAn / SM server.

[0319] Optionally, the CCF generates an access token based on local authorization information; the claims included in the access token may be as shown in Table 1.

[0320] In step S4203, the CCF sends an access token response message to the API caller, which includes a token.

[0321] In step S4204, the API caller sends a service API call request to the DA / SAn / SM server.

[0322] Optionally, the API caller sends a service API call request to the DA / SAn / SM server. The service API call request may include the service API to be called and an access token. The service API call request may also include at least one of the following: a requester ID used as the caller ID, an object ID (e.g., a digital asset ID, a spatial anchor ID, and / or a spatial map ID), a user ID (indicating the user requesting the service operation), the requested operation (e.g., creation, retrieval, discovery, invocation, reading, updating, and / or deletion of a digital asset), a metaverse application ID, and the requester's location.

[0323] Step S4205: The DA / SAn / SM server verifies the access token.

[0324] Optionally, the DA / SAn / SM server verifies the integrity of the access token by verifying the CCF signature. If the access token verification is successful, the DA / SAn / SM server verifies the service API call request based on the claims in the access token. After checking the standard claims in the access token, the DA / SAn / SM server checks the optional claims (if the access token includes optional claims), specifically whether the object ID in the service API call request matches the object ID (targetObject_ID) declared in the token, whether the user ID in the service API call request is in the owner ID_list declared in the token, whether the user ID in the service API call request is in the user ID_list declared in the token, whether the requested operation in the service API call request is in the operation_list declared in the token, and / or whether the metaverse application ID in the service API call request is in the application ID_list declared in the token; if so, authorization is successful.

[0325] Optionally, a standard declaration may include at least one of the following: an expiration date declaration, a calling client declaration, and a scope declaration. Optional declarations may include at least one of the following: an object ID declaration, an owner ID list declaration, a user ID list declaration, an operation list declaration, and an application ID list declaration.

[0326] Step S4206: The DA / SAn / SM server performs authorization verification.

[0327] Optionally, the DA / SAn / SM server performs authorization verification based on the access token verification and claim check, if the access token does not include sufficient optional claims for authorization, or if the DA / SAn / SM server has local authorization information (e.g., a DA file) that can be used for authorization verification. Alternatively, the operations described in steps S4102a and S4102 can be performed.

[0328] Optionally, the CCF and SEAL servers (i.e., DA / SAn / SM servers) are configured so that there are no conflicting authorization information in the CCF and SEAL servers.

[0329] Step S4207: The DA / SAn / SM server calls the service API to perform the operation.

[0330] Optionally, if the DA / SAn / SM server determines that the authorization is successful, it calls the service API to execute service logic (such as performing operations on objects).

[0331] In step S4208, the DA / SAn / SM server sends a service API call response to the API caller.

[0332] Optionally, the DA / SAn / SM server sends a service API call response (e.g., service API call result) to the API caller; the service API call result may be a successful operation (e.g., creating digital assets and / or spatial maps, etc.) or a reason for failure, or a confirmation indication of the object returned by the service API request (e.g., digital assets and / or spatial maps, etc.).

[0333] In some embodiments, the API caller may be an API caller in a VAL server or a VAL client; the API caller may be a first device in the previous embodiments; the DA / SAn / SM server may refer to at least one of a DA server, a SAn server, and an SM server; the DA / SAn / SM server may be a second device in the previous embodiments; and the CCF may be a third device in the previous embodiments.

[0334] The authorization information for the DA / SAn / SM server can be the first authorization information in the previous embodiments; the authorization information for the CCF can be the second authorization information. The access token request can be the second information in the previous embodiments; the access token can be the token in the previous embodiments. The service API call request can be the first information in the previous embodiments; the requester ID can be the first identifier in the previous embodiments; the object ID can be the second identifier in the previous embodiments; the user ID can be the third identifier in the previous embodiments; the requested operation can be the first operation in the previous embodiments; the metaverse application ID can be the fourth identifier in the previous embodiments; the requester's location can be the location indicated by the location information in the previous embodiments. The allowed user list can be the user identifier list in the previous embodiments; the allowed operation list can be the second indicator in the previous embodiments; the allowed application list can be the application identifier list in the previous embodiments.

[0335] The information processing method involved in the embodiments of this disclosure may include at least one of steps S4201 to S4204. For example, step S4201 can be implemented as an independent embodiment; step S4202 can be implemented as an independent embodiment; step S4203 can be implemented as an independent embodiment; step S4204 can be implemented as an independent embodiment; step S4205 can be implemented as an independent embodiment; step S4206 can be implemented as an independent embodiment; a combination of steps S4201, S4202, and S4203 can be implemented as an independent embodiment; a combination of steps S4204, S4205, and S4206 can be implemented as an independent embodiment; a combination of steps S4201 to S4206 can be implemented as an independent embodiment; a combination of steps S4201 to S4208 can be implemented as an independent embodiment.

[0336] In some embodiments, steps S4101, S4102, S4103, S4207, and S4208 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0337] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0338] This disclosure also proposes an apparatus (also referred to as a communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is proposed that includes units or modules for implementing the steps performed by network devices (e.g., access network devices, core network functional nodes, core network devices (e.g., first device, second device, third device, terminal, etc.) in any of the above methods.

[0339] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an Application-Specific Integrated Circuit (ASIC), and the functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a Programmable Logic Device (PLD), such as a Field Programmable Gate Array (FPGA), which can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0340] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0341] Figure 5B This is a schematic diagram of the structure of the first device 5100 provided in an embodiment of this disclosure. For example... Figure 5B As shown, the first device 5100 includes a first transceiver module 5101. In some embodiments, the first transceiver module 5101 is used to send first information to the second device. Optionally, the first transceiver module 5101 is used to perform at least one of the sending and / or receiving steps (e.g., steps S2101, S2103, and / or S2104, etc., but not limited thereto) performed by the first device 5100 in any of the above methods, which will not be elaborated here. In some embodiments, the first device 5100 may be a first processing module.

[0342] Figure 5C This is a schematic diagram of the structure of the second device 5200 provided in an embodiment of this disclosure. For example... Figure 5CAs shown, the second device 5200 includes at least one of a second transceiver module 5201 and a second processing module 5202. In some embodiments, the second transceiver module 5201 is used to acquire first information. Optionally, the second transceiver module 5201 is used to perform at least one of the sending and / or receiving steps performed by the second device 5200 in any of the above methods (e.g., steps S2104, S2105, and / or S2106, etc., but not limited thereto), which will not be elaborated here. In some embodiments, the second processing module 5202 is used to determine whether to authorize the first device to perform a first operation on an object. Optionally, the second processing module 5202 is used to perform at least one of the processing steps performed by the second device 5200 in any of the above methods (e.g., step S2107, etc., but not limited thereto), which will not be elaborated here.

[0343] Figure 6A This is a schematic diagram of the structure of the third device 5300 provided in an embodiment of this disclosure. For example... Figure 6A As shown, the third device 5300 includes at least one of a third transceiver module 5301 and a third processing module 5302. In some embodiments, the third transceiver module 5301 is used to acquire third information. Optionally, the third transceiver module 5301 is used to perform at least one of the sending and / or receiving steps (e.g., steps S2101, S2103, S2105, and / or S2106, etc., but not limited thereto) performed by the third device 5300 in any of the above methods, which will not be elaborated here. In some embodiments, the third processing module 5302 is used to generate a token. Optionally, the third processing module 5302 is used to perform at least one of the processing steps (e.g., step S2102, etc., but not limited thereto) performed by the third device 5300 in any of the above methods, which will not be elaborated here.

[0344] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, which may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver. For example, the first transceiver module described above includes a first transmitting module and / or a first receiving module. For example, the second transceiver module described above includes a second transmitting module and / or a second receiving module.

[0345] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.

[0346] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.

[0347] Figure 6AThis is a schematic diagram of the structure of the communication device 6100 proposed in this embodiment. The communication device 6100 can be a network device (e.g., access network device (e.g., base station), core network device (e.g., first device, second device, third device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 6100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0348] like Figure 6B As shown, the communication device 6100 is used to execute any of the above methods. In some embodiments, the communication device 6100 includes one or more processors 6101. The processor 6101 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 6100 is used to execute any of the above methods. Optionally, one or more processors 6101 are used to invoke instructions to cause the communication device 6100 to execute any of the above methods.

[0349] In some embodiments, the communication device 6100 further includes one or more transceivers 6102. When the communication device 6100 includes one or more transceivers 6102, the transceiver 6102 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2103, S2104, S2105, and / or S2106, but not limited thereto), and the processor 6101 performs at least one of other steps (e.g., steps S2102 and / or S2107, but not limited thereto). In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.

[0350] In some embodiments, the communication device 6100 further includes one or more memories 6103 for storing data and / or instructions. Optionally, one or more processors 6101 are used to invoke instructions stored in the memory 6103 to cause the communication device 6100 to perform any of the above methods. Optionally, all or part of the memory 6103 may also be located outside the communication device 6100. In an optional embodiment, the communication device 6100 may include one or more interface circuits 6104. Optionally, the interface circuit 6104 is connected to the memory 6103 and can be used to receive data and / or instructions from the memory 6103 or other devices, and can be used to send data and / or instructions to the memory 6103 or other devices. For example, the interface circuit 6104 can read data and / or instructions stored in the memory 6103 and send the data and / or instructions to the processor 6101.

[0351] The communication device 6100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 6100 described in this disclosure is not limited thereto, and the structure of the communication device 6100 may vary. Figure 6B The limitations. The communication device may be a standalone device or part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally including storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0352] ​ This is a schematic diagram of the structure of chip 6200 according to an embodiment of this disclosure. For cases where the communication device 6100 can be a chip or a chip system, please refer to... ​ The diagram shown is a schematic representation of the structure of chip 6200, but it is not limited to this.

[0353] Chip 6200 includes one or more processors 6201. Chip 6200 is used to perform any of the methods described above.

[0354] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data and / or instructions. Optionally, all or part of the memories 6203 may be located outside of chip 6200. Optionally, interface circuit 6202 is connected to memory 6203, and interface circuit 6202 can be used to receive data and / or instructions from memory 6203 or other devices, and interface circuit 6202 can be used to send data and / or instructions to memory 6203 or other devices. For example, interface circuit 6202 can read data and / or instructions stored in memory 6203 and send the data and / or instructions to processor 6201.

[0355] In some embodiments, the interface circuit 6202 performs at least one of the communication steps such as sending and / or receiving in the above-described method (e.g., steps S2101, S2103, S2104, S2105, and / or S2106, but not limited thereto). The interface circuit 6202 performing the communication steps such as sending and / or receiving in the above-described method refers, for example, to the interface circuit 6202 performing data and / or instruction interaction between the processor 6201, the chip 6200, the memory 6203, or the transceiver device. In some embodiments, the processor 6201 performs at least one of other steps (e.g., steps S2102 and / or S2107, but not limited thereto).

[0356] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0357] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0358] This disclosure also proposes a program product, including a program and / or instructions, which, when executed by a communication device, cause the communication device to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.

[0359] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Claims

1. An information processing method, characterized in that, Performed by the first device, including: Sending first information to a second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

2. The method according to claim 1, characterized in that, The first information also includes at least one of the following: A third identifier, wherein the third identifier is used to indicate the user requesting authorization; A fourth identifier, wherein the fourth identifier is used to indicate the application requesting authorization; Location information, wherein the location information is used to indicate the location of the first device.

3. The method according to claim 1 or 2, characterized in that, The first operation includes at least one of the following: Create the object; Retrieve the object; Invoke the object; Update the object; Delete the object.

4. The method according to any one of claims 1 to 3, characterized in that, The second identifier includes at least one of the following: Digital asset identifier, wherein the digital asset identifier is used to indicate that the object is a digital asset; A spatial anchor identifier, wherein the spatial anchor identifier is used to indicate that the object is a spatial anchor; A spatial map identifier, wherein the spatial map identifier is used to indicate that the object is a spatial map.

5. The method according to any one of claims 1 to 4, characterized in that, The first information also includes a token; the token includes at least one of the following: Expiration time, wherein the expiration time is set as the expiration time declaration of the token; The fifth identifier, wherein the fifth identifier is used to indicate the first device, and the fifth identifier is set as the calling client declaration of the token; A sixth identifier, wherein the sixth identifier is used to indicate the services supported by the second device, and the sixth identifier is set as a scope statement of the token; The seventh identifier, wherein the seventh identifier is used to indicate an object; A list of owner identifiers, wherein the list of owner identifiers is used to indicate the owner of the object; User ID list, wherein the user ID list is used to indicate allowed users; The second instruction, wherein the second instruction is used to indicate the permitted operation; An application identifier list, wherein the application identifier list is used to indicate allowed applications.

6. The method according to claim 5, characterized in that, The method further includes: Send a second message to a third device, wherein the second message is used to request the token; Receive the token sent by the third device.

7. The method according to claim 6, characterized in that, The second information also includes at least one of the following: The first identifier; The second identifier; The first instruction; A third identifier, wherein the third identifier is used to indicate the user requesting authorization; A fourth identifier, wherein the fourth identifier is used to indicate the application requesting authorization; Location information, wherein the location information is used to indicate the location of the first device.

8. An information processing method, characterized in that, Performed by a second device, including: The system receives first information sent by a first device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

9. The method according to claim 8, characterized in that, The first information also includes at least one of the following: A third identifier, wherein the third identifier is used to indicate the user requesting authorization; A fourth identifier, wherein the fourth identifier is used to indicate the application requesting authorization; Location information, wherein the location information is used to indicate the location of the first device.

10. The method according to claim 8 or 9, characterized in that, The first operation includes at least one of the following: Create the object; Retrieve the object; Invoke the object; Update the object; Delete the object.

11. The method according to any one of claims 8 to 10, characterized in that, The second identifier includes at least one of the following: Digital asset identifier, wherein the digital asset identifier is used to indicate that the object is a digital asset; A spatial anchor identifier, wherein the spatial anchor identifier is used to indicate that the object is a spatial anchor; A spatial map identifier, wherein the spatial map identifier is used to indicate that the object is a spatial map.

12. The method according to any one of claims 8 to 11, characterized in that, The first information also includes a token; the token includes at least one of the following: Expiration time, wherein the expiration time is set as the expiration time declaration of the token; The fifth identifier, wherein the fifth identifier is used to indicate the first device, and the fifth identifier is set as the calling client declaration of the token; A sixth identifier, wherein the sixth identifier is used to indicate the services supported by the second device, and the sixth identifier is set as a scope statement of the token; The seventh identifier, wherein the seventh identifier is used to indicate an object; A list of owner identifiers, wherein the list of owner identifiers is used to indicate the owner of the object; User ID list, wherein the user ID list is used to indicate allowed users; The second instruction, wherein the second instruction is used to indicate the permitted operation; Application identifier list, wherein the application identifier list is used to indicate permitted metaverse applications.

13. The method according to any one of claims 8 to 11, characterized in that, The method further includes: Based on the authorization information, determine whether the first device is allowed to call the service API; If the first device is allowed to call the service API, based on the authorization information, it is determined whether to authorize the first device to perform the first operation on the object.

14. The method according to claim 12, characterized in that, The method also includes one of the following: Based on the statement in the token, determine whether to authorize the first device to perform the first operation on the object; If the token does not contain sufficient claims for authorization, based on the authorization information, it is determined whether to authorize the first device to perform the first operation on the object.

15. The method according to claim 14, characterized in that, Based on the statement in the token, determining whether to authorize the first device to perform the first operation on the object includes: The first operation authorized to be performed by the first device on the object is determined based on at least one of the following: The third identifier included in the first information is an identifier in the list of owner identifiers in the token; The third identifier included in the first information is an identifier in the user identifier list in the token; The first operation indicated by the first indication included in the first information is an operation in the operation indicated by the second indication in the token; The fourth identifier included in the first information is an identifier in the list of application identifiers in the token.

16. The method according to any one of claims 13 to 15, characterized in that, The authorization information includes at least one of the following: First authorization information; wherein, the first authorization information is stored in the second device; Second authorization information; wherein the second authorization information is obtained from the third device.

17. The method according to claim 16, characterized in that, The method further includes: Send third information to a third device, wherein the third information is used to request the acquisition of the second authorization information; Receive the second authorization information sent by the third device.

18. An information processing method, characterized in that, Performed by a third device, including: The device receives third information sent by a second device, wherein the third information is used to request second authorization information; the second authorization information is used by the second device to determine whether to authorize the first device to perform a first operation on the object. Send the second authorization information to the second device.

19. The method according to claim 18, characterized in that, The method includes: Receive second information sent by the first device, wherein the second information is used to request a token; The token is generated based on the second information; Send the token to the first device.

20. The method according to claim 19, characterized in that, The generation of the token based on the second information includes one of the following: The token is generated based on the fact that the third identifier included in the second information is an identifier in the owner identifier list in the second authorization information; wherein, the owner identifier list is used to indicate the owner of the object; The token is generated based on the fact that the third identifier included in the second information is an identifier in the user identifier list in the second authorization information; wherein, the user identifier list is used to indicate the user who is allowed to use the object; If the user identifier list in the second authorization information is unavailable, the owner is requested to authorize the third identifier; if the owner authorizes the third identifier, the token is generated.

21. The method according to claim 20, characterized in that, The method also includes one of the following: If the owner identifier list is not present in the second authorization information, the owner identifier list is obtained from the second device; If the user identifier list is not present in the second authorization information, the user identifier list is obtained from the second device; If the second instruction is not present in the second authorization information, an operation list is obtained from the second device, the operation list including at least one permitted operation.

22. The method according to any one of claims 19 to 21, characterized in that, The token includes at least one of the following: Expiration time, wherein the expiration time is set as the expiration time declaration of the token; The fifth identifier, wherein the fifth identifier is used to indicate the first device, and the fifth identifier is set as the calling client declaration of the token; A sixth identifier, wherein the sixth identifier is used to indicate the services supported by the second device, and the sixth identifier is set as a scope statement of the token; The seventh identifier, wherein the seventh identifier is used to indicate an object; Owner ID list, wherein the owner ID list is used to indicate the owner of the object; User ID list, wherein the user ID list is used to indicate allowed users; The second instruction, wherein the second instruction is used to indicate the permitted operation; An application identifier list, wherein the application identifier list is used to indicate allowed applications.

23. An information processing method, characterized in that, Performed by a communication system, the communication system including a first device and a second device; the method includes: The first device sends first information to the second device, wherein the first information is used to request authorization for the first device to perform a first operation on an object; the first information includes at least one of the following: a first identifier, a second identifier, and a first indication; the first identifier is used to indicate the first device; the second identifier is used to indicate the object; and the first indication is used to indicate the first operation.

24. A communication device, characterized in that, The communication device is used to perform the information processing method according to any one of claims 1 to 7, or claims 8 to 17, or claims 18 to 22.

25. A communication system, characterized in that, include: A first device, a second device, and a third device; wherein the first device is configured to implement the information processing method of any one of claims 1 to 7, the second device is configured to implement the information processing method of any one of claims 8 to 17, and the third device is configured to implement the information processing method of any one of claims 18 to 22.

26. A storage medium storing instructions, characterized in that, When the instructions are executed on the communication device, the communication device performs the information processing method as described in any one of claims 1 to 7, or claims 8 to 17, or claims 18 to 22.

27. A computer program product, comprising at least one of a program and instructions, characterized in that, When at least one of the programs or instructions is executed by a communication device, it implements the information processing method according to any one of claims 1 to 7, or claims 8 to 17, or claims 18 to 22.