Method, apparatus and computer program

EP4445551A4Pending Publication Date: 2025-08-27NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
EP2021966783
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2021-12-09
Publication Date
2025-08-27

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

There is provided an apparatus comprising means for: receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validating an identity of the management service consumer based on the request; responsive to validating the identity, obtaining permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and sending an authorization response to the authorization service consumer based on the obtained permissions.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, APPARATUS AND COMPUTER PROGRAMFIELD

[0001] The present application relates to a method, apparatus, and computer program and in particular but not exclusively to authorizing a management service consumer.BACKGROUND

[0002] A communication system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications path. A communication system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email) , text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.

[0003] In a wireless communication system at least a part of a communication session between at least two stations occurs over a wireless link. Examples of wireless systems comprise public land mobile networks (PLMN) , satellite based communication systems and different wireless local networks, for example wireless local area networks (WLAN) . Some wireless systems can be divided into cells, and are therefore often referred to as cellular systems.

[0004] A user can access the communication system by means of an appropriate communication device or terminal. A communication device of a user may be referred to as user equipment (UE) or user device. A communication device is provided with an appropriate signal receiving and transmitting apparatus for enabling communications, for example enabling access to a communication network or communications directly with other users. The communication device may access a carrier provided by a station, for example a base station of a cell, and transmit and / or receive communications on the carrier.

[0005] The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols  and / or parameters which shall be used for the connection are also typically defined. One example of a communications system is UTRAN (3G radio) . Other examples of communication systems are the long-term evolution (LTE) of the Universal Mobile Telecommunications System (UMTS) radio-access technology and so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP) .

[0006] SUMMARY

[0007] According to an aspect, there is provided an apparatus comprising means for receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validating an identity of the management service consumer based on the request; responsive to validating the identity, obtaining permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and sending an authorization response to the authorization service consumer based on the obtained permissions.

[0008] The authorization service consumer may be the management service consumer or a management service producer.

[0009] The authorization response may comprise at least one of: an identifier of the management service consumer; the result of proceeding the request; a token for accessing the management service.

[0010] The token for accessing the management service may comprise the permissions assigned to the management service consumer and at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0011] The means may be for: receiving information identifying one or more access permissions for a role and / or group of management service consumer; and storing the received information, wherein the permissions are obtained from the stored information.

[0012] The request for authorization may comprise at least one of: information identifying the management service consumer; an identity token; a credential used to validate an identity of  the management service consumer; information identifying the management service; and context information associated with the management service consumer.

[0013] Validating the identity may comprise: sending, to an authentication service producer, the information identifying the management service consumer; and receiving, from the authentication service producer, a response indicating that the management service consumer identity is valid.

[0014] The authorization request may comprise the identity token, and wherein validating the identity may comprise: validating the identity based on the identity token.

[0015] Obtaining the permissions may comprise: determining the group and / or role that the management service consumer is associated with; and obtaining the permissions based on the determined group and / or role and context information associated with the management service consumer.

[0016] Determining the group and / or role that the management service consumer is assigned to may comprise: receiving, from an authorization administrative service consumer, information associating the management service consumer with the group and / or role; or receiving, from the authorization administrative service consumer, information associating a group of management service consumers including the management service consumer with a role.

[0017] The means may be for: constructing the token for accessing the management service based on the obtained permissions and context information.

[0018] The context information may comprise one or more of: an expiry time of the token for accessing the management service; location information; and a security state of the management service consumer.

[0019] The permissions may comprise at least one of: a role or group the of management service producer; one or more access rights on a managed resource; and one or more conditions of the one or more access rights.

[0020] The one or more access rights may relate to one or more of: creating information at the management service producer; reading information at the management service producer; updating information at the management service producer; and deleting information at the management service producer.

[0021] The one or more conditions of the one or more access rights may comprise a list of: a key to represent a type of condition; and a value to represent the condition.

[0022] The means may be for: receiving updated information identifying one or more access permissions for the role and / or group of management service consumer; and updating the stored information based on the received updated information.

[0023] The means may be for: determining, based on the updated stored information, that the permissions have changed; and sending, to the authorization service consumer, information indicating that the permissions have changed.

[0024] According to an aspect, there is provided an apparatus comprising means for: receiving, from a management service consumer, an access request comprising a token for accessing a management service; validating the token; responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; and responsive to determining that the management service consumer is authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0025] The access request may further comprise at least one of: an identity of the management service consumer; and an indication of the management service to be accessed.

[0026] The token may further comprise at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0027] The token may further comprise context information, and wherein the determining may be further based on the context information.

[0028] The context information may comprise one or more of: an expiry time of the token; location information; and a security state of the management service consumer.

[0029] The access right may relate to one or more of: creating information at the apparatus; reading information at the apparatus; updating information at the apparatus; and deleting information at the apparatus.

[0030] The condition of access right may comprise a list of: a key to represent the type of condition; and a value to represent the condition.

[0031] The permissions may further comprise a condition of an access right, and wherein the determining may be further based on the condition.

[0032] According to an aspect, there is provided an apparatus comprising at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to: receive, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validate an identity of the management service consumer based on the request; responsive to validating the identity, obtain permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and send an authorization response to the authorization service consumer based on the obtained permissions.

[0033] The authorization service consumer may be the management service consumer or a management service producer.

[0034] The authorization response may comprise at least one of: an identifier of the management service consumer; the result of proceeding the request; a token for accessing the management service.

[0035] The token for accessing the management service may comprise the permissions assigned to the management service consumer and at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0036] The at least one memory and at least one processor may be configured to cause the apparatus to: receive information identifying one or more access permissions for a role  and / or group of management service consumer; and store the received information, wherein the permissions are obtained from the stored information.

[0037] The request for authorization may comprise at least one of: information identifying the management service consumer; an identity token; a credential used to validate an identity of the management service consumer; information identifying the management service; and context information associated with the management service consumer.

[0038] The at least one memory and at least one processor may be configured to cause the apparatus to send, to an authentication service producer, the information identifying the management service consumer; and receive, from the authentication service producer, a response indicating that the management service consumer identity is valid.

[0039] The authorization request may comprise the identity token, and the at least one memory and at least one processor may be configured to cause the apparatus to validate the identity based on the identity token.

[0040] The at least one memory and at least one processor may be configured to cause the apparatus to: determine the group and / or role that the management service consumer is associated with; and obtain the permissions based on the determined group and / or role and context information associated with the management service consumer.

[0041] The at least one memory and at least one processor may be configured to cause the apparatus to: receive, from an authorization administrative service consumer, information associating the management service consumer with the group and / or role; or receive, from the authorization administrative service consumer, information associating a group of management service consumers including the management service consumer with a role.

[0042] The at least one memory and at least one processor may be configured to cause the apparatus to: construct the token for accessing the management service based on the obtained permissions and context information.

[0043] The context information may comprise one or more of: an expiry time of the token for accessing the management service; location information; and a security state of the management service consumer.

[0044] The permissions may comprise at least one of: a role or group the of management service producer; one or more access rights on a managed resource; and one or more conditions of the one or more access rights.

[0045] The one or more access rights may relate to one or more of: creating information at the management service producer; reading information at the management service producer; updating information at the management service producer; and deleting information at the management service producer.

[0046] The one or more conditions of the one or more access rights may comprise a list of: a key to represent a type of condition; and a value to represent the condition.

[0047] The at least one memory and at least one processor may be configured to cause the apparatus to: receive updated information identifying one or more access permissions for the role and / or group of management service consumer; and update the stored information based on the received updated information.

[0048] The at least one memory and at least one processor may be configured to cause the apparatus to: determine, based on the updated stored information, that the permissions have changed; and send, to the authorization service consumer, information indicating that the permissions have changed.

[0049] According to an aspect, there is provided an apparatus comprising at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to: receive, from a management service consumer, an access request comprising a token for accessing a management service; validate the token; responsive to validating the token, determine whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; and responsive to determining that the management service consumer is authorized for access, perform one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0050] The access request may further comprise at least one of: an identity of the management service consumer; and an indication of the management service to be accessed.

[0051] The token may further comprise at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0052] The token may further comprise context information, and wherein the determining may be further based on the context information.

[0053] The context information may comprise one or more of: an expiry time of the token; location information; and a security state of the management service consumer.

[0054] The access right may relate to one or more of: creating information at the apparatus; reading information at the apparatus; updating information at the apparatus; and deleting information at the apparatus.

[0055] The condition of access right may comprise a list of: a key to represent the type of condition; and a value to represent the condition.

[0056] The permissions may further comprise a condition of an access right, and wherein the determining may be further based on the condition.

[0057] According to an aspect, there is provided a method comprising: receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validating an identity of the management service consumer based on the request; responsive to validating the identity, obtaining permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and sending an authorization response to the authorization service consumer based on the obtained permissions.

[0058] The authorization service consumer may be the management service consumer or a management service producer.

[0059] The authorization response may comprise at least one of: an identifier of the management service consumer; the result of proceeding the request; a token for accessing the management service.

[0060] The token for accessing the management service may comprise the permissions assigned to the management service consumer and at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0061] The method may comprise: receiving information identifying one or more access permissions for a role and / or group of management service consumer; and storing the received information, wherein the permissions are obtained from the stored information.

[0062] The request for authorization may comprise at least one of: information identifying the management service consumer; an identity token; a credential used to validate an identity of the management service consumer; information identifying the management service; and context information associated with the management service consumer.

[0063] Validating the identity may comprise: sending, to an authentication service producer, the information identifying the management service consumer; and receiving, from the authentication service producer, a response indicating that the management service consumer identity is valid.

[0064] The authorization request may comprise the identity token, and wherein validating the identity may comprise: validating the identity based on the identity token.

[0065] Obtaining the permissions may comprise: determining the group and / or role that the management service consumer is associated with; and obtaining the permissions based on the determined group and / or role and context information associated with the management service consumer.

[0066] Determining the group and / or role that the management service consumer is assigned to may comprise: receiving, from an authorization administrative service consumer, information associating the management service consumer with the group and / or role; or receiving, from the authorization administrative service consumer, information associating a group of management service consumers including the management service consumer with a role.

[0067] The method may comprise: constructing the token for accessing the management service based on the obtained permissions and context information.

[0068] The context information may comprise one or more of: an expiry time of the token for accessing the management service; location information; and a security state of the management service consumer.

[0069] The permissions may comprise at least one of: a role or group the of management service producer; one or more access rights on a managed resource; and one or more conditions of the one or more access rights.

[0070] The one or more access rights may relate to one or more of: creating information at the management service producer; reading information at the management service producer; updating information at the management service producer; and deleting information at the management service producer.

[0071] The one or more conditions of the one or more access rights may comprise a list of: a key to represent a type of condition; and a value to represent the condition.

[0072] The method may comprise: receiving updated information identifying one or more access permissions for the role and / or group of management service consumer; and updating the stored information based on the received updated information.

[0073] The method may comprise: determining, based on the updated stored information, that the permissions have changed; and sending, to the authorization service consumer, information indicating that the permissions have changed.

[0074] According to an aspect, there is provided a method comprising: receiving, from a management service consumer, an access request comprising a token for accessing a management service; validating the token; responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; and responsive to determining that the management service consumer is authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0075] The access request may further comprise at least one of: an identity of the management service consumer; and an indication of the management service to be accessed.

[0076] The token may further comprise at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0077] The token may further comprise context information, and wherein the determining may be further based on the context information.

[0078] The context information may comprise one or more of: an expiry time of the token; location information; and a security state of the management service consumer.

[0079] The access right may relate to one or more of: creating information at the apparatus; reading information at the apparatus; updating information at the apparatus; and deleting information at the apparatus.

[0080] The condition of access right may comprise a list of: a key to represent the type of condition; and a value to represent the condition.

[0081] The permissions may further comprise a condition of an access right, and wherein the determining may be further based on the condition.

[0082] According to an aspect, there is provided a computer readable medium comprising program instructions for causing an apparatus to perform at least the following: receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validating an identity of the management service consumer based on the request; responsive to validating the identity, obtain permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and sending an authorization response to the authorization service consumer based on the obtained permissions.

[0083] The authorization service consumer may be the management service consumer or a management service producer.

[0084] The authorization response may comprise at least one of: an identifier of the management service consumer; the result of proceeding the request; a token for accessing the management service.

[0085] The token for accessing the management service may comprise the permissions assigned to the management service consumer and at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0086] The program instructions may cause the apparatus to perform: receiving information identifying one or more access permissions for a role and / or group of management service consumer; and storing the received information, wherein the permissions are obtained from the stored information.

[0087] The request for authorization may comprise at least one of: information identifying the management service consumer; an identity token; a credential used to validate an identity of the management service consumer; information identifying the management service; and context information associated with the management service consumer.

[0088] Validating the identity may comprise: sending, to an authentication service producer, the information identifying the management service consumer; and receiving, from the authentication service producer, a response indicating that the management service consumer identity is valid.

[0089] The authorization request may comprise the identity token, and wherein validating the identity may comprise: validating the identity based on the identity token.

[0090] Obtaining the permissions may comprise: determining the group and / or role that the management service consumer is associated with; and obtaining the permissions based on the determined group and / or role and context information associated with the management service consumer.

[0091] Determining the group and / or role that the management service consumer is assigned to may comprise: receiving, from an authorization administrative service consumer, information associating the management service consumer with the group and / or role; or receiving, from the authorization administrative service consumer, information associating a group of management service consumers including the management service consumer with a role.

[0092] The program instructions may cause the apparatus to perform: constructing the token for accessing the management service based on the obtained permissions and context information.

[0093] The context information may comprise one or more of: an expiry time of the token for accessing the management service; location information; and a security state of the management service consumer.

[0094] The permissions may comprise at least one of: a role or group the of management service producer; one or more access rights on a managed resource; and one or more conditions of the one or more access rights.

[0095] The one or more access rights may relate to one or more of: creating information at the management service producer; reading information at the management service producer; updating information at the management service producer; and deleting information at the management service producer.

[0096] The one or more conditions of the one or more access rights may comprise a list of: a key to represent a type of condition; and a value to represent the condition.

[0097] The program instructions may cause the apparatus to perform: receiving updated information identifying one or more access permissions for the role and / or group of management service consumer; and updating the stored information based on the received updated information.

[0098] The program instructions may cause the apparatus to perform: determining, based on the updated stored information, that the permissions have changed; and sending, to the authorization service consumer, information indicating that the permissions have changed.

[0099] According to an aspect, there is provided a computer readable medium comprising program instructions for causing an apparatus to perform at least the following: receiving, from a management service consumer, an access request comprising a token for accessing a management service; validating the token; responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; and responsive to determining that the management service consumer is  authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0100] The access request may further comprise at least one of: an identity of the management service consumer; and an indication of the management service to be accessed.

[0101] The token may further comprise at least one of: an identifier of the token; information identifying an issuer of the token as the authorization service producer; information identifying a consumer of the token as the management service consumer; context information of the token; and a type of the token.

[0102] The token may further comprise context information, and wherein the determining may be further based on the context information.

[0103] The context information may comprise one or more of: an expiry time of the token; location information; and a security state of the management service consumer.

[0104] The access right may relate to one or more of: creating information at the apparatus; reading information at the apparatus; updating information at the apparatus; and deleting information at the apparatus.

[0105] The condition of access right may comprise a list of: a key to represent the type of condition; and a value to represent the condition.

[0106] The permissions may further comprise a condition of an access right, and wherein the determining may be further based on the condition.

[0107] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the method according to any of the preceding aspects.

[0108] In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above.

[0109] DESCRIPTION OF FIGURES

[0110] Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which:

[0111] Figure 1 shows a representation of a network system according to some example embodiments;

[0112] Figure 2 shows a representation of a control apparatus according to some example embodiments;

[0113] Figure 3 shows a representation of an apparatus according to some example embodiments;

[0114] Figures 4 to 7 show example network resource models;

[0115] Figure 8 shows an example signalling exchange for authorization and authenticating a management service consumer;

[0116] Figure 9 shows a method according to some examples; and

[0117] Figure 10 shows a message exchange according to some examples.DETAILED DESCRIPTION

[0118] In the following certain embodiments are explained with reference to mobile communication devices capable of communication via a wireless cellular system and mobile communication systems serving such mobile communication devices. Before explaining in detail the exemplifying embodiments, certain general principles of a wireless communication system, access systems thereof, and mobile communication devices are briefly explained with reference to Figures 1, 2 and 3 to assist in understanding the technology underlying the described examples.

[0119] Figure 1 shows a schematic representation of a 5G system (5GS) . The 5GS may be comprised by a terminal or user equipment (UE) , a 5G radio access network (5GRAN) or next generation radio access network (NG-RAN) , a 5G core network (5GC) , one or more application function (AF) ; one or more User Plane Functions (UPFs) and one or more data networks (DN) .

[0120] The 5G-RAN may comprise one or more gNodeB (GNB) or one or more gNodeB (GNB) distributed unit functions connected to one or more gNodeB (GNB) centralized unit functions. The 5GC may comprise the following entities: Network Slice Selection Function (NSSF) ; Network Slice Specific Authentication and Authorization Function (NSSAAF) ; Network Exposure Function (NEF) ; Network Repository Function (NRF) ; Policy Control Function (PCF) ; Unified Data Management (UDM) ; Network Slice Admission Control Function (NSACF) ; Unstructured Data Storage Function (UDSF) ; User Data Repository (UDR) ;  Application Function (AF) ; Authentication Server Function (AUSF) ; an Access and Mobility Management Function (AMF) ; and Session Management Function (SMF) .

[0121] For the sake of clarity, in Figure 1 the UDSF, UDR, NEF and NRF have not been depicted. However, all of the network functions depicted in Figure 1 may interact with the UDSF, UDR, NEF and NRF as necessary. Furthermore, while not shown in the Figure, the 5GS may further comprise one or more management functions which may interact with any of the core network functions and / or RAN as necessary. For example, the management functions may produce an Authentication Service (AuS) , Authorization Service (ArS) , and Management Service (MnS) .

[0122] Figure 2 illustrates an example of a control apparatus 200 for controlling a function of the 5GRAN or the 5GC as illustrated on Figure 1. The control apparatus may comprise at least one random access memory (RAM) 211a, at least one read only memory (ROM) 211b, at least one processor 212, 213 and an input / output interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211 b. The at least one processor 212, 213 may be configured to execute an appropriate software code 215. The software code 215 may for example allow to perform one or more steps to perform one or more of the present aspects. The software code 215 may be stored in the ROM 211b. The control apparatus 200 may be interconnected with another control apparatus 200 controlling another function of the 5GRAN or the 5GC. In some embodiments, each function of the 5GRAN or the 5GC comprises a control apparatus 200. In alternative embodiments, two or more functions of the 5GRAN or the 5GC may share a control apparatus.

[0123] Figure 3 illustrates an example of a terminal 300, such as the terminal illustrated on Figure 1. The terminal 300 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’ , a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle) , a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (IoT) type communication device or any combinations of these or the like. The terminal 300 may provide, for example, communication of data for carrying communications. The communications may be one or more of voice, electronic mail (email) , text message, multimedia, data, machine data and so on.

[0124] The terminal 300 may receive signals over an air or radio interface 307 via appropriate apparatus for receiving and may transmit signals via appropriate apparatus for transmitting radio signals. In Figure 3 transceiver apparatus is designated schematically by block 306. The transceiver apparatus 306 may be provided for example by means of a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device.

[0125] The terminal 300 may be provided with at least one processor 301, at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access systems and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more of the present aspects. The software code 308 may be stored in the ROM 302a.

[0126] The processor, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by reference 304. The device may optionally have a user interface such as key pad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the device.

[0127] In 3GPP, a service based architecture may enable a management service (MnS) consumer to access and utilize capabilities of a MnS producer to provision or monitor logical networks, services or resources.

[0128] There may be different MnS consumers or users to access the MnSs, including internal and external MnS consumers (which may be machine users) , and internal MnS consumer (which may be acting on behalf of external or internal human users) . The MnS consumers and users could be in different management domains, with different capabilities, roles and security status, therefore they may be assigned different access control policies.

[0129] Access control for MnSs has been proposed to enhance service based management architecture, and related management services / capabilities to support access control. Different information elements and protocols may be implemented to support authentication and authorization for MnS access.

[0130] However, the management system may manage complicated managed object (MO) trees, also referred to herein as NRM trees. Performing authentication and authorization for complex NRM trees may be challenging.

[0131] Reference is made to Figure 4, which shows an example network resource model (NRM) which may be implemented in 3GPP. In the example of Figure 4, managed element 400 may be managed by Management System 402. As can be seen from Figure 4, the number of different Information Object Class (IOC) objects and number of different interactions between the objects related to the managed element 400 may be complicated, and thus management of the element 400 may be challenging.

[0132] Figures 5 and 6 show further example NRMs, being respectively for a NG-RAN and 5GC system.

[0133] For each managed object, the corresponding managed entity (e.g. a managed function, network slice, network slice subnet) may support different features to collect data. For example, as shown in Figure 7, 3GPP management system may provide management services / capabilities to collect alarm, KPI, measurement, trace, as well as QoE, analytics report, etc. The collected data could be requested by a MnS consumer or pushed by the MnS producer.

[0134] Further, each managed object may support different attributes (e.g. tens to hundreds attributes are supported by RAN and CN NFs, and network slice related MOs) and various reference points to other MOs, different operations (e.g. create, read, update, delete an MO or its attributes ) , different notifications (e.g. MO change notification, file ready notification, etc. ) .

[0135] Management services / capabilities of 3GPP management system, which combined with diverse and complicated MOs, features, attributes, operations, notifications and data reports, could be exposed to different users / consumers according to operator's policies or SLA signed between operator and its customer. Therefore, it may be beneficial to enforce fine grained access control to prevent unauthorized access of the management system to comply with the policies and SLA.

[0136] Reference is made to Figure 8, which shows a signalling exchange for authorization and authenticating a MnS consumer according to some examples.

[0137] In the example of Figure 8, a MnS consumer and MnS producer are configured in an Authentication Service (AnS) producer and Authorization Service (ArS) producer. The MnS consumer is assigned for a role within a group, and the permissions for a role or group are configured in the AnS producer.

[0138] At step 800, the MnS consumer sends an Authentication request to the AnS producer.

[0139] At step 802, in response to receiving the Authentication request, the AnS producer determines that the MnS consumer is authenticated, and returns an Authentication response to the MnS consumer. The response may comprise an assertion indicating that the MnS consumer is authenticated.

[0140] At step 804, the MnS sends an Authorization request to the ArS producer. The Authorization request may comprise the assertion.

[0141] At step 806, the ArS producer validates the assertion, checks the role / group of the MnS consumer, and assigns related permissions to the MnS consumer. The ArS constructs an access token based on the permissions and sends the token back to the MnS consumer.

[0142] In some examples, the access token may comprise the following attributes:

[0143]

[0144]

[0145] It should be understood that in some examples some of the attributes identified above may not be included in the access token.

[0146] At step 808, the MnS consumer checks the access token, and constructs a service request based on the permissions provided in the access token. The MnS consumer then sends the service request including the access token to the MnS producer.

[0147] At step 810, the MnS producer validates the access token received in the service request, and returns a result to the MnS consumer based on the service request.

[0148] Some aspects of the present disclosure may relate to information elements (IEs) of management protocol to support fine-grained authorization, as well as methods and apparatuses for interpreting and using IEs to implement access control.

[0149] Reference is made to Figure 9, which shows a method according to some examples.

[0150] At step 900, the method may comprise receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service.

[0151] At step 902, the method may comprise validating an identity of the management service consumer based on the request.

[0152] At step 904, the method may comprise, responsive to validating the identity, obtaining permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated.

[0153] At step 906, the method may comprise sending an authorization response to the authorization service consumer based on the obtained permissions.

[0154] In some examples, steps 900-906 may be performed by an authorization service producer.

[0155] At step 908, a method may comprise receiving, from a management service consumer, an access request comprising a token for accessing a management service.

[0156] At step 910, the method may comprise validating the token.

[0157] At step 912, the method may comprise responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer.

[0158] At step 914, the method may comprise, responsive to determining that the management service consumer is authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0159] In some examples, the method of steps 908-914 may be performed by a management service producer.

[0160] In some examples, the authorization service producer may receive a request for authorization of a management service consumer to access multiple management services. The token may be for accessing the multiple management services.

[0161] Reference is made to Figure 10, which shows a message exchange according to some examples.

[0162] Prior to performing an authorization and authentication operation, the ArS producer creates / updates / deletes an access right list for a managed object based on an access right provisioning request. An example message exchange for creating / updating / deleting the access right list is shown in Figure 10a.

[0163] As shown in Figure 10a, at step 1000, an Authorization Administrative Service consumer may send an provisioning request to the ArS producer including one or more of:

[0164] an access rights list for the managed object;

[0165] a role / group;

[0166] an association between the managed object and a role / group; and

[0167] a permission list related to the managed object for the role / group.

[0168] The access right provisioning request may be triggered by creating / updating / deleting a managed object (e.g. MOI of Subnetwork, ManagedElement, ManagedFunction, NetworkSlice, NetworkSliceSubnet, etc. ) or other changes, e.g. change of organization policies. That is to say, when a creating / updating / deleting operation is performed with respect to a managed object, the access provisioning request may be sent to the ArS producer.

[0169] An access right of a managed object may be one or more of:

[0170] · create / delete child MO instance (MOI) of a current MO (objectClass of the child MOI)

[0171] · The child MOI could be controller MOI (e.g. PM controller, subscription controller, etc., contained by a managed entity) or other functional MOI (e.g. network slice, network slice subnet, etc. contained by a subnetwork )

[0172] · read MOI tree (objectInstance of the current MOI)

[0173] · delete MOI (objectInstance of the current MOI)

[0174] · read MOIattribute (objectInstance of the current MOI + attributeName) -a value of the attribute may, in some examples, be considered as a further access condition when assigning permission to a group / role. e.g. in a NetworkSlice MOI, the consumer can only read service profiles for the services allocated to the consumer.

[0175] · update MOIattribute (objectInstance of the current MOI + attributeName)

[0176] In some examples, a value of the attribute may be considered as a further access condition when assign permission to a group / role –for example, a create / read / update / delete access right of the current MO.

[0177] At step 1002, when the provisioning request is received from the Authorization Administrative Service consumer, the ArS producer may create / update / delete a permissions list based on the request.

[0178] When a provisioning request including information associated with a group is received, the ArS producer may create / update / delete a group of MnS consumers / producers.

[0179] In some examples, the request may be triggered by ArS producer to sync group information in authentication service producer to authorization service producer.

[0180] When a provisioning request including information associated with a role is received, the ArS producer may create / update / delete a role. The request could be triggered by creating / updating / deleting a managed object or creating / updating / deleting a MnS consumer or group of MnS consumers.

[0181] The ArS producer may assign an owner to the managed object and / or associate the managed object with group of MnS producers and / or group of MnS consumers / roles based on the received request.

[0182] The ArS producer may add / remove / update permissions of group of MnS consumers / role for the managed object based on the request. In some examples, a permission may be constructed as information defining a subject, an access right, and conditions under which the access right is valid.

[0183] Upon receiving the request, the ArS producer may update a permission list of a group of MnS consumers / role according to permissions of the group of MnS consumers / role on each  managed object. In some examples, the ArS producer may send a response back to the Authorization Administrative Service consumer indicating a result of the request.

[0184] The ArS producer may associate a MnS consumer or group of MnS consumers with role based on the request. The request could be triggered by creating / updating a MnS consumer or group of MnS consumers.

[0185] Thus, in some examples, the ArS producer may receive information identifying one or more access rights for a managed object. The information may be received in an access right provisioning request. The access right provisioning request may be received from an authorisation administrative service consumer.

[0186] In some examples, shown at step 1003 in Figure 10a, the authorisation administrative service consumer may send, to the ArS producer, information associating a MnS consumer with a group and / or role, or a group of MnS consumers with a role.

[0187] After the ArS producer has been configured with the access permissions for the management service, the ArS producer may be queried to determine whether a management service consumer is authorized.

[0188] Figure 10b shows a message exchange that may follow the exchange of Figure 10a if the MnS producer supports access token authorization.

[0189] At step 1004, an authorization service consumer, which in this example is a MnS consumer, sends an authorization request to the ArS producer. The authorization request may be for authorization of a MnS consumer to access a management service. The request may comprise an identifier of the MnS consumer and an identity token. In some examples, the authorization request may comprise further information, such as context information (e.g. address of the client) .

[0190] The identity token may be either generated by MnS consumer as client credential or obtained from an AnS producer after the consumer successfully authenticates to the authentication service producer.

[0191] At step 1006, the ArS producer validates the identity of the MnS consumer. For example, the ArS producer may validate the identity token.

[0192] If the ArS producer does not support the identity token, when the ArS producer receives authorization request, the ArS producer may obtain the identity / identifier (and optionally further context information) from the request. The ArS producer may then checks the authentication state of the MnS consumer locally or with authentication service producer. The check may be based on the obtained identity / identifier.

[0193] If the ArS producer determines that the token is valid (i.e. the MnS consumer has been authenticated) , the ArS producer gets groups / roles information of the MnS consumer based on identity / identifier in the request, as shown by step 1008.

[0194] At step 1010, the ArS producer obtains permissions granted to the groups / roles which were assigned to the MnS consumer.

[0195] At step 1012, the ArS producer generates an access / authorization token for the MnS consumer. The access / authorization token may include a permissions list which satisfies context information, e.g. expire time, location and security state of the MnS consumer, etc. Thus, the permissions list may comprise permissions associated with a role and / or group of the MnS consumer.

[0196] At step 1014, the ArS producer sends a response to the MnS consumer. The response may comprise the generated access token.

[0197] At step 1016, the MnS consumer accesses a MnS producer using the access token. For example, the MnS consumer may send an access request message to the MnS producer. The access request may comprise the access token.

[0198] At step 1018, the MnS producer validates the access token and determines if the MnS consumer is allowed to access the MnS producer based on the access token and optionally context information associated with the request. The MnS producer may validate the access token based on underlay protocol, e.g. JSON Web Token (JWT) with JSON Web Signature (JWS) , to construct the token according to token type. If the token is valid, the MnS producer check permissions in the token.

[0199] If the MnS producer determines that the MnS consumer is allowed at step 1018 according to requested MnS, access right and pre-condition of each permission, then at step 1020 the MnS producer updates the resource (if needed) , and responds successfully to the consumer with the requested resource further according to post-condition of each permission.

[0200] While not shown in the Figure, if the MnS producer determines that the MnS consumer is not allowed at step 1018, then the MnS producer sends error message to the MnS consumer. For example, the MnS producer may send error to the MnS consumer if no permission is granted to the MnS consumer, or if the consumer has not been authenticated.

[0201] Figure 10c shows a message exchange that may follow the exchange of Figure 10a if the MnS producer does not support access token authorization.

[0202] At step 1024, the MnS consumer sends the access request directly to the MnS producer. The request may not include an access token.

[0203] At step 1026, the MnS producer checks the authorization of the MnS consumer on the MnS producer with the ArS producer and / or based on local policies configured at the MnS producer.

[0204] If the MnS producer determines that the MnS consumer is authorized at step 1026, then at step 1028, the MnS producer updates the resource (if needed) according to requested MnS, and responds successfully to the MnS consumer with the requested resource.

[0205] If the MnS producer determines that the MnS consumer is not allowed at step 1026, then at step 1030 the MnS producer sends error message to the MnS consumer. For example, the MnS producer may send error to the MnS consumer if no permission is granted to the MnS consumer, or if the consumer has not been authenticated.

[0206] In the event that the access token is updated for some reason, e.g. expired, invalid, permissions / conditions changed, etc., the authorization service producer may send a notification to related MnS producers. Based on the information, the MnS producer may reject a MnS consumer request or double check with authorization service producer before performing the MnS consumer request.

[0207] As explained previously, the access right may be one or more of:

[0208] · create / delete child MO instance (MOI) of the current MO (objectClass of the child MOI)

[0209] · read MOI tree (objectInstance of the current MOI)

[0210] · delete MOI (objectInstance of the current MOI)

[0211] · read MOIattribute (objectInstance of the current MOI + attributeName)

[0212] · update MOIattribute (objectInstance of the current MOI + attributeName)

[0213] · create / read / update / delete access right of the current MO

[0214] The access right may be defined by the following input parameters for create, read, update, delete (CRUD) operations:

[0215]

[0216] The access right may comprise one or more of the following attributes:

[0217]

[0218]

[0219] In response to create / read / update / delete access right, the ArS producer may send a message including one or more of the following attributes:

[0220]

[0221] When configuring the ArS producer for a managed object, the managed object provisioning (e.g. reading, updating) request may comprise one or more of the following input parameters:

[0222]

[0223]

[0224] In some examples, the response sent from the ArS producer to the Authorization Administrative Service consumer indicating a result of the request may comprise one or more of the following:

[0225]

[0226] In some examples, when configuring the ArS producer for a group of resources / objects, the request may comprise the following input parameters:

[0227]

[0228] The ResourceGroup data type may comprise one or more of the following attributes:

[0229]

[0230] The ResourceGroupProfile data type may comprise one or more of the following attributes:

[0231]

[0232] In some examples, the response sent from the ArS producer to the Authorization Administrative Service consumer indicating a result of the request may comprise one or more of the following:

[0233]

[0234] In some examples, when configuring the ArS producer for a role of an MnS consumer / group of MnS consumers, the create / read / update / delete request may comprise one or more of the following:

[0235] ParameterData typePCardinalityDescriptionidDNCM1It may identify a role MOI.roleRoleInfoCM1Role to be created / read / updated / deleted.

[0236] In some examples, the RoleInfo parameter may comprise one or more of the following:

[0237]

[0238] In some examples, the PermInfo attribute may comprise one or more of the following:

[0239]

[0240]

[0241] In some examples, the response sent from the ArS producer to the Authorization Administrative Service consumer indicating a result of the request may comprise one or more of the following:

[0242]

[0243] In some examples, the ArS producer may be provisioned with permission information for a group of MnS consumer or role. For example, the ArS producer may receive a read or update operation request. In such examples, the request may comprise one of more of the following:

[0244]

[0245] In some examples, in response to the provision request, the ArS producer may send a response comprising one or more of the following:

[0246]

[0247] In some examples, the MnS consumer may obtain the access token by sending an access token request. The access token request may comprise one or more of the following:

[0248]

[0249] In response, the ArS producer may provide a response comprising one or more of the following:

[0250]

[0251] The AccessToken attribute may comprise one or more of the following:

[0252]

[0253] Thus, according to some examples, a management service consumer may send a request for an access token for accessing a management service to an authorization service producer. The authorization service producer obtains information identifying the management service consumer from the request, and validates the identity of the management service consumer based on the obtained information. If the management service consumer identity is validated, the authorization service producer checks the permissions of the management service consumer, and constructs an access token based on the permissions. The authorization service producer then sends a response comprising the access token to the management service consumer. The management service consumer may then use the access token to access the management service.

[0254] In some examples, there is provided an apparatus comprising means for receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validating an identity of the management service consumer based on the request; responsive to validating the identity, obtaining  permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and sending an authorization response to the authorization service consumer based on the obtained permissions.

[0255] In some examples, the apparatus comprises at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to: receive, from an authorization service consumer, a request for authorization of a management service consumer to access a management service; validate an identity of the management service consumer based on the request; responsive to validating the identity, obtain permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; and send an authorization response to the authorization service consumer based on the obtained permissions.

[0256] In some examples, there is provided an apparatus comprising means for receiving, from a management service consumer, an access request comprising a token for accessing a management service; validating the token; responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; and responsive to determining that the management service consumer is authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0257] In some examples, the apparatus comprises at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to: receive, from a management service consumer, an access request comprising a token for accessing a management service; validate the token; responsive to validating the token, determine whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; and responsive to determining that the management service consumer is authorized for access, perform one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

[0258] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or  reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.

[0259] It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.

[0260] It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.

[0261] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0262] As used in this application, the term “circuitry” may refer to one or more or all of the following:

[0263] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0264] (b) combinations of hardware circuits and software, such as (as applicable) :

[0265] (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and

[0266] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0267] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. ”

[0268] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0269] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.

[0270] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.

[0271] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) , application specific integrated circuits (ASIC) , FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

[0272] Embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process.  Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0273] The scope of protection sought for various embodiments of the disclosure is set out by the independent claims. The embodiments and features, if any, described in this specification that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various embodiments of the disclosure.

[0274] The foregoing description has provided by way of non-limiting examples a full and informative description of the exemplary embodiment of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings of this disclosure will still fall within the scope of this invention as defined in the appended claims. Indeed, there is a further embodiment comprising a combination of one or more embodiments with any of the other embodiments previously discussed.

Claims

1.An apparatus comprising means for:receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service;validating an identity of the management service consumer based on the request;responsive to validating the identity, obtaining permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; andsending an authorization response to the authorization service consumer based on the obtained permissions.2.The apparatus of claim 1, wherein the authorization service consumer is the management service consumer or a management service producer.3.The apparatus of claim 1 or 2, wherein the authorization response comprises at least one of:an identifier of the management service consumer;the result of proceeding the request;a token for accessing the management service;4.The apparatus of claim 3, wherein the token for accessing the management service comprises the permissions assigned to the management service consumer and at least one of:an identifier of the token;information identifying an issuer of the token as the authorization service producer;information identifying a consumer of the token as the management service consumer;context information of the token; anda type of the token.5.The apparatus of any preceding claim, wherein the means is for:receiving information identifying one or more access permissions for a role and / or group of management service consumer; andstoring the received information,wherein the permissions are obtained from the stored information.6.The apparatus of any preceding claim, wherein the request for authorization comprises at least one of:information identifying the management service consumer;an identity token;a credential used to validate an identity of the management service consumer;information identifying the management service; andcontext information associated with the management service consumer.7.The apparatus of claim A. 6, wherein validating the identity comprises:sending, to an authentication service producer, the information identifying the management service consumer; andreceiving, from the authentication service producer, a response indicating that the management service consumer identity is valid.8.The apparatus of claim 6, wherein the authorization request comprises the identity token, and wherein validating the identity comprises:validating the identity based on the identity token.9.The apparatus of any preceding claim, wherein obtaining the permissions comprises:determining the group and / or role that the management service consumer is associated with; andobtaining the permissions based on the determined group and / or role and context information associated with the management service consumer.10.The apparatus of claim 9, wherein determining the group and / or role that the management service consumer is assigned to comprises:receiving, from an authorization administrative service consumer, information associating the management service consumer with the group and / or role; orreceiving, from the authorization administrative service consumer, information associating a group of management service consumers including the management service consumer with a role.11.The apparatus of claim 3 or any claim dependent thereon, wherein the means is for:constructing the token for accessing the management service based on the obtained permissions and context information.12.The apparatus of claim 11, wherein the context information comprises one or more of:an expiry time of the token for accessing the management service;location information; anda security state of the management service consumer.13.The apparatus of any preceding claim, wherein the permissions comprise at least one of:a role or group the of management service producer;one or more access rights on a managed resource; andone or more conditions of the one or more access rights.14.The apparatus of claim 13, wherein the one or more access rights relate to one or more of:creating information at the management service producer;reading information at the management service producer;updating information at the management service producer; anddeleting information at the management service producer.15.The apparatus of claim 13 or 14, wherein the one or more conditions of the one or more access rights comprises a list of:a key to represent a type of condition; anda value to represent the condition.16.The apparatus of any preceding claim, wherein the means is for:receiving updated information identifying one or more access permissions for the role and / or group of management service consumer; andupdating the stored information based on the received updated information.17.The apparatus of claim 16, wherein the means is for:determining, based on the updated stored information, that the permissions have changed; andsending, to the authorization service consumer, information indicating that the permissions have changed.18.An apparatus comprising means for:receiving, from a management service consumer, an access request comprising a token for accessing a management service;validating the token;responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; andresponsive to determining that the management service consumer is authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.19.The apparatus of claim 18, wherein the access request further comprises at least one of:an identity of the management service consumer; andan indication of the management service to be accessed.20.The apparatus of claim 18 or 19, wherein the token further comprises at least one of:an identifier of the token;information identifying an issuer of the token as the authorization service producer;information identifying a consumer of the token as the management service consumer;context information of the token; anda type of the token;21.The apparatus of any of claims 19 to 20, wherein the token further comprises context information, and wherein the determining is further based on the context information.22.The apparatus of claim 21, wherein the context information comprises one or more of:an expiry time of the token;location information; anda security state of the management service consumer.23.The apparatus of any of claims 18 to 22, wherein the access right relates to one or more of:creating information at the apparatus;reading information at the apparatus;updating information at the apparatus; anddeleting information at the apparatus.24.The apparatus of any of claims 18 to 23, wherein the condition of access right comprises a list of:a key to represent the type of condition; anda value to represent the condition.25.An apparatus comprising at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to:receive, from an authorization service consumer, a request for authorization of a management service consumer to access a management service;validate an identity of the management service consumer based on the request;responsive to validating the identity, obtain permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; andsend an authorization response to the authorization service consumer based on the obtained permissions.26.An apparatus comprising at least one processor and at least one memory including a computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the apparatus at least to:receive, from a management service consumer, an access request comprising a token for accessing a management service;validate the token;responsive to validating the token, determine whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; andresponsive to determining that the management service consumer is authorized for access, perform one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.27.A method comprising:receiving, from an authorization service consumer, a request for authorization of a management service consumer to access a management service;validating an identity of the management service consumer based on the request;responsive to validating the identity, obtaining permissions assigned to the management service consumer according to a role and / or group with which the management service consumer is associated; andsending an authorization response to the authorization service consumer based on the obtained permissions.28.A method comprising:receiving, from a management service consumer, an access request comprising a token for accessing a management service;validating the token;responsive to validating the token, determining whether the management service consumer is authorized for access based on the token, wherein the token comprises permissions associated with the management service consumer; andresponsive to determining that the management service consumer is authorized for access, performing one or more operations based on the access request and one or more access rights and conditions indicated by the permissions.

Citation Information

Patent Citations

  • Secure access control in communication system

    WO2020254918A1