Information processing method and device, communication system and storage medium

CN121866748APending Publication Date: 2026-04-14BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-11
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

The lack of a mechanism in the CAPIF system to revoke the relevant authorizations of resource owners makes it impossible to effectively manage the authorization status.

Method used

The first device sends a first message to the second device to request the revocation of the relevant authorization of the resource owner, and the second device processes the request to revoke the authorization.

Benefits of technology

It enables the effective revocation of authorization for resource owners in the CAPIF system, ensuring the management and control of authorization status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121866748A_ABST
    Figure CN121866748A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information processing method and device, a communication system and a storage medium. The information processing method is executed by a first device and comprises the steps that a first message is sent to a second device, the first message is used for requesting to cancel related authorization of a resource owner, and the resource owner is related to the first device.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, device, communication system and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to an information processing method, device, communication system and storage medium. BACKGROUND

[0002] In the technical field of communication, a Common Application Program Interface (API) Framework (CAPIF) system is introduced. The CAPIF system does not provide a corresponding mechanism for revocation of a resource owner.

[0003] SUMMARY

[0004] Embodiments of the present disclosure need to solve the problem that there is no mechanism in the CAPIF system to cause the related authorization of a resource owner to be revoked.

[0005] According to a first aspect of embodiments of the present disclosure, an information processing method is provided, executed by a first device, comprising: sending a first message to a second device, wherein the first message is used to request revocation of related authorization of a resource owner, and the resource owner is related to the first device.

[0006] According to a second aspect of embodiments of the present disclosure, an information processing method is provided, executed by a second device, wherein the second device is a fourth device, a fifth device or a sixth device, comprising: obtaining a first message, wherein the first message is used to request revocation of related authorization of a resource owner, and the resource owner is related to the first device.

[0007] According to a third aspect of embodiments of the present disclosure, an information processing method is provided, comprising: a first device sending a first message to a second device, wherein the first message is used to request revocation of authorization of a resource owner, and the resource owner is related to the first device.

[0008] According to a fourth aspect of embodiments of the present disclosure, a first network function is provided, comprising: a first transceiver module configured to send a first message to a second device, wherein the first message is used to request revocation of related authorization of a resource owner, and the resource owner is related to the first device.

[0009] According to a fifth aspect of embodiments of the present disclosure, a second network function is provided, comprising: a second transceiver module configured to obtain a first message, wherein the first message is used to request revocation of related authorization of a resource owner, and the resource owner is related to the first device.

[0010] According to a sixth aspect of the embodiments of the present disclosure, a communication device is provided, including one or more processors; wherein the communication device is configured to perform the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0011] According to a seventh aspect of the embodiments of the present disclosure, a communication system is provided, including: a first network function and a second network function; wherein the first network function is configured to perform the method described in the optional implementation of the first aspect, and the second network function is configured to perform the method described in the optional implementation of the second aspect.

[0012] According to an eighth aspect of the embodiments of the present disclosure, a storage medium is provided, the storage medium stores instructions, when the instructions are run on a communication device, the communication device performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0013] According to a ninth aspect of the embodiments of the present disclosure, a computer program product is provided, the computer program product includes a computer program or instructions, when the computer program or instructions are executed by a processor, the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect is implemented.

[0014] The embodiments of the present disclosure can initiate revocation of authorization related to resource owners in the CAPIF system. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0016] FIG. 1 is a structural schematic diagram of an information processing system according to an embodiment of the present disclosure.

[0017] FIG. 2A is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0018] FIG. 2B is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0019] FIG. 2C is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0020] FIG. 2D is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0021] FIG. 2E is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure. [0021.1][Corrected according to Rule 91 on 21.08.2024] FIG. 2F is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure.

[0022] FIG. 3A is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0023] FIG. 3B is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0024] FIG. 4A is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0025] FIG. 4B is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0026] FIG. 4C is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0027] FIG. 4D is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0028] FIG. 5 is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure.

[0029] FIG. 6A is a diagram illustrating a summary of a user authorization revocation mechanism, according to an embodiment of the present disclosure.

[0030] FIG. 6B is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0031] FIG. 6C is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0032] FIG. 6D is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0033] FIG. 6E is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0034] FIG. 6F is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0035] [Corrected according to Rule 91 on 21.08.2024] FIG. 6G is a flow diagram of a method for processing information, according to an embodiment of the present disclosure.

[0036] FIG. 7A is a structural diagram of a first device, according to an embodiment of the present disclosure.

[0037] FIG. 7B is a structural schematic diagram of a second device according to an embodiment of the present disclosure.

[0038] FIG. 8A is a structural schematic diagram of a communication device according to an embodiment of the present disclosure.

[0039] FIG. 8B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0040] Embodiments of the present disclosure provide an information processing method, device, communication system and storage medium.

[0041] In a first aspect, embodiments of the present disclosure provide an information processing method, performed by a first device, comprising: sending a first message to a second device, wherein the first message is used to request revocation of a related authorization of a resource owner, and the resource owner is related to the first device.

[0042] In the above embodiments, the CAPIF system can be enabled to initiate revocation of the related authorization of the resource owner.

[0043] In some embodiments of the first aspect, the first message further comprises at least one of: a first identifier, wherein the first identifier is an identifier of the resource owner; a second identifier, wherein the second identifier is an identifier of a third device; type information, wherein the type information is used to indicate a data type that needs to be revoked; and purpose information, wherein the purpose information is used to indicate a data processing purpose that needs to be revoked.

[0044] In the above embodiments, it can be implemented to determine which third device, which data type and / or which data processing purpose related authorization.

[0045] In some embodiments of the first aspect, the method further comprises: receiving a first response sent by the second device, wherein the first response is used to indicate that the related authorization of the resource owner is successfully revoked.

[0046] In the above embodiments, the revocation of the related authorization of the resource owner can be completed.

[0047] In some embodiments of the first aspect, the method further comprises: sending first information to the second device, wherein the first information is used to indicate the identity of the resource owner related to the first device; and receiving a third identifier sent by the second device, wherein the third identifier is determined by the second device based on the first information after determining that the identity of the resource owner is authenticated, and the third identifier is: a first identifier in the first information indicating the identity of the resource owner, or an identifier different from the first identifier generated by the second device for the resource owner.

[0048] In the above embodiments, authentication of the identity of the resource owner can be implemented.

[0049] In a second aspect, the embodiments of the present disclosure provide an information processing method, executed by a second device, the second device being a fourth device, a fifth device or a sixth device, comprising: obtaining a first message, wherein the first message is used to request revocation of authorization related to a resource owner, and the resource owner is related to a first device.

[0050] In some embodiments of the second aspect, in some embodiments, the first message further comprises at least one of: a first identifier, wherein the first identifier is an identifier of the resource owner; a second identifier, wherein the second identifier is an identifier of a third device; type information, wherein the type information is used to indicate a type of data that needs to be revoked; and purpose information, wherein the purpose information is used to indicate a data processing purpose that needs to be revoked.

[0051] In some embodiments of the second aspect, in some embodiments, the second device is the fourth device or the fifth device, and the method further comprises: receiving first information sent by the first device, wherein the first information is used to indicate the identity of the resource owner; determining that the identity authentication of the resource owner is passed based on the first information; determining a third identifier of the first device; and sending the third identifier to the first device, wherein the third identifier is: the first identifier in the first information that indicates the identity of the resource owner, or an identifier generated by the second device for the resource owner and different from the first identifier.

[0052] In some embodiments of the second aspect, in some embodiments, the second device is the fourth device, and obtaining the first message comprises one of: receiving the first message sent by the first device; or the second device is the fifth device, and obtaining the first message comprises one of: receiving the first message sent by the first device; or the second device is the sixth device, and obtaining the first message comprises one of: receiving the first message sent by the first device; and receiving the first message sent by the fifth device.

[0053] In some embodiments of the second aspect, in some embodiments, the second device is the fourth device or the fifth device, and the method further comprises: in a case where the first identifier is different from the third identifier, sending second information to the first device, wherein the second information is used to indicate a revocation request failure and / or a failure reason of the revocation request failure, and the failure reason is that the first identifier is not an identifier of an authenticated resource owner; and the third identifier is an identifier of the authenticated resource owner.

[0054] In the above embodiments, revocation of authorization related to only an authenticated resource owner can be implemented; and a reason for failure of revocation of authorization related to the resource owner can be known.

[0055] In some embodiments of the second aspect, in some embodiments, the method further comprises one of: in a case that the first identifier is the same as the third identifier, identifying the token to be revoked based on at least one of: the first identifier, the service information, the type information, and the purpose information; in a case that the first message does not comprise the first identifier, identifying the token to be revoked based on at least one of: the third identifier, the service information, the type information, and the purpose information; wherein the type information and / or the purpose information are used to determine the service information.

[0056] In the above embodiments, the token to be revoked can be successfully identified.

[0057] In some embodiments of the second aspect, in some embodiments, the method further comprises: sending, to the seventh device, a second message, wherein the second message is used to request revocation of the authorization, and the second message comprises at least one of: the first identifier, the second identifier, the type information, and the purpose information; and receiving a second response sent by the seventh device, wherein the second response is used to indicate that the authorization is successfully revoked; wherein the second device is the fourth device, and the seventh device is: the third device and / or the eighth device; or the second device is the fifth device, and the seventh device is the ninth device and / or the sixth device; or the second device is the fifth device, and the seventh device is the ninth device and / or the third device.

[0058] In some embodiments of the second aspect, in some embodiments, the method further comprises: sending, to the first device, a first response, wherein the first response is used to indicate that the authorization of the resource owner is successfully revoked.

[0059] In some embodiments of the second aspect, in some embodiments, the second device is the fifth device, and the method further comprises: receiving a second message sent by the sixth device, wherein the second message is used to request revocation of the authorization, and the second message comprises at least one of: the first identifier, the second identifier, the type information, and the purpose information; and sending, to the sixth device, a second response, wherein the second response is used to indicate that the authorization is successfully revoked.

[0060] In some embodiments of the second aspect, in some embodiments, the second message further comprises at least one of: location information of the ninth device, address information of the ninth device, and identifier information of the ninth device; the method further comprises: based on at least one of the location information, the address information, and the identifier information, sending the second message to the ninth device; and receiving a second response sent by the ninth device, wherein the second message is used to request revocation of the authorization, and the second response is used to indicate that the authorization is successfully revoked; and / or, based on the second identifier, sending the second message to a third device corresponding to the second identifier; and receiving a second response sent by the third device.

[0061] In some embodiments of the second aspect, in some embodiments, the method further comprises: receiving a first response sent by the sixth device, wherein the first response is used to indicate that the related authorization of the resource owner is successfully revoked; and sending the first response to the first device.

[0062] In some embodiments of the second aspect, in some embodiments, before receiving the second message sent by the sixth device, the method further comprises: in a case where it is determined that the service related to the first message is published to the sixth device, sending the first message to the sixth device; wherein the sixth device is capable of generating a token for accessing a device in a domain where the fifth device is located.

[0063] In some embodiments of the second aspect, in some embodiments, the second device is the sixth device, and the method further comprises: in a case where the first identifier is different from the third identifier, sending second information to the first device, wherein the second information is used to indicate that the revocation request fails and / or a failure reason of the revocation request, and the failure reason is that the first identifier is not an identifier of the authenticated resource owner; and the third identifier is an identifier of the authenticated resource owner.

[0064] In some embodiments of the second aspect, in some embodiments, the method further comprises at least one of: in a case where the first identifier is the same as the third identifier, identifying the token that needs to be revoked based on at least one of the following: the first identifier, the service information, the type information, and the purpose information; and in a case where the first message does not include the first identifier, identifying the token that needs to be revoked based on at least one of the following: the third identifier, the service information, the type information, and the purpose information; wherein the type information and / or the purpose information are used to determine the service information.

[0065] In some embodiments of the second aspect, in some embodiments, the method further comprises: sending a second message to the tenth device, wherein the second message is used to request to revoke the authorization, and the second message includes at least one of the following: the first identifier, the second identifier, the type information, and the purpose information; and the tenth device is at least one of the following: the third device, the fifth device, and the eleventh device; and receiving a second response sent by the tenth device, wherein the second response is used to indicate that the authorization is successfully revoked.

[0066] In some embodiments of the second aspect, in some embodiments, when the tenth device is the fifth device, the second message includes the second identifier, and the second identifier is determined based on information in the identified token that needs to be revoked; and the fifth device determines based on the identified token that needs to be revoked.

[0067] In some embodiments of the second aspect, in some embodiments, the receiving of the first message sent by the first device comprises: receiving, by the fifth device, the first message sent by the first device, wherein the first message is sent by the first device in a case where the fifth device determines that the service is capable of publishing the first message to the sixth device.

[0068] In a third aspect, the embodiments of the present disclosure provide an information processing method, comprising: sending, by a fifth device, a first response to a first device, wherein the first response is used to indicate that the related authorization of a resource owner is successfully revoked.

[0069] In a fourth aspect, the embodiments of the present disclosure provide a first network function, comprising: a first transceiver module configured to send a first message to a second device, wherein the first message is used to request to revoke the related authorization of a resource owner, and the resource owner is related to a first device.

[0070] In a fifth aspect, the embodiments of the present disclosure provide a second network function, comprising: a second transceiver module configured to obtain a first message, wherein the first message is used to request to revoke the related authorization of a resource owner, and the resource owner is related to a first device.

[0071] According to a sixth aspect of the embodiments of the present disclosure, a communication device is provided, comprising one or more processors; wherein the communication device is configured to perform the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0072] According to a seventh aspect of the embodiments of the present disclosure, a communication system is provided, comprising: a first network function and a second network function; wherein the first network function is configured to perform the method described in the optional implementation of the first aspect, and the second network function is configured to perform the method described in the optional implementation of the second aspect.

[0073] According to an eighth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, when the instructions run on a communication device, the communication device performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0074] According to a ninth aspect of the embodiments of the present disclosure, a computer program product is provided, and the computer program product comprises a computer program or instructions, and the computer program or instructions are executed by a processor to implement the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0075] In a tenth aspect, the embodiments of the present disclosure provide a computer program, when running on a computer, causes the computer to perform the information processing method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0076] Eleventhly, embodiments of this disclosure provide a chip or chip system; the chip or chip system includes processing circuitry configured to perform the methods described according to the first, second, third, or alternative implementations of the first, second, and third aspects above.

[0077] It is understood that the aforementioned devices (such as the first device, the second device, etc.), communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0078] This disclosure provides an information processing method, apparatus, communication system, and storage medium. In some embodiments, the terms "information processing method" and "information processing device" are interchangeable, as are "information processing system" and "communication system".

[0079] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0080] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be used interchangeably. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0081] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0082] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0083] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0084] In some embodiments, the terms “at least one of”, “one or more of”, “a plurality of”, “multiple”, and the like can be replaced with each other.

[0085] In some embodiments, the description of “at least one of A, B”, “A and / or B”, “in a case A, in another case B”, “in response to a case A, in response to a case B”, and the like can include the following technical solutions according to the case: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are executed). When there are more branches such as A, B, C, and the like, the above is similar.

[0086] In some embodiments, the description of “A or B” and the like can include the following technical solutions according to the case: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above is similar.

[0087] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments in the context of the description, and should not be construed as redundant limitation because of the use of the prefix words. For example, the ordinal words in front of the description objects "field" in "first field" and "second field" do not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the ordinal words in front of the description objects "level" in "first level" and "second level" do not limit the priority between the "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are "information", and "first information" and "second information" can be the same information or different information, and the contents thereof can be the same or different.

[0088] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0089] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0090] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0091] In some embodiments, the apparatus and the like can be interpreted as physical or virtual, and the name thereof is not limited to the name recorded in the embodiments. The terms of "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0092] In some embodiments, “network” can be interpreted as the devices (e.g., access network devices, core network devices, etc.) included in the network.

[0093] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be replaced with each other.

[0094] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0095] In some embodiments, an access network device, a core network device, or a network device can be replaced with a terminal. For example, for a structure in which communication between an access network device, a core network device, or a network device and a terminal is replaced with communication between a plurality of terminals (for example, also referred to as device-to-device (D2D), vehicle-to-everything (V2X), and so on), embodiments of the present disclosure can also be applied. In this case, a structure in which a terminal has all or part of the functions of an access network device can also be provided. Furthermore, the language of "uplink," "downlink," and so on can also be replaced with language corresponding to communication between terminals (for example, "side"). For example, an uplink channel, a downlink channel, and so on can be replaced with a side channel, and an uplink, a downlink, and so on can be replaced with a side link.

[0096] In some embodiments, a terminal can be replaced with an access network device, a core network device, or a network device. In this case, a structure in which an access network device, a core network device, or a network device has all or part of the functions of a terminal can also be provided.

[0097] In some embodiments, obtaining data, information, and the like can comply with laws and regulations of the country where the location is.

[0098] In some embodiments, data, information, and the like can be obtained after obtaining the consent of the user.

[0099] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0100] FIG. 1 is a structural schematic diagram of an information processing system 100 according to an embodiment of the present disclosure. As shown in FIG. 1, the information processing system 100 can include a terminal 101 and a network device 102.

[0101] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.

[0102] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an IOT device or terminal, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a VR terminal device, an AR terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like, but is not limited thereto.

[0103] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0104] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.

[0105] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and the functions of part of the protocol layers are controlled by the CU, and the functions of the remaining part or all of the protocol layers are distributed in the DU and controlled by the CU, but the present disclosure is not limited thereto.

[0106] In some embodiments, the core network device can be one device, including the first device, the second device, etc., or a plurality of devices or device groups, respectively including all or part of the above-mentioned first device and / or second device, etc. The first device and / or the second device can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next-generation core (NGC), and a 6G core network (6GCN).

[0107] In some embodiments, the first device can be a resource owner function; or the resource owner function runs on the first device.

[0108] In some embodiments, the name of the resource owner function is not limited; the resource owner function is a device or network element or function or entity used by the resource owner; and the resource owner function is any user or subscription user, etc.

[0109] In some embodiments, the third device is an API invoker; and the name of the third device is not limited.

[0110] In some embodiments, the API invoker can be a terminal or UE, or an application (such as a browser, etc.) or a public account or a mini-program running on the terminal or UE, or an application function, or an application server, or a server belonging to a third party (such as A company, B operator or C platform, etc.).

[0111] In some embodiments, the second device can be a fourth device, a fifth device, or a sixth device.

[0112] In some embodiments, when the second device is the fourth device, the seventh device is the third device or the eighth device.

[0113] In some embodiments, when the second device is the fifth device, the seventh device is the ninth device or the sixth device.

[0114] In some embodiments, when the second device is the fifth device, the seventh device is the ninth device or the third device.

[0115] In some embodiments, when the second device is the sixth device, the tenth device is the third device, the fifth device or the eleventh device.

[0116] In some embodiments, the fourth device, the fifth device and the sixth device can all be CCFs; wherein the fourth device is a CCF without domain differentiation, the fifth device is a CCF in the first domain, and the sixth device is a CCF in the second domain.

[0117] For example, the fourth device is a first CCF; the fifth device is a second CCF; and the sixth device is a third CCF.

[0118] For example, the fourth device is a CCF; the fifth device is a CCF-A; and the sixth device is a CCF-B.

[0119] In some embodiments, the names of the fourth device, the fifth device and the sixth device are not limited; the fourth device, the fifth device and the sixth device can all be devices or network elements or functions or entities, etc. that provide definable API authentication, authorization, journal recording and / or charging functions, or general requirements of network capability exposure API, etc.

[0120] In some embodiments, the eighth device, the ninth device and the eleventh device can all be AEFs; wherein the eighth device is an AEF without domain differentiation, the ninth device is an AEF in the first domain, and the eleventh device is an AEF in the second domain.

[0121] For example, the eighth device is a first AEF; the ninth device is a second AEF; and the eleventh device is a third AEF.

[0122] For example, the eighth device is an AEF; the ninth device is an AEF-A; and the eleventh device is an AEF-B.

[0123] In some embodiments, the names of the eighth device, the ninth device and the eleventh device are not limited; the eighth device, the ninth device and the eleventh device can all be devices or network elements or functions or entities, etc. that provide authentication and / or establish a TLS session.

[0124] In some embodiments, the first domain can be a first trust domain; and the second domain can be a second trust domain.

[0125] In some embodiments, the first domain can be domain A; and the second domain can be domain B.

[0126] In some embodiments, the first domain can be CAPIF domain A; and the second domain can be CAPIF domain B.

[0127] In some embodiments, the first domain and the second domain can belong to two different operations or companies or other institutions or organizations, etc.

[0128] For example, the first domain is deployed by an A operator; and the second domain is deployed by a B operator.

[0129] For example, the first domain is deployed by an A operator; and the second domain is deployed by a B operator.

[0130] It can be understood that the information processing system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0131] The following embodiments of the present disclosure can be applied to the information processing system 100 shown in FIG. 1 or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1 are exemplary, and the information processing system can include all or part of the subjects in FIG. 1, or other subjects other than those in FIG. 1. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0132] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, combination of 5G and 5G, combination of 5G and 6G, and the like).

[0133] In some embodiments, a resource owner can use CAPIF to authorize an API invoker to access its resources, e.g., location information, etc. The resource owner can use two defined authorization flows, e.g., authorization code flow or client credential flow, to perform the authorization.

[0134] In some embodiments, a resource owner can need to actively revoke its authorization information, e.g., the resource owner can need to deny all API invokers to access its location resources. However, currently, there is no mechanism in CAPIF system to enable a resource owner to trigger a token revocation procedure; there is also no mechanism in CAPIF system to check whether a resource owner is revoked from authorization.

[0135] In some embodiments, the UE can be a terminal, or the terminal can be a UE.

[0136] FIG. 2A is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2A, the embodiment of the present disclosure relates to an information processing method for an information processing system 100, and the method comprises:

[0137] In step S2101, the first device sends first information to the second device.

[0138] In some embodiments, the second device receives the first information sent by the first device.

[0139] Optionally, the first device is a resource owner function.

[0140] Optionally, the second device can be a fourth device, a fifth device or a sixth device. For example, the fourth device can be a CCF. For example, the fifth device can be a CCF-A. For example, the sixth device can be a CCF-B. For example, the second device can be a CCF, a CCF-A or a CCF-B.

[0141] Optionally, the first device can run on a terminal or a personal computer, or the first device can be a stand-alone device, etc.

[0142] Optionally, the second device can be a device deployed by an operator, or the second device can be a core network device, etc.

[0143] Optionally, the first device sends the first information to the fourth device.

[0144] Optionally, the fourth device receives the first information sent by the first device.

[0145] Optionally, the first device sends the first information to a fifth device.

[0146] Optionally, the fifth device receives the first information sent by the first device.

[0147] Optionally, the first device sends the first information to a sixth device.

[0148] Optionally, the sixth device receives the first information sent by the first device.

[0149] Optionally, the first device sends the first information to the fifth device, and the fifth device sends the first information to the sixth device.

[0150] Optionally, the sixth device receives the first information sent by the fifth device, and the first information is received by the fifth device from the first device.

[0151] In some embodiments, when the second device is a fourth device, the first device is in the first domain with the second device (i.e., the fourth device).

[0152] In some embodiments, when the second device is a fifth device, the first device is in the first domain with the second device (i.e., the fifth device).

[0153] In some embodiments, when the second device is a sixth device, the first device is in the first domain; and the second device (i.e., the sixth device) is in the second domain.

[0154] Optionally, the first domain can be a first trust domain; and the second domain can be a second trust domain.

[0155] Optionally, the first domain can be domain A; and the second domain can be domain B.

[0156] Optionally, the first domain can be CAPIF domain A; and the second domain can be CAPIF domain B.

[0157] Optionally, the first domain and the second domain can be defined by an operator or a company or other institution or organization, etc.

[0158] For example, the first domain is deployed by A operator; and the second domain is deployed by B operator. For another example, the first domain is deployed by A operator; and the second domain is deployed by B company.

[0159] In some embodiments, the first information is used to indicate the identity of a resource owner related to the first device.

[0160] In some embodiments, the first information comprises at least one of: a certificate, a key and an account number, a token, an account number and a password.

[0161] In some embodiments, the first device sends a third message to the second device, wherein the third message comprises the first information, and the third message is used to request authentication of the identity of the resource owner.

[0162] Optionally, the first information is used to authenticate the identity of the resource owner.

[0163] Optionally, the first information can comprise any information that can be used to authenticate the identity of the resource owner.

[0164] Optionally, the first information is not limited in name, and is for example resource owner authentication information.

[0165] Optionally, the third message is not limited in name, and is for example an authentication request message or an Onboard API invoker request message.

[0166] In some embodiments, the resource owner is associated with the first device.

[0167] In some embodiments, the resource owner can be a user or a subscription owner using the first device.

[0168] In some optional embodiments, the second device authenticates the identity of the resource owner. Optionally, the authentication can be replaced by verification.

[0169] Optionally, the second device authenticates the identity of the resource owner based on the first information.

[0170] In some optional embodiments, the second device determines a third identity of the first device.

[0171] Optionally, the second device generates the third identity of the first device upon determining that the authentication of the identity of the resource owner is successful.

[0172] Optionally, the second device uses the first identity of the resource owner as the third identity upon determining that the authentication of the identity of the resource owner is successful.

[0173] Optionally, the third identity is: the first identity in the first information indicating the identity of the resource owner, or an identity generated by the second device for the resource owner and different from the first identity.

[0174] Optionally, the third identity is an identity of the first device.

[0175] Optionally, the name of the third identifier is not limited, which is, for example, a resource owner ID or an authenticated resource owner ID, etc.

[0176] In some optional embodiments, the second device stores the third identifier of the first device. That is, the identifier of the authenticated resource owner is stored.

[0177] In step S2102, the second device sends the third identifier to the first device.

[0178] In some embodiments, the first device receives the third identifier sent by the second device.

[0179] Optionally, the fourth device sends the third identifier to the first device.

[0180] Optionally, the first device receives the third identifier sent by the fourth device.

[0181] Optionally, the fifth device sends the third identifier to the first device.

[0182] Optionally, the first device receives the third identifier sent by the fifth device.

[0183] Optionally, the sixth device sends the third identifier to the first device.

[0184] Optionally, the sixth device receives the third identifier sent by the first device.

[0185] Optionally, the sixth device sends the third identifier to the fifth device, and the fifth device sends the third identifier to the first device.

[0186] Optionally, the first device receives the first identifier sent by the fifth device, and the first identifier is received by the fifth device from the sixth device.

[0187] Optionally, the third identifier is determined by the second device based on the first information after determining that the resource owner identity authentication is passed; the third identifier is the first identifier indicating the identity of the resource owner in the first information, or an identifier generated by the second device for the resource owner and different from the first identifier.

[0188] In some embodiments, the second device sends a third response to the first device, wherein the third response includes the third identifier, and the third response is used to indicate that the resource owner identity authentication is passed.

[0189] In some optional embodiments, the second device sends a third response to the first device, wherein the third response is used to indicate the authentication result of the resource owner identity authentication. Optionally, the third response includes first indication information or second indication information; the first indication information is used to indicate that the resource owner identity authentication is passed; and the second indication information is used to indicate that the resource owner identity authentication is not passed.

[0190] At step S2103, the first device sends a first message to the second device.

[0191] In some embodiments, the second device receives the first message sent by the first device.

[0192] Optionally, the first device is a resource owner function.

[0193] Optionally, the resource owner function is running on the first device.

[0194] Optionally, the second device can be a fourth device, a fifth device or a sixth device. For example, the fourth device can be a CCF. For example, the fifth device can be a CCF-A. For example, the sixth device can be a CCF-B. For example, the second device can be a CCF, a CCF-A or a CCF-B.

[0195] Optionally, the first device sends the first message to the fourth device.

[0196] Optionally, the fourth device receives the first message sent by the first device.

[0197] Optionally, the first device sends the first message to the fifth device.

[0198] Optionally, the fifth device receives the first message sent by the first device.

[0199] Optionally, the first device sends the first message to the sixth device.

[0200] Optionally, the sixth device receives the first message sent by the first device.

[0201] Optionally, the first device sends the first message to the fifth device, and the fifth device sends the first message to the sixth device.

[0202] Optionally, the sixth device receives the first message sent by the fifth device, and the first message is received by the fifth device from the first device.

[0203] In some embodiments, the first message comprises at least one of the following: a first identity, a second identity, type information and destination information.

[0204] Optionally, the first identity is an identity of a resource owner.

[0205] Optionally, the first identifier can or can not be included in the first message. For example, the second device authenticates the resource owner related to the first device, and the authentication is passed, and the first device and the connection information (e.g., a Transport Layer Security (TLS) session identifier) related to the second device can be bound to the identifier of the resource owner in the subsequent interaction; thus, even if the first device does not send the first identifier, the second device can identify the identifier of the resource owner through the connection information.

[0206] Optionally, the name of the first identifier is not limited, which is, for example, a resource owner identifier.

[0207] Optionally, the second identifier is an identifier of the third device.

[0208] Optionally, the name of the second identifier is not limited, which is, for example, an API invoker ID.

[0209] Optionally, the third device is an API invoker.

[0210] Optionally, the third device can be in the first domain or in the second domain; or the third device is not in the first domain and the second domain.

[0211] Optionally, the API invoker can be a terminal or UE, or an application (e.g., a browser, etc.) or a public account or a mini program running on the terminal or UE, or an Application function, or an Application server, or a server belonging to a third party (e.g., A company, B operator, or C platform, etc.).

[0212] Optionally, the type information is used to indicate a type of data that needs to be revoked. For example, the type of data can be a location information type and / or a quality type, etc.

[0213] Optionally, the name of the type information is not limited, which is, for example, a data type, etc.

[0214] Optionally, the purpose information is used to indicate a data processing purpose that needs to be revoked. For example, the data processing purpose can be to revoke an authorization related to location information, or to improve or reduce the quality of a service, or to open location information, etc.

[0215] Optionally, the name of the purpose information is not limited, which is, for example, a data processing purpose, etc.

[0216] In some embodiments, the first message is used to request revoking the authorization related to the resource owner.

[0217] For example, the first message is used to request revoking the authorization of the third device to access at least one of the resource, the service, the service operation and the service API of the resource owner.

[0218] For example, the first message is used to request revoking the authorization of the API Invoker to access the resource of the resource owner.

[0219] Optionally, the resource owner is related to the first device in that the resource owner uses the first device.

[0220] For example, the first device has a resource owner function (the resource owner function can be an application), and the resource owner can manipulate the resource owner function on the first device to interact with the CCF.

[0221] For example, if the resource of the resource owner is related to the first device, the resource owner identity is the identity of the first device.

[0222] Optionally, the first message is used to request revoking the authorization of the resource owner to the API Invoker.

[0223] Optionally, the first message is used to request revoking the authorization related to the data type and / or the data processing purpose. For example, the authorization of the location information is revoked, i.e. the location information is prohibited to be opened.

[0224] In some embodiments, the name of the first message is not limited, which is, for example, an authorization revocation request, etc. At least one of the first identity, the second identity, the type information and the data processing purpose can also be called revocation related information.

[0225] In some optional embodiments, when the second device is the fifth device, the fifth device sends the first message to the sixth device.

[0226] In some optional embodiments, when the second device determines that the service related to the first message is published by the sixth device, the second device sends the first message to the sixth device.

[0227] Optionally, the service related to the first message can be an API service.

[0228] Optionally, at least one of the first identity, the type information and the purpose information corresponds to the API service.

[0229] Optionally, the sixth device is capable of generating a token for generating a device accessing a domain where the fifth device is located. That is, the sixth device (e.g., CCF-B) can generate a token for accessing a device (e.g., AEF-A) in a domain where CCF-A is located.

[0230] At step S2104, the second device checks the first message.

[0231] In some embodiments, the second device can also configure the first message, or obtain the first message from a protocol, etc.

[0232] In some embodiments, the second device checks the first message based on the third identity. Optionally, the second device checks the first message if the first message includes the identity. Optionally, the second device checks whether the first identity and the third identity are the same.

[0233] In some optional embodiments, the second device sends second information to the first device if the first identity and the third identity are different.

[0234] In some embodiments, the second information is used to indicate that the revocation request fails and / or a failure reason of the revocation request failure.

[0235] Optionally, the failure reason is that only the authorization related to the authenticated resource owner can be revoked.

[0236] Optionally, the failure reason is that the first identity is not the identity of the authenticated resource owner.

[0237] Optionally, only the authorization related to the authenticated resource owner can be revoked means that only the authorization related to the identity of the authenticated resource owner (i.e., the third identity) can be revoked.

[0238] Optionally, the resource owner corresponding to the first identity can include the authenticated resource owner and / or the unauthenticated resource owner; and the resource owner corresponding to the third identity can be the authenticated resource owner.

[0239] At step S2105, the second device identifies the token.

[0240] Optionally, the second device identifies the token to be revoked. Exemplarily, the token to be revoked is the token to be revoked.

[0241] In some embodiments, the second device identifies the token to be revoked based on at least one of the following: the first identity, the service information, the type information, and the destination information, if the first identity and the third identity are the same. Here, the first message includes the first identity.

[0242] In some embodiments, the second device identifies the token that needs to be revoked based on at least one of the third identity, the service information, the type information and the purpose information, if the first message does not comprise the first identity.

[0243] Optionally, the type information and / or the purpose information can be used to determine the service information. Here, the second device can store information indicating a correspondence between the type information and / or the purpose information and the service information.

[0244] Optionally, the token can comprise at least one of the first identity, the service information, the type information and the purpose information. The second device can identify whether the token is the token that needs to be revoked based on whether at least one of the third identity, the first identity in the first message, the type information and the purpose information matches at least one of the first identity, the service information, the type information and the purpose information in the token.

[0245] For example, the first message comprises the first identity, and the second device identifies the token that contains the same first identity as the first identity in the first message as the token that needs to be revoked based on the first identity.

[0246] For example, the first message does not comprise the first identity, and the second device identifies the token that contains the same first identity as the third identity as the token that needs to be revoked based on the third identity.

[0247] For example, the first message comprises the type information and / or the purpose information, and the second device identifies the token that contains the same type information and / or the purpose information as the type information and / or the purpose information in the first message as the token that needs to be revoked based on the type information and / or the purpose information.

[0248] For example, the first message comprises the type information and / or the purpose information, and the second device determines the service information based on the type information and / or the purpose information, and identifies the token that contains the same service information as the service information as the token that needs to be revoked based on the service information.

[0249] In step S2106, the second device sends a second message to the seventh device and / or the tenth device.

[0250] In some embodiments, the seventh device and / or the tenth device receives the second message sent by the second device.

[0251] Optionally, the seventh device can be at least one of the third device, the sixth device, the eighth device and the ninth device. For example, the third device is an API invoker. For example, the sixth device is a CCF-B. For example, the eighth device is an AEF. For example, the ninth device is an AEF-A.

[0252] Optionally, the tenth device can be at least one of the third device, the fifth device and the eleventh device. For example, the fifth device is the CCF-A. For example, the eleventh device is the AEF-B.

[0253] Optionally, the third device and the ninth device are in the first domain, and the eleventh device is in the second domain.

[0254] In some embodiments, the second message is used to request revoking the authorization.

[0255] Optionally, the second message is used to request revoking the authorization related to the resource owner.

[0256] Optionally, the second message is used to request revoking the authorization of the identified token.

[0257] Optionally, the second message is used to request revoking the identified token.

[0258] Optionally, the second message transmits information of the token to be revoked.

[0259] Optionally, the second message includes at least one of the first identity, the second identity, the type information and the purpose information.

[0260] Optionally, the second message further includes at least one of the location information of the ninth device, the address information of the ninth device and the identity information of the ninth device.

[0261] Optionally, the name of the second message is not limited, for example, authorization revocation request or token revocation request.

[0262] In some embodiments, the second device sends the second message to the seventh device.

[0263] In some embodiments, the seventh device receives the second message sent by the second device.

[0264] Optionally, the second device is the fourth device, and the seventh device is the third device and / or the eighth device. For example, the fourth device sends the second message to the third device. For example, the fourth device sends the second message to the eighth device.

[0265] Optionally, the second device is the fifth device, and the seventh device is the ninth device and / or the sixth device. For example, the fifth device sends the second message to the ninth device. For example, the fifth device sends the second message to the sixth device.

[0266] Optionally, the fifth device sends the second message to the ninth device based on the location information or the address information or the identity information.

[0267] Optionally, the fifth device sends the second message to a third device corresponding to the second identity based on the second identity.

[0268] In some optional embodiments, the second device is a sixth device, and the sixth device sends the second message to the fifth device and / or the eleventh device.

[0269] In some embodiments, the second device is a sixth device, and the sixth device sends the second message to the tenth device.

[0270] In some embodiments, the tenth device receives the second message sent by the sixth device.

[0271] Optionally, the sixth device sends the second message to the third device.

[0272] Optionally, the sixth device sends the second message to the fifth device.

[0273] Optionally, the sixth device sends the second message to the eleventh device.

[0274] The seventh device and / or the tenth device sends a second response to the second device, in step S2107.

[0275] In some embodiments, the second device receives the second response sent by the tenth device and / or the seventh device.

[0276] In some embodiments, the second message is used to indicate that the authorization is successfully revoked.

[0277] Optionally, the second response is used to indicate that the authorization related to the resource owner is successfully revoked.

[0278] Optionally, the second response is used to indicate that the authorization of the identified token is successfully revoked.

[0279] Optionally, the second response can also be used to indicate whether the authorization is successfully revoked. For example, the second response includes third indication information or fourth indication information; the third indication information is used to indicate that the authorization is successfully revoked; and the fourth indication information is used to indicate that the authorization is not successfully revoked.

[0280] Optionally, the name of the second response is not limited, and it is, for example, a token revocation response or a token revocation response.

[0281] In some embodiments, the seventh device sends the second response to the second device.

[0282] In some embodiments, the second device receives the second response sent by the seventh device.

[0283] Optionally, the second device is the fourth device, the seventh device is the third device and / or the eighth device. Illustratively, the third device sends the second response to the fourth device. Illustratively, the eighth device sends the second response to the fourth device.

[0284] Optionally, the second device is the fifth device, the seventh device is the ninth device and / or the sixth device. Illustratively, the ninth device sends the second response to the fifth device. Illustratively, the sixth device sends the second response to the fifth device.

[0285] In some optional embodiments, the second device is the sixth device, the fifth device and / or the eleventh device sends the second message to the sixth device.

[0286] In some embodiments, the second device is the sixth device, the tenth device sends the second response to the sixth device.

[0287] In some embodiments, the sixth device receives the second response sent by the tenth device.

[0288] Optionally, the third device sends the second response to the sixth device.

[0289] Optionally, the fifth device sends the second response to the sixth device.

[0290] Optionally, the sixth device sends the second response to the sixth device.

[0291] Step S2108, the second device sends the first response to the first device.

[0292] In some embodiments, the first device receives the first response sent by the second device.

[0293] Optionally, the fourth device sends the first response to the first device.

[0294] Optionally, the first device receives the first response sent by the fourth device.

[0295] Optionally, the fifth device sends the first response to the first device.

[0296] Optionally, the first device receives the first response sent by the fifth device.

[0297] Optionally, the sixth device sends the first response to the first device.

[0298] Optionally, the sixth device receives the first response sent by the first device.

[0299] Optionally, the sixth device sends the first response to the fifth device, and the fifth device sends the first response to the first device.

[0300] Optionally, the first device receives a first identifier sent by the fifth device, the first identifier being received by the fifth device from the sixth device.

[0301] In some embodiments, the first response is used to indicate that the authorization of the owner of the resource related to the first device is successfully revoked.

[0302] In some embodiments, the first response can also be used to indicate whether the authorization is successfully revoked or not. For example, the second response includes third indication information or fourth indication information; the third indication information is used to indicate that the authorization is successfully revoked; and the fourth indication information is used to indicate that the authorization is not successfully revoked.

[0303] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and the terms of “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “domain”, “field”, “symbol”, “symbol”, “codebook”, “codeword”, “code point”, “bit”, “data”, “program”, “chip”, etc. can be replaced with each other.

[0304] In some embodiments, “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, implementing autonomously, and other meanings.

[0305] In some embodiments, the terms of “send”, “transmit”, “report”, “issue”, “transmit”, “bidirectional transmission”, “send and / or receive” can be replaced with each other.

[0306] In some embodiments, the terms "certain", "preset", "pre-set", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced with each other, "certain A", "preset A", "pre-set A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in a protocol or the like, A obtained by setting, configuration, or indication, or the like, or a specific A, a certain A, an arbitrary A, or a first A, but are not limited thereto.

[0307] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.

[0308] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2101 to S2108. For example, step S2101 can be implemented as an independent embodiment; step S2102 can be implemented as an independent embodiment; step S2103 can be implemented as an independent embodiment; step S2104 can be implemented as an independent embodiment; step S2105 can be implemented as an independent embodiment; step S2106 can be implemented as an independent embodiment; step S2107 can be implemented as an independent embodiment; step S2108 can be implemented as an independent embodiment; a combination of step S2101 and step S2102 can be implemented as an independent embodiment; a combination of step S2103 and step S2104 can be implemented as an independent embodiment; a combination of step S2104 to step S2105 can be implemented as an independent embodiment; a combination of step S2103 and step S2104 and step S2105 can be implemented as an independent embodiment; a combination of step S2103 to step S2105 can be implemented as an independent embodiment; a combination of step S2106 and step S2107 can be implemented as an independent embodiment; a combination of step S2103 and step S2108 can be implemented as an independent embodiment; a combination of step S2105 and step S2106 and step S2107 can be implemented as an independent embodiment; a combination of step S2104 and step S2105 and step S2106 and step S2107 can be implemented as an independent embodiment; a combination of step S2103 and step S2104 and step S2105 and step S2106 and step S2107 can be implemented as an independent embodiment; a combination of step S2101 to step S2108 can be implemented as an independent embodiment.

[0309] In some embodiments, steps S2103 to S2108 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0310] In some embodiments, steps S2101 to S2102, S2104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0311] In some embodiments, steps S2101 to S2102, S2104, S2106, S2107 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0312] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0313] FIG. 2B is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2B, the embodiment of the present disclosure relates to an information processing method for an information processing system 100, and the above method comprises:

[0314] In step S2201, the first device sends first information to the fourth device.

[0315] The optional implementation of step S2201 can refer to the optional implementation of step S2101 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0316] In some optional embodiments, the fourth device authenticates the identity of the resource owner.

[0317] In step S2202, the fourth device sends a third identification to the first device.

[0318] The optional implementation of step S2202 can refer to the optional implementation of step S2102 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0319] In step S2203, the first device sends a first message to the fourth device.

[0320] The optional implementation of step S2203 can refer to the optional implementation of step S2103 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0321] In step S2204, the fourth device checks the first message.

[0322] The optional implementation of step S2204 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0323] In some optional embodiments, the fourth device sends the second information to the first device when the first identity is different from the third identity.

[0324] Step S2205, the fourth device identifies the token.

[0325] The optional implementation of step S2205 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0326] Step S2206 includes step S2206A and / or step S2206B.

[0327] Step S2206A, the fourth device sends the second message to the eighth device.

[0328] Step S2206B, the fourth device sends the second message to the third device.

[0329] The optional implementation of step S2206 can refer to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0330] Step S2207 includes step S2207A and / or step S2207B.

[0331] Step S2207A, the eighth device sends the second response to the fourth device.

[0332] Step S2207B, the third device sends the second response to the fourth device.

[0333] The optional implementation of step S2207 can refer to the optional implementation of step S2107 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0334] Step S2208, the fourth device sends the first response to the first device.

[0335] The optional implementation of step S2208 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0336] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2201 to S2208. For example, step S2201 can be implemented as an independent embodiment; step S2202 can be implemented as an independent embodiment; step S2203 can be implemented as an independent embodiment; step S2204 can be implemented as an independent embodiment; step S2205 can be implemented as an independent embodiment; step S2206 can be implemented as an independent embodiment; step S2207 can be implemented as an independent embodiment; step S2208 can be implemented as an independent embodiment; a combination of step S2201 and step S2202 can be implemented as an independent embodiment; a combination of step S2203 and step S2204 can be implemented as an independent embodiment; a combination of step S2204 to step S2205 can be implemented as an independent embodiment; a combination of step S2203, step S2204 and step S2205 can be implemented as an independent embodiment; a combination of step S2203 to step S2205 can be implemented as an independent embodiment; a combination of step S2206 and step S2207 can be implemented as an independent embodiment; a combination of step S2203 and step S2208 can be implemented as an independent embodiment; a combination of step S2205, step S2206 and step S2207 can be implemented as an independent embodiment; a combination of step S2204, step S2205, step S2206 and step S2207 can be implemented as an independent embodiment; a combination of step S2203, step S2204, step S2205, step S2206 and step S2207 can be implemented as an independent embodiment; and a combination of steps S2201 to S2208 can be implemented as an independent embodiment.

[0337] In some embodiments, steps S2203 to S2208 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0338] In some embodiments, steps S2201 to S2202 and step S2204 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0339] In some embodiments, steps S2201 to S2202, step S2204, step S2206 and step S2207 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0340] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0341] FIG. 2C is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure. As shown in FIG. 2C, the method for processing information is used in the information processing system 100, and the method comprises the following steps:

[0342] In step S2301, the first device sends first information to the fifth device.

[0343] The optional implementation of step S2301 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0344] In some optional embodiments, the fifth device authenticates the identity of the resource owner.

[0345] In step S2302, the fifth device sends a third identifier to the first device.

[0346] The optional implementation of step S2302 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0347] Step S2303 comprises step S2303A and step S2303B.

[0348] In step S2303A, the first device sends a first message to the fifth device.

[0349] In step S2304B, the fifth device sends the first message to the sixth device.

[0350] The optional implementation of step S2303 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0351] In step S2304, the sixth device checks the first message.

[0352] The optional implementation of step S2304 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0353] In some optional embodiments, the sixth device sends second information to the first device when the first identifier is different from the third identifier.

[0354] In step S2305, the sixth device identifies a token.

[0355] The optional implementation of step S2305 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0356] Step S2306 includes step S2306A and / or step S2306B and / or step S2306C.

[0357] Step S2306A, the sixth device sends the second message to the third device.

[0358] Step S2306B, the sixth device sends the second message to the fifth device.

[0359] Step S2306C, the fifth device sends the second message to the ninth device.

[0360] Optional implementation of step S2306 can refer to optional implementation of step S2106 in FIG. 2A, and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0361] Step S2307 includes step S2307A and / or step S2307B and / or step S2307C.

[0362] Step S2307A, the third device sends the second response to the sixth device.

[0363] Step S2307B, the ninth device sends the second response to the fifth device.

[0364] Step S2307C, the fifth device sends the second response to the sixth device.

[0365] Optional implementation of step S2307 can refer to optional implementation of step S2107 in FIG. 2A, and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0366] Step S2308 includes step S2308A and / or step S2308B.

[0367] Step S2308A, the sixth device sends the first response to the fifth device.

[0368] Step S2308B, the fifth device sends the first response to the first device.

[0369] Optional implementation of step S2308 can refer to optional implementation of step S2108 in FIG. 2A, and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0370] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2301 to S2308. For example, step S2301 can be implemented as an independent embodiment; step S2302 can be implemented as an independent embodiment; step S2303 can be implemented as an independent embodiment; step S2304 can be implemented as an independent embodiment; step S2305 can be implemented as an independent embodiment; step S2306 can be implemented as an independent embodiment; step S2307 can be implemented as an independent embodiment; step S2308 can be implemented as an independent embodiment; a combination of step S2301 and step S2302 can be implemented as an independent embodiment; a combination of step S2303 and step S2304 can be implemented as an independent embodiment; a combination of step S2304 to step S2305 can be implemented as an independent embodiment; a combination of step S2303, step S2304 and step S2305 can be implemented as an independent embodiment; a combination of step S2303 to step S2305 can be implemented as an independent embodiment; a combination of step S2306 and step S2307 can be implemented as an independent embodiment; a combination of step S2303 and step S2308 can be implemented as an independent embodiment; a combination of step S2305, step S2306 and step S2307 can be implemented as an independent embodiment; a combination of step S2304, step S2305, step S2306 and step S2307 can be implemented as an independent embodiment; a combination of step S2303, step S2304, step S2305, step S2306 and step S2307 can be implemented as an independent embodiment; and a combination of step S2301 to step S2308 can be implemented as an independent embodiment.

[0371] In some embodiments, steps S2303 to S2308 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0372] In some embodiments, steps S2301 to S2302, step S2304 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0373] In some embodiments, steps S2301 to S2302, step S2304, step S2306, step S2307 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0374] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0375] FIG. 2D is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure. As shown in FIG. 2D, the method for processing information is used for the information processing system 100, and the method comprises the following steps:

[0376] In step S2401, the first device sends first information to the sixth device.

[0377] The optional implementation of step S2401 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0378] In some optional embodiments, the sixth device authenticates the identity of the resource owner.

[0379] In step S2402, the sixth device sends a third identifier to the first device.

[0380] The optional implementation of step S2402 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0381] In step S2403, the first device sends a first message to the sixth device.

[0382] The optional implementation of step S2403 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0383] In step S2404, the sixth device checks the first message.

[0384] The optional implementation of step S2404 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0385] In some optional embodiments, the sixth device sends second information to the first device when the first identifier is different from the third identifier.

[0386] In step S2405, the sixth device identifies a token.

[0387] The optional implementation of step S2405 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0388] Step S2406 comprises step S2406A and / or step S2406B and / or step S2406C.

[0389] In step S2406A, the sixth device sends a second message to the eleventh device.

[0390] Step S2406B, the sixth device sends the second message to the fifth device. Optionally, the second message comprises the second identity.

[0391] Step S2406C, the fifth device sends the second message to the third device.

[0392] Optional implementation of step S2406 can refer to optional implementation of step S2106 in FIG. 2A and other associated parts in embodiments related to FIG. 2A, which will not be repeated here.

[0393] Step S2407 comprises step S2407A and / or step S2407B and / or step S2407C.

[0394] Step S2407A, the eleventh device sends the second response to the sixth device.

[0395] Step S2407B, the third device sends the second response to the fifth device.

[0396] Step S2407C, the fifth device sends the second response to the sixth device.

[0397] Optional implementation of step S2407 can refer to optional implementation of step S2107 in FIG. 2A and other associated parts in embodiments related to FIG. 2A, which will not be repeated here.

[0398] Step S2408 comprises step S2408A and / or step S2408B.

[0399] Step S2408, the sixth device sends the first response to the first device.

[0400] Optional implementation of step S2408 can refer to optional implementation of step S2108 in FIG. 2A and other associated parts in embodiments related to FIG. 2A, which will not be repeated here.

[0401] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2401 to S2408. For example, step S2401 can be implemented as an independent embodiment; step S2402 can be implemented as an independent embodiment; step S2403 can be implemented as an independent embodiment; step S2404 can be implemented as an independent embodiment; step S2405 can be implemented as an independent embodiment; step S2406 can be implemented as an independent embodiment; step S2407 can be implemented as an independent embodiment; step S2408 can be implemented as an independent embodiment; a combination of step S2401 and step S2402 can be implemented as an independent embodiment; a combination of step S2403 and step S2404 can be implemented as an independent embodiment; a combination of step S2404 to step S2405 can be implemented as an independent embodiment; a combination of step S2403, step S2404 and step S2405 can be implemented as an independent embodiment; a combination of step S2403 to step S2405 can be implemented as an independent embodiment; a combination of step S2406 and step S2407 can be implemented as an independent embodiment; a combination of step S2403 and step S2408 can be implemented as an independent embodiment; a combination of step S2405, step S2406 and step S2407 can be implemented as an independent embodiment; a combination of step S2404, step S2405, step S2406 and step S2407 can be implemented as an independent embodiment; a combination of step S2403, step S2404, step S2405, step S2406 and step S2407 can be implemented as an independent embodiment; and a combination of steps S2401 to S2408 can be implemented as an independent embodiment.

[0402] In some embodiments, steps S2403 to S2408 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0403] In some embodiments, steps S2401 to S2402, step S2404 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0404] In some embodiments, steps S2401 to S2402, step S2404, step S2406, step S2407 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0405] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0406] FIG. 2E is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure. As shown in FIG. 2E, the method for processing information is used in the information processing system 100, and the method comprises the following steps:

[0407] In step S2501, the first device sends first information to the fifth device.

[0408] The optional implementation of step S2501 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0409] In some optional embodiments, the fifth device authenticates the identity of the resource owner.

[0410] In step S2502, the fifth device sends a third identifier to the first device.

[0411] The optional implementation of step S2502 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0412] In step S2503, the first device sends a first message to the fifth device.

[0413] The optional implementation of step S2503 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0414] In step S2504, the fifth device checks the first message.

[0415] The optional implementation of step S2504 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0416] In some optional embodiments, the fifth device sends second information to the first device when the first identifier is different from the third identifier.

[0417] In step S2505, the fifth device identifies a token.

[0418] The optional implementation of step S2505 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0419] Step S2506 comprises step S2506A and / or step S2506B and / or step S2506C.

[0420] In step S2506A, the fifth device sends a second message to the ninth device.

[0421] Step S2506B, the fifth device sends the second message to the sixth device.

[0422] Step S2506C, the sixth device sends the second message to the third device.

[0423] Optional implementation of step S2506 can refer to optional implementation of step S2106 in FIG. 2A and other associated parts in embodiments related to FIG. 2A, which will not be repeated here.

[0424] Step S2507 includes step S2507A and / or step S2507B and / or step S2507C.

[0425] Step S2507A, the ninth device sends the second response to the fifth device.

[0426] Step S2507B, the third device sends the second response to the sixth device.

[0427] Step S2507C, the sixth device sends the second response to the fifth device.

[0428] Optional implementation of step S2507 can refer to optional implementation of step S2107 in FIG. 2A and other associated parts in embodiments related to FIG. 2A, which will not be repeated here.

[0429] Step S2508, the fifth device sends the first response to the first device.

[0430] Optional implementation of step S2508 can refer to optional implementation of step S2108 in FIG. 2A and other associated parts in embodiments related to FIG. 2A, which will not be repeated here.

[0431] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2501 to S2508. For example, step S2501 can be implemented as an independent embodiment; step S2502 can be implemented as an independent embodiment; step S2503 can be implemented as an independent embodiment; step S2504 can be implemented as an independent embodiment; step S2505 can be implemented as an independent embodiment; step S2506 can be implemented as an independent embodiment; step S2507 can be implemented as an independent embodiment; step S2508 can be implemented as an independent embodiment; a combination of step S2501 and step S2502 can be implemented as an independent embodiment; a combination of step S2503 and step S2504 can be implemented as an independent embodiment; a combination of step S2504 to step S2505 can be implemented as an independent embodiment; a combination of step S2503, step S2504 and step S2505 can be implemented as an independent embodiment; a combination of step S2503 to step S2505 can be implemented as an independent embodiment; a combination of step S2506 and step S2507 can be implemented as an independent embodiment; a combination of step S2503 and step S2508 can be implemented as an independent embodiment; a combination of step S2505, step S2506 and step S2507 can be implemented as an independent embodiment; a combination of step S2504, step S2505, step S2506 and step S2507 can be implemented as an independent embodiment; a combination of step S2503, step S2504, step S2505, step S2506 and step S2507 can be implemented as an independent embodiment; and a combination of step S2501 to step S2508 can be implemented as an independent embodiment.

[0432] In some embodiments, steps S2503 to S2508 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0433] In some embodiments, steps S2501 to S2502, step S2504 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0434] In some embodiments, steps S2501 to S2502, step S2504, step S2506, step S2507 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0435] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0436] FIG. 2F is an interaction diagram of a method for processing information, according to an embodiment of the present disclosure. As shown in FIG. 2F, the method for processing information is used in the information processing system 100, and the method comprises the following steps:

[0437] In step S2601, the first device sends first information to the fifth device.

[0438] The optional implementation of step S2601 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0439] In some optional embodiments, the fifth device authenticates the identity of the resource owner.

[0440] In step S2602, the fifth device sends a third identifier to the first device.

[0441] The optional implementation of step S2602 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0442] In step S2603, the first device sends a first message to the fifth device.

[0443] The optional implementation of step S2603 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0444] In step S2604, the fifth device checks the first message.

[0445] The optional implementation of step S2604 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0446] In some optional embodiments, the fifth device sends second information to the first device when the first identifier is different from the third identifier.

[0447] In step S2605, the fifth device identifies a token.

[0448] The optional implementation of step S2605 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0449] Step S2606 comprises step S2606A and / or step S2606B.

[0450] In step S2606A, the fifth device sends a second message to the ninth device.

[0451] Step S2606B, the fifth device sends the second message to the third device.

[0452] The optional implementation of step S2606 can refer to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0453] Step S2607 includes step S2607A and / or step S2607B.

[0454] Step S2607A, the ninth device sends the second response to the fifth device.

[0455] Step S2607B, the third device sends the second response to the fifth device.

[0456] The optional implementation of step S2607 can refer to the optional implementation of step S2107 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0457] Step S2608, the fifth device sends the first response to the first device.

[0458] The optional implementation of step S2608 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0459] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2601 to S2608. For example, step S2601 can be implemented as an independent embodiment; step S2602 can be implemented as an independent embodiment; step S2603 can be implemented as an independent embodiment; step S2604 can be implemented as an independent embodiment; step S2605 can be implemented as an independent embodiment; step S2606 can be implemented as an independent embodiment; step S2607 can be implemented as an independent embodiment; step S2608 can be implemented as an independent embodiment; a combination of step S2601 and step S2602 can be implemented as an independent embodiment; a combination of step S2603 and step S2604 can be implemented as an independent embodiment; a combination of step S2604 to step S2605 can be implemented as an independent embodiment; a combination of step S2603, step S2604 and step S2605 can be implemented as an independent embodiment; a combination of step S2603 to step S2605 can be implemented as an independent embodiment; a combination of step S2606 and step S2607 can be implemented as an independent embodiment; a combination of step S2603 and step S2608 can be implemented as an independent embodiment; a combination of step S2605, step S2606 and step S2607 can be implemented as an independent embodiment; a combination of step S2604, step S2605, step S2606 and step S2607 can be implemented as an independent embodiment; a combination of step S2603, step S2604, step S2605, step S2606 and step S2607 can be implemented as an independent embodiment; and a combination of step S2601 to step S2608 can be implemented as an independent embodiment.

[0460] In some embodiments, steps S2603 to S2608 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0461] In some embodiments, steps S2601 to S2602 and step S2604 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0462] In some embodiments, steps S2601 to S2602, step S2604, step S2606 and step S2607 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0463] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0464] FIG. 3A is a flow diagram illustrating a method for processing information according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiment of the present disclosure relates to a method for processing information, which is performed by a first device, and the method comprises the following steps:

[0465] In step S3101, the first information is sent.

[0466] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0467] In some embodiments, the first device can send the first information to the second device, but is not limited thereto, and can also send the first information to other subjects.

[0468] In step S3102, the third identifier is obtained.

[0469] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0470] In some embodiments, the first device receives the third identifier sent by the access network device, but is not limited thereto, and can also receive the third identifier sent by other subjects.

[0471] In some embodiments, the first device obtains the third identifier specified by a protocol.

[0472] In some embodiments, the first device obtains the third identifier from the upper layer(s).

[0473] In some embodiments, the first device processes to obtain the third identifier.

[0474] In some embodiments, step S3102 is omitted, and the first device autonomously implements the function indicated by the third identifier, or the above function is default or default.

[0475] In step S3103, the first message is sent.

[0476] The optional implementation of step S3103 can refer to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0477] In some embodiments, the first device can send the first message to the second device, but is not limited thereto, and can also send the first message to other subjects.

[0478] In step S3104, the first response is obtained.

[0479] The optional implementation of step S3104 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0480] In some embodiments, the second device receives the first response sent by the access network device, but is not limited thereto, and can also receive the first response sent by other subjects.

[0481] In some embodiments, the second device acquires the first response specified by the protocol.

[0482] In some embodiments, the second device acquires the first response from the upper layer(s).

[0483] In some embodiments, the second device processes to obtain the first response.

[0484] In some embodiments, step S3104 is omitted, and the second device autonomously implements the function indicated by the first response, or the above function is default or default.

[0485] The information processing method related to the embodiments of the present disclosure can include at least one of steps S3101 to S3104. For example, step S3101 can be implemented as an independent embodiment; step S3102 can be implemented as an independent embodiment; step S3103 can be implemented as an independent embodiment; step S3104 can be implemented as an independent embodiment; the combination of steps S3101 and S3102 can be implemented as an independent embodiment; the combination of steps S3103 and S3104 can be implemented as an independent embodiment; and the combination of steps S3101 to S3104 can be implemented as an independent embodiment.

[0486] In some embodiments, steps S3103 and S3104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0487] In some embodiments, steps S3101 and S3102 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0488] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished from the previous steps.

[0489] FIG. 3B is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to an information processing method, which is performed by a first device, and the above method comprises:

[0490] In step S3201, the first message is sent to the second device, where the first message is used to request revocation of the authorization related to the resource owner associated with the first device.

[0491] The optional implementation of step S3201 can refer to the optional implementation of step S2101 in FIG. 2A, or the optional implementation of step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A and FIG. 3A, which are not described herein again.

[0492] In some embodiments, the first message further includes a first identifier indicating a connection used to transmit the DP data, and the first identifier is used by the access network device to determine the first network element.

[0493] In some embodiments, the first message further includes at least one of the following: a first identifier, where the first identifier is an identifier of the resource owner; a second identifier, where the second identifier is an identifier of the third device; type information, where the type information is used to indicate a type of data that needs to be revoked; and purpose information, where the purpose information is used to indicate a data processing purpose that needs to be revoked.

[0494] In some embodiments, the method further includes receiving a first response sent by the second device, where the first response is used to indicate that the authorization of the resource owner associated with the first device is successfully revoked.

[0495] In some embodiments, the method further includes sending, to the second device, first information used to indicate an identity of the resource owner associated with the first device, and receiving a third identifier sent by the second device, where the third identifier is determined by the second device based on the first information after determining that the identity of the resource owner is authenticated, and the third identifier is one of the following: a first identifier in the first information used to indicate the identity of the resource owner, or an identifier generated by the second device for the resource owner and different from the first identifier.

[0496] The above embodiments can be implemented independently or in combination with each other, and the optional implementation can refer to the optional implementation of the steps in FIG. 2A and FIG. 3A, which are not described herein again.

[0497] FIG. 4A is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 4A, the present disclosure relates to an information processing method, which is performed by a second device, and the above method includes the following steps:

[0498] In step S4101, first information is obtained.

[0499] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, which are not described herein again.

[0500] In some embodiments, the second device receives the fourth message sent by the first device, but is not limited thereto, and can also receive the fourth message sent by other subjects.

[0501] In some embodiments, the second device acquires the fourth message as specified by a protocol.

[0502] In some embodiments, the second device acquires the fourth message from upper layer(s).

[0503] In some embodiments, the second device processes to obtain the fourth message.

[0504] In some embodiments, step S4101 is omitted, and the second device autonomously implements the function indicated by the fourth message, or the above function is default or default.

[0505] In some optional embodiments, the second device authenticates the identity of the resource owner.

[0506] Step S4102, sending the third identity.

[0507] Optional implementation of step S4102 can refer to optional implementation of step S2101 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0508] In some embodiments, the second device can send the third identity to the first device, but is not limited thereto, and can also send the third identity to other subjects.

[0509] Step S4103, acquiring the first message.

[0510] Optional implementation of step S4103 can refer to optional implementation of step S2103 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0511] In some embodiments, the second device receives the first message sent by the first device, but is not limited thereto, and can also receive the first message sent by other subjects.

[0512] In some embodiments, the second device acquires the first message as specified by a protocol.

[0513] In some embodiments, the second device acquires the first message from upper layer(s).

[0514] In some embodiments, the second device processes to obtain the first message.

[0515] In some embodiments, step S4103 is omitted, and the second device autonomously implements the function indicated by the first message, or the above function is default or default.

[0516] Step S4104, checking the first message.

[0517] Optional implementation of step S4104 can refer to optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0518] In some optional embodiments, the second device sends the second information to the first device when the first identity is different from the third identity.

[0519] Step S4105, identifying the token.

[0520] Optional implementation of step S4104 can refer to optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0521] Step S4106, sending the second message.

[0522] Optional implementation of step S4105 can refer to optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0523] In some embodiments, the second device can send the second message to the seventh device and / or the tenth device, but is not limited thereto, and can send the second message to other subjects.

[0524] In some optional embodiments, the second device is the sixth device, and the sixth device sends the second message to the fifth device and / or the eleventh device.

[0525] Step S4107, obtaining the second response.

[0526] Optional implementation of step S4107 can refer to optional implementation of step S2107 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0527] In some embodiments, the second device receives the second response sent by the seventh device and / or the tenth device, but is not limited thereto, and can receive the second response sent by other subjects.

[0528] In some embodiments, the second device obtains the second response as specified in the protocol.

[0529] In some embodiments, the second device obtains the second response from upper layer(s).

[0530] In some embodiments, the second device processes to obtain the second response.

[0531] In some embodiments, step S4106 is omitted, and the second device autonomously implements the function indicated by the second response, or the function is a default or default function.

[0532] Step S4108: sending the first response.

[0533] The optional implementation of step S4108 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be described here.

[0534] In some embodiments, the second device can send the first response to the first device, but is not limited thereto, and can also send the first response to other subjects.

[0535] The information processing method involved in the embodiments of the present disclosure can include at least one of steps S4101 to S4108. For example, step S4101 can be implemented as an independent embodiment; step S4102 can be implemented as an independent embodiment; step S4103 can be implemented as an independent embodiment; step S4104 can be implemented as an independent embodiment; step S4105 can be implemented as an independent embodiment; step S4106 can be implemented as an independent embodiment; step S4107 can be implemented as an independent embodiment; step S4108 can be implemented as an independent embodiment; a combination of step S4101 and step S4102 can be implemented as an independent embodiment; a combination of step S4103 and step S4104 can be implemented as an independent embodiment; a combination of step S4104 to step S4105 can be implemented as an independent embodiment; a combination of step S4103 and step S4104 and step S4105 can be implemented as an independent embodiment; a combination of step S4103 to step S4105 can be implemented as an independent embodiment; a combination of step S4106 and step S4107 can be implemented as an independent embodiment; a combination of step S4103 and step S4108 can be implemented as an independent embodiment; a combination of step S4105 and step S4106 and step S4107 can be implemented as an independent embodiment; a combination of step S4104 and step S4105 and step S4106 and step S4107 can be implemented as an independent embodiment; a combination of step S4103 and step S4104 and step S4105 and step S4106 and step S4107 can be implemented as an independent embodiment; and a combination of steps S4101 to S4108 can be implemented as an independent embodiment.

[0536] In some embodiments, steps S4103 to S4108 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0537] In some embodiments, steps S4101-S4102 and S4104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0538] In some embodiments, steps S4101-S4102, S4104, S4106, and S4107 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0539] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0540] FIG. 4B is a flow diagram illustrating a method of processing information according to an embodiment of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to a method of processing information, which is performed by a second device, and the above method comprises:

[0541] In step S4201, a first message is obtained, where the first message is used to request revocation of a resource owner-related authorization, and the resource owner is related to the first device. Optionally, the second device is a fourth device, a fifth device, or a sixth device,

[0542] Optional implementation of step S4201 can refer to optional implementation of step S2109 in FIG. 2A, or step S4106 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A and FIG. 4A, which are not repeated here.

[0543] In some embodiments, the first message further comprises at least one of: a first identifier, where the first identifier is an identifier of the resource owner; a second identifier, where the second identifier is an identifier of the third device; type information, where the type information is used to indicate a data type that needs to be revoked; and purpose information, where the purpose information is used to indicate a data processing purpose that needs to be revoked.

[0544] In some embodiments, the second device is the fourth device or the fifth device, and the method further comprises: receiving first information sent by the first device, where the first information is used to indicate the identity of the resource owner; determining that the identity authentication of the resource owner is passed based on the first information; determining a third identifier of the first device, where the third identifier is: a first identifier in the first information that indicates the identity of the resource owner, or an identifier generated by the second device for the resource owner and different from the first identifier; and sending the third identifier to the first device.

[0545] In some embodiments, the second device is the fourth device, and the obtaining the first message comprises one of: receiving the first message sent by the first device; or the second device is the fifth device, and the obtaining the first message comprises one of: receiving the first message sent by the first device; or the second device is the sixth device, and the obtaining the first message comprises one of: receiving the first message sent by the first device; and receiving the first message sent by the fifth device.

[0546] In some embodiments, the second device is the fourth device or the fifth device, and the method further comprises: in a case where the first identity is different from the third identity, sending, to the first device, second information, wherein the second information is used to indicate the revocation request failure and / or a failure cause of the revocation request failure, and the failure cause is that the first identity is not an identity of the authenticated resource owner; and the third identity is the identity of the authenticated resource owner.

[0547] In some embodiments, the method further comprises one of: in a case where the first identity is the same as the third identity, identifying the token that needs to be revoked based on at least one of: the first identity, the service information, the type information, and the purpose information; and in a case where the first message does not comprise the first identity, identifying the token that needs to be revoked based on at least one of: the third identity, the service information, the type information, and the purpose information; wherein the type information and / or the purpose information are used to determine the service information.

[0548] In some embodiments, the method further comprises: sending, to a seventh device, a second message, wherein the second message is used to request to revoke the authorization, and the second message comprises at least one of: the first identity, the second identity, the type information, and the purpose information; and receiving a second response sent by the seventh device, wherein the second response is used to indicate that the authorization is successfully revoked; wherein the second device is the fourth device, and the seventh device is: the third device and / or the eighth device; or the second device is the fifth device, and the seventh device is: the ninth device and / or the sixth device; or the second device is the fifth device, and the seventh device is: the ninth device and / or the third device.

[0549] In some embodiments, the method further comprises: sending, to the first device, a first response, wherein the first response is used to indicate that the authorization of the resource owner is successfully revoked.

[0550] In some embodiments, the second device is the fifth device, and the method further comprises: receiving a second message sent by a sixth device, wherein the second message is used to request to revoke the authorization, and the second message comprises at least one of: the first identity, the second identity, the type information, and the purpose information; and sending, to the sixth device, a second response, wherein the second response is used to indicate that the authorization is successfully revoked.

[0551] In some embodiments, the second message further comprises at least one of location information of the ninth device, address information of the ninth device, and identification information of the ninth device; the method further comprises: sending the second message to the ninth device based on at least one of the location information, the address information, and the identification information; receiving a second response sent by the ninth device; wherein the second message is used to request revocation of the authorization, and the second response is used to indicate that the authorization is successfully revoked; and / or, based on the second identification, sending the second message to a third device corresponding to the second identification; receiving a second response sent by the third device.

[0552] In some embodiments, the method further comprises: receiving a first response sent by the sixth device, wherein the first response is used to indicate that the authorization of the resource owner is successfully revoked; and sending the first response to the first device.

[0553] In some embodiments, before receiving the second message sent by the sixth device, the method further comprises: in a case where it is determined that the service related to the first message is published by the sixth device, sending the first message to the sixth device; wherein the sixth device is capable of generating a token for accessing a device in a domain where the fifth device is located.

[0554] In some embodiments, the second device is the sixth device, and the method further comprises: in a case where the first identification in the first message is different from the third identification, sending second information to the first device, wherein the second information is used to indicate that the revocation request fails and / or a failure reason of the revocation request, and the failure reason is that the first identification is not an identification of an authenticated resource owner; and the third identification is an identification of the authenticated resource owner.

[0555] In some embodiments, the method further comprises at least one of: in a case where the first identification is the same as the third identification, identifying a token that needs to be revoked based on at least one of the following: the first identification, service information, type information, and purpose information; and in a case where the first message does not comprise the first identification, identifying a token that needs to be revoked based on at least one of the following: the third identification, the service information, the type information, and the purpose information; wherein the type information and / or the purpose information are used to determine the service information.

[0556] In some embodiments, the method further comprises: sending a second message to a tenth device, wherein the second message is used to request revocation of the authorization, and the second message comprises at least one of the following: the first identification, the second identification, type information, and purpose information; and the tenth device is at least one of the following: the third device, the fifth device, and an eleventh device; and receiving a second response sent by the tenth device, wherein the second response is used to indicate that the authorization is successfully revoked.

[0557] In some embodiments, when the tenth device is the fifth device, the second message comprises the second identification, and the second identification is determined based on information in the identified token that needs to be revoked; and the fifth device is determined based on the identified token that needs to be revoked.

[0558] In some embodiments, the first message sent by the first device is received, including: receiving the first message sent by the first device through the fifth device, wherein the first message is sent in a case where the fifth device determines that the first message can be published to the sixth device.

[0559] The above embodiments can be implemented independently or in combination with each other. For optional implementation, refer to the optional implementation of the steps in FIG. 2A and FIG. 4A, which are not described here again.

[0560] FIG. 4C is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 4C, the embodiment of the present disclosure relates to an information processing method, which is performed by a second device, and the above method includes:

[0561] In step S4301, the first information is acquired.

[0562] For optional implementation of step S4301, refer to the optional implementation of step S2101 in FIG. 2A, or step S4101 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A and FIG. 4A, which are not described here again.

[0563] In step S4302, the third identifier is sent.

[0564] For optional implementation of step S4302, refer to the optional implementation of step S2102 in FIG. 2A, or step S4102 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A and FIG. 4A, which are not described here again.

[0565] The above embodiments can be implemented independently or in combination with each other. For optional implementation, refer to the optional implementation of the steps in FIG. 2A and FIG. 4A, which are not described here again.

[0566] FIG. 4D is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 4D, the embodiment of the present disclosure relates to an information processing method, which is performed by a second device, and the above method includes:

[0567] In step S4401, the first message is acquired.

[0568] For optional implementation of step S4401, refer to the optional implementation of step S2103 in FIG. 2A, or step S4103 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A and FIG. 4A, which are not described here again.

[0569] In step S4402, the first response is sent.

[0570] Optional implementation of step S4402 can refer to optional implementation of step S2108 in FIG. 2A, or step S4108 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A and FIG. 4A, which are not described here again.

[0571] The above embodiments can be implemented independently or in combination with each other, and optional implementation can refer to optional implementation of steps in FIG. 2A and FIG. 4A, which are not described here again.

[0572] [Corrected according to Rule 91 on 21.08.2024] FIG. 5 is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 5, the embodiment of the present disclosure relates to an information processing method, and is used for an information processing system 100. The method comprises one of the following steps:

[0573] Step S5101, the first device sends a first message to the second device, wherein the first message is used to request revocation of authorization of a resource owner, and the resource owner is related to the first device.

[0574] [Corrected according to Rule 91 on 21.08.2024] Optional implementation of step S5101 can refer to optional implementation of step S2109 in FIG. 2A, step S3105 in FIG. 3A, step S4106 in FIG. 4A, and step S5101 in FIG. 5, and other associated parts in the embodiments related to FIG. 2A, FIG. 3A, FIG. 4A and FIG. 5, which are not described here again.

[0575] Step S5102, the second device sends a first response to the first device, wherein the first response is used to indicate that the authorization of the resource owner related to the first device is successfully revoked.

[0576] [Corrected according to Rule 91 on 21.08.2024] Optional implementation of step S5102 can refer to optional implementation of step S2109 in FIG. 2A, step S4106 in FIG. 4A, and step S5101 in FIG. 5, and other associated parts in the embodiments related to FIG. 2A, FIG. 4A and FIG. 5, which are not described here again.

[0577] In some embodiments, the above method can include the method described in the above information processing system side, terminal side, access network device side, first network element side and / or second network element side, and other embodiments, which are not described here again.

[0578] FIG. 6A is a schematic diagram illustrating an overview of a user authorization revocation mechanism according to an embodiment of the present disclosure. As shown in FIG. 6A, the user authorization revocation mechanism can include: scenario one, an authorization revocation mechanism based on a CCF scenario; scenario two, an authorization revocation mechanism in which CCF-B generates a token for AEF-A; scenario three, an authorization revocation mechanism in which AEF-A generates a token; scenario four, an authorization revocation mechanism in which CCF-A generates a token for AEF-A; scenario five, an authorization revocation mechanism in which CCF-A generates a token for AEF-A and CCF-A directly interacts with an API invoker; and scenario six, a user authorization revocation mechanism based on a resource owner function. Scenario six can be used to support scenarios one to five.

[0579] Scenario one, an authorization revocation mechanism based on a CCF scenario:

[0580] FIG. 6B is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 6B, the present disclosure relates to an information processing method, which includes:

[0581] Preconditions:

[0582] A resource owner function (ROF) can be part of a UE, a personal computer, or the like.

[0583] A resource owner can be a user of a UE or a subscriber, depending on the use case and regulations.

[0584] Details of a resource owner authentication mechanism can be left to the application layer.

[0585] In step S6100, the CCF authenticates a resource owner by interacting with a resource owner function and obtains an authenticated resource owner ID.

[0586] Optionally, the resource owner function obtains address information of the CCF from a network side or an API invoker; the resource owner function sends an authentication request to the CCF to enable the CCF to authenticate the resource owner; and the CCF obtains an authenticated resource owner ID. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiments.

[0587] In step S6101, the resource owner function sends an authorization revocation request to the CCF.

[0588] Optionally, the resource owner sends a revocation request to the CCF, the revocation request being used to revoke the authorization related to the resource owner; the revocation request comprising revocation related information, the revocation related information comprising at least one of the following: the resource owner ID, the API invoker ID, the data type, and the data processing purpose. Optionally, the revocation request is the first message in the previous embodiments; and the API invoker ID is the second identifier in the previous embodiments.

[0589] At step S6102, the CCF checks the revocation related information.

[0590] Optionally, if the CCF determines that the revocation related information comprises the resource owner ID, the CCF checks the revocation related information against the authenticated resource owner ID. Optionally, the resource owner ID is the first identifier in the previous embodiments.

[0591] Optionally, if the CCF finds that the authenticated resource owner ID is different from the resource owner ID in the revocation related information, the CCF sends a failure message to the resource owner function. Illustratively, the failure message indicates that the resource owner can only revoke the authorization information related to the authenticated resource owner ID, or indicates that the revocation request fails.

[0592] Optionally, step S6102 is optional.

[0593] At step S6103, the CCF identifies the token to be revoked.

[0594] Optionally, if the CCF determines that the revocation related information comprises the resource owner ID and the resource owner ID is the same as the authenticated resource owner ID, the CCF uses the resource owner ID in the revocation related information to identify the token to be revoked. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiments.

[0595] Optionally, if the CCF determines that the revocation related information does not comprise the resource owner ID, the CCF uses the authenticated (e.g., authenticated through step S6100) resource owner ID to identify the token to be revoked.

[0596] Optionally, the CCF identifies the token to be revoked by checking whether the token contains the resource owner ID and the information (e.g., the API invoker ID, the data type, and / or the data processing purpose) included in the revocation related information.

[0597] Optionally, the CCF can map the processing type and data processing purpose to service information, and then the CCF detects whether the token contains the service information; if the token contains the service information, it is determined that the token is a token that needs to be revoked, or if the token does not contain the service information, it is determined that the token is not a token that needs to be revoked.

[0598] Optionally, the token contains revocation-related information (e.g., resource owner ID, API caller ID, data type, data processing purpose, and / or service information) that needs to be revoked.

[0599] Optionally, the CCF knows the source IP address of the resource owner function, so the CCF can bind the authenticated resource owner ID to the source IP address of the resource owner function. If the resource owner function does not send the resource owner ID in the authorization revocation request, the CCF can obtain the resource owner ID through the source IP address of the resource owner function.

[0600] Step S6104, the CCF interacts with the AEF and the API caller to revoke the identified token.

[0601] Optionally, the CCF sends a token revocation request to the AEF, wherein the token revocation request is used to request to revoke the identified token; the AEF sends a token revocation response to the CCF, wherein the token revocation response is used to indicate that the identified token is successfully revoked. Optionally, the token revocation request is the second message in the previous embodiment; the token revocation response is the second response in the previous embodiment.

[0602] Optionally, the CCF sends a token revocation request to the API caller; the API caller sends a token revocation response to the CCF.

[0603] Step S6105, the CCF sends an authorization revocation response to the resource owner.

[0604] Optionally, the authorization revocation response is used to indicate that the authorization related to the resource owner is successfully revoked. Optionally, the authorization revocation response is the first response in the previous embodiment.

[0605] In the embodiments of the present disclosure, part or all of the steps and optional implementation manners thereof can be combined with part or all of the steps of other embodiments, or can be combined with optional implementation manners of other embodiments.

[0606] Scheme two, the CCF-B generates a token authorization revocation mechanism for the AEF-A:

[0607] FIG. 6C is a flow diagram illustrating a method of information processing according to an embodiment of the present disclosure. As shown in FIG. 6C, the embodiments of the present disclosure relate to a method of information processing, which comprises:

[0608] The embodiments of the present disclosure are for the case that CCF-B generates AEF-A related token for API invoker in domain B.

[0609] In step S6200, CCF-A authenticates the resource owner by interacting with the resource owner function, and obtains the authenticated resource owner ID. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiments.

[0610] Optionally, the resource owner function obtains the address information of CCF-A from the network or the API invoker; the resource owner function sends an authentication request to CCF-A to make CCF-A authenticate the resource owner; and CCF-A obtains the authenticated resource owner ID.

[0611] In step S6201, the resource owner function sends an authorization revocation request to CCF-A. Optionally, the authorization revocation request is the first message in the previous embodiments.

[0612] Optionally, the resource owner sends an authorization revocation request to CCF-A, and the authorization revocation request is used to revoke the authorization related to the resource owner; the authorization revocation request comprises revocation related information, and the revocation related information comprises at least one of the following: resource owner ID, API invoker ID, data type, and data processing purpose.

[0613] In step S6202, CCF-A sends an authorization revocation request to CCF-B.

[0614] Optionally, CCF-B can generate a token for accessing domain A; CCF-A determines whether the service information (e.g., service API, service, service operation, etc. published by CCF-A to CCF-B) related to the revocation information (e.g., data type and / or data processing purpose that needs to be revoked) is published to CCF-B. If CCF-A determines that the service information related to the revocation information (e.g., data type and / or data processing purpose that needs to be revoked) is published to CCF-B, CCF-A sends an authorization revocation request to CCF-B. For example, CCF-A determines according to the local policy that the service related to the revocation information needs to be published to CCF-B, and then sends an authorization revocation request to CCF-B.

[0615] In step S6203, CCF-B checks the revocation related information.

[0616] Optionally, the CCF-B uses the resource owner ID provided by the CCF-A as the authenticated resource owner ID.

[0617] Optionally, the CCF-B checks the revocation-related information against the authenticated resource owner ID if the CCF-B determines that the revocation-related information includes the resource owner ID.

[0618] Optionally, the CCF-B sends a failure message to the resource owner function if the authenticated resource owner ID is found to be different from the resource owner ID in the revocation-related information. Illustratively, the failure message indicates that the resource owner can only revoke the authorization information related to the authenticated resource owner ID, or indicates that the revocation request fails.

[0619] Optionally, step S6203 is optional.

[0620] In step S6204, the CCF-B identifies the token to be revoked.

[0621] Optionally, the CCF-B uses the resource owner ID provided by the CCF-A as the authenticated resource owner ID.

[0622] Optionally, the CCF-B uses the resource owner ID in the revocation-related information to identify the token to be revoked if the CCF-B determines that the revocation-related information includes the resource owner ID and the resource owner ID is the same as the authenticated resource owner ID.

[0623] Optionally, the CCF-B uses the authenticated (e.g., authenticated in step S6200) resource owner ID to identify the token to be revoked if the CCF-B determines that the revocation-related information does not include the resource owner ID.

[0624] Optionally, the CCF-B identifies the token to be revoked by checking whether the token contains the resource owner ID and the information (e.g., API caller ID, data type, and / or data processing purpose) included in the revocation-related information.

[0625] Optionally, the CCF-B can map the processing type and data processing purpose to service information, and then the CCF-B detects whether the token contains the service information; if the token contains the service information, the CCF-B determines that the token is the token to be revoked, or if the token does not contain the service information, the CCF-B determines that the token is not the token to be revoked.

[0626] Optionally, the token contains the revocation-related information (e.g., resource owner ID, API caller ID, data type, data processing purpose, and / or service information) to be revoked.

[0627] Optionally, the CCF-B knows the source IP address of the resource owner function, thus the CCF-B can bind the authenticated resource owner ID to the source IP address of the resource owner function. If the resource owner function does not send the resource owner ID in the authorization revocation request, the CCF-B can obtain the resource owner ID by the source IP address of the resource owner function.

[0628] At step S6205, the CCF-B sends a token revocation request to the API invoker. Optionally, the token revocation request is the second message in the previous embodiments.

[0629] Optionally, the token revocation request is used to request revoking the identified token. Optionally, the token revocation response is the second response in the previous embodiments

[0630] At step S6206, the API invoker sends a token revocation response to the CCF-B.

[0631] Optionally, the token revocation response is used to indicate successful revoking of the identified token.

[0632] At step S6207, the CCF-B sends a token revocation request to the CCF-A.

[0633] Optionally, the CCF-B sends the token revocation request to the CCF-A, wherein the token revocation request includes information indicating the identified token. Optionally, the token revocation request further includes AEF information (e.g., location information of the AEF-A) related to the revoked token.

[0634] Optionally, the location information of the AEF includes an IP address of the AEF, an identity of the AEF, or a FQDN of the AEF.

[0635] At step S6208, the CCF-A sends a token revocation request to the AEF-A.

[0636] Optionally, the CCF-A selects the AEF-A based on the AEF information provided by the CCF-B, and sends the token revocation request to the AEF-A.

[0637] At step S6209, the AEF-A sends a token revocation response to the CCF-A.

[0638] At step S6210, the CCF-A sends a token revocation response to the CCF-B.

[0639] At step S6211, the CCF-B sends an authorization revocation response to the CCF-A. Optionally, the authorization revocation response is the first response in the previous embodiments.

[0640] Optionally, the authorization revocation response is used to indicate successful revoking of the resource owner related authorization.

[0641] Step S6212, CCF-A sends an authorization revocation response to the API invoker.

[0642] In the embodiments of the present disclosure, part or all of the steps, and the optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with the optional implementation manners of other embodiments.

[0643] Scheme three, the authorization revocation mechanism of AEF-A generating a token:

[0644] FIG. 6D is a flow diagram illustrating a method of processing information according to an embodiment of the present disclosure. As shown in FIG. 6D, the present disclosure relates to a method of processing information, which comprises:

[0645] Step S6300, CCF-B authenticates the resource owner by interacting with the resource owner function, and obtains an authenticated resource owner ID. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiments.

[0646] Optionally, the resource owner function obtains the address information of CCF-A from the network or the API invoker; the resource owner function sends an authentication request to CCF-A, so that CCF-A authenticates the resource owner; and CCF-A obtains the authenticated resource owner ID.

[0647] Step S6301, the resource owner function sends an authorization revocation request to CCF-B. Optionally, the authorization revocation request is the first message in the previous embodiments.

[0648] Optionally, the resource owner sends an authorization revocation request to CCF-B, and the authorization revocation request is used to revoke the authorization related to the resource owner; the authorization revocation request includes revocation-related information, and the revocation-related information includes at least one of the following: resource owner ID, API invoker ID, data type, and data processing purpose. Optionally, the resource owner ID is the first identifier in the previous embodiments; and the API invoker ID is the second identifier in the previous embodiments.

[0649] Step S6302, CCF-B checks the revocation-related information.

[0650] Optionally, if CCF-B determines that the revocation-related information includes the resource owner ID, it checks the revocation-related information against the authenticated resource owner ID.

[0651] Optionally, the CCF-B sends a failure message to the resource owner function if the authenticated resource owner ID is different from the resource owner ID in the revocation related information. Exemplarily, the failure message indicates that the resource owner can only revoke the authorization information related to the authenticated resource owner ID, or indicates that the revocation request fails.

[0652] Optionally, step S6302 is optional.

[0653] Step S6303, the CCF-B identifies the token to be revoked.

[0654] Optionally, the CCF-B identifies the token to be revoked using the resource owner ID in the revocation related information if it is determined that the resource owner ID is included in the revocation related information and the resource owner ID is the same as the authenticated resource owner ID.

[0655] Optionally, the CCF-B identifies the token to be revoked using the authenticated (e.g. authenticated through step S6300) resource owner ID if it is determined that the resource owner ID is not included in the revocation related information.

[0656] Optionally, the CCF-B identifies the token to be revoked by checking whether the token contains the resource owner ID and the information (e.g. API caller ID, data type and / or data processing purpose) included in the revocation related information.

[0657] Optionally, the CCF-B can map the processing type and data processing purpose to service information, and then the CCF-B detects whether the token contains the service information; if the token contains the service information, it is determined that the token is the token to be revoked, or if the token does not contain the service information, it is determined that the token is not the token to be revoked.

[0658] Optionally, the token contains the revocation related information (e.g. resource owner ID, API caller ID, data type, data processing purpose and / or service information) to be revoked.

[0659] Optionally, the CCF-B knows the source IP address of the resource owner function, so the CCF-B can bind the authenticated resource owner ID to the source IP address of the resource owner function. If the resource owner function does not send the resource owner ID in the authorization revocation request, the CCF-B can obtain the resource owner ID through the source IP address of the resource owner function.

[0660] Step S6304, the CCF-B sends a token revocation request to the AEF-B.

[0661] Step S6305, the AEF-B sends a token revocation response to the CCF-B.

[0662] Step S6306, CCF-B sends a token revocation request to CCF-A.

[0663] Optionally, the token revocation request includes information indicating the identified token. Optionally, the token revocation request further includes AEF information (e.g., location information of AEF-A) related to the revoked token.

[0664] Optionally, the token revocation request includes an API invoker ID, the API invoker ID being determined according to information in the identified token to be revoked; and the CCF-A is determined according to the information in the identified token to be revoked.

[0665] Optionally, the CCF-B stores a correspondence between the API invoker ID and the CCF-A ID, and the CCF-B sends the token revocation request to the CCF-A according to the correspondence.

[0666] Optionally, the identified token to be revoked includes the CCF-A ID, and the CCF-B determines to send the token revocation request to the CCF-A according to the CCF-A ID.

[0667] Step S6307, CCF-A sends a token revocation request to the API invoker.

[0668] Optionally, the CCF-A sends the token revocation request to the AEF-A according to the AEF information. Optionally, the token revocation request is the second message in the foregoing embodiment.

[0669] Step S6308, the API invoker sends a token revocation response to the CCF-A. Optionally, the token revocation response is the second response in the foregoing embodiment.

[0670] Step S6309, the CCF-A sends a token revocation response to the CCF-B.

[0671] Step S6310, the CCF-B sends an authorization revocation response to the CCF-A.

[0672] Step S6311, the CCF-A sends an authorization revocation response to the resource owner function. Optionally, the authorization revocation response is the first response in the foregoing embodiment.

[0673] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.

[0674] Scheme four, an authorization revocation mechanism for the CCF-A to generate a token for the AEF-A:

[0675] FIG. 6E is a flow diagram illustrating a method for processing information according to an embodiment of the present disclosure. As shown in FIG. 6E, the embodiments of the present disclosure relate to a method for processing information, which includes the following steps.

[0676] The embodiments of the present disclosure are for the case that the CCF-A generates the AEF-A token for the API invoker in the domain B.

[0677] In step S6400, the CCF-A authenticates the resource owner by interacting with the resource owner function, and obtains the authenticated resource owner ID. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiments.

[0678] Optionally, the resource owner function obtains the address information of the CCF-A from the network or the API invoker; the resource owner function sends an authentication request to the CCF-A to make the CCF-A authenticate the resource owner; and the CCF-A obtains the authenticated resource owner ID.

[0679] In step S6401, the resource owner function sends an authorization revocation request to the CCF-A. Optionally, the authorization revocation request is the first message in the previous embodiments.

[0680] Optionally, the resource owner sends an authorization revocation request to the CCF-A, and the authorization revocation request is used to revoke the authorization related to the resource owner; the authorization revocation request includes revocation-related information, and the revocation-related information includes at least one of the following: the resource owner ID, the API invoker ID, the data type, and the data processing purpose. Optionally, the resource owner ID is the first identifier in the previous embodiments; and the API invoker ID is the second identifier in the previous embodiments.

[0681] In step S6402, the CCF-A checks the revocation-related information.

[0682] Optionally, the CCF-A checks the revocation-related information against the authenticated resource owner ID if it is determined that the revocation-related information includes the resource owner ID.

[0683] Optionally, the CCF-A sends a failure information to the resource owner function if it is found that the authenticated resource owner ID is different from the resource owner ID in the revocation-related information. Illustratively, the failure information indicates that the resource owner can only revoke the authorization information related to the authenticated resource owner ID, or indicates that the revocation request fails.

[0684] Optionally, step S6402 is optional.

[0685] In step S6403, the CCF-A identifies the token to be revoked.

[0686] Optionally, if the CCF-A determines that the revocation-related information includes the resource owner ID and the resource owner ID is the same as the authenticated resource owner ID, the CCF-A uses the resource owner ID in the revocation-related information to identify the token that needs to be revoked.

[0687] Optionally, if the CCF-A determines that the revocation-related information does not include the resource owner ID, the CCF-A uses the authenticated (e.g., authenticated in step S6400) resource owner ID to identify the token that needs to be revoked. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiment.

[0688] Optionally, the CCF-A identifies the token that needs to be revoked by checking whether the token contains the resource owner ID and the information (e.g., API caller ID, data type, and / or data processing purpose) included in the revocation-related information.

[0689] Optionally, the CCF-A can map the processing type and the data processing purpose to service information, and then the CCF-A detects whether the token contains the service information; if the token contains the service information, it is determined that the token is the token that needs to be revoked, or if the token does not contain the service information, it is determined that the token is not the token that needs to be revoked.

[0690] Optionally, the token contains revocation-related information (e.g., resource owner ID, API caller ID, data type, data processing purpose, and / or service information) that needs to be revoked. Optionally, the resource owner ID is the first identifier in the previous embodiment; the API caller ID is the second identifier in the previous embodiment.

[0691] Optionally, the CCF-A knows the source IP address of the resource owner function, so the CCF-A can bind the authenticated resource owner ID to the source IP address of the resource owner function. If the resource owner function does not send the resource owner ID in the authorized revocation request, the CCF-A can obtain the resource owner ID through the source IP address of the resource owner function.

[0692] In step S6404, the CCF-A sends a token revocation request to the AEF-A. Optionally, the token revocation request is the second message in the previous embodiment

[0693] Optionally, if the CCF-A is used to generate a token for an API caller, the CCF-A sends a token revocation request to the AEF-A, wherein the token revocation request includes information (e.g., Json Web Token (JWT) identifier, token, etc.) indicating the identified token.

[0694] Step S6405, the AEF-A sends a token revocation response to the CCF-A. Optionally, the token revocation response is the second response in the previous embodiments.

[0695] Step S6406, the CCF-A sends a token revocation request to the CCF-B.

[0696] Step S6407, the CCF-B sends a token revocation request to the API invoker.

[0697] Step S6408, the API invoker sends a token revocation response to the CCF-B.

[0698] Step S6409, the CCF-B sends a token revocation response to the CCF-A. Optionally, the authorization revocation response is the first response in the previous embodiments.

[0699] Step S6410, the CCF-A sends the authorization revocation response to the resource owner function.

[0700] In the embodiments of the present disclosure, part or all of the steps, and the optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with the optional implementation manners of other embodiments.

[0701] Scheme five, an authorization revocation mechanism in which the CCF-A generates a token for the AEF-A and the CCF-A directly interacts with the API invoker:

[0702] FIG. 6F is a flow diagram illustrating a method of processing information according to an embodiment of the present disclosure. As shown in FIG. 6F, the embodiments of the present disclosure relate to a method of processing information, which includes:

[0703] The embodiments of the present disclosure are for the case in which the CCF-A generates an AEF-A token for an API invoker in a domain B.

[0704] Step S6500, the CCF-A authenticates a resource owner by interacting with a resource owner function, and obtains an authenticated resource owner ID. Optionally, the authenticated resource owner ID is the third identifier in the previous embodiments.

[0705] Optionally, step S6500 is similar to step S6300, and the description of step S6500 can be referred to the description of step S6400.

[0706] Step S6501, the resource owner function sends an authorization revocation request to the CCF-A. Optionally, the authorization revocation request is the first message in the previous embodiments.

[0707] Optionally, step S6501 is similar to step S6401, and the description of step S6501 can be referred to the description of step S6401.

[0708] Step S6502, CCF-A checks revocation related information.

[0709] Optionally, step S6502 is similar to step S6402, and the description of step S6502 can refer to the description of step S6402.

[0710] Optionally, step S6502 is optional.

[0711] Step S6503, CCF-A identifies the token to be revoked.

[0712] Optionally, step S6503 is similar to step S6403, and the description of step S6503 can refer to the description of step S6403.

[0713] Step S6504, CCF-A sends a token revocation request to AEF-A. Optionally, the token revocation request is the second message in the previous embodiment

[0714] Step S6505, AEF-A sends a token revocation response to CCF-A. Optionally, the token revocation response is the second response in the previous embodiment.

[0715] Step S6506, CCF-A sends a token revocation request to the API invoker.

[0716] Step S6507, the API invoker sends a token revocation request to CCF-A.

[0717] Step S6508, CCF-A sends an authorization revocation response to the resource owner function. Optionally, the authorization revocation response is the first response in the previous embodiment.

[0718] In the embodiments of the present disclosure, part or all of the steps, and the optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with the optional implementation manners of other embodiments.

[0719] Scheme six, user authorization revocation mechanism based on resource owner function.

[0720] [According to Rule 91, corrected on 21.08.2024] FIG. 6G is a flowchart of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 6G, the present disclosure relates to an information processing method, which comprises:

[0721] Precondition:

[0722] A resource owner (e.g., a human, a user, or a UE) obtains onboarding registration information for authenticating the CCF and establishing a secure Transport Layer Security (TLS) communication with the CCF in a login procedure. The registration information includes address information and a Certificate Authority (CA) certificate of the CCF; the registration information can also include an onboarding credential (e.g., an OAuth 2.0 token). The onboarding credential can include a resource owner ID.

[0723] For the case that a human acts as the resource owner, the resource owner sends the onboarding credential to the resource owner function.

[0724] Step S6601, the resource owner establishes a TLS-based secure session with the CCF.

[0725] Optionally, the resource owner function and the CCF shall establish a TLS (server certificate authentication) based secure session. The resource owner function uses the registration information of the resource owner to establish a TLS session with the CCF.

[0726] Step S6602, the resource owner sends an onboarding resource owner request message to the CCF.

[0727] Optionally, the resource owner function sends an onboarding resource owner request message to the CCF after successfully establishing a TLS session.

[0728] Optionally, the resource owner function sends the onboarding credential of the resource owner to the CCF.

[0729] Step S6603, the CCF verifies the onboarding credential.

[0730] Optionally, the CCF verifies the onboarding credential; if the onboarding credential is verified, the CCF determines that the identity of the resource owner in the onboarding credential is the identity of an authenticated resource owner.

[0731] Optionally, the CCF generates an identity for the authenticated resource owner.

[0732] Step S6604, the CCF sends the authenticated resource owner ID to the resource owner function. Optionally, the authenticated resource owner ID is the third identity in the previous embodiment.

[0733] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.

[0734] Embodiments of the present disclosure relate to an information processing method, which comprises:

[0735] Resource owner function:

[0736] In some embodiments, the resource owner function is capable of sending an online subscription credential comprising a resource owner ID to the CCF.

[0737] In some embodiments, the resource owner function is capable of providing revocation-related information to the CCF, which can comprise at least one of the following: resource owner ID, API invoker ID, data type, and data processing purpose.

[0738] CCF:

[0739] In some embodiments, the CCF can obtain an authenticated resource owner ID by verifying the online subscription credential.

[0740] In some embodiments, the CCF can generate or assign a resource owner ID for the authenticated resource owner.

[0741] In some embodiments, the CCF is capable of receiving revocation-related information from the resource owner function; the revocation-related information can comprise at least one of the following: resource owner ID, API invoker ID, data type, and data processing purpose.

[0742] The following embodiments on the CCF side are adapted to be performed on the CCF-A or CCF-B side:

[0743] In some embodiments, the CCF checks the revocation-related information against the authenticated resource owner ID if it determines that the information in the revocation-related information comprises the resource owner ID.

[0744] In some embodiments, the CCF sends a failure message to the resource owner function if it determines that the authenticated resource owner ID is different from the resource owner ID in the revocation-related information; the failure message indicates that the revocation request fails and / or the reason for the revocation request failure, which is that only the authorization information related to the authenticated resource owner ID can be revoked.

[0745] In some embodiments, the CCF is capable of mapping the data type and / or data processing purpose to service information, and checking whether the token comprises the service information.

[0746] CCF-A:

[0747] The embodiments of the present disclosure are for the case that CCF-A generates a token for accessing AEF-A in domain A.

[0748] In some embodiments, CCF-A can check whether the service related to revocation related information (e.g., data type and / or data processing purpose) is published by CCF-B; if so, CCF-A sends the revocation related information to CCF-B.

[0749] In some embodiments, CCF-A can receive a token revocation request from CCF-B, which can include AEF information (e.g., location information of AEF, etc.) related to the revoked token. CCF-A requests the corresponding AEF (e.g., AEF-A) to revoke the token based on the AEF information.

[0750] In the embodiments of the present disclosure, for the case that CCF-A can generate a token for accessing AEF-A in domain A, CCF-A should be able to request API invoker in domain B to revoke the token using CCF-B.

[0751] CCF-B:

[0752] The embodiments of the present disclosure are for the case that CCF-B can generate a token for accessing AEF-A in domain A.

[0753] In some embodiments, CCF-B can receive revocation related information from CCF-A.

[0754] In some embodiments, CCF-B can request AEF-A to revoke the token through CCF-A; the information sent from CCF-B to CCF-A can also include AEF information (e.g., location information of AEF, etc.) related to the revoked token.

[0755] In the embodiments of the present disclosure, for the case that CCF-A can generate a token for accessing AEF-A in domain A, CCF-B should be able to receive a token revocation request from CCF-A, and then trigger API invoker in domain B to revoke the token.

[0756] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.

[0757] The embodiments of the present disclosure also propose an apparatus for implementing any of the above methods, for example, an apparatus including units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is proposed, including units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0758] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the units or modules of the above apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of the elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0759] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0760] FIG. 7A is a structural schematic diagram of a first device 7100 according to an embodiment of the present disclosure. As shown in FIG. 7A, the first device 7100 includes a first transceiving module 7101. In some embodiments, the first transceiving module 7101 is configured to transmit a first message. Optionally, the first transceiving module 7101 is configured to perform at least one of the steps of transmitting and / or receiving performed by the first device 7100 in any of the above methods (for example, steps S2101 and / or steps S2102 and / or steps S2103 and / or steps S2108, but not limited thereto), and details are not described herein again.

[0761] FIG. 7B is a structural schematic diagram of the second device 7200. As shown in FIG. 7B, the second device 7200 includes a second transceiver module 7201 and a processing module 7202. In some embodiments, the second transceiver module 7201 is configured to obtain the first message. Optionally, the second transceiver module 7201 is configured to perform at least one of the receiving and / or sending steps (for example, steps S2101 and / or S2102 and / or S2103 and / or S2106 and / or S2107 and / or S2108, but not limited thereto) performed by the second device 7200 in any of the above methods, details of which are not described herein again. In some embodiments, the processing module 7202 is configured to check the first message. Optionally, the processing module 7202 is configured to perform at least one of the processing steps (for example, steps S2104 and / or S2105, but not limited thereto) of the second device 7200 in any of the above methods, details of which are not described herein again.

[0762] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver. For example, the first transceiver module includes a first sending module and / or a first receiving module. For example, the second transceiver module includes a second sending module and / or a second receiving module.

[0763] In some embodiments, the processing module can be one module or include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module. Optionally, the processing module can be mutually replaced with a processor.

[0764] FIG. 8A is a structural schematic diagram of a communication device 8100. The communication device 8100 can be a network device (for example, an access network device, a core network device, etc.), a terminal, etc., a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 8100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0765] As shown in FIG. 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general processor or a special-purpose processor, etc., such as a baseband processor or a central processor. The baseband processor can be used to process communication protocols and communication data, and the central processor can be used to control a communication apparatus (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 8100 is configured to perform any of the above methods. Optionally, the one or more processors 8101 are configured to invoke instructions to cause the communication device 8100 to perform any of the above methods.

[0766] In some embodiments, the communication device 8100 further includes one or more transceivers 8102. When the communication device 8100 includes one or more transceivers 8102, the transceiver 8102 performs at least one of the communication steps (e.g., steps S2101 and / or steps S2102 and / or steps S2103 and / or steps S2106 and / or steps S2107 and / or steps S2108, etc., but not limited to) in the above methods, and the processor 8101 performs at least one of the other steps (e.g., steps S2104 and / or steps S2105, etc., but not limited to). In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc., can be replaced with each other, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be replaced with each other.

[0767] In some embodiments, the communication device 8100 further includes one or more memories 8103 for storing data. Optionally, all or part of the memory 8103 can also be outside the communication device 8100. In optional embodiments, the communication device 8100 can include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8103, and the interface circuit 8104 can be used to receive data from the memory 8103 or other devices, and can be used to send data to the memory 8103 or other devices. For example, the interface circuit 8104 can read data stored in the memory 8103 and send the data to the processor 8101.

[0768] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 8A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0769] FIG. 8B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 8B can be referred to, but is not limited thereto.

[0770] The chip 8200 includes one or more processors 8201. The chip 8200 is configured to execute any of the above methods.

[0771] In some embodiments, the chip 8200 further includes one or more interface circuits 8202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 8200 further includes one or more memories 8203 for storing data. Optionally, all or part of the memory 8203 can be outside the chip 8200. Optionally, the interface circuit 8202 is connected to the memory 8203, and the interface circuit 8202 can be configured to receive data from the memory 8203 or other devices, and the interface circuit 8202 can be configured to send data to the memory 8203 or other devices. For example, the interface circuit 8202 can read data stored in the memory 8203 and send the data to the processor 8201.

[0772] In some embodiments, the interface circuit 8202 performs at least one of the communication steps (for example, steps S2101 and / or step S2102 and / or step S2103 and / or step S2106 and / or step S2107 and / or step S2108, but not limited to) of the above method such as transmitting and / or receiving. The interface circuit 8202 performing the communication steps of the above method such as transmitting and / or receiving refers to, for example, the interface circuit 8202 performing data interaction between the processor 8201, the chip 8200, the memory 8203, or the transceiver device. In some embodiments, the processor 8201 performs at least one of the other steps (for example, steps S2104 and / or step S2105, but not limited to).

[0773] The various modules and / or devices described in each of the embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated according to the circumstances. Optionally, part or all of the steps can also be performed by a plurality of modules and / or devices in cooperation, which is not limited here.

[0774] The disclosure also proposes a storage medium, and the above storage medium stores instructions, which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Optionally, the above storage medium is an electronic storage medium. Optionally, the above storage medium is a computer readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices. Optionally, the above storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a transitory storage medium.

[0775] The disclosure also proposes a program product, which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the above program product is a computer program product.

[0776] The disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. An information processing method characterized by comprising: The method is performed by a first device, comprising: sending a first message to a second device, wherein the first message is used to request revocation of a related authorization of a resource owner, the resource owner being related to the first device.

2. The method of claim 1, wherein, The first message further comprises at least one of: a first identifier, wherein the first identifier is an identifier of the resource owner; a second identifier, wherein the second identifier is an identifier of a third device; type information, wherein the type information is used to indicate a type of data that needs to be revoked; purpose information, wherein the purpose information is used to indicate a data processing purpose that needs to be revoked.

3. The method according to claim 1 or 2, characterized in that, The method further comprises: receiving a first response sent by the second device, wherein the first response is used to indicate that the related authorization of the resource owner is successfully revoked.

4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: sending first information to the second device, wherein the first information is used to indicate an identity of a resource owner related to the first device; receiving a third identifier sent by the second device, wherein the third identifier is determined by the second device based on the first information after determining that the identity of the resource owner is authenticated, and the third identifier is either a first identifier indicating the identity of the resource owner in the first information or an identifier generated by the second device for the resource owner and different from the first identifier.

5. An information processing method characterized by comprising: The method is performed by a second device, the second device being a fourth device, a fifth device or a sixth device, comprising: obtaining a first message, wherein the first message is used to request revocation of a related authorization of a resource owner, the resource owner being related to a first device.

6. The method of claim 5, wherein, The first message further comprises at least one of: a first identifier, wherein the first identifier is an identifier of the resource owner; a second identifier, wherein the second identifier is an identifier of a third device; type information, wherein the type information is used to indicate a type of data that needs to be revoked; purpose information, wherein the purpose information is used to indicate a data processing purpose that needs to be revoked.

7. The method according to claim 5 or 6, characterized in that, The method further comprises: receiving first information sent by the first device, wherein the first information is used to indicate an identity of the resource owner; based on the first information, determining that the identity of the resource owner is authenticated; determining a third identifier of the first device, wherein the third identifier is either a first identifier indicating the identity of the resource owner in the first information or an identifier generated by the second device for the resource owner and different from the first identifier; sending the third identifier to the first device.

8. The method of any one of claims 5 to 7, wherein: the second device is the fourth device, and the obtaining the first message comprises one of: receiving the first message sent by the first device; or, the second device is the fifth device, and the obtaining the first message comprises one of: receiving the first message sent by the first device; or, the second device is the sixth device, and the obtaining the first message comprises one of: receiving the first message sent by the first device; receiving the first message sent by the fifth device.

9. The method of claim 8, wherein, The second device is the fourth device or the fifth device, and the method further comprises: The first identifier is different from the third identifier, and the second information is sent to the first device, wherein the second information is used to indicate at least one of the following: a revocation request failure and a failure reason for the revocation request failure, and the failure reason is that the first identifier is not an identifier of the authenticated resource owner.

10. The method of claim 9, wherein, The method further comprises one of the following: The first identifier is different from the third identifier, and the second information is sent to the first device, wherein the second information is used to indicate at least one of the following: a revocation request failure and a failure reason for the revocation request failure, and the failure reason is that the first identifier is not an identifier of the authenticated resource owner. The method further comprises one of the following: The first identifier is different from the third identifier, and the second information is sent to the first device, wherein the second information is used to indicate at least one of the following: a revocation request failure and a failure reason for the revocation request failure, and the failure reason is that the first identifier is not an identifier of the authenticated resource owner.

11. The method of claim 10, wherein, The method further comprises: The second message is sent to the seventh device, wherein the second message is used to request revocation of authorization, and the second message comprises at least one of the following: the first identifier, the second identifier, the type information, and the purpose information; The second response sent by the seventh device is received, wherein the second response is used to indicate successful revocation of authorization. The second device is the fourth device, and the seventh device is at least one of the following: the third device and the eighth device; or The second device is the fifth device, and the seventh device is at least one of the following: the ninth device and the sixth device; or The second device is the fifth device, and the seventh device is at least one of the following: the ninth device and the third device.

12. The method of claim 11, wherein, The method further comprises: The first response is sent to the first device, wherein the first response is used to indicate successful revocation of the relevant authorization of the resource owner.

13. The method of claim 8, wherein, The second device is the fifth device, and the method further comprises: The second message sent by the sixth device is received, wherein the second message is used to request revocation of authorization, and the second message comprises at least one of the following: the first identifier, the second identifier, the type information, and the purpose information, The second response is sent to the sixth device, wherein the second response is used to indicate successful revocation of authorization.

14. The method of claim 13, wherein, The second message further comprises at least one of the following: location information of the ninth device, address information of the ninth device, and identifier information of the ninth device; and the method further comprises: The second message is sent to the ninth device based on at least one of the following: the location information of the ninth device, the address information of the ninth device, and the identifier information of the ninth device; and the second response sent by the ninth device is received, wherein the second message is used to request revocation of authorization, and the second response is used to indicate successful revocation of authorization; and the second message further comprises at least one of the following: the location information, the address information, and the identifier information. And / or The second message is sent to the third device corresponding to the second identifier based on the second identifier; and the second response sent by the third device is received.

15. The method according to claim 13 or 14, characterized in that, The method further includes: receiving a first response sent by the second device, wherein the first response is used to indicate that the related authorization of the resource owner is successfully revoked; sending the first response to the first device.

16. The method according to any one of claims 13 to 15, characterized in that, Before the receiving the second message sent by the sixth device, the method further includes: in a case where it is determined that the service related to the first message is the service that the sixth device publishes, sending the first message to the sixth device; wherein the sixth device is capable of generating a token for accessing a device in a domain where the fifth device is located.

17. The method of claim 8, wherein, The second device is the sixth device, and the method further includes: in a case where the first identity is different from the third identity, sending second information to the first device, wherein the second information is used to indicate at least one of the following: a revocation request failure and a failure cause of the revocation request failure, the failure cause being that the first identity is not an identity of an authenticated resource owner; and the third identity being an identity of the authenticated resource owner.

18. The method of claim 17, wherein, The method further includes at least one of the following: in a case where the first identity is the same as the third identity, identifying a token that needs to be revoked based on at least one of the following: the first identity, service information, type information, and purpose information; in a case where the first message does not include the first identity, identifying a token that needs to be revoked based on at least one of the following: the third identity, service information, the type information, and the purpose information; wherein at least one of the type information and the purpose information is used to determine the service information.

19. The method of claim 18, wherein, The method further includes: sending a second message to a tenth device, wherein the second message is used to request revocation of authorization, and the second message includes at least one of the following: a first identity, a second identity, type information, and purpose information; and the tenth device is at least one of the following: a third device, the fifth device, and an eleventh device; receiving a second response sent by the tenth device, wherein the second response is used to indicate that the authorization is successfully revoked.

20. The method of claim 19, wherein, When the tenth device is the fifth device, the second message includes the second identity, and the second identity is determined based on information in the identified token that needs to be revoked; and the fifth device is determined based on the identified token that needs to be revoked.

21. The method according to any one of claims 17 to 20, characterized in that, The receiving the first message sent by the first device includes: receiving, by the fifth device, the first message sent by the first device, wherein the first message is sent in a case where the fifth device determines that the first message can be published to a sixth device by a service.

22. The method according to any one of claims 17 to 21, characterized in that, The method further includes: sending, by the fifth device, a first response to the first device, wherein the first response is used to indicate that the related authorization of the resource owner is successfully revoked.

23. An information processing method characterized by comprising: The method includes: a first device sending a first message to a second device, wherein the first message is used to request revocation of authorization of a resource owner, and the resource owner is related to the first device.

24. A first device, comprising: The method includes: The first transceiver module is configured to send a first message to the second device, wherein the first message is used to request revocation of a related authorization of a resource owner, and the resource owner is related to the first device.

25. A second device, comprising: The first transceiver module is configured to send a first message to the second device, wherein the first message is used to request revocation of a related authorization of a resource owner, and the resource owner is related to the first device. The first transceiver module is configured to send a first message to the second device, wherein the first message is used to request revocation of a related authorization of a resource owner, and the resource owner is related to the first device.

26. A communications device, characterized by One or more processors; The communication device is configured to perform the information processing method in any one of claims 1-4, or claims 5-22, or claim 23. The first device and the second device; wherein the first device is configured to implement the information processing method in any one of claims 1-4, and the second device is configured to implement the information processing method in any one of claims 5-22.

27. A communication system, characterized by The instructions, when executed on the communication device, cause the communication device to perform the information processing method in any one of claims 1-4, or claims 5-22, or claim 23. The computer program or instructions, when executed on the processor, implement the information processing method in any one of claims 1-4, or claims 5-22, or claim 23.

28. A storage medium, the storage medium storing instructions, wherein, ​ 29. A computer program product comprising a computer program or instructions, characterized in that, ​