System and method for anonymous authorization of end users in communication network

By using network functions and authentication/authorization servers to generate aggregated service credentials in 6G networks, user identities are anonymized and authenticated, thus solving the problem of user privacy leakage caused by multiple service providers and achieving protection of user privacy and network security.

CN122056010APending Publication Date: 2026-05-15HUAWEI TECH CO LTD
0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2023-10-18
Publication Date
2026-05-15

Smart Images

  • Figure CN122056010A_ABST
    Figure CN122056010A_ABST
Patent Text Reader

Abstract

Systems and methods are provided for anonymous authorization involving an end user in a communication network. According to an aspect, a method for subscribing to one or more services may be provided. The method may include receiving a subscription request from a user for subscribing to one or more services, and selecting the one or more services identified by one or more service IDs corresponding to the subscription request. The method further includes obtaining one or more service credentials corresponding to the one or more services, and generating an aggregated service credential by aggregating the one or more service credentials. The method further includes sending the aggregated service credentials to an authentication / authorization server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication networks, and more particularly to systems and methods for anonymous authorization of end users in communication networks. Background Technology

[0002] The upcoming 6G mobile communication era is expected to bring about significant changes in how various services are seamlessly integrated. Unlike previous generations of technology, the 6G system envisions multiple service providers collaborating to offer diverse services. However, this new network architecture also presents security challenges. When users attempt to access services, vulnerabilities may emerge in the 6G network, potentially exposing sensitive user data. The involvement of multiple service providers complicates data protection and increases the risk to user privacy. Interactions between different providers could lead to the leakage of user privacy information during transmission at various stages of the system. Finding a balance between providing diverse services and maintaining robust security measures is a key issue that 6G systems need to address.

[0003] Therefore, there is a need for a system and method for anonymous authorization of end users in communication networks to eliminate or mitigate one or more limitations of the prior art.

[0004] This background information is provided to disclose information that the applicant believes may be relevant to the present invention. Nothing in the foregoing is necessarily, and should not be construed as, prior art constituting the present invention. Summary of the Invention

[0005] This invention provides a system and method for anonymous authorization of end users in a communication network. According to one aspect, a method for subscribing to one or more services is provided. The method may include a network function receiving a subscription request from a user. The subscription request may be used to subscribe to one or more services. The method may further include: the network function selecting the one or more services, the one or more services being identified by one or more service IDs corresponding to the subscription request. The method may further include: the network function obtaining one or more service credentials corresponding to the one or more services. The method may further include: the network function generating an aggregated service credential, the aggregated service credential being generated by aggregating the one or more service credentials. The method may further include: the network function sending the aggregated service credential to an authentication / authorization server. The method may further include: the authentication / authorization server receiving the aggregated service credential from the network function.

[0006] The network function obtaining one or more service credentials corresponding to the one or more services may include: the network function receiving the one or more service credentials from one or more service providers. The service providers provide the one or more services. The network function obtaining one or more service credentials corresponding to the one or more services may also include: the network function generating the one or more service credentials.

[0007] The one or more services may be provided by one or more service providers, each of which may provide at least one service. The subscription request may include one or more of the user's temporary identifier (ID), service requirements, and user authentication parameters generated based on credentials derived from the temporary ID. Service credentials may be generated based on at least one of the following: the user's temporary ID, the service ID corresponding to the service, the user authentication parameters, and information about the service provider, wherein the service provider provides the service.

[0008] According to one aspect, a system for subscribing to one or more services can be provided. The system may include a network function and an authentication / authorization server. The network function may be used to receive a subscription request from a user, wherein the subscription request is for subscribing to one or more services. The network function may also be used to select the one or more services, wherein the one or more services are identified by one or more service IDs corresponding to the subscription request. The network function may also be used to obtain one or more service credentials corresponding to the one or more services. The network function may also be used to generate an aggregated service credential by aggregating the one or more service credentials. The network function may also be used to send the aggregated service credential to the authentication / authorization server. The authentication / authorization server may be used to receive the aggregated service credential from the network function.

[0009] According to one aspect, a method for requesting a service in a 6G network can be provided. The method may include: a network function receiving a service request from a user. The service request may be a request for a service. The method may further include: the network function generating an authentication code. The authentication code is associated with one or more of a service ID identifying the service, an SP ID identifying the service provider (SP) providing the service, and authentication information of the user. The method may further include: the network function sending an authentication request to an authentication / authorization server. The authentication request includes one or both of the generated authentication code and the user's temporary ID. The method may further include: the network function receiving an authentication response from the authentication / authorization server indicating the authentication result of the authentication request. The method may further include: the network function determining, based on the authentication response, whether the user can access the service. The service request may include one or more of the user's temporary identifier (ID), the service specification of the service, and the user's authentication information. The user's authentication information may be generated at least based on the temporary ID. The user's authentication information may be further generated based on the service ID.

[0010] The method may further include: the authentication / authorization server verifying the authentication code using aggregated service credentials. The method may further include: the authentication / authorization server sending an authentication response, the authentication response indicating the authentication result of the authentication request.

[0011] The method may further include: the authentication / authorization server receiving the authentication request. The method may further include: the authentication / authorization server sending the authentication response.

[0012] According to one aspect, a system for requesting services in a 6G network can be provided. The system may include a network function and an authentication / authorization server. The network function may be used to receive service requests from users. The service request is a request for a service. The network function may also be used to generate an authentication code, wherein the authentication code is associated with one or more of the following: a service ID identifying the service, an SP ID identifying the service provider (SP) providing the service, and authentication information of the user. The network function may also be used to send an authentication request to the authentication / authorization server. The authentication request includes one or both of the generated authentication code and the user's temporary ID. The network function may also be used to receive an authentication response from the authentication / authorization server indicating the authentication result of the authentication request. The network function may also be used to determine, based on the authentication response, whether the user can access the service. The authentication / authorization server may be used to receive the authentication request. The authentication / authorization server may also be used to send the authentication response.

[0013] According to another aspect, an apparatus is provided. The apparatus includes modules for performing one or more of the methods and systems described herein.

[0014] According to one aspect, an apparatus is provided, wherein the apparatus includes: a memory for storing a program; and a processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to perform one or more of the methods and systems described herein.

[0015] According to another aspect, a computer-readable medium is provided, wherein the computer-readable medium stores program code executable by a device, the program code being used to perform one or more of the methods and systems described herein.

[0016] According to one aspect, a chip is provided, wherein the chip includes a processor and a data interface, the processor reading instructions stored in a memory through the data interface to execute one or more of the methods and systems described herein.

[0017] Other aspects of the invention provide apparatus and systems for implementing the methods described according to the first aspect disclosed herein. For example, wireless stations and access points may be configured with machine-readable storage including instructions that, when executed by a processor of these devices, cause the devices to perform one or more of the methods and systems described herein.

[0018] The embodiments described above in conjunction with various aspects of the present invention can be implemented based on these aspects. Those skilled in the art will understand that embodiments can be implemented in conjunction with the aspects described therein, but may also be implemented together with other embodiments of the described aspects. It will be apparent to those skilled in the art that embodiments are mutually exclusive or inconsistent with each other. Some embodiments may be described in conjunction with one aspect, but may also be applicable to other aspects, as will be apparent to those skilled in the art. Attached Figure Description

[0019] Other features and advantages of the present invention will become apparent from the following specific embodiments, taken in conjunction with the accompanying drawings, in which: Figure 1 The network topology is shown according to one aspect.

[0020] Figure 2 Another network topology based on one aspect is shown.

[0021] Figure 3 A method for user registration is shown, based on one aspect.

[0022] Figure 4 The method of registering a service provider is shown according to one aspect.

[0023] Figure 5 This illustrates a service subscription method based on one aspect.

[0024] Figure 6 This illustrates another service subscription method based on one aspect.

[0025] Figure 7 This illustrates a service authorization method triggered by a user on one side.

[0026] Figure 8 This illustrates another service authorization method based on one aspect.

[0027] Figure 9 This illustrates a method for subscribing to one or more services, based on one aspect.

[0028] Figure 10 The method for requesting a service is illustrated according to one aspect.

[0029] Figure 11 Apparatus according to different aspects of the invention is shown, which can perform any or all of the operations of the methods, systems and features explicitly or implicitly described herein.

[0030] It should be noted that in all the accompanying drawings, similar features are identified by similar reference numerals. Detailed Implementation

[0031] This invention provides a system and method for anonymous authorization of end users in a communication network. According to one aspect, at least reference is made to... Figure 5 , Figure 6 and Figure 9 A method 900 for subscribing to one or more services can be provided. Method 900 can be performed by a network function (e.g., network (SPM) 120). The method may include: receiving a subscription request 501 or 601 from a user for subscribing to one or more services. The method may further include: selecting one or more services identified by one or more service IDs corresponding to the subscription request. The method may further include: obtaining one or more service credentials corresponding to one or more services, and further generating an aggregated service credential by aggregating the one or more service credentials. The method may further include: sending the aggregated service credential 507 or 605 to an authentication / authorization server (e.g., a trusted third party 130).

[0032] According to another perspective, at least referencing Figure 7 , Figure 8 and Figure 10 A method 1000 for requesting a service can be provided. Method 1000 can be performed by a network function (e.g., network (SPM) 120). The method includes: receiving 1001 a request for the service from a user (e.g., service request 701 or 801). The method may further include: generating 1002 an authentication code associated with one or more of a service ID identifying the service, a SPID identifying the service provider (SP) providing the service, and authentication information of the user. The method may further include: sending 1003 an authentication request 703 or 803 to an authentication / authorization server (e.g., a trusted third party 130), the authentication request including one or both of the generated authentication code and a temporary ID of the user. The method may further include: receiving 1004 an authentication response 705 or 805 from the authentication / authorization server (trusted third party 130) indicating the authentication result of the authentication request, and determining 1005 whether the user can access the service based on the authentication response.

[0033] According to one approach, anonymous authorization can be provided when a user requests services from a communication network. According to another approach, both the user and the service provider (SP) can register with a trusted third party, and the user can request services from the network, which will then select services for the user. In some such networks (e.g., 6G networks), to ensure secure communication between the user and the SP, both the user and the SP may need to be verified by a trusted third party (a corresponding authentication / authorization server).

[0034] According to one aspect, the network can manage services, including selecting services for users (i.e., performing service selection). The network can manage services through one or more network functions and is therefore responsible for service provision management. One or more network functions may be referred to as service provision management (SPM) functions. Here and elsewhere, function names are provided for descriptive purposes only, and such names are subject to change without necessarily affecting the scope of this disclosure. According to one aspect, because the network can manage services, there may not be a direct communication channel between the user and the SP before service authorization (or before a service request submitted by the user to the SP is authorized).

[0035] According to one aspect, systems and methods for authenticating users and service providers (SPs) over a network can be provided. According to this aspect, when a user requests a service from the network, the user's real identifier (ID) can be separated from the user's temporary ID. Therefore, the network may not know the user's real ID because the user may use a temporary ID to request services.

[0036] According to one aspect, when the network does not know the user's real ID and the trusted third party does not know the service ID, the service ID and the user's real ID can be separated. According to one or more aspects, the trusted third party can be responsible for one or more of the authentication and authorization of the user, service, and service provider. Therefore, anonymous service authorization can be provided after the authentication operations described according to one or more aspects of this document.

[0037] As the next-generation mobile communication system, 6G is expected to provide far more than just communication channels or connectivity services; it will enable intelligent services. 6G can support the computing and processing capabilities of various services in a distributed and collaborative manner. These services may include one or more data communication, data processing, or data computing functions, or various vertical applications (e.g., vehicle-to-everything (V2X) and the Internet of Things (IoT)). These services can be network-native services provided by network providers or plug-in services provided by third parties. In one respect, traditional 5G networks can be identified as providing connectivity-specific services.

[0038] In some networks (e.g., 6G networks), each service may require an authentication mechanism when a user accesses one or more services, which can improve the security of the 6G network.

[0039] Furthermore, the interconnection between multiple untrusted providers in 6G could increase the risk of privacy breaches. More specifically, combining multiple services from different service providers (SPs) could increase the risk of leaking sensitive personal user data. For example, users may not want the SPs to know that they are using an SP's service or what service they are using. Users may only want to access the service but may not want to know the information about the SP providing the service. Therefore, it may be desirable to hide the link between the user ID and the service (used by the user) from the network or service provider. Additionally, it may be desirable that the user ID and associated services are not linked.

[0040] According to one aspect, systems and methods for anonymous authorization (of users) can be provided, allowing user IDs to be separated (not linked) from services available to the user. According to another aspect, anonymous authorization can also be provided for services in addition to verifying users and service providers (SPs). According to one or more aspects, the systems, methods, and apparatus provided herein can improve user privacy, for example, in 6G networks.

[0041] The 3rd Generation Partnership Project (3GPP) establishes secondary authentication / authorization for users through a Data Network Authentication, Authorization, and Accounting (DN-AAA) server. This server provides the authorization process, granting users access to application services. The authorization process is triggered by the Session Management Function (SMF) during Protocol Data Unit (PDU) session establishment. The SMF can send sensitive authentication / authorization information of the user to the DN-AAA server. The sending of sensitive authentication / authorization information by the SMF may raise privacy concerns for users.

[0042] To address privacy concerns, some existing solutions offer a cross-domain service authentication protocol where users can choose their services. Users register with an identity server and obtain ID credentials from it. Users subscribe to services from a service provider (SP) and receive a list of service information (e.g., service IDs, service provider public keys). Simultaneously, the SP generates a service credential for each user for each service and sends this credential to the identity server. When a user requests a selected service, the identity server authenticates the user and the service and grants access to the service. Compared to 3GPP, this protocol aims to protect user privacy by separating the user ID from the service ID required by the user.

[0043] However, in some scenarios, the network can be as follows: Figure 1 In network topology 100, services are determined or selected for the user. Figure 1 A network topology according to one aspect is illustrated. In an exemplary embodiment, user 110 may send a service request regarding food consumption analysis. Network (e.g., SPM) 120 may determine, based on or according to network performance, user location, and service request, the data collection service 106 provided by DAM provider 102, the data training service 104 provided by AI provider 101, and the communication connectivity service 108 provided by network provider 103. User 110 may need to be authenticated by a trusted third party 130 to be granted access to these services. Furthermore, these service providers 101, 102, and 103 may need to be verified by the trusted third party 130 before allowing the user access to their services.

[0044] According to one aspect, network (e.g., SPM) 120 can participate in the authentication of user 110 and one or more SPs 101, 102 and 103 through a trusted third party 130.

[0045] To establish a secure communication channel between user 110 and one or more SPs 101, 102, or 103, each user and SP may require authentication by a trusted third party 130. Since the network (e.g., SMP) 120 can manage one or more services provided by one or more SPs and may have the ability to select one or more services for a user, a direct communication channel between the user and SP may not necessarily exist before service authorization. Therefore, the network (e.g., SMP) 120 can participate in the authentication of both the user and the service provider through the trusted third party 130. Thus, authentication of both the user and the service provider can be provided, depending on the aspect.

[0046] As mentioned, network (e.g., SMP) 120 can manage one or more services provided by different SPs 101, 102, and 103. Therefore, combining multiple services through network (e.g., SMP) 120 may increase the risk of leaking sensitive user data. On one hand, anonymous service authorization can be provided, which can enhance user privacy in 6G.

[0047] refer to Figure 1 Network (e.g., SPM) 120 can refer to one or more network functions responsible for: managing one or more services of one or more SPs and selecting or subscribing to one or more services for one or more users. Each SP can provide a set of services; for example, SP 101 could be an AI provider providing services 104 and 105, SP 102 could be a DAM provider providing services 106 and 107, and SP 103 could be a network provider providing services 108 and 109.

[0048] According to one aspect, user 110 may subscribe to or select one or more services provided by one or more SPs through one or more network functions (e.g., SPM) 120. Therefore, user 110 may not communicate with the SP when selecting or subscribing to one or more services. Instead, the network may communicate with one or more SPs on behalf of the user through one or more network functions (e.g., SPM) 120 to subscribe to or select one or more services. A trusted third party 130 may be responsible for authenticating one or more of the user, SPs, and services.

[0049] On one hand, user ID privacy and service privacy can be enhanced. Such improvements can be applied in contexts where a network (e.g., its administrator or owner) may be interested in user information (e.g., user ID), and a trusted third party 130 may be interested in services (e.g., services used by the user (or frequently used services)). The network may be interested in user information (e.g., user ID) for certain purposes. For example, by tracing the user ID, the network can obtain one or more of the user's itinerary and user behavior. The trusted third party 130 may be interested in the services received by the user (e.g., frequently used services). This information sought by the network and the trusted third party can be identifying information used to identify the exact user.

[0050] In some embodiments, such as in topology 100, services may be deployed by different SPs 101, 102, and 103. Trust relationships may not exist between SPs. Each SP may provide a set of services. Depending on one aspect, each SP and user may register with a trusted third party 130. User 110 may subscribe to services with the assistance of a network (e.g., SPM) 120. User 110 may need to be authenticated when accessing or requesting access to one or more services over the network.

[0051] According to one approach, a method for anonymous authorization can be provided, which allows users and service providers (SPs) to be verified when a user requests a service. After authenticating the user and SP, the user can obtain permission to access one or more requested services. The authentication process can improve the privacy protection of user IDs and service IDs.

[0052] According to one aspect, the network (e.g., SPM) 120 can participate in the authentication of users and one or more SPs. According to another aspect, user ID privacy and service ID privacy can be enhanced during service authorization.

[0053] According to one approach, a method for anonymous authorization can be provided to enable users and service providers (SPs) to be authenticated with the participation of a network (one or more network functions, such as SPM). According to another approach, the user's real ID can be separated from their temporary ID. For example, when a user requests a service from the network, the user can request it using their temporary ID instead of their real ID.

[0054] According to one aspect, the service ID and the user's real ID can be separated, so that the network 120 does not know the user's real ID, and the trusted third party 130 does not know the service ID (identifying the service the user is requesting). Therefore, as described according to one or more aspects of this document, anonymous service authorization can be provided after authenticating the user and the SP.

[0055] According to one perspective, it can involve three stages: registration stage, service subscription stage, and service authorization stage.

[0056] According to one aspect, during the registration phase, each SP can register with a trusted third party 130, obtain SP credentials, and provide a list of available services to the trusted third party 130. User 110 can register with a trusted third party and obtain one or more temporary ID credentials, a list of temporary IDs, and a list of available services. User 110 can use the temporary IDs to subscribe to services from the SP.

[0057] According to one aspect, during the service subscription phase, user 110 can use a temporary ID to request a subscription to one or more services offered by one or more SPs. A network (e.g., SPM) 120 can negotiate the service subscription with the SP on behalf of the user. The network (e.g., SPM) 120 can manage subscription and service credentials associated with the user's temporary ID and service information (e.g., service ID, service provider ID).

[0058] According to one aspect, during the service authorization phase, a user can send a service request for one or more services to a network (e.g., SPM) 120. The network (e.g., SPM) 120 can select one or more services and generate an authentication code, which can be used by a trusted third party 130 for anonymous verification or authorization of the user, services, and service providers. The network (e.g., SPM) 120 can anonymously authorize services to the user and then establish or configure a secure tunnel between the user 110 and one or more SPs.

[0059] While existing solutions (3GPP) provide secondary authentication / authorization for users, such operations may leak sensitive user authentication / authorization information to third parties. Some existing solutions offer an authentication / authorization protocol based on the separation of service ID and user ID, aiming to improve privacy. However, these solutions are all based on users subscribing to services themselves. In 6G scenarios, users may not be able to choose services. Instead, service selection can be done by the network. Therefore, according to one aspect, a system and method for anonymous authorization for users can be provided, which can enhance user privacy. According to one aspect, the network (e.g., SPM) 120 can be used to select services for users and participate in the authentication of users and one or more SPs. According to one aspect, the user's real ID can be separated from the user's temporary ID, so that when a user requests a service, the network may not know the user's real ID, thereby improving user privacy. According to one aspect, the service ID can be separated from the user's real ID, so that the trusted third party 130 participating in the authentication of users, services, and SPs does not know the service ID. Therefore, service management functions (performed by the network (e.g., SPM) 120) can be separated from ID management functions (performed by the trusted third party 130). According to one or more aspects described in this article, separating a user's real ID from their temporary ID and separating a service ID from their real ID can provide anonymous service authorization after the authentication process.

[0060] Figure 2 Another network topology according to one aspect is illustrated. Network topology 200 may be similar to topology 100, wherein additional interactions (or communication channels or instances) 202, 204, and 206 are provided. Interaction 204, connecting user 110 to trusted third party 130, may refer to the user's registration with the trusted third party during the registration phase. Similarly, interaction 206, connecting SP to trusted third party 130, may refer to the service provider's registration with trusted third party 130 during the registration phase. Interaction 202, connecting user to SP, may refer to the tunnel established by network 120 after service authorization.

[0061] Topology 200 illustrates a system model for performing one or more user-related authentication and authorization operations when a user requests a service. User 110 can be a terminal device or a client. There can be multiple independent SPs 101, 102, and 103, which can register with the network (e.g., during the registration phase). An SP can provide a set of services. The network can subscribe to or select services provided by one or more SPs on behalf of the user.

[0062] According to one aspect, network (e.g., SPM) 120 can manage services provided by one or more SPs. Network 120 can subscribe to one or more services on behalf of user 110. Network 120 can determine or select services based on the user's service needs. Network 120 can manage service credentials. Network 120 can generate authentication codes used to verify the user, the required service, and the service provider offering the required service to the user. After service authorization, network 120 can establish or configure a secure tunnel between the user and the service provider.

[0063] According to one aspect, a trusted third party (130) can handle user registration and SP registration. The trusted third party (130) can generate one or both temporary ID credentials and SP credentials. The trusted third party (130) can verify the user, one or more SPs, and one or more required services. The trusted third party (130) can generate temporary IDs.

[0064] According to one aspect, user 110 can register with a trusted third party 130. User 110 can also request service subscriptions or subscribe to services. User 110 can also request services or send service requests.

[0065] According to one aspect, an SP can register with a trusted third party (130). An SP can generate one or more service credentials corresponding to one or more services provided by the SP. An SP can also provide one or more services.

[0066] As described in this document, during the registration phase, the SP can register with a trusted third party 130, obtain one or more SP credentials, and provide the trusted third party with a list of available services. During the registration phase, the user 110 can register with the trusted third party 130 and obtain one or more of the user's temporary ID credentials, a list of temporary IDs, and a list of available services. The temporary ID credentials can correspond to or be associated with a temporary ID (therefore, temporary ID credentials can be linked to temporary IDs). Users can use one or more temporary IDs to subscribe to one or more services offered by one or more SPs.

[0067] According to one aspect, during the service subscription phase, user 110 can request a service subscription from an SP using a temporary ID. A network (e.g., SPM) 120 can negotiate the service subscription with one or more SPs on behalf of the user. The network (e.g., SPM) 120 can manage subscription and service credentials that can be associated with the user's temporary ID and service information (e.g., service ID, service provider ID).

[0068] According to one approach, during the service authorization phase, user 110 may first exchange a temporary ID and then send a service request to network (e.g., SPM) 120 requesting one or more services. The user exchanging the temporary ID may mean that the user uses their temporary ID instead of their real ID to request one or more services. Network (e.g., SPM) 120 may select one or more services and generate an authentication code that can be used to anonymously verify one or more of the user, one or more services, and one or more SPs providing the one or more services. Network (e.g., SPM) 120 may then anonymously authorize (perform anonymous authorization) the requested one or more services to the user through a trusted third party. Network (e.g., SPM) 120 may then establish or configure a secure tunnel between the user and one or more SPs.

[0069] According to one aspect, the network (e.g., SPM) 120 can manage service profiles and service subscriptions, and select services for users. For service subscriptions, a temporary user ID can be used to subscribe to services on behalf of the user. By using a temporary user ID instead of the user's real ID, the user's real ID can be separated from the temporary ID, and the network (e.g., SPM) 120 cannot know the user's real ID.

[0070] According to one aspect, the network (e.g., SPM) 120 can participate in the following operations: verifying the user, SP, and required service based on one or more of temporary ID credentials, service credentials, and SP credentials, or performing verification on the user, SP, and required service. Therefore, one or more of the user, service, and SP can be anonymously authorized, authenticated, or both, thereby enhancing user ID privacy.

[0071] Figure 3A method for user registration is illustrated according to one aspect. Method 300 may refer to the (user) registration phase. Method 300 illustrates how user 110 can register with a trusted third party 130. The method may include user 110 sending a registration request 301. Request 301 may include the user's real ID. The method may further include: trusted third party 130 verifying 302 the user and generating 302 one or more temporary IDs for the user. Then, trusted third party 130 may generate 303 a temporary ID credential for the user. This credential may be associated with the user's temporary ID. In some embodiments, there may be more than one temporary ID and more than one corresponding credential. The method may further include: trusted third party 130 sending a registration response 304 to user 110. The response 304 may include a temporary ID credential, a temporary ID, and one or more of the available services from the service provider's list of available services when the service provider registers with the trusted third party. User 110 may save the temporary ID credential, the temporary ID, and one or more of the available services. The credential for the temporary ID may be linked to or mapped to the temporary ID. A trusted third party 130 can obtain a temporary ID by generating a temporary IDS or by obtaining a temporary ID from another entity (e.g., one or more service providers).

[0072] In some embodiments, one or more SPs may assign one or more temporary IDs to a user. The temporary IDs may follow a specific format. In some embodiments, one or more SPs may send the temporary IDs to a trusted third party during registration.

[0073] Figure 4 This illustrates a method for registering a service provider according to one aspect. Method 400 may refer to the SP registration phase. Method 400 illustrates how an SP 410 (which may be similar to SP 101, 102, or 103) can register with a trusted third party 130. Method 400 may include: SP 410 sending a registration request 401 to the trusted third party 130. The request 401 may include one or more of the following: SP ID, a list of available services (e.g., service ID, service abstraction, service information). Method 400 may also include: the trusted third party verifying 402 the SP and generating SP credentials for the SP. These SP credentials may be associated with the SP ID. The trusted third party 130 may then send a registration response 404 to the user. This response may include the SP credentials. SP 410 may save the received SP credentials.

[0074] According to one perspective, user credentials generated by a trusted third party can be used to generate authentication codes or parameters, as described herein. According to another perspective, SP credentials generated by a trusted third party can be used to generate authentication codes. Therefore, authentication of both the user and the SP can be based on one of these methods or verified using an authentication code.

[0075] Figure 5 A service subscription method according to one aspect is illustrated. In method 500, user 110 may send a subscription request 501 to network (e.g., SPM) 120 to subscribe to one or more services. Upon receiving subscription request 501, network (e.g., SPM) 120 may initiate subscription negotiation with one or more SPs on behalf of the user through one or more network functions. One or more SPs may generate their service credentials and send the service credentials to network (e.g., SPM) 120. In method 500, one or more SPs 410 can control the subscription through the service credentials.

[0076] According to one aspect, method 500 may include: user 110 sending a subscription request 501 to network (e.g., SPM) 120. The request 501 may include one or more of the user's temporary ID, service requests, or service information (which may include one or more service IDs, one or more SP IDs), obtained from a trusted third party 130 during the user registration phase (e.g., method 300). The subscription request 501 may also include an authentication parameter (authentication parameter / auth-para). This authentication parameter may be the output of a user-generated function. The input to the function may include credentials for the temporary ID and a user-generated random number.

[0077] Method 500 may also include: a network (e.g., SPM 120) selecting services provided by SP 410 via one or more network functions. Send a subscription agreement request 503 to SP 410. This request 503 may include the user's temporary ID, authentication parameters, and service information. The ID. In some embodiments, the network (e.g., SPM) 120 may not need to identify or may not be able to identify the service. Therefore, network (e.g., SPM) 120 can request services from SP 410 based on service needs (and then SP can determine the services based on the service needs).

[0078] Method 500 may also include: SP 410 for service s Generate a 504 service credential. This service credential can be associated with one or more of the service ID, authentication parameters, and SP information (e.g., the SP's public key, private key, or both). In some embodiments, SP 410 can generate a 504 service credential for each service (e.g., in the case where one or more users request multiple services, the SP can generate a service credential for each service for each user). The generated service credential can be associated with a user (based on authentication parameters).

[0079] Method 500 may further include: SP 410 sending a subscription agreement response 505 to network (e.g., SPM) 120. The response 505 may include one or more of the following: SP ID, service credentials, and service information (e.g., a list of service IDs, a service abstraction). For each service ID, a corresponding service abstraction may be included. A service abstraction may refer to an abstraction of a service, describing the service without providing the underlying implementation details of the service or system. In some embodiments, there may be multiple SPs, and multiple SPs may provide the same service. Therefore, in some embodiments, the same service (identified by the same service ID) may be provided by different SPs (with different SP IDs).

[0080] Method 500 may further include, upon receiving a subscription response including service credentials, network (e.g., SPM) 120 aggregating 506 all service credentials and obtaining aggregated service credentials 507. The inputs to aggregated service credentials 507 are all service credentials associated with the user, and the SP ID. Aggregated service credentials 507 can be generated in a manner that the entity receiving the aggregated service credentials may be unable to determine the inputs (e.g., service credentials and SP ID).

[0081] Method 500 may further include: network (e.g., SPM) 120 sending an aggregated service credential with a temporary user ID to a trusted third party 130 507. Method 500 may further include: network (e.g., SPM) 120 sending a subscription response to the user 508. The response may include service information (e.g., a list of service IDs, service abstraction). Method 500 may further include: trusted third party 130 storing the aggregated service credential 509. Although trusted third party 130 may know the aggregated service credential, trusted third party 130 may not know or be able to generate the service credential and SP ID. As will be understood, although method 500 shows one SP 410, multiple SPs may be involved.

[0082] Figure 6 Another service subscription method 600 according to one aspect is illustrated. Method 600 is based on a network (e.g., SPM) 120 that generates service credentials. In method 600, user 110 may send a subscription request 601 to network (e.g., SPM) 120 to subscribe to one or more services. Upon receiving subscription request 601, network (e.g., SPM) 120 may initiate subscription negotiation with one or more SPs on behalf of the user through one or more network functions. Network (e.g., SPM) 120 may generate its service credentials and send aggregated service credentials to a trusted third party. Figure 6In this context, the network (e.g., SPM) 120 can generate one or more service credentials (604), and aggregate these service credentials to obtain an aggregated service credential. Therefore, the network (e.g., SPM) 120 can control one or more user service profiles. Figure 5 In contrast, SP 410 generates one or more 504 service credentials, thus controlling one or more user service profiles.

[0083] According to one aspect, method 600 may include: a user sending a subscription request 601 to a network (e.g., SPM) 120. The request 601 may include one or more of the user's temporary ID, service request, or service information, obtained from a trusted third party 130 during the user registration phase. The request 601 may also include authentication parameters. These authentication parameters may be the output of a user-generated function. The input to the function may include credentials for the temporary ID and a user-generated random number.

[0084] Method 600 may also include: network (e.g., SPM) 120 selecting services provided by SP 410. Send a subscription agreement request 602 to SP 410. This request 602 may include the user's temporary ID and information about the service. The indication (e.g., service ID, service request, or at least one of these). In some embodiments, the network (e.g., SPM) 120 may not identify or be unable to identify the service. Therefore, network (e.g., SPM) 120 can request services from SP 410 based on service needs (and SP determines the services based on service needs).

[0085] Method 600 may further include: SP 410 sending a subscription agreement response 603 to network (e.g., SPM) 120. Response 603 may include service information (e.g., a list of service IDs, a service abstraction) and one or more authenticated SPs associated with SP credentials generated by the SP. The authenticated SP may be the output of a function whose input is associated with SP credentials or SP information (e.g., SP ID).

[0086] Method 600 may further include: network (e.g., SPM) 120 generating 604 service credentials for each service. The service credentials may be associated with one or more of a service ID, authentication parameters, and authentication SP. Network (e.g., SPM) 120 may also aggregate all service credentials associated with a user and obtain or generate 604 aggregated service credentials 605.

[0087] Method 600 may further include: network (e.g., SPM) 120 sending an aggregated service credential with a temporary user ID to a trusted third party 130 605. Method 600 may further include: network (e.g., SPM) 120 sending a subscription response to the user 606. The response 606 may include service information. The trusted third party 130 may store or save the aggregated service credential 607. As will be understood, although method 500 is shown to involve one SP 410, multiple SPs may be involved.

[0088] refer to Figure 5 and Figure 6 The network (e.g., SPM) 120 can manage service profiles and service subscriptions. The network (e.g., SPM) 120 can also select one or more services for a user and subscribe to one or more services for the user. A temporary ID can be used for user service subscriptions, separating the user's real ID from the temporary ID, thereby preventing the network (e.g., SPM) 120 from knowing the user's real ID.

[0089] According to one perspective, the service authorization phase follows the subscription phase. The aggregated service credentials generated during the service subscription phase can be linked to a user, one or more services, and one or more service providers (SPs). Therefore, when a user requests a service, an authentication process can be performed to authenticate the user, the service, and one or more SPs.

[0090] Figure 7 A service authorization method 700 triggered by a user is illustrated. In method 700, user 110 may send a service request 701 to a network (e.g., SPM) 120 for one or more services. Upon receiving the service request 701 from the user, the network (e.g., SPM) 120 may generate an authentication code (authentication-code / auth-code) and send the authentication code to a trusted third party 130 to verify one or more of the user, SP, and services. After successful authentication, the network (e.g., SPM) 120 may establish a secure tunnel between the user and the SP. In this case, refer to Figure 7 The authentication code can be associated with one or more of the following: user information, service information, and SP information.

[0091] According to one aspect, method 700 may include: user 110 sending a service request 701 to network (e.g., SPM) 120. The request 701 may include one or more of the user's temporary ID, service ID, and authentication information (authentication information / auth-info) associated with the user. The authentication information may be the output of a user-generated function. The input to the function may include one or more of the service ID and user information (e.g., temporary ID, user-generated secret number). The service ID may be known to the user and included in the service request. Therefore, the authentication information may be associated with the user ID and the service ID.

[0092] Method 700 may further include: a network (e.g., an SPM) 120 generating a 702 authentication code (auth-code) based on one or more of authentication information, a service ID, and SP information (e.g., an SP ID). Since the network (e.g., the SPM) 120 manages the services of the SPs, the SPM can identify the SP providing the service identified by the service ID. Therefore, the generated authentication code can be linked to one or more of the user ID, service ID, and SP ID.

[0093] Method 700 may further include: a network (e.g., SPM) 120 sending an authentication request 703 to a trusted third party 130. The request 703 may include a temporary ID and an authentication code. Method 700 may further include: the trusted third party 130 verifying or validating the authentication code 704 by calculating the authentication code and the aggregated service credential. This verification includes one or more of user verification, service verification, and SP verification. According to one aspect, the trusted third party can verify the authentication code by comparing it with the aggregated service credential, since the aggregated service credential is linked to the user ID, service ID, and SP ID. As mentioned above, the authentication code can be linked to the user ID, service ID, and SP ID, while the aggregated service credential is linked to all service IDs and their corresponding service provider IDs, as well as a user ID. Therefore, the authentication code can be verified by comparing (e.g., calculating) the authentication code and the aggregated service credential.

[0094] Method 700 may further include: a trusted third party 130 sending an authentication response 705 to a network (e.g., SPM) 120 indicating an authentication result. In some embodiments, if the authentication response indicates a positive authentication result (authentication code verified), the network (e.g., SPM) 120 may configure and establish a 706 secure tunnel between the user and the SP. The network (e.g., SPM) 120 may grant the user authorization for the service. Method 700 may further include: the network (e.g., SPM) 120 sending a service response 707 to the user, the service response 707 indicating authorization for the service.

[0095] Figure 8 Another service authorization method according to one aspect is illustrated. In method 800, an authentication code generated by the network (e.g., SPM) 120 can be associated with service information and SP information. Furthermore, the authentication code can be used to authenticate users, which is performed by a trusted third party 130 by examining user credentials.

[0096] According to one aspect, method 800 may include: user 110 sending a service request 801 to network (e.g., SPM) 120. The request 801 may include one or more of the user's temporary ID, the user's authentication information (e.g., ID authentication information), and a service request. The ID authentication information may be the output of a function, generated by the user. The input to the function may include user information (e.g., temporary ID, user credentials (referring to credentials for the user's temporary ID)). Since the user may not know the ID of the requested service, the service request may be included in the service request, rather than in the service ID. In method 800, user 110 may only know one or both of the user information (e.g., user ID (e.g., temporary ID) and user credentials), so the user can generate their authentication information (e.g., ID authentication information) based on the user information. This generated authentication information can then be used by a trusted third party to verify user 804, as described herein.

[0097] Method 800 may further include: network (e.g., SPM) 120 selecting one or more services based on service requirements and generating an authentication code / auth-code. This authentication code may be associated with a selected temporary ID or ID authentication information, a service ID, and SP information (e.g., SP ID).

[0098] Method 800 may further include: a network (e.g., SPM) 120 sending an authentication request 803 to a trusted third party 130. The request 803 may include one or more of a temporary ID, an authentication code, and ID authentication information. The trusted third party 130 may also verify or validate the authentication code 804 by calculating the authentication code and the aggregated service credential. In some embodiments, the verification operation 804 may be similar to verification operation 704. The trusted third party 130 may also verify or validate the ID authentication information 804 by calculating the ID authentication information and the temporary ID credential. This verification 804 may include one or more of user verification, service verification, and SP verification.

[0099] Method 800 may further include: a trusted third party 130 sending an authentication response 805 to a network (e.g., SPM) 120. The authentication response 805 may indicate the result of the authentication operation 804 performed by the trusted third party 130. Method 800 may further include: the network (e.g., SPM) 120 configuring and establishing a secure tunnel 806 between the user 110 and the SP. The network (e.g., SPM) 120 may grant the user authorization for the service. Method 800 may further include: the network (e.g., SPM) 120 sending a service response 807 to the user, the service response 807 indicating authorization for the service.

[0100] refer to Figure 7 and Figure 8 To establish a secure communication link between user 110 and SP, both the user and SP may need to be authenticated by a trusted third party 130. Since the network (e.g., SPM) 120 can manage services and select one or more services for the user, a direct communication channel between the user and service provider may not be required before service authorization. Therefore, in some embodiments, authentication of both the user and service provider can be provided, where authentication involves the network (e.g., SPM). Following successful authentication, anonymous authorization can be provided to authorize the provision of services to the user while protecting user and service privacy.

[0101] The operations described in one or more methods described herein can be performed using existing authentication technologies. For illustrative purposes, an example can be provided to demonstrate how one or more methods can be implemented. In this example, the SP generates service credentials during the service subscription phase, and the user learns the service ID during the service authorization phase.

[0102] The parameter (1λ) can be set, where, These are safety parameters, output. Type A – 3 pairings are available. Among them, G1, 2. It is a prime number. The set of three cyclic groups, , Based on H: {0,1}* → The hash function. In one embodiment, one or more parameters in the parameter settings can be used to generate identity credentials and service credentials.

[0103] One or more keys can be generated by a trusted third party and one or more Service Providers (SPs). The trusted third party can generate its private and public keys by: selecting... and (yd) ,calculate , ← ( , )and , )← ( ),Will k is set to (as a private key) will k is set to ( , , , , ), as the public key. Each service provider can generate its private and public keys according to the following operations: P :choose ,calculate ← ,Will k is set to ,Will k is set to .

[0104] In one embodiment, the registration phase (e.g., method 300) may involve user 110 selecting a secret value. and random values And calculate = Then, the user can send a registration request to a trusted third party, 130. D, For example, registration request 301. After performing zero-knowledge proof on the knowledge of and , the trusted third party 130 can generate a temporary ID TID, choosing a random value. ,calculate ′= ( uTID, (XC)uTID). Then, the trusted third party 130 can send a registration response {TID, For example, a registration response of 304. A trusted third party 130 can store {ID, User 110 can calculate ′, TID}. = ( guTID, ( uTID)(x+yv))=( 1, 2) As proof of identity The tid is used to decipher blind signatures. If a trusted third party generates multiple temporary IDs, then each temporary ID has its corresponding... tid. A similar operation can be performed to implement method 400 for registering service providers and obtaining SP credentials.

[0105] In one embodiment, the service subscription phase (e.g., method 500) can be implemented as follows: User 110 can select a secret value. and another random value ,calculate = t. Then, the user can send a subscription request {TID,} to the network (e.g., SPM) 120. T, , a, service request}, for example, subscription request 501 to subscribe to a service. The network (e.g., SPM) 120 can be selected. P (For example, SP 410) provides the following services ,Towards P (For example, SP 410) sends a subscription agreement request {TID, T, , , s This is a subscription agreement request 503 error. P You can choose a random value Calculate 504 = ( ( , As a service Service Certificate And calculate TT = .Then, P (SP 410) can send a subscription agreement response to the network (e.g., SPM) 120. TT For example, a subscription response 505. A network (e.g., SPM) 120 can aggregate 506 service credentials of a consistent size: calculation = ( , ),polymerization{ } to obtain aggregate service credentials, . ,in, This is a collection of indexes of services subscribed to by the user. The network (e.g., SPM) 120 can send an aggregated service credential 507 with the user's temporary ID to a trusted third party 130. A similar operation can be performed to implement method 600 for service subscription, where the network (e.g., SPM) 120, instead of the SP, generates the service credential.

[0106] According to one aspect, the service request phase (or service authorization phase) (e.g., method 700 or 800) can be implemented as follows: When user 110 requests service sj, the user can select a random value. ,calculate , A= Then, the user can send a service request {TID, A, sj,} to the network (e.g., SPM) 120. For example, a service request might be 701 or 801. A network (e.g., SPM) can calculate a 702 or 802 authentication code, A'= Send an authentication request {TID, A' to a trusted third party 130 For example, authentication requests may return 703 or 803. A trusted third party can verify... s = ( By checking whether ( ′) = ( , To perform a checksum error 704 or 804.

[0107] According to one aspect, systems and methods for anonymous authorization can be provided. Based on such systems and methods, users and service providers (SPs) can be authenticated with the participation of a network (e.g., SPM) 120. Anonymous authorization can be performed by separating the user's real ID from their temporary ID, as the user can use their temporary ID to request services, thus preventing the network from knowing the user's real ID. Furthermore, anonymous authorization can be accomplished by separating the service ID from the user's real ID, thereby preventing trusted third parties from knowing the service the user is requesting (e.g., the service ID). Therefore, as described herein, anonymous service authorization can be provided after authentication. Thus, ID privacy and service privacy can be protected.

[0108] As described herein, one or more service credentials can be generated for service authentication. Additionally, one or more user ID credentials can be generated for user authentication. Furthermore, one or more SP credentials can be generated for SP authentication. According to one aspect, the network (e.g., SPM) 120 can manage the service and generate 702 and 802 authentication codes for verification by a trusted third party 130. These authentication codes can be linked to one or more of the service credentials, ID credentials, and SP credentials.

[0109] Figure 9 A method for subscribing to one or more services is illustrated according to one aspect. Method 900 may include: a network function (e.g., network (SPM) 120) receiving a subscription request (901) from a user (501 or 601). The subscription request may be used to subscribe to one or more services. The method may further include: the network function selecting one or more services (902), the one or more services being identified by one or more service IDs corresponding to the subscription request. The method may further include: the network function obtaining one or more service credentials corresponding to the one or more services (903). The method may further include: the network function generating an aggregated service credential (904), the aggregated service credential being generated by aggregating one or more service credentials. The method may further include: the network function sending the aggregated service credential (905) to an authentication / authorization server (e.g., a trusted third party 130) (507 or 605). The method may further include: the authentication / authorization server receiving the aggregated service credential from the network function.

[0110] The network function obtaining one or more service credentials corresponding to the one or more services may include: the network function receiving the one or more service credentials from one or more service providers, and the service providers providing the one or more services. The network function obtaining one or more service credentials corresponding to the one or more services may also include: the network function generating the one or more service credentials.

[0111] The one or more services may be provided by one or more service providers, each of which may provide at least one service. The subscription request 501 or 601 may include one or more of the user's temporary identifier (ID), service request, and user authentication parameters generated based on credentials derived from the temporary ID. Service credentials may be generated based on at least one of the following: the user's temporary ID, the service ID corresponding to the service, the user authentication parameters, and information about the service provider, wherein the service provider provides the service.

[0112] According to one aspect, a system for subscribing to one or more services can be provided. The system may include a network function (e.g., a network (SPM) 120) and an authentication / authorization server (e.g., a trusted third party 130). The network function may be used to receive a subscription request 501 or 601 from a user, wherein the subscription request is for subscribing to one or more services. The network function may also be used to select the one or more services, which are identified by one or more service IDs corresponding to the subscription request. The network function may also be used to obtain one or more service credentials corresponding to the one or more services. The network function may also be used to generate an aggregated service credential by aggregating the one or more service credentials. The network function may also be used to send the aggregated service credential to the authentication / authorization server. The authentication / authorization server may be used to receive the aggregated service credential from the network function.

[0113] Figure 10 A method for requesting a service is illustrated according to one aspect. Method 1000 may include: a network function (e.g., network (SPM) 120) receiving a service request 1001 or 801 from a user. The service request may be a request for a service. The method may further include: the network function generating an authentication code 1002, wherein the authentication code is associated with one or more of the following: a service ID identifying the service, an SP ID identifying the service provider (SP) providing the service, and authentication information of the user. The method may further include: the network function sending an authentication request 1003 or 803 to an authentication / authorization server (e.g., a trusted third party 130), the authentication request including one or more of the generated authentication code and a temporary ID of the user. The method may further include: the network function receiving an authentication response 1004 or 805 from the authentication / authorization server indicating the authentication result of the authentication request. The method may further include: the network function determining, based on the authentication response, whether the user can access the service 1005.

[0114] Service request 701 or 801 may include one or more of the following: a user's temporary identifier (ID), the service specification, and the user's authentication information. The user's authentication information may be generated at least based on the temporary ID. The user's authentication information may also be generated further based on the service ID.

[0115] The method may further include: the authentication / authorization server verifying a 704 or 804 authentication code using aggregated service credentials. The method may further include: the authentication / authorization server sending an authentication response 705 or 805 indicating the authentication result of the authentication request.

[0116] The method may further include: the authentication / authorization server receiving an authentication request 703 or 803. The method may further include: the authentication / authorization server sending an authentication response 705 or 805.

[0117] According to one aspect, a system for requesting services in a 6G network can be provided. The system may include a network function (e.g., a network (SPM) 120) and an authentication / authorization server (e.g., a trusted third party 130). The network function may be used to receive a service request 701 or 801 from a user, wherein the service request is a request for a service. The network function may also be used to generate an authentication code 702 or 802. The authentication code is associated with one or more of the following: a service ID identifying the service, an SP ID identifying the service provider (SP) providing the service, and authentication information of the user. The network function may also be used to send an authentication request 703 or 803 to the authentication / authorization server, the authentication request including one or more of the generated authentication code and a temporary ID of the user. The network function may also be used to receive an authentication response 705 or 805 from the authentication / authorization server indicating the authentication result of the authentication request. The network function may also be used to determine, based on the authentication response, whether the user can access the service. The authentication / authorization server may be used to receive the authentication request 703 or 803. The authentication / authorization server may also be used to send the authentication response 705 or 805. Figure 11An apparatus 1100 according to different aspects of the present invention is illustrated, which can perform any or all of the operations of the methods, systems, and features explicitly or implicitly described herein. For example, a computer with network capabilities can be configured as apparatus 1100. In some aspects, apparatus 1100 can be a device connected to network infrastructure via a wireless interface, such as a mobile phone, smartphone, or other device that can be classified as user equipment (UE). In some aspects, apparatus 1100 can be a machine-type communications (MTC) device (also known as a machine-to-machine (m2m) device), or other such device that can be classified as a UE even though it does not provide direct service to a user. In some aspects, apparatus 1100 can perform one or more operations of one or more methods described herein. For example, according to one or more aspects described herein, apparatus 1100 can be a user 110, a network (e.g., SMP) 120, a trusted third party 130, or an SP 410.

[0118] As shown, device 1100 may include processor 1110 (e.g., a central processing unit (CPU) or a dedicated processor, such as a graphics processing unit (GPU), or other such processor unit), memory 1120, non-transient mass storage 1130, input / output interface 1140, network interface 1150, and transceiver 1160, all of which are communicatively coupled via a bidirectional bus 1170. Transceiver 1160 may include one or more antennas. Depending on some aspects, any or all of the elements may be utilized, or only a subset of these elements may be utilized. Furthermore, device 1100 may include multiple instances of certain elements, such as multiple processors, multiple memories, or multiple transceivers. Additionally, elements of the hardware device may be directly coupled to other elements without requiring a bidirectional bus. Alternatively, other electronic components or processing electronics besides processors and memory (e.g., integrated circuits, application-specific integrated circuits, field-programmable gate arrays, digital circuits, analog circuits, chips, dies, multi-chip modules, substrates, etc., or combinations thereof) may also be used to perform the required logical operations.

[0119] Memory 1120 may include any type of non-transitory memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), read-only memory (ROM), or any combination thereof. Mass storage element 1130 may include any type of non-transitory storage device, such as a solid-state drive, hard disk drive, disk drive, optical disk drive, USB flash drive, or any computer program product for storing data and machine-executable program code. According to some aspects, memory 1120 or mass storage 1130 may record thereon statements and instructions executable by processor 1110 for performing any of the methods described herein.

[0120] The processor 1110 and memory 1120 can be used together as a chipset, which can be provided together for installation in a wireless communication device 1100 to implement WLAN functionality. The chipset can be used to receive data, including but not limited to PPDUs, as input from a network interface 1150. The chipset can be used to output data, including but not limited to PPDUs, to the network interface 1150.

[0121] The aspects of this invention can be implemented using electronic hardware, software, or a combination thereof. In some aspects, the invention can be implemented by one or more computer processors executing program instructions stored in memory. In some aspects, the invention is implemented in part or in whole in hardware, for example, using one or more field-programmable gate arrays (FPGAs) or application-specific integrated circuits (ASICs) to rapidly perform processing operations.

[0122] It should be understood that although specific aspects of the technology have been described herein for illustrative purposes, various modifications can be made without departing from the scope of the technology. Therefore, the specification and drawings are to be considered merely as a description of the invention as defined in the appended claims, and are intended to cover any and all modifications, variations, combinations, or equivalents falling within the scope of the invention. Specifically, computer program products or program elements for storing machine-readable signals, or program memories or storage devices such as magnetic wires, optical fibers, magnetic tapes, or disks, are provided within the scope of the technology for controlling the operation of a computer according to the method of the technology and / or constructing some or all of its components according to the system of the technology.

[0123] The actions associated with the methods described herein can be implemented as coded instructions in a computer program product. In other words, a computer program product is a computer-readable medium on which software code is recorded, which executes the method when the computer program product is loaded into memory and executed on the microprocessor of a wireless communication device.

[0124] Furthermore, each operation of this method can be performed on any computing device such as a personal computer, server, or PDA, based on one or more program units, modules, or objects, or a portion thereof, generated from any programming language such as C++ or Java. Additionally, each operation, or the file or object implementing each operation, can be performed by dedicated hardware or a circuit module designed for this purpose.

[0125] Based on the foregoing description, this invention can be implemented solely in hardware, or it can be implemented using software and a necessary general-purpose hardware platform. Based on this understanding, the technical solution of this invention can be embodied in the form of a software product. The software product can be stored in a non-volatile or non-transitory storage medium, such as a compact disc read-only memory (CD-ROM), a USB flash drive, or a removable hard disk. The software product includes a plurality of instructions that enable a computer device (personal computer, server, or network device) to perform the methods provided in the various aspects of this invention. For example, such performance may correspond to the simulation of the logical operations described herein. The software product may additionally or alternatively include a plurality of instructions that enable a computer device to perform operations for configuring or programming digital logic devices according to the various aspects of this invention.

[0126] While the invention has been described with reference to specific features and aspects thereof, it will be apparent that various modifications and combinations thereof can be made without departing from the invention. Therefore, the specification and drawings are to be regarded merely as illustrative of the invention as defined by the appended claims and are intended to cover any and all modifications, variations, combinations, or equivalents falling within the scope of the invention.

Claims

1. A method, characterized in that, include: The network function receives a subscription request from a user, the subscription request being used to subscribe to one or more services; The network function selects one or more services identified by one or more service IDs corresponding to the subscription request; The network function obtains one or more service credentials corresponding to the one or more services; The network function generates an aggregated service credential, which is generated by aggregating one or more service credentials. The network function sends the aggregated service credential to the authentication / authorization server.

2. The method according to claim 1, characterized in that, The network function obtains one or more service credentials corresponding to the one or more services, including: The network function receives one or more service credentials from one or more service providers, who then provide the one or more services. The network function generates the one or more service credentials.

3. The method according to any one of claims 1 to 2, characterized in that, The one or more services are provided by one or more service providers, each of which provides at least one service.

4. The method according to any one of claims 1 to 3, characterized in that, The subscription request includes one or more of the user's temporary identifier ID, service requirements, and user authentication parameters generated based on the credentials of the temporary ID.

5. The method according to claim 3, characterized in that, The service credentials for the service are generated based on at least one of the following: the user's temporary ID, the service ID corresponding to the service, the user authentication parameters, and information about the service provider, who provides the service.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: The authentication / authorization server receives the aggregated service credentials from the network function.

7. A system, characterized in that, include: Network functions and authentication / authorization servers; The network function is used for: Receive a subscription request from a user, the subscription request being used to subscribe to one or more services; Select the one or more services identified by the one or more service IDs corresponding to the subscription request; Obtain one or more service credentials corresponding to the one or more services; An aggregated service credential is generated by aggregating one or more service credentials; Send the aggregated service credential to the authentication / authorization server; The authentication / authorization server is used for: Receive the aggregation service credential from the network function.

8. A method, characterized in that, include: The network function receives service requests from users, where the service request is a request for a service. The network function generates an authentication code, which is associated with one or more of the following: a service identifier ID that identifies the service, an SP ID that identifies the service provider SP that provides the service, and the user's authentication information. The network function sends an authentication request to the authentication / authorization server, the authentication request including one or more of the generated authentication code and the user's temporary ID; The network function receives an authentication response from the authentication / authorization server, indicating the authentication result of the authentication request; The network function determines whether the user can access the service based on the authentication response.

9. The method according to claim 8, characterized in that, The service request includes one or more of the user's temporary identifier ID, the service specification of the service, and the user's authentication information.

10. The method according to claim 8 or 9, characterized in that, The user's authentication information is generated at least based on the temporary ID.

11. The method according to claim 10, characterized in that, The user's authentication information is further generated based on the service ID.

12. The method according to any one of claims 8 to 11, characterized in that, Also includes: The authentication / authorization server verifies the authentication code using the aggregated service credential. The authentication / authorization server sends an authentication response, which indicates the authentication result of the authentication request.

13. The method according to any one of claims 8 to 12, characterized in that, Also includes: The authentication / authorization server receives the authentication request; The authentication / authorization server sends the authentication response.

14. A system, characterized in that, include: Network functions and authentication / authorization servers; The network function is used for: Receive a service request from the user, wherein the service request is a request for a service; Generate an authentication code, which is associated with one or more of the following: a service ID that identifies the service, an SP ID that identifies the service provider SP that provides the service, and the user's authentication information; Send an authentication request to the authentication / authorization server, the authentication request including one or more of the generated authentication code and the user's temporary ID; Receive an authentication response from the authentication / authorization server indicating the authentication result of the authentication request; Based on the authentication response, it is determined whether the user can access the service; The authentication / authorization server is used for: Receive the authentication request; Send the authentication response.

15. An apparatus, characterized in that, Includes processing electronic components for performing any one of claims 1 to 14.

16. An apparatus, characterized in that, include: At least one processor; At least one machine-readable medium storing executable instructions, which, when executed by the at least one processor, cause the apparatus to perform any one of the methods according to claims 1 to 14.

17. A computer device, characterized in that, It includes a non-transitory computer-readable medium storing instructions that, when executed by a computer processor, cause the computer to perform the method according to any one of claims 1 to 14.