Authentication Server and Communication Method

The network node facilitates authorized API calls between non-collaborating users by identifying and obtaining approval from the second user, enhancing security and service quality management in 5G networks.

JP7698048B2Active Publication Date: 2025-06-24NTT DOCOMO INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023542067
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-17
Publication Date
2025-06-24
Estimated Expiration
2041-08-17

AI Technical Summary

Technical Problem

Existing 5G CAPIF architecture does not handle scenarios where API invokers need approval from non-collaborating users, and the Authorization code grant type fails when clients cannot redirect to authorization servers.

Method used

A network node that receives authorization requests, identifies the second user, notifies the second user of the request, and issues an access token upon authorization, enabling API calls without client redirection.

Benefits of technology

Enables API calls from one user to another user's resources with approval, preventing unauthorized access and ensuring secure service quality management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007698048000001
    Figure 0007698048000001
  • Figure 0007698048000002
    Figure 0007698048000002
  • Figure 0007698048000003
    Figure 0007698048000003
Patent Text Reader

Abstract

This network node comprises: a reception unit that receives, from a first user, an authorization request for an Application Programming Interface (API) call, for which the authorization of a second user is required; a control unit that identifies the second user on the basis of the authorization request; and a transmission unit that transmits, to the second user, information to the effect that the authorization request has been received from the first user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to Authentication Server and a communication method.

Background Art

[0002] In 3GPP (3rd Generation Partnership Project), in order to achieve further increase in system capacity, further increase in data transmission speed, further reduction in latency in the radio section, etc., a wireless communication method called 5G or NR (New Radio) (hereinafter, this wireless communication method is referred to as "5G" or "NR") is being studied. In 5G, in order to meet the requirement of achieving a throughput of 10 Gbps or more and reducing the latency in the radio section to 1 ms or less, various wireless technologies are being studied.

[0003] In NR, a network architecture including 5GC (5G Core Network) corresponding to EPC (Evolved Packet Core), which is the core network in the network architecture of LTE (Long Term Evolution), and NG-RAN (Next Generation - Radio Access Network) corresponding to E-UTRAN (Evolved Universal Terrestrial Radio Access Network), which is the RAN (Radio Access Network) in the network architecture of LTE, is being studied (see Non-Patent Document 1).

[0004] Also, for example, an architecture (hereinafter referred to as the "CAPIF architecture") that configures the Northbound interface between the NEF (Network Exposure Function) and the AF (Application Function) in a 5G system by the CAPIF (Common API Framework) is being considered (see Non-Patent Documents 2, 3, and 4). CAPIF is defined as a framework that can be applied to all APIs (Application Programming Interfaces) provided by 3GPP.

[0005] In the 3GPP core network, APIs are open to external applications. In CAPIF, third-party applications can call the APIs and access the API exposing function. At this time, the CCF (CAPIF Core Function) in the network manages the applications that can call the APIs and authenticates and authorizes the API invoker (the application that calls the API).

[0006] In CAPIF, the API invoker is authorized to call the API by being authenticated by the CCF, and can access the API exposing function.

[0007] Also, as a mechanism for authorization other than CAPIF, there is OAuth 2.0: IETF RFC 6749. By using the Authorization code grant type method defined therein, the authorization server (corresponding to the CCF) can authorize the client (corresponding to the API invoker) to access the protected resource (corresponding to the API exposing function) without passing confidential information such as passwords to the client.

[0008] In the authorization code grant type, the client (typically, an application on a smartphone) requests access to the authorization server from the resource owner cooperating with the client by performing an HTTP redirect in a web browser. Then, the exchange of authentication and authorization information takes place between the authorization server and the resource owner, i.e., in a place where the client cannot recognize it.

Prior Art Documents

Non-Patent Documents

[0009]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

Non-Patent Document 4

Summary of the Invention

[0010] As another use case, it is conceivable that user A, who is an API invoker, calls an API related to another non-cooperating user B (for example, information related to service quality such as QoS and location information, or privacy). In this case, in order for user A to call the API related to user B, it is necessary to obtain the approval of user B.

[0011] However, as described above, the current CAPIF assumes that if the API invoker is authenticated, the API call is authorized, so it cannot handle the above use case where approval from another user is required. To handle the above use case, an extension of CAPIF is required.

[0012] In addition, in the case of the Authorization code grant type, when the client is not collaborating with the resource owner (another user), the client cannot redirect to the authorization server. In this case, since the resource owner cannot receive the redirect instruction from the client, the authorization server is unaware that the client is requesting access to the protected resource and cannot authorize access to the protected resource.

[0013] One aspect of the present disclosure provides a network node and a communication method that enable a user to call an API related to another non-collaborating user after confirming the availability of the API call with the other user.

[0014] A network node according to one aspect of the present disclosure includes a receiving unit that receives an authorization request for calling an API (Application Programming Interface) that requires authorization from a second user from a first user, a control unit that identifies the second user based on the authorization request, and a transmitting unit that transmits information indicating that the authorization request has been received from the first user to the second user.

[0015] A communication method according to one aspect of the present disclosure includes a first user notifying a network node of an authorization request for calling an API (Application Programming Interface) that requires authorization from a second user, the network node identifying the second user based on the authorization request, the network node transmitting information indicating that the authorization request has been received from the first user to the second user, the second user verifying the authorization request and authorizing the first user, the second user transmitting information indicating that the API call of the first user has been authorized to the network node, the network node issuing an access token based on the authorization of the second user, the network node transmitting the access token to the first user, and the first user using the access token to call an API that requires authorization from the second user.

Brief Description of the Drawings

[0016]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Embodiments for Carrying Out the Invention

[0017] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the embodiments described below are merely examples, and the embodiments to which the present disclosure is applied are not limited to the following embodiments.

[0018] In the operation of the wireless communication system according to the embodiment of the present disclosure, existing technologies may be used as appropriate. The existing technologies are, for example, existing LTE or existing 5G, but are not limited to existing LTE or existing 5G.

[0019] In the following description, node names, signal names, etc. described in the current 5G standard document (or LTE standard document) are used. However, node names, signal names, etc. having the same functions as these may be called by different names.

[0020] For example, in the embodiments of the present disclosure described below, terms such as SS (Synchronization Signal), PSS (Primary SS), SSS (Secondary SS), PBCH (Physical Broadcast Channel), PRACH (Physical Random Access Channel), PDCCH (Physical Downlink Control Channel), PDSCH (Physical Downlink Shared Channel), PUCCH (Physical Uplink Control Channel), PUSCH (Physical Uplink Shared Channel), etc. used in existing LTE may be used. Also, the above-mentioned terms in NR correspond to NR-SS, NR-PSS, NR-SSS, NR-PBCH, NR-PRACH, NR-PDCCH, NR-PDSCH, NR-PUCCH, NR-PUSCH, etc. However, even for signals used in NR, it is not always necessary to specify "NR-".

[0021] (System Configuration Example A) FIG. 1 is a diagram for explaining an example of a communication system 1A. As shown in FIG. 1, the communication system 1A includes, for example, a UE10A (which may also be referred to as a User Equipment (user) terminal or (user) node), a plurality of network nodes 20A, 30A-1 to 30A-10 (which may also be referred to as Network Functions (NFs)), and 40A. Hereinafter, it is assumed that one network node corresponds to each function, but one network node may implement a plurality of functions, or a plurality of network nodes may implement one function. Also, the "connection" described below may be a logical connection or a physical connection.

[0022] The NG-RAN (Next Generation - Radio Access Network) 20A is a network node having a radio access function and may be, for example, a gNB (next generation Node B) (which may also be referred to as a base station). The NG-RAN 20A is connected to the UE10A, the AMF (Access and Mobility Management Function) 30A-1, and the UPF (User Plane Function) 40A.

[0023] AMF30A-1 is a network node that has functions such as the termination of the RAN interface, the termination of the NAS (Non-Access Stratum), registration management, connection management, reachability management, and mobility management. AMF30A-1 is connected to UE10A, NG-RAN20A, SMF (Session Management function)30A-2, NSSF (Network Slice Selection Function)30A-3, NEF (Network Exposure Function)30A-4, NRF (Network Repository Function)30A-5, UDM (Unified Data Management)30A-6, AUSF (Authentication Server Function)30A-7, PCF (Policy Control Function)30A-8, AF (Application Function)30A-9, and NWDAF (Network Data Analytics Function)30A-10. Note that AMF30A-1 may be called an access mobility management device.

[0024] AMF30A-1, SMF30A-2, NSSF30A-3, NEF30A-4, NRF30A-5, UDM30A-6, AUSF30A-7, PCF30A-8, AF30A-9, and NWDAF30A-10 are network nodes that are interconnected with each other via the interfaces Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, Naf, and Nnwdaf based on their respective services.

[0025] SMF30A-2 is a network node that has functions such as session management, UE's IP (Internet Protocol) address allocation and management, DHCP (Dynamic Host Configuration Protocol) function, ARP (Address Resolution Protocol) proxy, and roaming function. Note that SMF30A-2 may be called a session management device.

[0026] NSSF30A-3 is a network node that has functions such as selecting the network slice to which the UE connects, determining the permitted NSSAI (Network Slice Selection Assistance Information), determining the configured NSSAI, and determining the set of AMFs to which the UE connects.

[0027] NEF30A-4 is a network node that has the function of notifying other NFs of capabilities and events.

[0028] NRF30A-5 is a network node that has the function of discovering NF instances that provide services.

[0029] UDM30A-6 is a network node that manages subscriber data and authentication data. UDM30A-6 is connected to a UDR (User Data Repository) that holds the data.

[0030] AUSF30A-7 is a network node that authenticates the subscriber / UE10 against the subscriber data held in the UDR.

[0031] PCF30A-8 is a network node that has the function of performing network policy control.

[0032] AF30A-9 is a network node that has the function of controlling the application server.

[0033] NWDAF30A-10 is a network node that collects and analyzes data obtained by the network and provides the analysis results.

[0034] UPF40A is a network node that has functions such as an external PDU (Protocol Data Unit) session point for interconnecting with NG-RAN20 and DN (Data Network) 50A, packet routing and forwarding, and user plane QoS (Quality of Service) handling, and performs functions such as sending and receiving user data. Note that UPF40A may also be called a user plane device.

[0035] For example, a certain UPF40A and DN50A may constitute a network slice. In the wireless communication network according to the embodiment of the present disclosure, a plurality of network slices are constructed. Note that one UPF40A may operate one network slice, or one UPF40A may operate a plurality of network slices.

[0036] Also, physically, UPF40A is, for example, one or a plurality of computers (such as servers), and a plurality of resources formed by logically integrating and dividing the hardware resources (CPU, memory, hard disk, network interface, etc.) of the computer are regarded as a resource pool, and each resource in the resource pool can be used as a network slice. When UPF40A operates a network slice, for example, it is to manage the association between the network slice and the resource, start and stop the resource, monitor the operating status of the resource, and the like.

[0037] (System Configuration Example B) FIG. 2 is a diagram for explaining an example of a communication system 1B in a roaming environment. As shown in FIG. 2, the communication system 1B is composed of, for example, a UE10B which is a communication terminal (node) used by a user, a plurality of network nodes 20B, 30B-1 to 30B-12, and 40B.

[0038] The communication system 1B is a system included in a 5G network system and is a system that provides network services to the UE10B through data communication. The network service refers to a service that uses network resources such as communication services (such as dedicated line services) and application services (such as video distribution, services using sensor devices such as embedded devices).

[0039] Also, in FIG. 2, it is assumed that the UE10B is in a roaming environment. For the UE10 to be in a roaming environment means that, unlike the HPLMN (Home Public Land Mobile Network), which is the network (home network) with which the user of the UE10 contracts, the UE10B is accessing and communicating with the VPLMN (Visited Public Land Mobile Network), which is the network (in-circuit network) where the UE10B is located.

[0040] The VPLMN of the communication system 1B is composed of the UE10B, the (R)AN ((Radio) Access Network) 20B, the AMF (Access and Mobility Management Function) 30B-1, the SMF (Session Management function) 30B-2, the NSSF (Network Slice Selection Function) 30B-3, the NEF (Network Exposure Function) 30B-4, the NRF (Network Repository Function) 30B-5, the PCF (Policy Control Function) 30B-8, the NSACF (Network Slice Admission Control Function) 30B-10, the SEPP (Security Edge Protection Proxy) 30B-12, and the UPF (User Plane Function) 40B.

[0041] Also, the HPLMN of the communication system 1B is composed of SMF30B-2, NSSF30B-3, NEF30B-4, NRF30B-5, UDM (Unified Data Management) 30B-6, AUSF (Authentication Server Function) 30B-7, PCF30B-8, AF (Application Function) 30B-9, NSACF30B-10, NSSAAF (Network Slice Specific Authentication and Authorization Function) 30B-11, SEPP30B-12, and UPF40B.

[0042] (R)AN20B is a network node having a radio access function, and may be, for example, a gNB (next generation Node B) (which may also be called a base station).

[0043] AMF30B-1 is a network node having functions such as termination of the RAN interface, termination of the NAS (Non-Access Stratum), registration management, connection management, reachability management, and mobility management.

[0044] SMF30B-2 is a network node having functions such as session management, UE IP (Internet Protocol) address allocation and management, DHCP (Dynamic Host Configuration Protocol) function, ARP (Address Resolution Protocol) proxy, and roaming function.

[0045] NSSF30B-3 is a network node having functions such as selection of the network slice to which the UE connects, determination of the permitted NSSAI (Network Slice Selection Assistance Information), determination of the configured NSSAI, and determination of the AMF set to which the UE connects.

[0046] NEF30B-4 is a network node that has the function of notifying other NFs of capabilities and events.

[0047] NRF30B-5 is a network node that has the function of discovering NF instances that provide services.

[0048] UDM30B-6 is a network node that manages subscriber data and authentication data. UDM30B-6 is connected to a UDR (User Data Repository) that holds the data.

[0049] AUSF30B-7 is a network node that authenticates a subscriber / UE10B with respect to the subscriber data held in the UDR.

[0050] PCF30B-8 is a network node that has the function of performing policy control of the network.

[0051] AF30B-9 is a network node that has the function of controlling an application server.

[0052] NSACF30B-10B is a network node that has the function of controlling the approval of network slices.

[0053] NSSAAF30B-11 is a network node that has the function of controlling the authentication and authorization of network slices.

[0054] SEPP30B-12 is a network node that has a proxy for controlling message filtering and policy restrictions in the control plane interaction between operators. Note that SEPP30B-12 on the VPLMN side is denoted as vSEPP30B-12v, and SEPP30B-12 on the HPLMN side is denoted as hSEPP30B-12h. vSEPP30B-12v and hSEPP30B-12h provide functions related to the security and integrity of messages (such as HTTP Request, HTTP Response, etc.) transmitted and received between the VPLMN and the HPLMN.

[0055] UPF40B is a network node that has functions such as an external PDU (Protocol Data Unit) session point, packet routing and forwarding, and user plane QoS (Quality of Service) handling.

[0056] Note that N1, N2, N3, N4, N9 are reference points between network nodes. Also, N32 between vSEPP30B-12v and hSEPP30B-12h is a reference point at the connection point between the VPLMN and the HPLMN.

[0057] (R)AN20B is connected to UE10B, AMF30B-1, and UPF40B.

[0058] In the VPLMN, AMF30B-1, SMF30B-2, NSSF30B-3, NEF30B-4, NRF30B-5, PCF30B-8, NSACF30B-10 are interconnected via their respective service-based interfaces Namf, Nsmf, Nnssf, Nnef, Nnrf, Npcf, Nsacf.

[0059] In the HPLMN, SMF30B-2, NSSF30B-3, NEF30B-4, NRF30B-5, UDM30B-6, AUSF30B-7, PCF30B-8, AF30B-9, NSACF30B-10, and NSSAAF30B-11 are interconnected with each other via the interfaces Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, Naf, Nsacf, and Nnssaaf based on their respective services.

[0060] vSEPP30B-12v is connected to AMF30B-1, SMF30B-2, NSSF30B-3, NEF30B-4, NRF30B-5, PCF30B-8, and NSACF30B-10 of the VPLMN and is connected to hSEPP30B-12h via N32.

[0061] hSEPP30B-12h is connected to SMF30B-2, NSSF30B-3, NEF30B-4, NRF30B-5, UDM30B-6, AUSF30B-7, PCF30B-8, AF30B-9, NSACF30B-10, and NSSAAF30B-11 of the HPLMN and is connected to vSEPP30B-12v via N32.

[0062] The UPF40B on the VPLMN side is interconnected with (R)AN20B, SMF30B-2, and the UPF40B on the HPLMN side. The UPF40B of the HPLMN is interconnected with SMF30B-2 and the DN (Data Network) 50B.

[0063] (CAPIF Architecture) The above NEF30A-4(30B-4) is considered to implement an API that can be called from AF30A-9(30B-9) by applying the CAPIF architecture. The CAPIF architecture provides a mechanism to support the operation of service APIs. For example, it enables the API invoker to discover the service API provided by the API provider and allows communication using the service API. In addition, the CAPIF architecture has a mechanism to conceal the connection topology of the PLMN trust domain from an API invoker accessing the service API from outside the PLMN trust domain.

[0064] Next, the CAPIF architecture will be described with reference to FIG. 3. As shown in FIG. 3, CAPIF consists of an API invoker 101, a CCF 102, and an API provider domain 103.

[0065] The API invoker 101 is an application of the API caller. The API invoker 101 can be connected to the CCF 102 and the API provider domain 103 and is pre-registered (onboarded) with the CCF 102. Note that the API invoker 101 may be a third-party application or an application operated by the same operator that provides the CCF 102 and the API provider domain 103.

[0066] Also, a security method is agreed upon between the API invoker 101 and the CCF 102. Note that the Client Credential method defined in OAuth 2.0 is used for this security method. In this method, API calls are authorized only by authenticating the client (API invoker).

[0067] If the API invoker 101 is authenticated and authorized by the CCF 102, it can call the API and access the API exposing function 103-1.

[0068] The CCF 102 is a network node that manages applications capable of making API calls. When it receives an authorization request for an API call from the API invoker 101, it verifies the authorization request and authenticates and authorizes the API invoker 101.

[0069] The API provider domain 103 has functions such as the API exposing function 103-1, the API publishing function 103-2, and the API management function 103-3. The API provider domain 103 authenticates and authorizes the access of the API invoker 101 using the API exposing function 103-1. Also, the API provider domain 103 publishes the Service API on the CCF 102 using the API publishing function 103-2. Additionally, the API provider domain 103 audits the API call logs received from the CCF 102 and monitors the status of the Service API using the API management function 103-3.

[0070] (Sequence of CAPIF) Next, the sequence of CAPIF, that is, the sequence until the API invoker 101 makes an API call, will be described with reference to FIG. 4. It is assumed that the API invoker 101 has been pre-registered (onboarded) with the CCF 102 and a security method has been agreed upon between the API invoker 101 and the CCF 102.

[0071] First, in S101, API invoker 101 sends an authorization request for API calls to CCF 102. At this time, API invoker 101 also sends authentication information to CCF 102.

[0072] In S102, CCF 102 verifies the authorization request from API invoker 101 and performs the authentication process of API invoker 101.

[0073] When the authentication process is completed, in S103, CCF 102 sends the authorization information for API calls, specifically the access token.

[0074] In S104, API invoker 101 makes an API call using the authorization information (access token) to access API exposing function 103-1.

[0075] (System configuration of the Authorization code grant type) Next, the configuration of a system using the Authorization code grant type defined in OAuth 2.0 will be described with reference to FIG. 5. Note that the Authorization code grant type is widely used in SNS (Social Networking Service) linkage of smartphone applications, etc.

[0076] As shown in FIG. 5, the Authorization code grant type is used in a system consisting of a client 201, a resource owner 202, an authorization server 203, and a protected resource 204.

[0077] The client 201 corresponds to the API invoker 101 of CAPIF and is, for example, an application of a third-party service capable of linking with an SNS, and is typically an application on a smartphone.

[0078] The client 201 requests access to the authorization server 203 through the HTTP redirect in the web browser, which is to be coordinated with the resource owner 202 that cooperates with the client 201.

[0079] When the client 201 receives the authorization code from the authorization server 203 via the resource owner 202, it requests the issuance of an access token by sending the authentication information and the authorization code to the authorization server 203, and receives the access token from the authorization server 203. The client 201 uses the access token to access the protected resource 204.

[0080] The resource owner 202 is, for example, a user who owns an SNS account or a terminal owned by the user. When redirected from the client 201, the resource owner 202 receives authentication from the authorization server 203 and authorizes the client 201 to access the protected resource 204.

[0081] The authorization server 203 corresponds to the CCF102 of CAPIF and is, for example, an SNS server. The authorization server 203 authenticates the resource owner 202, redirects the resource owner 202 to the client 201, and sends the authorization code to the client 201.

[0082] When the authorization server 203 receives a request for the issuance of an access token from the client 201, it verifies the request from the client 201 and issues an access token to the client 201 if there is no problem.

[0083] The protected resource 204 corresponds to the API exposing function 103-1 of CAPIF and is, for example, personal information within the SNS.

[0084] (Sequence of the Authorization code grant type) Next, the sequence of the Authorization code grant type, that is, the sequence until the client 201 accesses the protected resource 204, will be described with reference to FIG. 6.

[0085] First, in S201, the client 201 redirects the resource owner 202 to the authorization server 203.

[0086] In S202, the authorization server 203 authenticates the resource owner 202. Also, in S203, the resource owner 202 authorizes the client 201 to access the protected resource 204.

[0087] Next, in S204, the authorization server 203 issues an authorization code and redirects the resource owner 202 to the client 201. When receiving the redirect, in S205, the resource owner 202 sends the authorization code to the client 201.

[0088] Next, in S206, the client 201 requests the authorization server 203 to issue an access token by sending the authorization code and its own authentication information to the authorization server 203.

[0089] In S207, the authorization server 203 verifies the authorization code for the request from the client. If there is no problem, it authenticates the client 201 and, in S208, issues an access token to the client 201.

[0090] In S209, the client 201 uses the access token to access the protected resource 204.

[0091] (Configuration of the new system) Next, the configuration of the system newly proposed in the present application, that is, the system that extends CAPIF, will be described with reference to FIGS. 7 and 8. Note that FIG. 8 shows the system shown in FIG. 7 from another perspective.

[0092] As shown in FIGS. 7 and 8, the newly proposed system consists of user 301, user 302, CCF 303, and API provider domain 304. In this embodiment, user 301 is the first user node, and user 302 is the second user node.

[0093] User 301 is, for example, the user of a terminal such as a smartphone or the terminal (node) owned by the user, and may be an API invoker or a client. Note that user 301 may also be an application server operated by a service provider. In this case, another user 305 who is a service consumer may use the application server, and the request of user 305 may trigger a request for authorization of API calls. In this system, since user 305 is optional, user 305 is shown by a dotted line in FIG. 7.

[0094] User 301 can be connected to CCF 303 and API provider domain 304 and is pre-registered (onboarded) with CCF 303. Note that user 301 and user 302 are not coordinated.

[0095] User 301 sends its own authentication information to CCF 303 and also sends a request for authorization of API calls that require the authorization of user 302 to CCF 303. When user 301 is notified by CCF 303 that user 302 has approved and receives an access token, user 301 uses the access token to call API provider domain 304 and access API exposing function 304-1. Thereby, user 301 can call APIs that require the authorization of user 302.

[0096] User 302 is the resource owner or the terminal (node) owned by the resource owner and can be connected to CCF 303.

[0097] When user 302 receives a notice from CCF303 indicating that it has received an authorization request for an API call from user 301, user 302 verifies the authorization request. If, as a result of the verification, user 302 authorizes user 301, user 302 sends its own authentication information to CCF303. When user 302 is authenticated by CCF303, user 302 sends information indicating that it authorizes the API call of user 301 to CCF303.

[0098] CCF303 is a network node that manages applications capable of making API calls. When CCF303 receives an authorization request for an API call that requires the authorization of user 302 from user 301 along with authentication information, CCF303 verifies the authorization request and authenticates user 301. Also, based on the authorization request of user 301, CCF303 identifies user 302, the user for whom approval (authorization) is to be obtained, and notifies user 302 that it has received an authorization request for an API call from user 301.

[0099] Also, when CCF303 receives authentication information from user 302, CCF303 authenticates user 302. Furthermore, when CCF303 is notified by user 302 that user 302 authorizes the API call of user 301, CCF303 issues an access token to user 301.

[0100] Note that in this embodiment, the authentication method performed by CCF303 is not particularly limited. For example, authentication may be performed using a password, key exchange, or SIM information.

[0101] The API provider domain 304 has functions including an API exposing function 304-1, an API publishing function 304-2, and an API management function 304-3. The API provider domain 304 authenticates and authorizes the access of the user 301 by using the API exposing function 304-1. Also, the API provider domain 304 publishes the Service API on the CCF 303 by using the API publishing function 304-2. Further, the API provider domain 304 audits the API call logs received from the CCF 102 and monitors the status of the Service API by using the API management function 304-3.

[0102] (Sequence of the new system) Next, the sequence of the system newly proposed in the present application, that is, the sequence until the user 301 makes a call to an API that requires authorization from the user 302 will be described with reference to FIG. 9. It is assumed that the user 301 has been pre-registered (onboarded) to the CCF 303.

[0103] First, in S301, the user 301 sends an authorization request for a call to an API that requires authorization from the user 302 to the CCF 303. At this time, the user 301 also sends authentication information to the CCF 303.

[0104] In S302, the CCF 303 verifies the authorization request from the user 301 and performs the authentication process of the user 301.

[0105] When the authentication process is completed, in S303, the CCF 303 identifies the user 302 to be authorized based on the authorization request of the user 301, and in S304, notifies the user 302 that an authorization request for an API call from the user 301 has been received.

[0106] In S305, user 302 sends authentication information to CCF 303. In S306, CCF 303 performs the authentication process for user 302.

[0107] In S307, user 302 authorizes the API call of user 301 and sends information indicating the authorization to CCF 303.

[0108] In S308, CCF 303 issues an access token indicating that it has been authorized by user 302 and sends the access token to user 301.

[0109] In S309, user 301 uses the access token to make an API call and accesses API exposing function 304-1.

[0110] <Effect> As described above, according to this embodiment, based on the authorization request for an API call that requires the authorization of user 302 from user 301, CCF identifies user 302 (resource owner), so that it is possible to obtain the authorization of another user without the need for redirection.

[0111] Thereby, it is possible to give authorization from another user for API use so that an unintended user or a malicious user cannot arbitrarily change the service quality of another user or steal information related to privacy. Once the authorization from another user is obtained, the service provider can change the service quality of a specific user group, for example, uniformly improve the communication quality of the participants in a certain conference, and improve the convenience of API use.

[0112] (Device Configuration) Next, a functional configuration example of the terminal 10, the base station 20, and the NEF 30A-4 (30B-4) that execute the processes and operations described so far will be described. The terminal 10, the base station 20, and the NEF 30A-4 (30B-4) include the functions described in the above example. However, the terminal 10, the base station 20, and the NEF 30A-4 (30B-4) may include only some of the functions described in the above example.

[0113] <Terminal 10> FIG. 10 is a diagram showing an example of the functional configuration of the terminal 10 according to an embodiment of the present disclosure. As shown in FIG. 10, the terminal 10 includes a transmission unit 510, a reception unit 520, a setting unit 530, and a control unit 540. The functional configuration shown in FIG. 10 is merely an example. As long as the operations according to the embodiments of the present disclosure can be executed, the function classification and the names of the functional units may be anything.

[0114] The transmission unit 510 generates a transmission signal from the transmission data and wirelessly transmits the generated transmission signal. The reception unit 520 wirelessly receives various signals and acquires signals of a higher layer from the received physical layer signals. Further, the reception unit 520 has a function of receiving NR-PSS, NR-SSS, NR-PBCH, DL / UL / SL control signals, etc. transmitted from the base station 20. Further, for example, the transmission unit 510 transmits PSCCH (Physical Sidelink Control Channel), PSSCH (Physical Sidelink Shared Channel), PSDCH (Physical Sidelink Discovery Channel), PSBCH (Physical Sidelink Broadcast Channel), etc. to another terminal 10 as D2D communication, and the reception unit 520 receives PSCCH, PSSCH, PSDCH, PSBCH, etc. from another terminal 10.

[0115] The setting unit 530 stores various setting information received from the base station 20 by the receiving unit 520 in a storage device (storage unit), and reads out the setting information from the storage device as necessary. Further, the setting unit 530 also stores preset pre-setting information in the storage device. The contents of the setting information and the pre-setting information may include, for example, information related to a PDU session. Note that the setting unit 530 may be included in the control unit 540.

[0116] The control unit 540 controls the entire terminal 10. In particular, as described in the above example, the control unit 540 performs control related to communication by a PDU session or the like. The functional unit related to signal transmission in the control unit 540 may be included in the transmission unit 510, and the functional unit related to signal reception in the control unit 540 may be included in the receiving unit 520.

[0117] <Base station 20> FIG. 11 is a diagram showing an example of the functional configuration of the base station 20 according to an embodiment of the present disclosure. As shown in FIG. 11, the base station 20 includes a transmission unit 610, a reception unit 620, a setting unit 630, and a control unit 640. The functional configuration shown in FIG. 11 is merely an example. As long as the operations according to the embodiments of the present disclosure can be executed, the functional divisions and the names of the functional units may be any.

[0118] The transmission unit 610 includes a function of generating a signal to be transmitted to the terminal 10 and wirelessly transmitting the generated signal. Further, the transmission unit 610 transmits an inter-network node message to another network node. Further, the transmission unit 610 transmits user data transmitted from the terminal 10 to the DH50 as necessary. The reception unit 620 includes a function of receiving various signals transmitted from the terminal 10 and obtaining information of a higher layer, for example, from the received signals. Further, the transmission unit 610 has a function of transmitting NRPSS, NR-SSS, NR-PBCH, DL / UL control signals, etc. to the terminal 10. Further, the reception unit 620 receives an inter-network node message from another network node.

[0119] The setting unit 630 stores the pre-set pre-setting information and various setting information to be transmitted to the terminal 10 in a storage device (storage unit), and reads out the pre-setting information and the setting information from the storage device as necessary. The contents of the pre-setting information and the setting information may include, for example, node connection information, information related to the PDU session, and the like. Note that the setting unit 630 may be included in the control unit 640.

[0120] The control unit 640 controls the entire base station 20. In particular, as described in the above example, the control unit 640 performs control related to communication by means of a PDU session or the like (in particular, transmission of user data transmitted from the terminal 10 to DH50 based on a notification from another network node). Further, the control unit 640 controls communication with the terminal 10 based on a terminal capability report regarding radio parameters received from the terminal 10. A functional unit related to signal transmission in the control unit 640 may be included in the transmission unit 610, and a functional unit related to signal reception in the control unit 640 may be included in the reception unit 620.

[0121] <Configuration of NEF> FIG. 12 is a diagram showing an example of the functional configuration of the NEF30A-4 (30B-4) according to an embodiment of the present disclosure. As shown in FIG. 12, the NEF30A-4 (30B-4) includes a transmission unit 710, a reception unit 720, a setting unit 730, and a control unit 740. The functional configuration shown in FIG. 12 is merely an example. As long as the operations according to the embodiments of the present disclosure can be executed, the functional divisions and the names of the functional units may be any.

[0122] The transmission unit 710 includes a function of generating a signal to be transmitted and transmitting the generated signal to the network. The reception unit 720 includes a function of receiving various signals and acquiring information of a higher layer, for example, from the received signals.

[0123] The setting unit 730 stores the pre-set pre-setting information and setting information in a storage device (storage unit), and reads out the pre-setting information and the setting information from the storage device as necessary. Note that the setting unit 730 may be included in the control unit 740.

[0124] The control unit 740 controls the entire NEF30A-4 (30B-4). The functional unit related to signal transmission in the control unit 740 may be included in the transmission unit 710, and the functional unit related to signal reception in the control unit 740 may be included in the reception unit 720.

[0125] (Hardware Configuration) Note that the block diagrams used in the description of the above embodiments show blocks of functional units. These functional blocks (components) are realized by any combination of at least one of hardware and software. Also, the method of realizing each functional block is not particularly limited. That is, each functional block may be realized using one physically or logically combined device, or two or more physically or logically separated devices may be directly or indirectly (e.g., using wired, wireless, etc.) connected and realized using these multiple devices. The functional block may be realized by combining software with the above one device or the above multiple devices.

[0126] Functions include, but are not limited to, judgment, decision, determination, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, solution, selection, selection, establishment, comparison, assumption, expectation, regarded as, notification (broadcasting), notification (notifying), communication (communicating), forwarding, configuration (configuring), reconfiguration (reconfiguring), allocation (allocating, mapping), assignment (assigning), etc. For example, a functional block (component) that functions to transmit is called a transmission unit or a transmitter. In any case, as described above, the realization method is not particularly limited.

[0127] For example, a base station, a terminal, etc. in an embodiment of the present disclosure may function as a computer that performs the processing of the wireless communication method of the present disclosure. FIG. 13 is a diagram showing an example of the hardware configuration of a terminal, a base station, and a network node according to an embodiment of the present disclosure. The above-described terminal 10, base station 20, and NEF 30A-4 (30B-4) may physically be configured as a computer device including a processor 1001, a memory 1002, a storage 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, and the like.

[0128] In the following description, the term "device" can be read as a circuit, a device, a unit, etc. The hardware configuration of the terminal 10, the base station 20, and the NEF 30A-4 (30B-4) may be configured to include one or more of each device shown in the figure, or may be configured without including some devices.

[0129] Each function in the terminal 10, the base station 20, and the NEF 30A-4 (30B-4) is realized by causing the processor 1001 to load a predetermined software (program) onto hardware such as the processor 1001 and the memory 1002, so that the processor 1001 performs calculations and controls communication by the communication device 1004, or controls at least one of reading and writing data in the memory 1002 and the storage 1003.

[0130] The processor 1001 controls the entire computer by operating an operating system, for example. The processor 1001 may be constituted by a central processing unit (CPU) including an interface with peripheral devices, a control device, an arithmetic device, a register, and the like. For example, the above-described control unit 540, control unit 640, control unit 740, etc. may be realized by the processor 1001.

[0131] Also, the processor 1001 reads a program (program code), software module, data, etc. from at least one of the storage 1003 and the communication device 1004 into the memory 1002, and executes various processes according to these. As the program, a program that causes a computer to execute at least a part of the operations described in the above embodiments is used. For example, the control unit 540 of the terminal 10, the control unit 640 of the base station 20, and the control unit 740 of the NEF 30A-4 (30B-4) may be stored in the memory 1002 and realized by a control program operating in the processor 1001, and the same may be true for other functional blocks. Although it has been described that the above various processes are executed by one processor 1001, they may be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may be implemented by one or more chips. Note that the program may be transmitted from a network via a telecommunication line.

[0132] The memory 1002 is a computer-readable recording medium, and may be constituted by at least one of, for example, ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), RAM (Random Access Memory), etc. The memory 1002 may be referred to as a register, cache, main memory (main storage device), etc. The memory 1002 can store a program (program code), software module, etc. executable for implementing the wireless communication method according to an embodiment of the present disclosure.

[0133] Storage 1003 is a computer-readable recording medium, and may be constituted by at least one of, for example, an optical disc such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (for example, a compact disc, a digital versatile disc, a Blu-ray (registered trademark) disc), a smart card, a flash memory (for example, a card, a stick, a key drive), a floppy (registered trademark) disk, a magnetic strip, etc. Storage 1003 may be called an auxiliary storage device. The above-described storage medium may be, for example, a database, a server, or other appropriate medium including at least one of the memory 1002 and the storage 1003.

[0134] The communication device 1004 is hardware (a transmission / reception device) for performing communication between computers via at least one of a wired network and a wireless network, and is also referred to as, for example, a network device, a network controller, a network card, a communication module, etc. The communication device 1004 may be configured to include, for example, a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc. in order to realize at least one of frequency division duplex (FDD: Frequency Division Duplex) and time division duplex (TDD: Time Division Duplex). For example, the above-described transmission unit 510, reception unit 520, transmission unit 610, reception unit 620, transmission unit 710, reception unit 720, etc. may be realized by the communication device 1004.

[0135] The input device 1005 is an input device (for example, a keyboard, a mouse, a microphone, a switch, a button, a sensor, etc.) that receives an external input. The output device 1006 is an output device (for example, a display, a speaker, an LED lamp, etc.) that performs an output to the outside. Note that the input device 1005 and the output device 1006 may have an integrated configuration (for example, a touch panel).

[0136] Also, each device such as the processor 1001 and the memory 1002 is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus or may be configured using different buses for each device.

[0137] Also, the terminal 10, the base station 20, and the NEF 30A-4 (30B-4) may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA), and some or all of the functional blocks may be realized by the hardware. For example, the processor 1001 may be implemented using at least one of these hardware components.

[0138] (Notification of Information, Signaling) The notification of information is not limited to the aspects / embodiments described in this disclosure and may be performed using other methods. For example, the notification of information may be implemented by physical layer signaling (e.g., downlink control information (DCI), uplink control information (UCI)), upper layer signaling (e.g., radio resource control (RRC) signaling, medium access control (MAC) signaling, notification information (master information block (MIB), system information block (SIB))), other signals, or a combination thereof. Also, the RRC signaling may be referred to as an RRC message and may be, for example, an RRC connection setup message, an RRC connection reconfiguration message, or the like.

[0139] (Applicable System) Each aspect / embodiment described in the present disclosure may be applicable to at least one of systems using LTE (Long Term Evolution), LTE-A (LTE-Advanced), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), FRA (Future Radio Access), NR (New Radio), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, UWB (Ultra-WideBand), Bluetooth (registered trademark), other suitable systems, and next-generation systems extended based on these. Also, multiple systems may be combined (for example, a combination of at least one of LTE and LTE-A and 5G, etc.) and applied.

[0140] (Processing Procedures, etc.) The processing procedures, sequences, flowcharts, etc. of each aspect / embodiment described in the present disclosure may be reordered as long as there is no contradiction. For example, for the methods described in the present disclosure, the elements of various steps are presented using an exemplary order and are not limited to the specific order presented.

[0141] (Base Station Operation) The specific operations assumed to be performed by the base station in the present disclosure may, in some cases, be performed by its upper node. In a network consisting of one or more network nodes having a base station, various operations performed for communication with a terminal can clearly be performed by at least one of the base station and other network nodes other than the base station (for example, but not limited to, MME or S-GW, etc.). Although the case where there is one other network node other than the base station has been exemplified above, a combination of a plurality of other network nodes (for example, MME and S-GW) may also be possible.

[0142] (Input / output direction) Information, etc. (see the item "Information, Signal") can be output from the upper layer (or lower layer) to the lower layer (or upper layer). It may also be input and output via a plurality of network nodes.

[0143] (Handling of input / output information, etc.) The input / output information, etc. may be stored in a specific location (for example, memory) or may be managed using a management table. The input / output information, etc. can be overwritten, updated, or appended. The output information, etc. may be deleted. The input information, etc. may be transmitted to other devices.

[0144] (Determination method) The determination may be made based on a value represented by 1 bit (0 or 1), or may be made based on a boolean value (Boolean: true or false), or may be made by comparing numerical values (for example, comparison with a predetermined value).

[0145] (Software) Software should be broadly construed to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., whether called software, firmware, middleware, microcode, hardware description language, or by any other name.

[0146] Also, software, instructions, information, etc. may be transmitted and received via a transmission medium. For example, when software is transmitted from a website, server, or other remote source using at least one of wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL), etc.) and wireless technologies (such as infrared, microwave, etc.), at least one of these wired and wireless technologies is included within the definition of a transmission medium.

[0147] (Information, signal) The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc., which may be referred to throughout the above description, may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.

[0148] Note that terms described in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings. For example, at least one of channel and symbol may be a signal (signaling). Also, a signal may be a message. Also, a Component Carrier (CC) may be called a carrier frequency, cell, frequency carrier, etc.

[0149] (“System”, “network”) The terms "system" and "network" used in this disclosure are used interchangeably.

[0150] (Parameter, channel name) Also, the information, parameters, etc. described in this disclosure may be represented using absolute values, relative values from a predetermined value, or by using corresponding other information. For example, a radio resource may be indicated by an index.

[0151] The names used for the above-described parameters are not limiting names in any way. Furthermore, mathematical formulas, etc. using these parameters may be different from those explicitly disclosed in this disclosure. Since various channels (e.g., PUCCH, PDCCH, etc.) and information elements can be identified by any suitable names, the various names assigned to these various channels and information elements are not limiting names in any way.

[0152] (Base station (radio base station)) In this disclosure, terms such as "base station (BS:Base Station)", "radio base station", "fixed station", "NodeB", "eNodeB (eNB)", "gNodeB (gNB)", "access point", "transmission point", "reception point", "transmission / reception point", "cell", "sector", "cell group", "carrier", "component carrier", etc. may be used interchangeably. The base station may also be referred to by terms such as macro cell, small cell, femto cell, pico cell, etc.

[0153] A base station can accommodate one or more (e.g., three) cells. When the base station accommodates multiple cells, the entire coverage area of the base station can be divided into multiple smaller areas, and each of these smaller areas can also provide communication services by a base station subsystem (e.g., a small indoor base station (RRH: Remote Radio Head)). The term "cell" or "sector" refers to part or all of the coverage area of at least one of the base station and the base station subsystem that provides communication services in this coverage.

[0154] (Terminal) In the present disclosure, terms such as "mobile station (MS)", "user terminal", "user equipment (UE)", "terminal", etc. can be used interchangeably.

[0155] A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other appropriate term.

[0156] (Base station / Mobile station) At least one of the base station and the mobile station may also be called a transmitting device, a receiving device, a communication device, etc. Note that at least one of the base station and the mobile station may also be a device mounted on a moving body, the moving body itself, etc. The moving body may be a vehicle (e.g., a car, an airplane, etc.), a moving body that moves without a driver (e.g., a drone, an autonomous vehicle, etc.), or a robot (humanoid or non-humanoid). Note that at least one of the base station and the mobile station also includes devices that do not necessarily move during communication operations. For example, at least one of the base station and the mobile station may be an IoT (Internet of Things) device such as a sensor.

[0157] Also, the base station in the present disclosure may be replaced by a user terminal. For example, for a configuration in which communication between a base station and a user terminal is replaced with communication between a plurality of user terminals (which may be referred to as, for example, D2D (Device-to-Device), V2X (Vehicle-to-Everything), etc.), each aspect / embodiment of the present disclosure may be applied. In this case, the functions of the above-described base station 20 may be configured to be possessed by the terminal 10. Also, terms such as "uplink" and "downlink" may be replaced with terms corresponding to inter-terminal communication (for example, "side"). For example, an uplink channel, a downlink channel, etc. may be replaced with a side channel.

[0158] Similarly, the terminal in the present disclosure may be replaced by a base station. In this case, the functions of the above-described terminal 10 may be configured to be possessed by the base station 20.

[0159] (Meaning and Interpretation of Terms) As used in this disclosure, the terms "determining" and "deciding" may encompass a wide variety of operations. "Determining" and "deciding" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up (e.g., searching in a table, database, or another data structure), ascertaining, and considering something as having been "determined" or "decided". Also, "determining" and "deciding" may include considering something as having been "determined" or "decided" after receiving (e.g., receiving information), transmitting (e.g., transmitting information), inputting, outputting, accessing (e.g., accessing data in a memory), etc. Further, "determining" and "deciding" may include considering something as having been "determined" or "decided" after resolving, selecting, choosing, establishing, comparing, etc. That is, "determining" and "deciding" may include considering that some operation has been "determined" or "decided". Also, "determining (deciding)" may be read as "assuming", "expecting", "considering", etc.

[0160] The terms "connected" and "coupled," or any variations thereof, mean any direct or indirect connection or coupling between two or more elements, and can include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements can be physical, logical, or a combination thereof. For example, "connected" may be read as "accessed." As used in this disclosure, two elements can be considered to be "connected" or "coupled" to each other using at least one of one or more wires, cables, and printed electrical connections, as well as, by way of some non-limiting and non-exhaustive examples, electromagnetic energy having wavelengths in the radio frequency region, microwave region, and optical (both visible and invisible) region.

[0161] (Reference signal) The reference signal can also be abbreviated as RS (Reference Signal) and may be called a Pilot depending on the applicable standard.

[0162] (Meaning of "based on") As used in this disclosure, the recitation "based on" does not mean "based solely on" unless otherwise specified. In other words, the recitation "based on" means both "based solely on" and "based at least in part on."

[0163] ( "First," "Second") Any reference to an element using the designations "first," "second," etc. as used in this disclosure does not generally limit the quantity or order of those elements. These designations can be used in this disclosure as a convenient way to distinguish between two or more elements. Thus, a reference to a first and second element does not mean that only two elements can be employed or that the first element must precede the second element in any way.

[0164] (Means) In the configurations of each of the above devices, the "section" may be replaced with "means", "circuit", "device", etc.

[0165] (Open format) In the present disclosure, when the terms "include", "including" and their variants are used, these terms are intended to be inclusive, similar to the term "comprising". Further, the term "or" used in the present disclosure is not intended to be an exclusive disjunction.

[0166] (Time units such as TTI, frequency units such as RB, radio frame configuration) A radio frame may be composed of one or more frames in the time domain. Each of the one or more frames in the time domain may be called a subframe. A subframe may further be composed of one or more slots in the time domain. A subframe may have a fixed time length (e.g., 1 ms) that does not depend on numerology.

[0167] Numerology may be a communication parameter applied to at least one of transmission and reception of a certain signal or channel. Numerology may indicate, for example, at least one of subcarrier spacing (SCS), bandwidth, symbol length, cyclic prefix length, transmission time interval (TTI), number of symbols per TTI, radio frame configuration, specific filtering processing performed by a transceiver in the frequency domain, specific windowing processing performed by a transceiver in the time domain, etc.

[0168] A slot may be composed of one or more symbols (such as OFDM (Orthogonal Frequency Division Multiplexing) symbols, SC-FDMA (Single Carrier Frequency Division Multiple Access) symbols, etc.) in the time domain. A slot may be a time unit based on a numerology.

[0169] A slot may include a plurality of mini-slots. Each mini-slot may be composed of one or more symbols in the time domain. Also, a mini-slot may be called a sub-slot. A mini-slot may be composed of a smaller number of symbols than a slot. A PDSCH (or PUSCH) transmitted in a time unit larger than a mini-slot may be called a PDSCH (or PUSCH) mapping type A. A PDSCH (or PUSCH) transmitted using a mini-slot may be called a PDSCH (or PUSCH) mapping type B.

[0170] A radio frame, a sub-frame, a slot, a mini-slot, and a symbol all represent time units for signal transmission. Different names corresponding to each of them may be used.

[0171] For example, one sub-frame may be called a Transmission Time Interval (TTI), or a plurality of consecutive sub-frames may be called a TTI, or one slot or one mini-slot may be called a TTI. That is, at least one of the sub-frame and the TTI may be a sub-frame (1 ms) in existing LTE, or a period shorter than 1 ms (e.g., 1 - 13 symbols), or a period longer than 1 ms. Note that the unit representing the TTI may be called a slot, a mini-slot, etc. instead of a sub-frame.

[0172] Here, TTI refers to, for example, the minimum time unit for scheduling in wireless communication. For example, in an LTE system, the base station performs scheduling to allocate radio resources (such as the frequency bandwidth and transmission power that can be used at each user terminal) to each user terminal in units of TTI. Note that the definition of TTI is not limited to this.

[0173] TTI may be a transmission time unit such as a channel-coded data packet (transport block), code block, codeword, etc., or may be a processing unit such as scheduling and link adaptation. Note that when TTI is given, the time interval (e.g., the number of symbols) in which a transport block, code block, codeword, etc. are actually mapped may be shorter than the TTI.

[0174] Note that when one slot or one mini-slot is called TTI, one or more TTIs (i.e., one or more slots or one or more mini-slots) may be the minimum time unit for scheduling. Also, the number of slots (mini-slots) constituting the minimum time unit for the scheduling may be controlled.

[0175] A TTI having a time length of 1 ms may be called a normal TTI (TTI in LTE Rel.8 - 12), normal TTI, long TTI, normal subframe, normal subframe, long subframe, slot, etc. A TTI shorter than the normal TTI may be called a shortened TTI, short TTI, partial TTI (partial or fractional TTI), shortened subframe, short subframe, mini-slot, sub-slot, slot, etc.

[0176] Note that a long TTI (e.g., a normal TTI, subframe, etc.) may be read as a TTI having a time length exceeding 1 ms, or a short TTI (e.g., a shortened TTI, etc.) may be read as a TTI having a TTI length less than that of the long TTI and not less than 1 ms.

[0177] A resource block (RB) is a resource allocation unit in the time domain and the frequency domain, and in the frequency domain, it may include one or more consecutive subcarriers. The number of subcarriers included in an RB may be the same regardless of the numerology, for example, it may be 12. The number of subcarriers included in an RB may be determined based on the numerology.

[0178] Also, the time domain of an RB may include one or more symbols, and may be the length of 1 slot, 1 mini-slot, 1 sub-frame, or 1 TTI. 1 TTI, 1 sub-frame, etc. may each be composed of one or more resource blocks.

[0179] Note that one or more RBs may be referred to as a physical resource block (PRB), a sub-carrier group (SCG), a resource element group (REG), a PRB pair, an RB pair, etc.

[0180] Also, a resource block may be composed of one or more resource elements (REs). For example, 1 RE may be a radio resource region of 1 subcarrier and 1 symbol.

[0181] A bandwidth part (BWP) (which may also be called a partial bandwidth, etc.) may represent a subset of consecutive common resource blocks (RBs) for a certain numerology in a certain carrier. Here, the common RB may be specified by the index of the RB based on the common reference point of the carrier. A PRB is defined in a certain BWP and may be numbered within the BWP.

[0182] The BWP may include a BWP for UL (UL BWP) and a BWP for DL (DL BWP). One or more BWPs may be configured within one carrier for a UE.

[0183] At least one of the configured BWPs may be active, and the UE may not be assumed to transmit and receive a predetermined signal / channel outside the active BWP. Note that in the present disclosure, “cell”, “carrier”, etc. may be read as “BWP”.

[0184] The structures such as the radio frames, subframes, slots, minislots, and symbols described above are merely examples. For example, the number of subframes included in a radio frame, the number of slots per subframe or radio frame, the number of minislots included in a slot, the number of symbols and RBs included in a slot or minislot, the number of subcarriers included in an RB, and the number of symbols, symbol length, cyclic prefix (CP) length, etc. within a TTI can be variously changed.

[0185] In the present disclosure, for example, when an article is added by translation like a, an, and the in English, the present disclosure may include that the noun following these articles is in the plural form.

[0186] In the present disclosure, the term “A and B are different” may mean “A and B are different from each other”. Note that the term may also mean “A and B are different from C respectively”. Terms such as “separate” and “coupled” may also be interpreted in the same way as “different”.

[0187] (Variations of aspects, etc.) Each aspect / embodiment described in the present disclosure may be used alone, in combination, or switched and used during execution. Also, the notification of predetermined information (for example, the notification of “being X”) is not limited to being explicitly performed, and may be performed implicitly (for example, by not performing the notification of the predetermined information).

[0188] As described above in detail, it is obvious to those skilled in the art that the present disclosure is not limited to the embodiments described in the present disclosure. The present disclosure can be implemented as modifications and variations without departing from the spirit and scope of the present disclosure defined by the claims. Therefore, the description of the present disclosure is for illustrative purposes and does not have any limiting meaning for the present disclosure.

Industrial Applicability

[0189] One aspect of the present disclosure is useful for a mobile communication system.

Explanation of Signs

[0190] 10 UE (Terminal) 20 gNB (Base Station) 30A-4, 30B-4 NEF (Network Exposure Function) 510, 610, 710 Transmission Unit 520, 620, 720 Reception Unit 530, 630, 730 Setting Unit 540, 640, 740 Control Unit

Claims

[

1. ] A receiving unit that receives an authorization request for a call to an API (Application Programming Interface) that requires authorization from a user node of a resource owner from a user node of a client; A control unit that identifies the user node of the resource owner based on the authorization request; A transmitting unit that transmits information indicating that the authorization request has been received from the user node of the client to the user node of the resource owner; comprising: The receiving unit receives information indicating that the API call of the user node of the client has been authorized from the user node of the resource owner; The control unit issues an access token based on the authorization of the user node of the resource owner; The transmitting unit transmits the access token to the user node of the client. An authentication server. [

2. ] A user node of a client, A transmitting unit that transmits an authorization request for a call to an API (Application Programming Interface) that requires authorization from a user node of a resource owner to an authentication server; A receiving unit that receives information indicating that the user node of the resource owner has been authorized and an access token from the authentication server; A control unit that calls an API that requires authorization from the user node of the resource owner using the access token. A user node comprising: [

3. ] A user node of a resource owner, A receiving unit that receives from an authentication server information indicating that an authorization request for an API (Application Programming Interface) call has been received from a user node of a client; A control unit that verifies the authorization request and authorizes the user node of the client; A transmitting unit that transmits to the authentication server information indicating that the API call of the user node of the client has been authorized. A user node comprising: [

4. ] The user node of the client notifies the authentication server of an authorization request for a call to an API (Application Programming Interface) that requires authorization from the user node of the resource owner, The authentication server identifies the user node of the resource owner based on the authorization request. The authentication server transmits information indicating that it has received the authorization request from the user node of the client to the user node of the resource owner. The user node of the resource owner verifies the authorization request and authorizes the user node of the client. The user node of the resource owner transmits information indicating that it has authorized the API call of the user node of the client to the authentication server. The authentication server issues an access token based on the authorization of the user node of the resource owner. The authentication server transmits the access token to the user node of the client. The user node of the client uses the access token to call an API that requires authorization from the user node of the resource owner. Communication method.

Citation Information

Patent Citations

  • Making it easier for third parties to batch process requests to request authorization from resource owners for repeated access to resources

    JP2017509936A

  • Information processing system, apparatus, information processing device, information processing method and program

    JP2018156250A

  • Access control system, method for controlling of the same, and program

    JP2019096076A