Secure avatar registration and management
Patent Information
- Application Number
- GB2024002649
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-25
- Publication Date
- 2025-08-27
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Field Various example embodiments relate to secure avatar registration and management. More specifically, various example embodiments exemplarily relate to measures (including methods, apparatuses and computer program products) for realizing secure avatar registration and management. Background The present specification generally relates to avatars for digital environments such as metaverse environments. An avatar may represent a user in metaverse environments such as 3rd Generation Partnership Project (3GPP) 5th Generation (5G) metaverse. In such metaverse, each user can have avatars created for various use cases. Avatar is very sensitive and privacy critical entity for which it is to be ensured that only the actual owner (and registered user) of the avatar is able to use and give access rights to third parties to use the avatar. Thus, avatars may be associated with digital rights. The digital rights comprise the rights of ownership and / or usage of a 2D / 3D graphics representation of the avatar by one or more persons each associated with e.g. a mobile subscription. The digital rights thus enable a person with usage rights to an avatar to use that avatar as their representation in a metaverse environment, for example using an application on their user equipment (UE), another UE, or a universal subscriber identity module (USIM)-less device. Here, a UE is a terminal or mobile equipment (ME) comprising a USIM. A mobile equipment is any device capable of connecting via a radio interface to a public land mobile network (PLMN), such as a mobile phone, that may comprise a USIM. A USIM stores information on a user's mobile subscription, providing support for authentication, authorization, encryption, and integrity protection of data transmitted via the radio interface. In this context, it is demanded that such metaverse systems involving usage of avatars, e.g. a 5G system or a successor system providing such metaverse technology is enabled to identify avatars and associate avatars with respective subscribers (i.e. owners of the avatars) and to authorize avatars to be used in mobile metaverse services. Hence, the problem arises that, to enable authorizing, in a 5G or successor system, a user of a UE to use a particular avatar as their representation in a metaverse environment, a mechanism is needed enabling to determine whether the user's avatar corresponds to one of avatars with digital rights known to the 5G (or beyond) system, for example based on visual appearance or other attributes of the user's avatar and the known avatars, and if the determination is positive, to further determine whether the user has usage rights to the known avatar. Hence, there is a need to provide for secure avatar registration and management and in particular for registering the digital rights of an avatar. Summary Various example embodiments aim at addressing at least part of the above issues and / or problems and drawbacks. Various aspects of example embodiments are set out In the appended claims. According to an exemplary aspect, there is provided a method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. According to an exemplary aspect, there is provided a method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request. According to an exemplary aspect, there is provided a method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided a method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, means for associating a user identification feature with an avatar identifier of said avatar, means for storing said user identification feature, said avatar identifier, and said information on said avatar, and means for transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. According to an exemplary aspect, there is provided an apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, means for decrypting said avatar registration request utilizing said first key, and means for transmitting, towards a second network entity, said decrypted avatar registration request. According to an exemplary aspect, there is provided an apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration 5 request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating circuitry configured to associate a user identification feature with an avatar identifier of said avatar, storing circuitry configured to store said user identification feature, said avatar identifier, and said information on said avatar, and transmitting circuitry configured to transmit, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. According to an exemplary aspect, there is provided an apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting circuitry configured to decrypt said avatar registration request utilizing said first key, and transmitting circuitry configured to transmit, towards a second network entity, said decrypted avatar registration request. According to an exemplary aspect, there is provided an apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information Indicative of said avatar Identifier. According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request. According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided a computer program product comprising computer-executable computer program code which, when the program is run on a computer (e.g. a computer of an apparatus according to any one of the aforementioned apparatus-related exemplary aspects of the present disclosure), is configured to cause the computer to carry out the method according to any one of the aforementioned method-related exemplary aspects of the present disclosure. Such computer program product may comprise (or be embodied) a (tangible) computer-readable (storage) medium or the like on which the computerexecutable computer program code is stored, and / or the program may be directly loadable into an internal memory of the computer or a processor thereof. Any one of the above aspects enables an efficient and secured communication and processing in relation to avatar registration to thereby solve at least part of the problems and drawbacks identified in relation to the prior art. By way of example embodiments, there is provided secure avatar registration and management. More specifically, by way of example embodiments, there are provided measures and mechanisms for realizing secure avatar registration and management. Thus, improvement is achieved by methods, apparatuses and computer program products enabling / realizing secure avatar registration and management. Brief description of the drawings In the following, the present disclosure will be described in greater detail by way of non-limiting examples with reference to the accompanying drawings, in which FIG. 1 is a block diagram illustrating an apparatus according to example embodiments, FIG. 2 is a block diagram illustrating an apparatus according to example embodiments, FIG. 3 is a block diagram illustrating embodiments, FIG. 4 is a block diagram illustrating embodiments, FIG. 5 is a block diagram illustrating embodiments, an apparatus according to example an apparatus according to example an apparatus according to example FIG. 6 is a block diagram illustrating an apparatus according to example embodiments, FIG. 7 is a schematic diagram of a procedure according to example embodiments, FIG. 8 is a schematic diagram of a procedure according to example embodiments, FIG. 9 is a schematic diagram of a procedure according to example embodiments, FIG. 10 is a schematic diagram of a procedure according to example embodiments, FIG. 11 shows a schematic diagram of signaling sequences according to example embodiments, FIG. 12 shows a schematic diagram of symmetric hashing concept, FIG. 13 shows a schematic diagram of signaling sequences according to example embodiments, and FIG. 14 is a block diagram alternatively illustrating apparatuses according to example embodiments. Detailed description The present disclosure is described herein with reference to particular nonlimiting examples and to what are presently considered to be conceivable embodiments. A person skilled in the art will appreciate that the disclosure is by no means limited to these examples, and may be more broadly applied. It is to be noted that the following description of the present disclosure and its embodiments mainly refers to specifications being used as non-limiting examples for certain exemplary network configurations and deployments. Namely, the present disclosure and its embodiments are mainly described in relation to 3GPP specifications being used as non-limiting examples for certain exemplary network configurations and deployments. As such, the description of example embodiments given herein specifically refers to terminology which is directly related thereto. Such terminology is only used in the context of the presented non-limiting examples, and does naturally not limit the disclosure in any way. Rather, any other communication or communication related system deployment, etc. may also be utilized as long as compliant with the features described herein. Hereinafter, various embodiments and implementations of the present disclosure and Its aspects or embodiments are described using several variants and / or alternatives. It is generally noted that, according to certain needs and constraints, all of the described variants and / or alternatives may be provided alone or in any conceivable combination (also including combinations of individual features of the various variants and / or alternatives). As used herein, "at least one of the following: " and "at least one of " and similar wording, where the list of two or more elements are joined by "and" or "or", mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements. According to example embodiments, in general terms, there are provided measures and mechanisms for (enabling / realizing) secure avatar registration and management. In brief, according to example embodiments, a management service to handle avatar related services of a user and avatar registration mechanisms either via an access and mobility management function (AMF) using non-access stratum (NAS) keys or via a unified data management (UDM) using a pre-shared long key K are provided. In addition, keys based on biometric identifiers or templates or other biometric related information may be utilized. In this way, example embodiments are applicable also to no USIM-cases and to roaming scenarios. According to such example embodiments, different biometric identifiers may be utilized to associate different avatars with a same user. According to example embodiments, a unique avatar identifier (ID) is created and stored in association with information indicative of the owning (associated) user. The information indicative of the owning (associated) user may be device information (corresponding to a registering device), subscriber information (corresponding to a registering subscriber), or information provided by the registering entity or generated based on such information provided by the registering entity. Such information provided by the registering entity may include biometric templates and (symmetric) hashing functions. Such information generated based on such information provided by the registering entity may include quick response (QR) codes or bar codes including at least part of the information provided by the registering entity and / or being indicative of at least part of the information provided by the registering entity. Such QR code or bar code may be generated as part of a successful registration and may be provided as part of a successful registration response. Other (graphical) representations other than QR codes or bar codes being able to be indicative of at least part of the information provided by the registering entity and to thus serve as a kind of identification may be used instead. According to further example embodiments, a successful registration of an avatar, which is initiated by a subscriber (corresponding to a user), is considered as an implicit user-consent to allow a 5th Generation system (5GS) (or successor, or similar) to maintain the mapping or association between the subscriber and the registered avatar(s). According to example embodiments of one option, the avatar registration and mapping mechanism is configured via UDM in 5GS through some or all of the following summarized steps: - a long-term key K is pre-shared at both a UE (as an example of a terminal) and the UDM, - the UE sends an avatar registration request which is encrypted with the key K and contains a device ID and avatar details to an avatar management service (AMS), and the AMS forwards this message to an UDM for decryption and authorization, - the UDM decrypts and authenticates the registration request message with the key K and sends the authentication response to the AMS, and - the AMS assigns a unique avatar ID for the avatar and maps it to the subscriber. According to example embodiments of another option, the avatar registration and mapping mechanism is configured via an AMF in 5GS through some or all of the following summarized steps: - a UE sends an avatar registration request encrypted with NAS encryption keys and containing biometric templates and symmetric hashing functions to the AMF, - the AMF uses the NAS keys to check the integrity and decrypt the message and forwards the avatar registration request to an AMS, - the AMS may generate and registers a unique avatar ID and stores the biometric templates of the user and generates a QR / bar code for a new avatar registration which is forwarded to the AMF, and the AMF forwards the QR / bar code to the UE as an avatar registration response (the QR code enables the user to use the registered avatar also on a different UE than its own UE (or the registering UE), or on a device not containing a USIM). Example embodiments are specified below in more detail. FIG. 1 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a network node or entity 10 such as an avatar management service entity (or a network node or entity providing such functionality) comprising a receiving circuitry 11, an associating circuitry 12, a storing circuitry 13, and a transmitting circuitry 14. The receiving circuitry 11 receives, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar. The associating circuitry 12 associates a user identification feature with an avatar identifier of said avatar. The storing circuitry 13 stores said user identification feature, said avatar identifier, and said information on said avatar. The transmitting circuitry 14 transmits, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. FIG. 7 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 1 may perform the method of FIG. 7 but is not limited to this method. The method of FIG. 7 may be performed by the apparatus of FIG. 1 but is not limited to being performed by this apparatus. As shown in FIG. 7, a procedure according to example embodiments comprises an operation of receiving (S71), from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, an operation of associating (S72) a user identification feature with an avatar identifier of said avatar, an operation of storing (S73) said user identification feature, said avatar identifier, and said information on said avatar, and an operation of transmitting (S74), towards said first network entity, an avatar registration response including information indicative of said avatar identifier. FIG. 2 is a block diagram illustrating an apparatus according to example embodiments. In particular, FIG. 2 illustrates a variation of the apparatus shown in FIG. 1. The apparatus according to FIG. 2 may thus further comprise a generating circuitry 21, and / or a checking circuitry 22. In an embodiment at least some of the functionalities of the apparatus shown in FIG. 1 (or 2) may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes. According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and an exemplary method according to example embodiments may comprise an operation of transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, and an operation of receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key. According to further example embodiments, said second network entity is a unified data management entity or an authentication server function entity. According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of generating said avatar identifier. According to further example embodiments, said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier. According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each 16 other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of generating said avatar identifier. According to further example embodiments, said avatar registration request includes said avatar identifier. According to further example embodiments, said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function. According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements. According to a variation of the procedure shown in FIG. 7, exemplary details of the transmitting operation (S74) are given, which are inherently independent from each other as such. Such exemplary transmitting operation (S74) according to example embodiments may comprise an operation of generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. According to further example embodiments, said code Is at least one of the following: a bar code, or a quick response code. According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference. FIG. 3 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a network node or entity 30 such as an access and mobility management function entity (or a network node or entity providing such functionality) comprising a receiving circuitry 31, a decrypting circuitry 32, and a transmitting circuitry 33. The receiving circuitry 31 receives, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key. The decrypting circuitry 32 decrypts said avatar registration request utilizing said first key. The transmitting circuitry 33 transmits, towards a second network entity, said decrypted avatar registration request. FIG. 8 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 3 may perform the method of FIG. 8 but is not limited to this method. The method of FIG. 8 may be performed by the apparatus of FIG. 3 but is not limited to being performed by this apparatus. As shown in FIG. 8, a procedure according to example embodiments comprises an operation of receiving (S81), from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, an operation of decrypting (S82) said avatar registration request utilizing said first key, and an operation of transmitting (S83), towards a second network entity, said decrypted avatar registration request. FIG. 4 is a block diagram illustrating an apparatus according to example embodiments. In particular, FIG. 4 illustrates a variation of the apparatus shown in FIG. 3. The apparatus according to FIG. 4 may thus further comprise an encrypting circuitry 41, a verifying circuitry 42, a generating circuitry 43, and / or an adding circuitry 44. In an embodiment at least some of the functionalities of the apparatus shown in FIG. 3 (or 4) may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes. According to a variation of the procedure shown in FIG. 8, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, an operation of encrypting said avatar registration response utilizing said first key, and an operation of transmitting, towards said first network entity, said encrypted avatar registration response. According to a variation of the procedure shown in FIG. 8, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of verifying integrity of said avatar registration response utilizing said first key. According to a variation of the procedure shown in FIG. 8, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of generating said avatar identifier, and an operation of adding said avatar identifier to said decrypted avatar registration request. According to further example embodiments, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. According to further example embodiments, said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. According to further example embodiments, said code is at least one of the following: a bar code, or a quick response code. According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said first network entity is an access and mobility management function entity. According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference. FIG. 5 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a terminal 50 such as a user equipment comprising a transmitting circuitry 51 and a receiving circuitry 52. The transmitting circuitry 51 transmits, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key. The receiving circuitry 52 receives, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. FIG. 9 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 5 may perform the method of FIG. 9 but is not limited to this method. The method of FIG. 9 may be performed by the apparatus of FIG. 5 but is not limited to being performed by this apparatus. As shown in FIG. 9, a procedure according to example embodiments comprises an operation of transmitting (S91), towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and an operation of receiving (S92), from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. In an embodiment at least some of the functionalities of the apparatus shown in FIG. 5 may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes. According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference. FIG. 6 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a terminal 60 such as a user equipment comprising a transmitting circuitry 61 and a receiving circuitry 62. The transmitting circuitry 61 transmits, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request Is encrypted utilizing a first key. The receiving circuitry 62 receives, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. FIG. 10 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 6 may perform the method of FIG. 10 but is not limited to this method. The method of FIG. 10 may be performed by the apparatus of FIG. 6 but is not limited to being performed by this apparatus. As shown in FIG. 10, a procedure according to example embodiments comprises an operation of transmitting (S101), towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and an operation of receiving (S102), from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. In an embodiment at least some of the functionalities of the apparatus shown in FIG. 6 may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes. According to further example embodiments, said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. According to further example embodiments, said code Is at least one of the following: a bar code, or a quick response code. According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. According to further example embodiments, said first network entity is an access and mobility management function entity. According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference. Example embodiments outlined and specified above are explained below in more specific terms. FIG. 11 shows a schematic diagram of signaling sequences according to example embodiments, and in particular illustrates an example processing of an avatar registration via a UDM according to example embodiments of the one option mentioned above. Initially, a UE (as an example of a terminal) is primarily authenticated, and NAS and access stratum (AS) security contexts are established. As part or as a result of this authentication procedure, a pre-shared long term key K is available on both sides, the UE and the UDM. In case of no-USIM scenarios, in the lack of such authentication procedure and consequently of the availability of pre-shared long term key K, biometric based keys Kb can be considered instead of K. In such scenarios, such biometric based keys Kb or bases for deprival of such biometric based keys Kb would thus be exchanged beforehand. According to example embodiments of the one option, an AMS is provided and responsible for generating unique avatar IDs and mapping the unique avatar IDs to subscriber(s) / user(s). There can be a l:n mapping, where one user can have multiple avatars for different purposes. According to example embodiment, the UE is preconfigured with the connectivity information of such AMS. In a step 1 of FIG. 11, according to example embodiments of the one option, the UE transmits an avatar registration request to the AMS. One user can register multiple avatars using this procedure. However, at-a-time, only one avatar can be registered. In other words, one avatar registration request is for requesting registration of one avatar. If the UE has an avatar created, it needs to register the avatar in AMS. Heretofore, the avatar registration request is encrypted with (or utilizing) the mentioned key K. According to example embodiments, the avatar registration request contains a device ID (corresponding to the requesting device) and avatar details. The avatar details include, for example, a purpose of the avatar, a list of third parties requesting the avatar service, etc. A table defining information elements (IE) representing (and included in) the avatar details is included below and discussed afterwards. IE Name Description Mandatory (M) / Optional (0) Default Value Datatype Hash Included (Y / N) Hash Value Device ID A unique ID of the XR device which is used for avatar registration and further usage of the avatar M None String (Alphanumeric) Y hashed value of device ID Avatar ID A unique ID of the avatar getting registered. This can be generated by the device for each avatar registration request sent by the same user using that device. (M / )0 None Integer OR String Y hashed value of avatar ID Avatar Name User can give a name to the avatar he / she is registering. If no name is given by user, avatar ID is the unique way to identify the avatar. This avatar name may also be generated by the system in some implementations. M None String (Alphanumeric) Y hashed value of avatar name avatar_ purpose Enumerated value indicating the purpose of the avatar. According to the purpose, user can provide the visual representation images / URL in other fields below. For example: Generic = 0 Official = 1 Gaming = 2 Shopping = 3 Religious = 4 M 0 ENUM N NA Format of Graphic al / Visual representation Enumerated value indicating the format of the visual representation (images) provided for this avatar : 2D (0) 3D(1) M 0 ENUM N NA Image Hashing algorithm used Perpetual hashing algorithm can be used to determine hash value of the images which represent the avatar getting registered. This can be an ENUM with a list of perpetual hashing algorithms represented with a number. NO_HASHING_AL GORITHM = 0 Average Hashing (aHash) = 1 Median Hashing (mHash) = 2 Perceptual Hashing (pHash) = 3 M 0 ENUM N NA Difference Hashing (dHash) = 4 Block Hashing (bHash) = 5 Wavelet Hashing (wHash) = 6 ColorMoment Hashing = 7 Visual representation of Avatar 2D / 3D image or a list of images provided for the avatar getting registered. 0 None Array of images Y Array of hashes for each image Datatype format of images Images can be, for example, png, gif, jpeg, etc formats. This IE provides the data-type used. This can be an ENUM in some implementations, OR, it can be derived from the images provided. So, this can be an optional IE. 0 None String N NA Avatar download URL One or more URL can be given to download the visual representations of the avatar being registered. Either the URL OR the images must be provided for the avatar to be registered successfully. 0 None String (URL format) Y Hash of URL Avatar This field can 0 5 m Integer N NA Social define a social or Distan distance of the floating cing avatar getting point Privacy registered. This Prefe can be defined in rence order of meters. For example, if a user wants to register an avatar for gaming with social distancing of 5 meters, no other avatar in the game should be allowed to come closer than 5 meters w.r.t. this avatar. Avatar_details can comprise IEs like encrypted 2D / 3D images and visual perspectives representing the avatar, privacy preferences of avatar (like minimum distance requirement from other avatars (e.g. in meters)), a name given by the user to the avatar, etc. With NAS and AS security context being established, the encryption keys from one of these security contexts (preferably NAS security context) can be used to encrypt these details. The purpose of the avatar can be an enumerated value indicating, for example: - Official Meetings and conferences: 0 - Gaming: 1 - Shopping: 2 - Religious: 3, etc. For example, the user performing this avatar registration may want to have one avatar with formal attire for official work, one fancy look for gaming, a cool look for shopping, and one avatar for religious pilgrimage kind of augmented reality (AR) / virtual reality (VR) experience, etc. For this, the user can register multiple avatars, each with different purpose, and a different look and feel depending on the venue where the avatars needs to appear in the virtual world. Along with the images, a hashed value can be included to allow consuming applications / services to ensure that the data is not modified anywhere in transit or at rest. In a step 2 of FIG. 11, according to example embodiments of the one option, the AMS forwards the avatar registration request (message) to the UDM for decryption and authorization. In steps 3 and 4 of FIG. 11, according to example embodiments of the one option, the UDM gets the key Kb corresponding to the device ID (e.g. under consideration of the AS / NAS keys) and decrypts and authenticates the avatar registration request (message). In a step 5 of FIG. 11, according to example embodiments of the one option, once decrypted, the UDM sends a (successful) authentication response (message) with the device ID, subscriber information, and the avatar details. In a step 6 of FIG. 11, according to example embodiments of the one option, the AMS, once having received the (successful) authentication response, assigns a unique avatar ID and creates a mapping of the avatar (ID) with the device ID and the subscriber information. In a step 7 of FIG. 11, according to example embodiments of the one option, the AMS stores the mapping and the avatar details. In a step 8 of FIG. 11, according to example embodiments of the one option, the registration response is shared (transmitted towards the UE) with a status. If the authentication is failed from the UDM, the registration response 31 contains an error status. In the case of successful registration, the avatar ID is passed to device with the registration response. Once the registration is successful, the avatar can be uniquely identified, and a mapping between the avatar and the subscriber / user is established in the 5GS. This enables subsequent authentication of the avatar. According to example embodiments, a successful registration of the avatar, which is initiated by the subscriber, is considered as an implicit user-consent to allow the 5GS to maintain the mapping between the subscriber and avatar(s). FIG. 13 shows a schematic diagram of signaling sequences according to example embodiments, and in particular illustrates an example processing of an avatar registration via an AMF according to example embodiments of the another option mentioned above. Example embodiments of the another option are applicable also to roaming scenarios as well as no-USIM scenarios. According to these example embodiments, there is no need to preconfigure the AMS at the UE, since the avatar registration request (message) is transmitted to (and routed via) an AMF. Here, the AMS is assumed to be in the home network. According to these example embodiments, NAS keys are used for protecting the registration request. Initially, a UE (as an example of a terminal) is primarily authenticated, and NAS and AS security contexts are established. In a step 1 of FIG. 13, according to example embodiments of the another option, an avatar registration request is sent from the UE to the AMF. This procedure is required for every new avatar created by a user. One user may have multiple such avatars. The avatar registration request includes biometric templates and a list of symmetric hashing functions supported by the UE. Each avatar can be registered with each biometric template. Multiple hashing functions may be supported by UEs. FIG. 12 shows a schematic diagram of symmetric hashing concept, and in particular illustrates generation of biometric encryption and integrity keys (Kbenc and Kbint) from biometric templates using symmetric hashing functions. The biometric templates are shared by the user during the registration procedure along with the symmetric hashing functions (with the avatar registration request). The 5G network stores these templates and map the templates to a unique digital avatar ID, as discussed later with respect to steps 7 to 10 of FIG. 13. Known feature extraction algorithms to form biometric template are, for example, ISEF Egde detection and CANNY Edge Detection And SIFT Based Algorithm. With respect to the symmetric hashing functions, it is noted that a small change in the input (missing information, noise, or a change in the order of the input etc.) can cause a significant change in the hash value. A certain class of hash functions can, however, be formulated that are invariant to the order in which the input pattern is presented to the hash function. Such hash functions are known as order-independent or symmetric hash functions. Consider an input sequence X = xlx2x3. . .xn and the following two hash functions (examples) . / / ) + AjXj Aj 7" Al ' ' ' Y"" 1 + + (2) If the order of the input is changed to X = x2x3xn. . ,xl, the first hash function (1) yields a different hash value (different from the result of the original input sequence X = xlx2x3. . .xn), whereas the result of the second hash function (2) which is a symmetric hash function remains unchanged. Similar hash functions (such as function (2)) that are symmetric can be generated. Moreover, arbitrary combinations of more than one (symmetric) hash function yield new (symmetric) hash functions. Thus, a whole family of symmetric hash functions can be achieved by combining elementary symmetric hash functions. Returning to step 1 of FIG. 13, according to example embodiments of the another option, the avatar registration request is encrypted using NAS encryption keys and integrity protected using NAS integrity keys. These keys are derived as per legacy NAS security context establishment procedures. In steps 2 and 3 of FIG. 13, according to example embodiments of the another option, once the AMF receives the avatar registration request message, the AMF uses the NAS keys to check integrity of the avatar registration request message and to decrypt the avatar registration request message. According to example embodiments of the another option, the AMF may generate and maintain unique avatar IDs (optional step 4 of FIG. 13). However, the preferred alternative is generation and maintenance of avatar IDs by the AMS as is later on discussed with respect to step 6 of FIG. 13. In a step 5 of FIG. 13, according to example embodiments of the another option, the (decrypted) avatar registration request is forwarded by the AMF to the AMS, which may be an entity in the core network. According to example embodiments, the (decrypted) avatar registration request includes biometric templates and a list of symmetric hashing functions supported by the UE. The (decrypted) avatar registration request may further include a unique digital asset ID identifying a digital asset container. If, in optional step 4 of FIG. 13, a unique avatar ID was generated, this may be included as well. In a step 6 of FIG. 13, according to example embodiments of the another option, the AMS generates the unique avatar ID, which is preferred over the optional step 4 of FIG. 13 as mentioned above. In a step 7 of FIG. 13, according to example embodiments of the another option, the AMS registers / stores the unique avatar ID. In a step 8 of FIG. 13, according to example embodiments of the another option, the AMS stores the received biometric template(s). In a step 9 of FIG. 13, according to example embodiments of the another option, the AMS checks for supported symmetric hashing functions. In particular, the AMS may check if the symmetric hashing functions supported by the UE are secure enough and are supported by the AMS or not, which might lead (upon negative result) to an error being sent in step 12 of FIG. 13. In a step 10 of FIG. 13, according to example embodiments of the another option, the AMS generates a QR / bar code for this new avatar registration. The generated QR / bar code contains information about the unique avatar ID and the symmetric hashing functions (e.g. fnl and fn2 in FIG. 12) to be used to ensure that the user is able to securely access the avatar. A QR / bar code reader at UE can decode this if needed. In a step 11 of FIG. 13, according to example embodiments of the another option, the AMS sends an avatar registration response to the AMF. The avatar registration response includes the QR / bar code. In a step 12 of FIG. 13, according to example embodiments of the another option, the AMF forwards this avatar registration response including the QR / bar code to the UE. The avatar registration response is prepared using the NAS encryption and integrity keys. Once the registration is successful, the avatar can be uniquely identified, the user is enabled to access its avatars from different UEs, as long as the QR / bar code is retained. This enables subsequent authentication of the avatar. According to example embodiments, a successful registration of the avatar, which is initiated by the subscriber, is considered as an implicit user-consent to allow the 5GS to maintain the mapping between the subscriber and avatar(s). The above-described procedures and functions may be implemented by respective functional elements, processors, or the like, as described below. In the foregoing exemplary description of the network entity, only the units that are relevant for understanding the principles of the disclosure have been described using functional blocks. The network entity may comprise further units that are necessary for its respective operation. However, a description of these units is omitted in this specification. The arrangement of the functional blocks of the devices is not construed to limit the disclosure, and the functions may be performed by one block or further split into sub-blocks. When in the foregoing description it is stated that the apparatus, i.e. network node or entity (or some other means) is configured to perform some function, this is to be construed to be equivalent to a description stating that a (i.e. at least one) processor or corresponding circuitry, potentially in cooperation with computer program code stored in the memory of the respective apparatus, is configured to cause the apparatus to perform at least the thus mentioned function. Also, such function is to be construed to be equivalently implementable by specifically configured circuitry or means for performing the respective function (i.e. the expression "unit configured to" is construed to be equivalent to an expression such as "means for"). In FIG. 14, an alternative illustration of apparatuses according to example embodiments is depicted. As indicated in FIG. 14, according to example embodiments, the apparatus (network node or entity) 10' (corresponding to the network node or entity 10) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. Further, according to example embodiments, the apparatus (network node or entity) 30' (corresponding to the network node or entity 30) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. Further, according to example embodiments, the apparatus (network node or entity) 50' (corresponding to the network node or entity 50) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. Further, according to example embodiments, the apparatus (network node or entity) 60' (corresponding to the network node or entity 60) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. The apparatuses 10, 30, 50, 60 may be connected via link 145 with another apparatus (the interface of the another apparatus), e.g., another of the apparatuses 10, 30, 50, 60. The processor 141 and / or the interface 143 may also include a modem or the like to facilitate communication over a (hardwire or wireless) link, respectively. The interface 143 may include a suitable transceiver coupled to one or more antennas or communication means for (hardwire or wireless) communications with the linked or connected device(s), respectively. The interface 143 Is generally configured to communicate with at least one other apparatus, i.e. the interface thereof. The memory 142 may store respective programs assumed to include program instructions or computer program code that, when executed by the respective 37 processor, enables the respective electronic device or apparatus to operate in accordance with the example embodiments. In general terms, the respective devices / apparatuses (and / or parts thereof) may represent means for performing respective operations and / or exhibiting respective functionalities, and / or the respective devices (and / or parts thereof) may have functions for performing respective operations and / or exhibiting respective functionalities. When in the subsequent description it is stated that the processor (or some other means) is configured to perform some function, this is to be construed to be equivalent to a description stating that at least one processor, potentially in cooperation with computer program code stored in the memory of the respective apparatus, is configured to cause the apparatus to perform at least the thus mentioned function. Also, such function is to be construed to be equivalently implementable by specifically configured means for performing the respective function (i.e. the expression "processor configured to [cause the apparatus to] perform xxx-ing" is construed to be equivalent to an expression such as "means for xxx-ing"). According to example embodiments, an apparatus representing the network node or entity 10 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar (thus the apparatus comprising corresponding means for receiving), to perform associating a user identification feature with an avatar identifier of said avatar (thus the apparatus comprising corresponding means for associating), to perform storing said user identification feature, said avatar identifier, and said information on said avatar (thus the apparatus comprising 38 corresponding means for storing), and to perform transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier (thus the apparatus comprising corresponding means for transmitting). According to example embodiments, an apparatus representing the network node or entity 30 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key (thus the apparatus comprising corresponding means for receiving), to perform decrypting said avatar registration request utilizing said first key (thus the apparatus comprising corresponding means for decrypting), and to perform transmitting, towards a second network entity, said decrypted avatar registration request (thus the apparatus comprising corresponding means for transmitting). According to example embodiments, an apparatus representing the network node or entity 50 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key (thus the apparatus comprising corresponding means for transmitting) and to perform receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key (thus the apparatus comprising corresponding means for receiving). According to example embodiments, an apparatus representing the network node or entity 60 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key (thus the apparatus comprising corresponding means for transmitting) and to perform receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key (thus the apparatus comprising corresponding means for receiving). For further details regarding the operability / functionality of the individual apparatuses, reference is made to the above description in connection with any one of FIGs. 1 to 13, respectively. For the purpose of the present disclosure as described herein above, it should be noted that - method steps likely to be implemented as software code portions and being run using a processor at a network server or network entity (as examples of devices, apparatuses and / or modules thereof, or as examples of entities including apparatuses and / or modules therefore), are software code 40 independent and can be specified using any known or future developed programming language as long as the functionality defined by the method steps is preserved; - generally, any method step is suitable to be implemented as software or by hardware without changing the idea of the embodiments and its modification in terms of the functionality implemented; - method steps and / or devices, units or means likely to be implemented as hardware components at the above-defined apparatuses, or any module(s) thereof, (e.g., devices carrying out the functions of the apparatuses according to the embodiments as described above) are hardware independent and can be implemented using any known or future developed hardware technology or any hybrids of these, such as MOS (Metal Oxide Semiconductor), CMOS (Complementary MOS), BiMOS (Bipolar MOS), BiCMOS (Bipolar CMOS), ECL (Emitter Coupled Logic), TTL (Transistor-Transistor Logic), etc., using for example ASIC (Application Specific IC (Integrated Circuit)) components, FPGA (Field-programmable Gate Arrays) components, CPLD (Complex Programmable Logic Device) components or DSP (Digital Signal Processor) components; - devices, units or means (e.g. the above-defined network entity or network register, or any one of their respective units / means) can be implemented as individual devices, units or means, but this does not exclude that they are implemented in a distributed fashion throughout the system, as long as the functionality of the device, unit or means is preserved; - an apparatus like the user equipment and the network entity / network register may be represented by a semiconductor chip, a chipset, or a (hardware) module comprising such chip or chipset; this, however, does not exclude the possibility that a functionality of an apparatus or module, instead of being hardware implemented, be implemented as software in a (software) module such as a computer program or a computer program product comprising executable software code portions for execution / being run on a processor; - a device may be regarded as an apparatus or as an assembly of more than one apparatus, whether functionally in cooperation with each other or 41 functionally independently of each other but in a same device housing, for example. In general, it is to be noted that respective functional blocks or elements according to above-described aspects can be implemented by any known means, either in hardware and / or software, respectively, if it is only adapted to perform the described functions of the respective parts. The mentioned method steps can be realized in individual functional blocks or by individual devices, or one or more of the method steps can be realized in a single functional block or by a single device. Generally, any method step is suitable to be implemented as software or by hardware without changing the idea of the present disclosure. Devices and means can be implemented as individual devices, but this does not exclude that they are implemented in a distributed fashion throughout the system, as long as the functionality of the device is preserved. Such and similar principles are to be considered as known to a skilled person. Software in the sense of the present description comprises software code as such comprising code means or portions or a computer program or a computer program product for performing the respective functions, as well as software (or a computer program or a computer program product) embodied on a tangible medium such as a computer-readable (storage) medium having stored thereon a respective data structure or code means / portions or embodied in a signal or in a chip, potentially during processing thereof. The present disclosure also covers any conceivable combination of method steps and operations described above, and any conceivable combination of nodes, apparatuses, modules or elements described above, as long as the above-described concepts of methodology and structural arrangement are applicable. In view of the above, there are provided measures for secure avatar registration and management. Such measures exemplarily comprise receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. Even though the disclosure is described above with reference to the examples according to the accompanying drawings, it is to be understood that the disclosure is not restricted thereto. Rather, it is apparent to those skilled in the art that the present disclosure can be modified in many ways without departing from the scope of the inventive idea as disclosed herein. Among others, the following Items are covered by the above disclosure: Item 1. A method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information Indicative of said avatar identifier. Item 2. The method according to Item 1, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the method further comprises transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key. Item 3. The method according to Item 2, wherein said second network entity is a unified data management entity or an authentication server function entity. Item 4. The method according to Item 2 or 3, further comprising generating said avatar identifier. Item 5. The method according to any of Items 2 to 4, wherein said user identification feature is at least one of the following: - said device identifier, or - subscriber information obtained based on said device identifier. Item 6. The method according to any of Items 2 to 5, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 7. The method according to any of Items 2 to 5, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 8. The method according to Item 1, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 9. The method according to Item 8, further comprising generating said avatar identifier. Item 10. The method according to Item 8, wherein said avatar registration request includes said avatar identifier. Item 11. The method according to any of Items 8 to 10, wherein said user identification feature is at least one of the following: - said at least one biometric template, or - said at least one symmetric hashing function. Item 12. The method according to any of Items 8 to 11, further comprising checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements. Item 13. The method according to any of Items 8 to 12, wherein in relation to said transmitting, the method further comprises generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 14. The method according to Item 13, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 15. The method according to any of Items 1 to 14, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 16. A method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request. Item 17. The method according to Item 16, further comprising receiving, from said second network entity, an avatar registration response including information Indicative of an avatar identifier, encrypting said avatar registration response utilizing said first key, and transmitting, towards said first network entity, said encrypted avatar registration response. Item 18. The method according to Item 17, further comprising verifying integrity of said avatar registration response utilizing said first key. Item 19. The method according to Item 17 or 18, further comprising generating said avatar identifier, and adding said avatar identifier to said decrypted avatar registration request. Item 20. The method according to any of Items 17 to 19, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 21. The method according to Item 20, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 22. The method according to Item 21, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 23. The method according to any of Items 16 to 22, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 24. The method according to any of Items 16 to 22, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 25. The method according to any of Items 16 to 24, wherein said first network entity is an access and mobility management function entity. Item 26. The method according to any of Items 16 to 25, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 27. A method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 28. The method according to Item 27, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 29. The method according to Item 27, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 30. The method according to any of Items 27 to 29, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 31. A method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 32. The method according to Item 31, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 33. The method according to Item 32, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 34. The method according to any of Items 31 to 33, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 35. The method according to any of Items 31 to 33, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 36. The method according to any of Items 31 to 35, wherein said first network entity is an access and mobility management function entity. Item 37. The method according to any of Items 31 to 36, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 38. An apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, means for associating a user identification feature with an avatar identifier of said avatar, means for storing said user identification feature, said avatar identifier, and said information on said avatar, and means for transmitting, towards said first network entity, an avatar registration response including Information indicative of said avatar identifier. Item 39. The apparatus according to Item 38, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the apparatus further comprises means for transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, means for receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key. Item 40. The apparatus according to Item 39, wherein said second network entity is a unified data management entity or an authentication server function entity. Item 41. The apparatus according to Item 39 or 40, further comprising means for generating said avatar identifier. Item 42. The apparatus according to any of Items 39 to 41, wherein said user identification feature is at least one of the following: - said device identifier, or - subscriber information obtained based on said device identifier. Item 43. The apparatus according to any of Items 39 to 42, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 44. The apparatus according to any of Items 39 to 42, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 45. The apparatus according to Item 38, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 46. The apparatus according to Item 45, further comprising means for generating said avatar identifier. Item 47. The apparatus according to Item 45, wherein said avatar registration request includes said avatar identifier. Item 48. The apparatus according to any of Items 45 to 47, wherein said user identification feature is at least one of the following: - said at least one biometric template, or - said at least one symmetric hashing function. Item 49. The apparatus according to any of Items 45 to 48, further comprising means for checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements. Item 50. The apparatus according to any of Items 45 to 49, further comprising means for generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 51. The apparatus according to Item 50, wherein said code Is at least one of the following: - a bar code, or - a quick response code. Item 52. The apparatus according to any of Items 38 to 51, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 53. An apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, means for decrypting said avatar registration request utilizing said first key, and means for transmitting, towards a second network entity, said decrypted avatar registration request. Item 54. The apparatus according to Item 53, further comprising means for receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, means for encrypting said avatar registration response utilizing said first key, and means for transmitting, towards said first network entity, said encrypted avatar registration response. Item 55. The apparatus according to Item 54, further comprising means for verifying integrity of said avatar registration response utilizing said first key. Item 56. The apparatus according to Item 54 or 55, further comprising means for generating said avatar identifier, and means for adding said avatar identifier to said decrypted avatar registration request. Item 57. The apparatus according to any of Items 54 to 56, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 58. The apparatus according to Item 57, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 59. The apparatus according to Item 58, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 60. The apparatus according to any of Items 53 to 59, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 61. The apparatus according to any of Items 53 to 59, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 62. The apparatus according to any of Items 53 to 61, wherein said first network entity is an access and mobility management function entity. Item 63. The apparatus according to any of Items 53 to 62, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 64. An apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 65. The apparatus according to Item 64, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 66. The apparatus according to Item 64, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 67. The apparatus according to any of Items 64 to 66, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 69. The apparatus according to Item 68, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 70. The apparatus according to Item 69, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 71. The apparatus according to any of Items 68 to 70, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 72. The apparatus according to any of Items 68 to 70, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. said first network entity is an access and mobility management function entity. Item 74. The apparatus according to any of Items 68 to 73, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 75. An apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating circuitry configured to associate a user identification feature with an avatar identifier of said avatar, storing circuitry configured to store said user identification feature, said avatar identifier, and said information on said avatar, and transmitting circuitry configured to transmit, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. Item 76. The apparatus according to Item 75, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the apparatus further comprises transmitting circuitry configured to transmit, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, receiving circuitry configured to receive, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key. Item 77. The apparatus according to Item 76, wherein said second network entity is a unified data management entity or an authentication server function entity. Item 78. The apparatus according to Item 76 or 77, further comprising generating circuitry configured to generate said avatar identifier. Item 79. The apparatus according to any of Items 76 to 78, wherein said user identification feature is at least one of the following: - said device identifier, or - subscriber information obtained based on said device identifier. Item 80. The apparatus according to any of Items 76 to 79, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 81. The apparatus according to any of Items 76 to 79, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 82. The apparatus according to Item 75, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 83. The apparatus according to Item 82, further comprising generating circuitry configured to generate said avatar identifier. Item 84. The apparatus according to Item 82, wherein said avatar registration request includes said avatar identifier. Item 85. The apparatus according to any of Items 82 to 84, wherein said user identification feature is at least one of the following: - said at least one biometric template, or - said at least one symmetric hashing function. Item 86. The apparatus according to any of Items 82 to 85, further comprising checking circuitry configured to check said at least one symmetric hashing function for compatibility and / or compliance with security requirements. Item 87. The apparatus according to any of Items 82 to 86, further comprising generating circuitry configured to generate a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. said code is at least one of the following: - a bar code, or - a quick response code. Item 89. The apparatus according to any of Items 75 to 88, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 90. An apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting circuitry configured to decrypt said avatar registration request utilizing said first key, and transmitting circuitry configured to transmit, towards a second network entity, said decrypted avatar registration request. Item 91. The apparatus according to Item 90, further comprising receiving circuitry configured to receive, from said second network entity, an avatar registration response including information indicative of an avatar identifier, encrypting circuitry configured to encrypt said avatar registration response utilizing said first key, and transmitting circuitry configured to transmit, towards said first network entity, said encrypted avatar registration response. Item 92. The apparatus according to Item 91, further comprising verifying circuitry configured to verify integrity of said avatar registration response utilizing said first key. Item 93. The apparatus according to Item 91 or 92, further comprising generating circuitry configured to generate said avatar identifier, and adding circuitry configured to add said avatar identifier to said decrypted avatar registration request. Item 94. The apparatus according to any of Items 91 to 93, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 95. The apparatus according to Item 94, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 96. The apparatus according to Item 95, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 97. The apparatus according to any of Items 90 to 96, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 98. The apparatus according to any of Items 90 to 96, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 99. The apparatus according to any of Items 90 to 98, wherein said first network entity is an access and mobility management function entity. Item 100. The apparatus according to any of Items 90 to 99, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 102. The apparatus according to Item 101, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 103. The apparatus according to Item 101, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 104. The apparatus according to any of Items 101 to 103, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 105. An apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 106. The apparatus according to Item 105, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 107. The apparatus according to Item 106, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 108. The apparatus according to any of Items 105 to 107, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 109. The apparatus according to any of Items 105 to 107, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 110. The apparatus according to any of Items 105 to 109, wherein said first network entity is an access and mobility management function entity. Item 111. The apparatus according to any of Items 105 to 110, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said Images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 112. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. Item 113. The apparatus according to Item 112, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the instructions, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key. Item 114. The apparatus according to Item 113, wherein said second network entity is a unified data management entity or an authentication server function entity. Item 115. The apparatus according to Item 113 or 114, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: 68 generating said avatar identifier. Item 116. The apparatus according to any of Items 113 to 115, wherein said user identification feature is at least one of the following: - said device identifier, or - subscriber information obtained based on said device identifier. Item 117. The apparatus according to any of Items 113 to 116, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 118. The apparatus according to any of Items 113 to 116, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 119. The apparatus according to Item 112, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 120. The apparatus according to Item 119, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating said avatar identifier. Item 121. The apparatus according to Item 119, wherein said avatar registration request includes said avatar identifier. Item 122. The apparatus according to any of Items 119 to 121, wherein said user identification feature is at least one of the following: - said at least one biometric template, or - said at least one symmetric hashing function. Item 123. The apparatus according to any of Items 119 to 122, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements. Item 124. The apparatus according to any of Items 119 to 123, wherein in relation to said transmitting, the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 125. The apparatus according to Item 124, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 126. The apparatus according to any of Items 112 to 125, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 127. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request. Item 128. The apparatus according to Item 127, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, encrypting said avatar registration response utilizing said first key, and transmitting, towards said first network entity, said encrypted avatar registration response. Item 129. The apparatus according to Item 128, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: verifying integrity of said avatar registration response utilizing said first key. Item 130. The apparatus according to Item 128 or 129, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating said avatar identifier, and adding said avatar identifier to said decrypted avatar registration request. Item 131. The apparatus according to any of Items 128 to 130, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 132. The apparatus according to Item 131, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 133. The apparatus according to Item 132, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 134. The apparatus according to any of Items 127 to 133, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 135. The apparatus according to any of Items 127 to 133, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 136. The apparatus according to any of Items 127 to 135, wherein said first network entity is an access and mobility management function entity. Item 137. The apparatus according to any of Items 127 to 136, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 138. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 139. The apparatus according to Item 138, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 140. The apparatus according to Item 138, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 141. The apparatus according to any of Items 138 to 140, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 142. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 143. The apparatus according to Item 142, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 144. The apparatus according to Item 143, wherein said code is at least one of the following: - a bar code, or - a quick response code. Item 145. The apparatus according to any of Items 142 to 144, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 146. The apparatus according to any of Items 142 to 144, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network. Item 147. The apparatus according to any of Items 142 to 146, wherein said first network entity is an access and mobility management function entity. Item 148. The apparatus according to any of Items 142 to 147, wherein said information on said avatar includes at least one of the following: - a device identifier of a device requesting said registering said avatar, or - a device-side avatar identifier of said avatar, or - a name of said avatar, or - a usage purpose of said avatar, or - a format of a graphical and / or visual representation of said avatar, or - an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or - said images constituting said graphical and / or visual representation of said avatar, or - a data type of said graphical and / or visual representation of said avatar, or - a download address of said images constituting said graphical and / or visual representation of said avatar, or - information on a social distancing privacy preference. Item 149. A computer program product comprising computer-executable computer program code which, when the program Is run on a computer, Is configured to cause the computer to carry out the method according to any one of Item 1 to 16, 16 to 26, 27 to 30, or 31 to 37. Item 150. The computer program product according to Item 149, wherein the computer program product comprises a computer-readable medium on which the computer-executable computer program code is stored, and / or wherein the program is directly loadable into an internal memory of the computer or a processor thereof. List of acronyms and abbreviations 3GPP 3rd Generation Partnership Project 5G 5th Generation 5GS 5th Generation system AMF access and mobility management function AMS avatar management service AR augmented reality AS access stratum ID identifier IE information elements ME mobile equipment NAS non-access stratum PLMN public land mobile network QR quick response UDM unified data management UE user equipment USIM universal subscriber identity module VR virtual reality
Claims
1. A method comprisingreceiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar,associating a user identification feature with an avatar identifier of said avatar,storing said user identification feature, said avatar identifier, and said information on said avatar, andtransmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.
2. The method according to claim 1, whereinsaid avatar registration request includes a device identifier of a device requesting said registering said avatar,said avatar registration request is encrypted utilizing a first key, and the method further comprisestransmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, andreceiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key.
3. The method according to claim 2, whereinsaid second network entity is a unified data management entity or an authentication server function entity, and / or wherein the method further comprisesgenerating said avatar identifier, and / or wherein said user identification feature is at least one of the following:said device identifier, orsubscriber information obtained based on said device identifier.
4. The method according to any of claims 2 to 3, whereinsaid first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network, or whereinsaid first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.
5. The method according to claim 1, whereinsaid avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.
6. The method according to claim 5, further comprisinggenerating said avatar identifier, or whereinsaid avatar registration request includes said avatar identifier.
7. The method according to any of claims 5 to 6, wherein said user identification feature is at least one of the following:said at least one biometric template, orsaid at least one symmetric hashing function, and / or wherein the method further compriseschecking said at least one symmetric hashing function for compatibility and / or compliance with security requirements.
8. The method according to any of claims 5 to 7, whereinin relation to said transmitting, the method further comprisesgenerating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier, wherein optionallysaid code is at least one of the following:a bar code, ora quick response code.
9. The method according to any of claims 1 to 8, wherein said information on said avatar includes at least one of the following:a device identifier of a device requesting said registering said avatar, ora device-side avatar identifier of said avatar, ora name of said avatar, ora usage purpose of said avatar, ora format of a graphical and / or visual representation of said avatar, oran image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, orsaid images constituting said graphical and / or visual representation of said avatar, ora data type of said graphical and / or visual representation of said avatar, ora download address of said images constituting said graphical and / or visual representation of said avatar, orinformation on a social distancing privacy preference.
10. A method comprisingreceiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key,decrypting said avatar registration request utilizing said first key, andtransmitting, towards a second network entity, said decrypted avatar registration request.
11. The method according to claim 10, further comprisingreceiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier,encrypting said avatar registration response utilizing said first key, and transmitting, towards said first network entity, said encrypted avatar registration response.
12. The method according to claim 11, further comprisingverifying integrity of said avatar registration response utilizing said first key, and / or wherein the method further comprisesgenerating said avatar identifier, andadding said avatar identifier to said decrypted avatar registration request.
13. The method according to any of claims 11 to 12, whereinsaid avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.
14. The method according to claim 13, whereinsaid avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier, wherein optionallysaid code is at least one of the following:a bar code, ora quick response code.
15. The method according to any of claims 10 to 14, whereinsaid first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network, or whereinsaid first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.
16. The method according to any of claims 10 to 15, whereinsaid first network entity is an access and mobility management function entity, and / or wherein said information on said avatar includes at least one of the following:a device identifier of a device requesting said registering said avatar, ora device-side avatar identifier of said avatar, ora name of said avatar, ora usage purpose of said avatar, ora format of a graphical and / or visual representation of said avatar, oran image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, orsaid images constituting said graphical and / or visual representation of said avatar, ora data type of said graphical and / or visual representation of said avatar, ora download address of said images constituting said graphical and / or visual representation of said avatar, orinformation on a social distancing privacy preference.
17. A method comprisingtransmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, andreceiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.
18. A method comprisingtransmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, andreceiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.
19. The method according to claim 18, whereinsaid avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier, wherein optionallysaid code is at least one of the following:a bar code, ora quick response code.
20. The method according to any of claims 17 to 19, whereinsaid first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network, or whereinsaid first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.
21. The method according to any of claims 17 to 20, whereinsaid first network entity is an access and mobility management function entity, and / or wherein said information on said avatar includes at least one of the following:a device identifier of a device requesting said registering said avatar, ora device-side avatar identifier of said avatar, ora name of said avatar, ora usage purpose of said avatar, ora format of a graphical and / or visual representation of said avatar, oran image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, orsaid images constituting said graphical and / or visual representation of said avatar, ora data type of said graphical and / or visual representation of said avatar, ora download address of said images constituting said graphical and / or visual representation of said avatar, orinformation on a social distancing privacy preference.
22. An apparatus comprisingmeans for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar,means for associating a user identification feature with an avatar identifier of said avatar,means for storing said user identification feature, said avatar identifier, and said information on said avatar, andmeans for transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key,means for decrypting said avatar registration request utilizing said first key, andmeans for transmitting, towards a second network entity, said decrypted avatar registration request.
24. An apparatus comprisingmeans for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, andmeans for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.
25. An apparatus comprisingmeans for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, andmeans for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.Application No: GB2402649.4Examiner: Lloyd EdwardsClaims searched: 1-9, 22Date of search: 22 July 2024Patents Act 1977: Search Report under Section 17Documents considered to be relevant:Category Relevant to claims Identity of document and passage or figure of particular relevance X 1-9, 22 US 2024 / 0046687 Al (NAGANO et al.) Please see at least paragraph 45 X 1-9, 22 CN 108347428 A (21 VIANET GROUP INC;) Please see discussion under "Summary of the invention" X 1-9, 22 JP 2023182552 A (AI TECH INST CO LTD) Please see paragraphs 10-17, 29 X 1-9, 22 KR 100465644 Bl (LEE JUNG WON) Please see paragraphs 23, 62Categories:X Document indicating lack of novelty or inventive step A Document indicating technological background and / or state of the art. Y Document indicating lack of inventive step if P Document published on or after the declared priority date but combined with one or more other documents of same category. before the filing date of this invention. & Member of the same patent family E Patent document published on or after, but with priority date earlier than, the filing date of this application.Field of Search:International Classification:Subclass Subgroup Valid From H04L 0009 / 40 01 / 01 / 2022 G06F 0021 / 31 01 / 01 / 2013 G06F 0021 / 32 01 / 01 / 2013 G06T 0013 / 40 01 / 01 / 2011Application No: GB2402649.4Examiner: Lloyd EdwardsClaims searched: 1-25Date of search: 26 September 2024Patents Act 1977Further Search Report under Section 17Documents considered to be relevant:Category Relevant to claims Identity of document and passage or figure of particular relevance v A 1-25 CN 108347428 A (21 VIANET GROUP INC) Please see summary of invention X 1-25 US 2024 / 0046687 Al (NAGANO et al.) Please see paragraph 45 X 1-25 JP 2023182552 A (AI TECH INST CO LTD) Please see paragraphs 10-17 X 1-25 KR 100465644 Bl (LEE JUNG WON) Please see paragraph 23 X 10-21, 23-25 CN 108696355 B (TCL CORP) Please see summary of inventionCategories:X Document indicating lack of novelty or inventive step A Document indicating technological background and / or state of the art. Y Document indicating lack of inventive step if P Document published on or after the declared priority date but combined with one or more other documents of same category. before the filing date of this invention. & Member of the same patent family E Patent document published on or after, but with priority date earlier than, the filing date of this application.Field of Search:International Classification:Subclass Subgroup Valid From H04L 0009 / 40 01 / 01 / 2022Subclass Subgroup Valid From G06F 0021 / 31 01 / 01 / 2013 G06F 0021 / 32 01 / 01 / 2013 G06T 0013 / 40 01 / 01 / 2011
Citation Information
Patent Citations
Registration system, method and apparatus of application program based on block chain
CN108347428A
A method and system for preventing user avatar theft
CN108696355B
Avatar authenticity registration method, avatar authenticity registration system, representation data management system, and representation data management method
JP2023182552A
System for providing avatar service and method thereof
KR100465644B1
Techniques for verifying user identities during computer-mediated interactions
US20240046687A1