Communication device, network node device, and authorization control method

The communication device dynamically controls API call authorization by detecting predefined events to revoke authorization, addressing the lack of revocation mechanisms in conventional systems and improving user experience.

JP7819296B2Active Publication Date: 2026-02-24NTT DOCOMO INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024510596
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-28
Publication Date
2026-02-24
Estimated Expiration
2042-03-28

AI Technical Summary

Technical Problem

Conventional technologies lack a mechanism for revoking authorization for authorized API calls in 3GPP core networks, leading to potential unauthorized or unnecessary API calls that can affect user experience.

Method used

A communication device with a control unit to determine conditions for revoking authorization and a transmission unit to send revocation requests to a network node device, allowing dynamic control of API call authorization based on predefined events.

Benefits of technology

Enables flexible and automatic revocation of API call authorization based on dynamic factors like location, application status, and communication quality, preventing unauthorized API calls and enhancing user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007819296000001
    Figure 0007819296000001
  • Figure 0007819296000002
    Figure 0007819296000002
  • Figure 0007819296000003
    Figure 0007819296000003
Patent Text Reader

Abstract

This communication device comprises: a control unit that determines whether an event that satisfies conditions for canceling authorization for API calls has occurred; and a transmission unit that, when it is determined that the event has occurred, transmits a request to cancel the authorization for API calls to a network node device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an API call from an external application to a network node device. [Background technology]

[0002] The 3GPP (3rd Generation Partnership Project) is currently studying a wireless communication system called 5G or NR (New Radio) (hereinafter referred to as "5G" or "NR") in order to achieve even larger system capacity, even faster data transmission speeds, and even lower latency in wireless sections. Various wireless technologies are being studied for 5G to meet the requirements of achieving a throughput of 10 Gbps or more while keeping latency in wireless sections to 1 ms or less.

[0003] In NR, a network architecture is being considered that includes 5GC (5G Core Network), which corresponds to EPC (Evolved Packet Core), which is the core network in the network architecture of LTE (Long Term Evolution), and NG-RAN (Next Generation - Radio Access Network), which corresponds to E-UTRAN (Evolved Universal Terrestrial Radio Access Network), which is the RAN (Radio Access Network) in the network architecture of LTE (e.g., Non-Patent Document 1).

[0004] Furthermore, for example, an architecture is being considered in which the northbound interface between a network exposure function (NEF) and an application function (AF) in a 5G system is configured using the common API framework (CAPIF) (for example, Non-Patent Documents 2 and 3). [Prior art documents] [Non-patent literature]

[0005] [Non-Patent Document 1] 3GPP TS 23.501 V17.2.0(2021-09) [Non-patent document 2] 3GPP TS 29.522 V17.3.0(2021-09) [Non-patent document 3] 3GPP TS 23.222 V17.5.0(2021-06) Summary of the Invention [Problem to be solved by the invention]

[0006] In a 3GPP core network, a network node device opens an API (Application Programming Interface) to external applications, and for example, a third-party application can call the API for the network node device.

[0007] It is also possible to authorize API calls, that is, to allow only authorized API calls and to reject unauthorized API calls.

[0008] However, conventional technologies do not have a mechanism for revoking authorization for an API call that has already been authorized, which means that unnecessary API calls may be made, potentially causing unexpected effects on users.

[0009] The present invention has been made in view of the above points, and has an object to provide a technique that makes it possible to revoke authorization for an authorized API call. [Means for solving the problem]

[0010] According to the disclosed technology, a control unit that determines whether an event that satisfies a condition for revoking authorization for an API call has occurred; a transmission unit that transmits a request to revoke authorization for calling the API to a network node device when it is determined that the event has occurred; A communication device is provided, comprising: [Effects of the Invention]

[0011] The disclosed technology provides a technology that allows for the revocation of authorization for an authorized API call. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram illustrating an example of a communication system. [Figure 2] FIG. 1 is a diagram illustrating an example of a communication system in a roaming environment. [Figure 3] FIG. 10 is a diagram illustrating an example of an API call. [Figure 4] FIG. 1 is a diagram for explaining a problem. [Figure 5] FIG. 1 is a diagram for explaining an outline of a processing procedure according to an embodiment of the present invention. [Figure 6] FIG. 10 is a sequence diagram showing a specific example of a processing procedure according to an embodiment of the present invention. [Figure 7] FIG. 10 is a sequence diagram showing a variation of the processing procedure according to the embodiment of the present invention. [Figure 8] 1 is a diagram illustrating an example of a system according to an embodiment of the present invention. [Figure 9] 1 is a diagram illustrating an example of a system according to an embodiment of the present invention. [Figure 10] 1 is a diagram illustrating an example of a functional configuration of a base station 10 (and a network node device 30, an authorization server 35, and a resource holder client 40) according to an embodiment of the present invention. [Figure 11] FIG. 2 is a diagram illustrating an example of a functional configuration of a terminal 20 (and a resource holder client 40) according to the embodiment of the present invention. [Figure 12] FIG. 1 illustrates an example of a hardware configuration of an apparatus according to an embodiment of the present invention. [Figure 13] 1 is a diagram showing an example of a configuration of a vehicle according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Note that the embodiment described below is an example, and the embodiment to which the present invention is applied is not limited to the following embodiment.

[0014] In operation of the wireless communication system according to the embodiment of the present invention, existing technology is used as appropriate. The existing technology is, for example, existing LTE or existing NR (5G), but is not limited to existing LTE or existing NR.

[0015] Furthermore, in the embodiments of the present invention, "configuring" radio parameters etc. may mean that predetermined values ​​are pre-configured, or that radio parameters notified from the network node device 30 or the terminal 20 are set.

[0016] Fig. 1 is a diagram illustrating an example of a communication system. As shown in Fig. 1, the communication system is composed of a UE, which is a terminal 20, and multiple network node devices 30. Hereinafter, it is assumed that one network node device 30 corresponds to each function, but multiple functions may be realized by one network node device 30, or multiple network node devices 30 may realize one function. Furthermore, the "connection" described below may be a logical connection or a physical connection.

[0017] Furthermore, the base station 10, the terminal 20, and the network node device 30 may all be called "communication devices."

[0018] The RAN (Radio Access Network) is a network node device 30 having a radio access function, which may include a base station 10, and is connected to a UE, an AMF (Access and Mobility Management Function), and a UPF (User plane function). The AMF is a network node device 30 having functions such as terminating the RAN interface, terminating the NAS (Non-Access Stratum), registering management, connecting management, reachability management, and mobility management. The UPF is a network node device 30 having functions such as a PDU (Protocol Data Unit) session point to the outside that interconnects with the DN (Data Network), routing and forwarding of packets, and user plane QoS (Quality of Service) handling. The UPF and the DN constitute a network slice. In the wireless communication network according to the embodiment of the present invention, multiple network slices are constructed.

[0019] The AMF is connected to the UE, RAN, SMF (Session Management function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (Network Repository Function), UDM (Unified Data Management), AUSF (Authentication Server Function), PCF (Policy Control Function), and AF (Application Function). The AMF, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, and AF are network node devices 30 that are connected to each other via interfaces based on their respective services: Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.

[0020] The SMF is a network node device 30 having functions such as session management, UE IP (Internet Protocol) address allocation and management, DHCP (Dynamic Host Configuration Protocol) function, ARP (Address Resolution Protocol) proxy, and roaming function. The NEF is a network node device 30 having a function of notifying other NFs (Network Functions) of capabilities and events. The NSSF is a network node device 30 having functions such as selecting a network slice to which a UE connects, determining permitted Network Slice Selection Assistance Information (NSSAI), determining an NSSAI to be set, and determining an AMF set to which a UE connects. The PCF is a network node device 30 having a function of controlling network policies. The AF is a network node device 30 having a function of controlling application servers. The NRF is a network node device 30 having a function of discovering NF instances that provide services. The UDM is a network node device 30 that manages subscriber data and authentication data. The UDM is connected to a UDR (User Data Repository) that stores the data.

[0021] Fig. 2 is a diagram illustrating an example of a communication system in a roaming environment. As shown in Fig. 2, the network is composed of a UE, which is a terminal 20, and multiple network node devices 30. Hereinafter, it is assumed that one network node device 30 corresponds to each function, but multiple functions may be realized by one network node device 30, or multiple network node devices 30 may realize one function. Furthermore, the "connection" described below may be a logical connection or a physical connection.

[0022] The RAN is a network node device 30 having a radio access function, and is connected to the UE, AMF, and UPF. The AMF is a network node device 30 having functions such as RAN interface termination, NAS termination, registration management, connection management, reachability management, and mobility management. The UPF is a network node device 30 having functions such as a PDU session point to the outside that interconnects with the DN, packet routing and forwarding, and user plane QoS handling. The UPF and DN constitute a network slice. In the wireless communication network according to the embodiment of the present invention, multiple network slices are constructed.

[0023] The AMF is connected to the UE, RAN, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, AF, and SEPP (Security Edge Protection Proxy). The AMF, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, and AF are network node devices 30 that are connected to each other via interfaces based on their respective services: Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.

[0024] The SMF is a network node device 30 having functions such as session management, UE IP address allocation and management, DHCP function, ARP proxy, and roaming function. The NEF is a network node device 30 having a function of notifying other NFs of capabilities and events. The NSSF is a network node device 30 having functions such as selecting a network slice to which a UE connects, determining an allowed NSSAI, determining an NSSAI to be configured, and determining an AMF set to which a UE connects. The PCF is a network node device 30 having a function of controlling network policies. The AF is a network node device 30 having a function of controlling application servers. The NRF is a network node device 30 having a function of discovering NF instances that provide services. The SEPP is a non-transparent proxy that filters control plane messages between PLMNs (Public Land Mobile Networks). The vSEPP shown in FIG. 2 is a SEPP in a visited network, and the hSEPP is a SEPP in a home network.

[0025] As shown in Figure 2, a UE is in a roaming environment connected to a RAN and an AMF in a Visited PLMN (VPLMN). The VPLMN and a Home PLMN (HPLMN) are connected via a vSEPP and an hSEPP. The UE can communicate with a UDM in the HPLMN via the AMF in the VPLMN, for example.

[0026] The operation of this embodiment may be performed in either the configuration shown in Fig. 1 or 2. Furthermore, the operation of this embodiment may be performed in a configuration other than the configurations shown in Fig. 1 and 2.

[0027] In the above-mentioned NEF, APIs (Application Programming Interfaces) that can be called from the AF can be implemented by applying the Common API Framework (CAPIF) architecture. The CAPIF architecture provides a mechanism to support service API operations, for example, allowing an API invoker to discover service APIs provided by an API provider and enabling communication using the service APIs. The CAPIF architecture also has a mechanism to hide the topology of the PLMN trust domain from an API invoker that accesses the service API from outside the PLMN trust domain.

[0028] The API caller application 30A described below may be provided in the AF, and the API providing function (AEF) 30C may be provided in the NEF, but this is not limitative, and the API caller application 30A and the AEF 30C may each be provided in any network node device 30. The AEF 30C may be provided in the base station 10. Furthermore, the API caller application 30A may be provided in the terminal 20.

[0029] Furthermore, a resource holder client 40 (resource owner) described later may be a network node device 30, a terminal 20, a base station 10, or any other device.

[0030] 3 is a diagram showing an example of an API call. In the 3GPP core network, APIs are open to external applications, and third-party applications can call the APIs in the network node device 30. When an API is called, a CAPIF Core Function (also referred to as CCF) in the core network authenticates and / or authorizes the calling application 30A (API invoker) and manages which applications can call the API.

[0031] As shown in Figure 3, an application 30A that calls an API is pre-registered with a CAPIF core function 30B using the CAPIF-API. The CAPIF core function 30B authenticates and authorizes the third-party application 30A. Also, as shown in Figure 3, an API providing function (also referred to as an API Exposing Function, AEF) 30C exposes a service API to the authenticated and authorized application 30A, and the application 30A that calls the API can use the functions of the API by calling the API.

[0032] The APF (API Publishing Function) 30D has a function of publishing service API information of API providers to the CAPIF core function 30B. The AMF (API Management Function) 30E has various management functions related to API calls.

[0033] Furthermore, CAPIF can be extended so that the resource holder client 40 can authorize the API call source application 30A to make an API call via the authorization server 35. The resource holder client 40 may also be called a network node device, a terminal, a resource holder client device, a resource owner, a communication device, etc.

[0034] (About the assignment) The resource holder client 40 can grant authorization for an API call request from the API caller application 30A (API invoker), but once authorization has been granted, there is a possibility that the API caller application 30A will request an additional API call unless the authorization is revoked. The following describes the issues that arise from the fact that additional API calls are possible unless the authorization is revoked.

[0035] For example, suppose that a resource holder client 40 grants permission to call a QoS change API for temporary use in a competitive game. In this case, if the permission is forgotten to be revoked after the game ends, the API caller application 30A (API invoker) can continue to freely change the QoS of the resource holder client 40. It is undesirable that settings related to the end user's communication quality, such as QoS, be changed without the permission of the end user (resource holder).

[0036] It is desirable that the resource holder client 40 be able to revoke authorization at an appropriate time for operations that affect the end user's communication quality, such as changing the QoS, as well as operations that affect privacy, such as obtaining location information, and operations that involve billing, such as charges for each API.

[0037] Fig. 4 is a diagram for explaining the above situation. Note that the configuration of Fig. 4 itself shows the configuration of a communication system according to an embodiment of the present invention, and each device shown in the figure is capable of performing data communication with other devices via a network.

[0038] 4, an API caller application 30A is authorized to call a certain API. Specifically, for example, an access token for calling the API is issued by an authorization server 35. A database 50 stores information related to authorization.

[0039] By using the access token, the API caller application 30A can call the API to the AEF 30C as long as the authorization is not revoked, as long as the access token is within its validity period. This causes the above-mentioned problem, so as shown in Figure 4, it is necessary to revoke the authorization when it is no longer necessary.

[0040] An example of operation according to this embodiment to solve this problem will be described below.

[0041] (Configuration and Operation Example According to the Embodiment) In this embodiment, as shown in FIG. 5, in a system configuration having an authorization server 35, a resource holder client 40, and a database 50, the above-mentioned authorization can be revoked.

[0042] The authorization server 35 is a type of network node device. The authorization server 35 may include the functions of the AEF 30C, may include the functions of the CAPIF core function 30B, may be a network node device that includes both the AEF 30C and the CAPIF core function 30B, or may be a network node device that is neither the AEF 30C nor the CAPIF core function 30B.

[0043] The database 50 is a device that holds authorization information, and is a type of network node device. The database 50 may be provided outside the authorization server 35, or may be provided inside the authorization server 35. The authorization information held by the database 50 is, for example, information that associates an access token (character string), an API ID, and information indicating whether or not the call to the API is authorized. This information is registered in the database 50 by the authorization server 35.

[0044] An example of operation will be described with reference to FIG.

[0045] First, as a prerequisite, the resource holder client 40 has granted authorization for a specific API call to the API caller application 30A. Specifically, in this state, the database 50 stores an access token, the ID of the specific API, and information indicating that the call to the specific API is authorized, and the API caller application 30A holds this access token.

[0046] As a preliminary preparation, conditions for canceling API call authorization are set in advance in the resource holder client 40.

[0047] As shown in FIG. 5, when the resource holder client 40 detects the occurrence of an event that satisfies the above conditions, it transmits an authorization revocation request to the authorization server 35.

[0048] The authorization server 35 that receives the authorization revocation request authenticates the resource holder client 40, and if the authentication (specifically, verification of authentication information) is successful, the authorization server 35 invalidates the authorization for the given API call.

[0049] For example, the authorization server 35 deletes the access token of the corresponding entry in the database 50. That is, if the entry information is {access token, API ID, call allowed}, the authorization server 35 deletes "{access token, API ID, call allowed}".

[0050] Alternatively, the authorization server 35 may revoke authorization by changing {access token, API ID, callable} to {access token, API ID, call unavailable}. In other words, authorization may be revoked by making the access token unusable.

[0051] <Conditions for revocation of authorization> Conditions that trigger transmission of an authorization revocation request include, for example, the following conditions (1) to (5): Note that the following conditions (1) to (5) are all examples, and the conditions that trigger transmission of an authorization revocation request are not limited to the following conditions (1) to (5).

[0052] (1) App status For example, the resource holder client 40 may revoke the authorization to call the QoS change API when the competitive game application is terminated, and then may reauthorize the QoS change API when the competitive game application is started.

[0053] (2) Time For example, the resource holder client 40 revokes the authorization for an API call when a preset time has elapsed since the time the API call was authorized.

[0054] Also, for example, the resource holder client 40 may revoke the API call authorization at a preset time.

[0055] (3) Location information For example, when the resource holder client 40 detects that it has moved to a preset location (position) (for example, moved outside of Tokyo), it revokes the authorization to call the API.

[0056] The resource holder client 40 may determine that it is in a specific location using location information acquired by a GPS function, may determine based on the cell ID of the cell in which it is located, may determine from an image acquired by a camera it holds, may determine from sound acquired by a microphone it holds, or may determine by some other method.

[0057] (4) Communication quality For example, the resource holder client 40 measures the communication delay to a specific server, and revokes the authorization to call the API when it detects that the delay value exceeds a preset reference value.

[0058] Furthermore, the resource holder client 40 and an external server may cooperate to detect an event (an event indicating that a condition has been satisfied).

[0059] For example, if the condition is that "the communication delay to a certain server exceeds a threshold," it is possible to check whether the condition is met by measuring the round-trip time it takes for a resource holder client 40 to send a packet to a specific server and for the packet to return to the resource holder client 40.

[0060] (5) Wireless quality For example, when the resource holder client 40 detects that the strength of the radio waves received from the base station has been below a preset reference value for a preset period of time, the resource holder client 40 revokes the authorization to call the API.

[0061] In the above examples (1) to (5), the resource holder client 40 itself holds the conditions for revoking authorization and determines whether an event that satisfies the conditions has occurred, but this is just an example. Another entity (called the external server 60) outside the resource holder client 40 may hold the conditions for revoking authorization and determine whether an event that satisfies the conditions has occurred.

[0062] When the external server 60 detects that an event that satisfies the conditions for revoking authorization has occurred, for example, the external server 60 notifies the resource holder client 40 that an event that satisfies the conditions for revoking authorization has occurred. Thereafter, as in the process described above, the resource holder client 40 transmits a revocation request to the authorization server 35. Alternatively, when the external server 60 detects that an event that satisfies the conditions for revoking authorization has occurred, the external server 60 itself may transmit a revocation request to the authorization server 35.

[0063] <Multiple APIs> If there are multiple authorized APIs, the resource holder client 40 holds the conditions for each API, and when it detects that the conditions corresponding to a certain API have been met, it sends a request to revoke authorization for that API.

[0064] In this case, the resource holder client 40 holds, as conditions, information (table) in the format of, for example, "(API_1, condition 1), (API_2, condition 2), . . . , (API_n, condition n)."

[0065] <Regarding reauthorization> It is also possible to re-authorize an API call after revoking it as described above. In this case, for example, the resource holder client 40 transmits an API call authorization request to the authorization server 35.

[0066] Upon receiving the authorization request, the authorization server 35 authenticates the resource holder client 40, and if the authentication (specifically, verification of authentication information) is successful, the authorization server 35 validates the authorization for the API call. For example, the authorization server 35 changes the corresponding entry in the database 50 from {access token, API ID, call not permitted} to {access token, API ID, call permitted}. Furthermore, if the entry has been deleted, the authorization server 35 generates a new entry, i.e., {access token, API ID, call permitted}, and issues the access token to the API caller application 30A.

[0067] When re-authorization is performed, similar to the cancellation described above, the resource holder client 40 may send an API call authorization request to the authorization server 35 when it detects the occurrence of an event that satisfies the conditions previously set as the re-authorization conditions.

[0068] (Example sequence) Next, a more detailed example of the operation of this embodiment will be described with reference to the sequence diagram in Fig. 6. As a prerequisite for the following operation, it is assumed that a call to a certain API has been authorized. Furthermore, the resource holder client 40 holds a condition for requesting the revocation of authorization.

[0069] Tokens include access tokens and refresh tokens, and hereinafter these will be collectively referred to as "tokens." Tokens may also be called "access permission information."

[0070] As shown in S101, the API caller application 30A holds a token, and information about the token is stored in the database 50. The information about the token is, for example, information such as {token, API ID, callable}.

[0071] In S102, the resource holder client 40 detects an event that satisfies a preset condition.

[0072] In S103, the resource holder client 40 transmits an authorization revocation request to the authorization server 35. This request message includes, for example, the ID of the target API and information indicating that it is a revocation request.

[0073] In S104, the authorization server 35 authenticates the resource holder client 40. Any authentication method may be used, and for example, authentication may be performed by the authorization server 35 requesting an ID / password from the resource holder client 40, and the resource holder client 40 transmitting the ID / password to the authorization server 35. Here, it is assumed that the authentication is successful.

[0074] In S105, the authorization server 35 transmits a token deletion request to the database 50. This request message includes, for example, the ID of the target API. In S106, the database 50 deletes the token corresponding to the target API. Alternatively, as described above, the token may not be deleted and may be managed as "uncallable."

[0075] In S107, the database 50 returns a deletion response to the authorization server 35. In S108, the authorization server 35 returns a response to the resource holder client 40 indicating that the call authorization for the target API has been revoked.

[0076] Thereafter, in S109, the API call source application 30A uses an old token (a token that has been deleted or is no longer callable) to send a call request for the target API to the AEF 30C. The AEF 30C accesses the database 50 and attempts to reference information about the token, but fails to do so. Alternatively, the AEF 30C checks the information about the token and determines that it is "uncallable." In S111, the AEF 30C sends an API call denial message to the API call source application 30A.

[0077] <Sequence Variations> As described above, the external server 60 may detect an event that satisfies the cancellation condition. An example of a sequence in which the external server 60 detects an event that satisfies the cancellation condition is shown in Fig. 7. In the following, the same parts as in Fig. 6 will be omitted or simply explained.

[0078] 7, communication is possible between the resource holder client 40 and the external server 60, and the external server 60 can obtain, at any time, information required for detecting an event that satisfies the cancellation condition from the resource holder client 40. Note that if an event that satisfies the cancellation condition can be detected without using information from the resource holder client 40, it is not necessary to obtain information from the resource holder client 40.

[0079] In S102, the external server 60 detects an event that satisfies a preset condition.

[0080] In S103, the external server 60 transmits an authorization revocation request to the authorization server 35. This request message includes, for example, information indicating the resource holder client 40 (such as an IP address), the ID of the target API, and information indicating that this is a revocation request. In S104, the authorization server 35 authenticates the resource holder client 40.

[0081] After steps S105 to S107, in step S108 the authorization server 35 returns a response indicating that the call authorization for the target API has been revoked to the external server 60. After step S108, the external server may notify the API caller application 30A of information indicating that the call authorization for the target API has been revoked.

[0082] (Example of a specific system configuration) Fig. 8 shows a specific example of the configuration of a system according to this embodiment, assuming a 5G system. Fig. 8 shows, as an example, a case where UE (terminal) 20 is a resource holder client 40, and CCF 30B is an authorization server 35. Database 50 may also be included in CCF 30B.

[0083] 8, the CCF 30B including the CAPIF-API, the AEF 30C including the service API, the APF (API Publishing Function) 30D, the AMF (API Management Function) 30E, the UE 20 (e.g., resource holder client 40), the core network, and the access network belong to the PLMN (PLMN Trust domain), which is a trusted domain. On the other hand, an API caller application 30A (e.g., a game server) exists outside the PLMN.

[0084] As shown in FIG. 8, the UE 20 may be connected to an API caller application 30A, an AEF 30C, and a CCF 30B via an access network and a core network.

[0085] Fig. 9 is a diagram showing another example of a system configuration. As shown in Fig. 9, the PLMN, which is a trusted domain, includes the CCF 30B including the CAPIF-API, the AEF 30C including the service API, the APF 30D, the AMF 30E, the UE 20-1, the UE 20-2, the core network, and the access network. The UE 20-1 includes, for example, an application that is the source of an API call request. The UE 20-2 is, for example, a resource holder client 40. Note that the application and resource holder client functions may be provided in the same device (terminal, etc.).

[0086] 9, the UE 20-1 may be connected to the CCF 30B and the AEF 30C via the access network and the core network, and the UE 20-2 may be connected to the CCF 30B and the AEF 30C via the access network and the core network.

[0087] 8 and 9 show examples of system configurations, and the present invention is not limited to these. For example, the AEF 30C, the APF 30D, and the AMF 30E may be outside the trusted PLMN domain.

[0088] (Effects of the embodiment) The technology described above allows for the conditions for revoking authorization to be set in advance for the resource holder client 40 (terminal held by the resource holder), thereby preventing API calls from being inadvertently allowed.

[0089] The existing OAuth 2.0 specifications allow the token itself to have an expiration date, but the technology according to this embodiment goes beyond that and makes it possible to more flexibly control the revocation of authorization based on dynamic information such as the device's location information, the application status, and real-time communication quality.

[0090] This allows API calls to be permitted only under certain conditions, and to be canceled in other cases, without the device user having to do it manually, but automatically.

[0091] (Device configuration) Next, a description will be given of examples of functional configurations of the base station 10, network node device 30, resource holder client 40, database 50, and terminal 20 that perform the processes and operations described above. The authorization server 35, database 50, and external server 60 are all types of network node device 30. The authorization server 35 may have the database 50 installed inside.

[0092] The base station 10, the network node device 30, the resource holder client 40, the database 50, the external server 60, and the terminal 20 may all be called "communication devices."

[0093] <Base Station 10 and Network Node Device 30> Fig. 10 is a diagram showing an example of the functional configuration of base station 10. As shown in Fig. 10, base station 10 has a transmitting unit 110, a receiving unit 120, a setting unit 130, and a control unit 140. The functional configuration shown in Fig. 10 is merely an example. The functional divisions and names of the functional units may be any names as long as they can perform the operations according to the embodiment of the present invention.

[0094] The network node device 30 (for example, the network node device 30 having the function of the AEF 30C, the authorization server 35, the database 50, the external server 60, etc.) may have the same functional configuration as the base station 10 shown in FIG. 10. Furthermore, a network node device 30 having a plurality of different functions in the system architecture may be composed of a plurality of network node devices 30 separated by function. Furthermore, the network node device 30 is not limited to a network node device existing in a core network or an access network, but may correspond to a network node device belonging to a PLMN domain. Furthermore, the resource holder client 40 may also have the functional configuration shown in FIG. 10.

[0095] The transmitter 110 includes a function of generating a signal to be transmitted to the terminal 20 or another network node device 30, and transmitting the signal by wire or wirelessly. The receiver 120 includes a function of receiving various signals transmitted from the terminal 20 or another network node device 30, and acquiring, for example, information of a higher layer from the received signal.

[0096] The setting unit 130 stores various setting information in a storage device and reads it out from the storage device as needed.

[0097] The control unit 140 controls the entire device. The function unit in the control unit 140 related to signal transmission may be included in the transmitting unit 110, and the function unit in the control unit 140 related to signal reception may be included in the receiving unit 120.

[0098] <Terminal 20> FIG. 11 is a diagram showing an example of the functional configuration of the terminal 20. As shown in FIG. 11, the terminal 20 has a transmitting unit 210, a receiving unit 220, a setting unit 230, and a control unit 240. The functional configuration shown in FIG. 11 is merely an example. The names of the functional divisions and functional units may be any as long as they can perform the operations related to the embodiment of the present invention. The terminal 20 may function as a resource holder client 40.

[0099] The transmitter 210 creates a transmission signal from the transmission data and transmits the transmission signal wirelessly. The receiver 220 receives various signals wirelessly and acquires higher layer signals from the received physical layer signals. The receiver 220 also has a function of receiving NR-PSS, NR-SSS, NR-PBCH, DL / UL control signals, reference signals, etc. transmitted from the base station 10 or the network node device 30.

[0100] The setting unit 230 stores various setting information received from the base station 10 or the network node device 30 by the receiving unit 220 in a storage device, and reads it from the storage device as needed. The storage device also stores conditions for revoking authorization.

[0101] The control unit 240 performs, for example, processing related to connection control to the network and network slices. A functional unit related to signal transmission in the control unit 240 may be included in the transmitting unit 210, and a functional unit related to signal reception in the control unit 240 may be included in the receiving unit 220. When the terminal 20 functions as the resource holder client 40, the terminal 20 may be provided with a display capable of input and output, similar to a smartphone or the like.

[0102] <Additional Notes> This embodiment provides at least a communication device, a network node device, and an authorization control method as shown in Supplementary Items 1 to 6 below. (Additional note 1) a control unit that determines whether an event that satisfies a condition for revoking authorization for an API call has occurred; a transmission unit that transmits a request to revoke authorization for calling the API to a network node device when it is determined that the event has occurred; A communication device comprising: (Additional note 2) The condition is at least one of a plurality of conditions including a condition related to an application state, a condition related to time, a condition related to a location, a condition related to communication quality, and a condition related to wireless quality. Item 1. A communication device according to item 1. (Additional note 3) a receiving unit that receives a request to revoke authorization for an API call from a communication device that has detected an event that satisfies a condition for revoking authorization for the API call; a control unit that executes a process of canceling authorization for calling the API based on the request; A network node device comprising: (Additional note 4) The control unit deletes the access permission information used to call the API from a database, or makes the access permission information unusable. A network node device according to supplementary item 3. (Additional note 5) Determine whether an event has occurred that satisfies the conditions for revoking authorization for an API call; When it is determined that the event has occurred, transmitting a request to the network node device to revoke authorization for calling the API. An authorization control method performed by a communication device. (Additional note 6) receiving a request to revoke authorization for an API call from a communication device that has detected an event that satisfies a condition for revoking authorization for the API call; Based on the request, execute a process to revoke authorization for the call to the API. An authorization control method executed by a network node device.

[0103] All of Supplementary Items 1 to 6 provide a technology that enables revoking authorization for an API call that has been authorized. Supplementary Item 2 enables determination based on various conditions. Supplementary Item 4 enables appropriate processing to revoke authorization for an API call.

[0104] (Hardware configuration) The block diagrams (FIGS. 10 and 11) used to explain the above embodiments show functional blocks. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wires, wirelessly, etc.) and these multiple devices. The functional block may be realized by combining the single device or the multiple devices with software.

[0105] Functions include, but are not limited to, judgment, determination, judgment, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, resolution, selection, election, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocation, mapping, and assignment. For example, a functional block (component) that performs transmission is called a transmitting unit or transmitter. As mentioned above, there are no particular limitations on how these functions are implemented.

[0106] For example, the network node device 30, the terminal 20, etc. according to an embodiment of the present disclosure may function as a computer that performs processing of the wireless communication method of the present disclosure. Fig. 12 is a diagram illustrating an example of the hardware configuration of the base station 10, the terminal 20, the network node device 30, the authorization server 35, the resource holder client 40, the external server 60, etc. according to an embodiment of the present disclosure. Each of the above-mentioned devices may be physically configured as a computer device including a processor 1001, a storage device 1002, an auxiliary storage device 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, etc.

[0107] In the following description, the term "apparatus" can be read as a circuit, a device, a unit, etc. The hardware configurations of the base station 10, the terminal 20, the network node apparatus 30, the authorization server 35, the resource holder client 40, etc. may be configured to include one or more of the apparatuses shown in the drawings, or may be configured to exclude some of the apparatuses.

[0108] Each function in the base station 10, terminal 20, network node device 30, authorization server 35, resource holder client 40, external server 60, etc. is realized by loading specified software (programs) onto hardware such as processor 1001, memory device 1002, etc., so that the processor 1001 performs calculations, controls communication by the communication device 1004, and controls at least one of reading and writing data in the memory device 1002 and auxiliary memory device 1003.

[0109] The processor 1001 controls the entire computer by running, for example, an operating system. The processor 1001 may be configured as a central processing unit (CPU) including an interface with peripheral devices, a control device, an arithmetic unit, a register, etc. For example, the above-mentioned control unit 140, control unit 240, etc. may be realized by the processor 1001.

[0110] The processor 1001 also loads programs (program codes), software modules, data, etc. from at least one of the auxiliary storage device 1003 and the communication device 1004 into the storage device 1002 and executes various processes in accordance with the programs. The programs used are those that cause a computer to execute at least some of the operations described in the above-described embodiments. For example, the control unit 140 shown in FIG. 10 may be implemented by a control program stored in the storage device 1002 and executed by the processor 1001. Furthermore, for example, the control unit 240 shown in FIG. 11 may be implemented by a control program stored in the storage device 1002 and executed by the processor 1001. While the above-described various processes have been described as being executed by one processor 1001, they may also be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may be implemented by one or more chips. The programs may also be transmitted from a network via a telecommunications line.

[0111] The storage device 1002 is a computer-readable recording medium and may be configured, for example, by at least one of a read-only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a random access memory (RAM), etc. The storage device 1002 may also be called a register, a cache, a main memory, etc. The storage device 1002 can store executable programs (program codes), software modules, etc. for implementing a communication method according to an embodiment of the present disclosure.

[0112] The secondary storage device 1003 is a computer-readable recording medium, and may be, for example, at least one of an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disk, a digital versatile disk, a Blu-ray disc), a smart card, a flash memory (e.g., a card, a stick, a key drive), a floppy disk, a magnetic strip, etc. The above-mentioned storage medium may be, for example, a database, a server, or other suitable medium including at least one of the storage device 1002 and the secondary storage device 1003.

[0113] The communication device 1004 is hardware (transmission / reception device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as, for example, a network device, a network controller, a network card, or a communication module. The communication device 1004 may be configured to include a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc. to realize at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, a transmission / reception antenna, an amplifier unit, a transmission / reception unit, a transmission path interface, etc. may be realized by the communication device 1004. The transmission / reception unit may be implemented as a transmission unit and a reception unit that are physically or logically separated.

[0114] The input device 1005 is an input device (for example, a keyboard, a mouse, a microphone, a switch, a button, a sensor, etc.) that receives input from the outside. The output device 1006 is an output device (for example, a display, a speaker, an LED lamp, etc.) that performs output to the outside. Note that the input device 1005 and the output device 1006 may be integrated into one device (for example, a touch panel).

[0115] Furthermore, each device such as the processor 1001 and the storage device 1002 is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus, or may be configured using different buses between each device.

[0116] Furthermore, the base station 10, the terminal 20, the network node device 30, the authorization server 35, the resource holder client 40, the external server 35, etc. may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), a field programmable gate array (FPGA), etc., and some or all of the functional blocks may be realized by the hardware. For example, the processor 1001 may be implemented using at least one of these pieces of hardware.

[0117] Furthermore, the vehicle 2001 may include each of the terminal 20, the base station 10, the network node device 30, the authorization server 35, the resource holder client 40, and the external server 60, or any one or more of these. Fig. 13 shows a configuration example of the vehicle 2001. As shown in Fig. 13, the vehicle 2001 includes a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a shift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021 to 2029, an information service unit 2012, and a communication module 2013. Each aspect / embodiment described in the present disclosure may be applied to a communication device mounted on the vehicle 2001, for example, the communication module 2013. All or any of the functions of the terminal 20, the base station 10, the network node device 30, the authorization server 35, and the resource holder client 40 may be incorporated into the communication module 2013.

[0118] The drive unit 2002 is configured, for example, by an engine, a motor, or a hybrid of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also called a handle), and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel operated by the user.

[0119] The electronic control unit 2010 is composed of a microprocessor 2031, a memory (ROM, RAM) 2032, and a communication port (IO port) 2033. Signals are input to the electronic control unit 2010 from various sensors 2021 to 2029 provided in the vehicle 2001. The electronic control unit 2010 may also be called an ECU (Electronic Control Unit).

[0120] The signals from the various sensors 2021 to 2029 include a current signal from a current sensor 2021 that senses the current of the motor, a rotation speed signal of the front and rear wheels obtained by a rotation speed sensor 2022, an air pressure signal of the front and rear wheels obtained by an air pressure sensor 2023, a vehicle speed signal obtained by a vehicle speed sensor 2024, an acceleration signal obtained by an acceleration sensor 2025, an accelerator pedal depression amount signal obtained by an accelerator pedal sensor 2029, a brake pedal depression amount signal obtained by a brake pedal sensor 2026, a shift lever operation signal obtained by a shift lever sensor 2027, and a detection signal for detecting obstacles, vehicles, pedestrians, etc. obtained by an object detection sensor 2028.

[0121] The information service unit 2012 is composed of various devices, such as a car navigation system, an audio system, speakers, a television, and a radio, for providing various types of information such as driving information, traffic information, and entertainment information, and one or more ECUs for controlling these devices. The information service unit 2012 uses information obtained from external devices via the communication module 2013, etc., to provide various types of multimedia information and multimedia services to the occupants of the vehicle 2001.

[0122] The driving assistance system unit 2030 is composed of various devices that provide functions for preventing accidents and reducing the driver's driving burden, such as a millimeter-wave radar, a LiDAR (Light Detection and Ranging), a camera, a positioning locator (e.g., GNSS, etc.), map information (e.g., high-definition (HD) map, autonomous vehicle (AV) map, etc.), a gyro system (e.g., an IMU (Inertial Measurement Unit), an INS (Inertial Navigation System), etc.), an AI (Artificial Intelligence) chip, and an AI processor, as well as one or more ECUs that control these devices. The driving assistance system unit 2030 also transmits and receives various information via the communication module 2013 to realize the driving assistance function or the autonomous driving function.

[0123] The communication module 2013 can communicate with the microprocessor 2031 and components of the vehicle 2001 via the communication port. For example, the communication module 2013 transmits and receives data via the communication port 2033 to and from the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axle 2009, microprocessor 2031 and memory (ROM, RAM) 2032 in the electronic control unit 2010, and sensors 2021 to 29, which are provided in the vehicle 2001.

[0124] The communication module 2013 is a communication device that can be controlled by the microprocessor 2031 of the electronic control unit 2010 and can communicate with an external device. For example, it transmits and receives various information to and from the external device via wireless communication. The communication module 2013 may be located either inside or outside the electronic control unit 2010. The external device may be, for example, a base station, a mobile station, or the like.

[0125] The communication module 2013 transmits, via wireless communication to an external device, a current signal from the current sensor that is input to the electronic control unit 2010. The communication module 2013 also transmits, via wireless communication to an external device, the rotation speed signals of the front and rear wheels acquired by a rotation speed sensor 2022, the air pressure signals of the front and rear wheels acquired by an air pressure sensor 2023, the vehicle speed signal acquired by a vehicle speed sensor 2024, the acceleration signal acquired by an acceleration sensor 2025, the accelerator pedal depression amount signal acquired by an accelerator pedal sensor 2029, the brake pedal depression amount signal acquired by a brake pedal sensor 2026, the shift lever operation signal acquired by a shift lever sensor 2027, and the detection signals for detecting obstacles, vehicles, pedestrians, etc. acquired by an object detection sensor 2028, which are input to the electronic control unit 2010.

[0126] The communication module 2013 receives various information (traffic information, traffic signal information, inter-vehicle information, etc.) transmitted from external devices and displays it on an information service unit 2012 provided in the vehicle 2001. The communication module 2013 also stores the various information received from the external devices in a memory 2032 that can be used by the microprocessor 2031. Based on the information stored in the memory 2032, the microprocessor 2031 may control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axle 2009, sensors 2021 to 2029, etc. provided in the vehicle 2001.

[0127] (Supplementary explanation of the embodiment) Although the embodiments of the present invention have been described above, the disclosed invention is not limited to such embodiments, and those skilled in the art will understand various modifications, alterations, alternatives, and substitutions. While specific numerical examples have been used to facilitate understanding of the invention, unless otherwise specified, these numerical values ​​are merely examples, and any appropriate values ​​may be used. The division of items in the above description is not essential to the present invention; items described in two or more items may be used in combination as needed, and items described in one item may apply to items described in another item (as long as there is no contradiction). Boundaries between functional units or processing units in a functional block diagram do not necessarily correspond to physical component boundaries. The operations of multiple functional units may be performed by a single physical component, or the operations of one functional unit may be performed by multiple physical components. The order of the processing procedures described in the embodiments may be reversed as long as there is no contradiction. For convenience of describing the processes, the base station 10, terminal 20, network node device 30, authorization server 35, resource holder client 40, etc. have been described using functional block diagrams, but such devices may be realized by hardware, software, or a combination thereof. Software operated by a processor included in the base station 10, terminal 20, network node device 30, authorization server 35, resource holder client 40, etc. according to the embodiments of the present invention may each be stored in any appropriate storage medium, such as random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, register, hard disk (HDD), removable disk, CD-ROM, database, server, etc.

[0128] Furthermore, the notification of information is not limited to the aspects / embodiments described in the present disclosure, and may be performed using other methods. For example, the notification of information may be performed by physical layer signaling (e.g., Downlink Control Information (DCI), Uplink Control Information (UCI)), higher layer signaling (e.g., Radio Resource Control (RRC) signaling, Medium Access Control (MAC) signaling), broadcast information (Master Information Block (MIB), System Information Block (SIB)), other signals, or a combination thereof. Furthermore, the RRC signaling may be referred to as an RRC message, and may be, for example, an RRC Connection Setup message, an RRC Connection Reconfiguration message, or the like.

[0129] Each aspect / embodiment described in the present disclosure may be applied to at least one of systems using LTE (Long Term Evolution), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), FRA (Future Radio Access), NR (New Radio), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark), IEEE 802.20, UWB (Ultra-Wideband), Bluetooth (registered trademark), or other appropriate systems, and next-generation systems extended based on these. Furthermore, a combination of multiple systems (e.g., a combination of at least one of LTE and LTE-A with 5G, etc.) may also be applied.

[0130] The order of the procedures, sequences, flowcharts, etc. of each aspect / embodiment described herein may be changed unless it is consistent. For example, the methods described in this disclosure present elements of various steps using an example order and are not limited to the particular order presented.

[0131] In this specification, a specific operation that is described as being performed by the base station 10 may also be performed by its upper node in some cases. In a network consisting of one or more network nodes having the base station 10, it is clear that various operations performed for communication with the terminal 20 may be performed by at least one of the base station 10 and another network node other than the base station 10 (such as, but not limited to, an MME or an S-GW). Although the above example illustrates a case where there is one other network node other than the base station 10, the other network node may be a combination of multiple other network nodes (such as an MME and an S-GW).

[0132] The information or signals described in the present disclosure may be output from a higher layer (or a lower layer) to a lower layer (or a higher layer), or may be input / output via multiple network nodes.

[0133] Input and output information may be stored in a specific location (for example, memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be sent to another device.

[0134] In the present disclosure, the determination may be made based on a value represented by one bit (0 or 1), a Boolean value (true or false), or a numerical comparison (e.g., comparison with a predetermined value).

[0135] Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc., whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.

[0136] Software, instructions, information, etc. may also be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then these wired and / or wireless technologies are included within the definition of transmission media.

[0137] The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.

[0138] Note that terms explained in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings. For example, at least one of a channel and a symbol may be a signal (signaling). Furthermore, a signal may be a message. Furthermore, a component carrier (CC) may be called a carrier frequency, a cell, a frequency carrier, etc.

[0139] As used in this disclosure, the terms "system" and "network" are used interchangeably.

[0140] Furthermore, the information, parameters, etc. described in the present disclosure may be expressed using absolute values, may be expressed using relative values ​​from a predetermined value, or may be expressed using other corresponding information. For example, a radio resource may be indicated by an index.

[0141] The names used for the above-described parameters are not intended to be limiting in any way. Furthermore, the mathematical expressions using these parameters may differ from those explicitly disclosed in this disclosure. The various channels (e.g., PUCCH, PDCCH, etc.) and information elements may be identified by any suitable names, and therefore the various names assigned to these various channels and information elements are not intended to be limiting in any way.

[0142] In this disclosure, terms such as "base station (BS)," "radio base station," "base station," "fixed station," "NodeB," "eNodeB (eNB)," "gNodeB (gNB)," "access point," "transmission point," "reception point," "transmission / reception point," "cell," "sector," "cell group," "carrier," and "component carrier" may be used interchangeably. Base stations may also be referred to by terms such as macrocell, small cell, femtocell, and picocell.

[0143] A base station can accommodate one or more (e.g., three) cells. When a base station accommodates multiple cells, the overall coverage area of ​​the base station can be divided into multiple smaller areas, and each smaller area can be provided with communication service by a base station subsystem (e.g., a small indoor base station (RRH: Remote Radio Head)). The term "cell" or "sector" refers to a part or the entire coverage area of ​​a base station and / or base station subsystem that provides communication service within this coverage.

[0144] In this disclosure, the terms "Mobile Station (MS)," "user terminal," "User Equipment (UE)," "terminal," etc. may be used interchangeably.

[0145] A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other suitable terminology.

[0146] At least one of the base station and the mobile station may be called a transmitting device, a receiving device, a communication device, etc. At least one of the base station and the mobile station may be a device mounted on a mobile body, or the mobile body itself. The mobile body may be a vehicle (e.g., a car, an airplane, etc.), an unmanned mobile body (e.g., a drone, an autonomous vehicle, etc.), or a robot (manned or unmanned). At least one of the base station and the mobile station may also include devices that do not necessarily move during communication operations. For example, at least one of the base station and the mobile station may be an IoT (Internet of Things) device such as a sensor.

[0147] Furthermore, a base station in the present disclosure may be read as a terminal. For example, the aspects / embodiments of the present disclosure may be applied to a configuration in which communication between a base station and a terminal is replaced with communication between a plurality of terminals 20 (which may be called, for example, D2D (Device-to-Device) or V2X (Vehicle-to-Everything)). In this case, the terminal 20 may be configured to have the functions of the base station 10 described above. Furthermore, terms such as "uplink" and "downlink" may be read as terms corresponding to communication between terminals (for example, "side"). For example, terms such as an uplink channel and a downlink channel may be read as a side channel.

[0148] Similarly, the term "terminal" in the present disclosure may be read as "base station." In this case, the base station may be configured to have the functions of the terminal described above.

[0149] As used in this disclosure, the terms "determining" and "determining" may encompass a wide variety of actions. "Determining" and "determining" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiring (e.g., searching in a table, database, or other data structure), ascertaining, and the like. "Determining" and "determining" may also include receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, accessing (e.g., accessing data in memory), and the like. Furthermore, "judgment" and "decision" can include regarding resolving, selecting, choosing, establishing, comparing, etc. as having been "judged" or "decided." In other words, "judgment" and "decision" can include regarding some action as having been "judged" or "decided." Furthermore, "judgment (decision)" can be interpreted as "assuming," "expecting," "considering," etc.

[0150] The terms "connected," "coupled," or any variation thereof, refer to any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be physical, logical, or a combination thereof. For example, "connected" may be read as "access." As used in this disclosure, two elements may be considered to be "connected" or "coupled" to each other using one or more wires, cables, and / or printed electrical connections, as well as electromagnetic energy having wavelengths in the radio frequency range, microwave range, and optical (both visible and invisible) range, as some non-limiting and non-exhaustive examples.

[0151] The reference signal may be abbreviated as RS (Reference Signal) or may be called a pilot depending on the applicable standard.

[0152] As used in this disclosure, the phrase "based on" does not mean "based only on," unless expressly stated otherwise. In other words, the phrase "based on" means both "based only on" and "based at least on."

[0153] As used in this disclosure, any reference to an element using a designation such as "first," "second," etc. does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Thus, a reference to a first and a second element does not imply that only two elements may be employed or that the first element must in some way precede the second element.

[0154] The "means" in the configuration of each of the above devices may be replaced with "part," "circuit," "device," etc.

[0155] When used in this disclosure, the terms "include," "including," and variations thereof are intended to be inclusive, similar to the term "comprising." Furthermore, when used in this disclosure, the term "or" is not intended to be an exclusive or.

[0156] A radio frame may be composed of one or more frames in the time domain. Each of the one or more frames in the time domain may be called a subframe. A subframe may further be composed of one or more slots in the time domain. A subframe may have a fixed time length (e.g., 1 ms) that is independent of numerology.

[0157] Numerology may be communication parameters that apply to at least one of transmission and reception of a signal or channel, such as subcarrier spacing (SCS), bandwidth, symbol length, cyclic prefix length, transmission time interval (TTI), number of symbols per TTI, radio frame structure, specific filtering operations performed by the transceiver in the frequency domain, and specific windowing operations performed by the transceiver in the time domain.

[0158] A slot may be composed of one or more symbols (such as an Orthogonal Frequency Division Multiplexing (OFDM) symbol or a Single Carrier Frequency Division Multiple Access (SC-FDMA) symbol) in the time domain. A slot may be a time unit based on numerology.

[0159] A slot may include multiple minislots. Each minislot may consist of one or multiple symbols in the time domain. A minislot may also be called a subslot. A minislot may consist of fewer symbols than a slot. A PDSCH (or PUSCH) transmitted in a time unit larger than a minislot may be called PDSCH (or PUSCH) mapping type A. A PDSCH (or PUSCH) transmitted using a minislot may be called PDSCH (or PUSCH) mapping type B.

[0160] The radio frame, subframe, slot, minislot, and symbol all represent time units for transmitting signals, and may be referred to by other names corresponding to the radio frame, subframe, slot, minislot, and symbol.

[0161] For example, one subframe may be called a transmission time interval (TTI), multiple consecutive subframes may be called a TTI, or one slot or one minislot may be called a TTI. That is, at least one of the subframe and the TTI may be a subframe (1 ms) in existing LTE, a period shorter than 1 ms (for example, 1-13 symbols), or a period longer than 1 ms. Note that the unit representing the TTI may be called a slot, minislot, or the like instead of a subframe. Furthermore, one slot may be called a unit time. The unit time may differ for each cell depending on the numerology.

[0162] Here, TTI refers to, for example, the smallest time unit for scheduling in wireless communication. For example, in an LTE system, a base station performs scheduling to allocate wireless resources (such as frequency bandwidth and transmission power that can be used by each terminal 20) to each terminal 20 in TTI units. Note that the definition of TTI is not limited to this.

[0163] The TTI may be a transmission time unit for a channel-encoded data packet (transport block), a code block, a code word, etc., or may be a processing unit for scheduling, link adaptation, etc. When a TTI is given, the time interval (e.g., the number of symbols) to which a transport block, a code block, a code word, etc. is actually mapped may be shorter than the TTI.

[0164] When one slot or one minislot is called a TTI, one or more TTIs (i.e., one or more slots or one or more minislots) may be the minimum time unit for scheduling. Also, the number of slots (minislots) constituting the minimum time unit for scheduling may be controlled.

[0165] A TTI having a time length of 1 ms may be called a regular TTI (TTI in LTE Rel. 8-12), normal TTI, long TTI, regular subframe, normal subframe, long subframe, slot, etc. A TTI shorter than a regular TTI may be called a shortened TTI, short TTI, partial or fractional TTI, shortened subframe, short subframe, minislot, subslot, slot, etc.

[0166] In addition, a long TTI (e.g., a normal TTI, a subframe, etc.) may be interpreted as a TTI having a time length of more than 1 ms, and a short TTI (e.g., a shortened TTI, etc.) may be interpreted as a TTI having a TTI length shorter than the TTI length of a long TTI and equal to or greater than 1 ms.

[0167] A resource block (RB) is a resource allocation unit in the time domain and frequency domain, and may include one or more consecutive subcarriers in the frequency domain. The number of subcarriers included in an RB may be the same regardless of numerology, for example, 12. The number of subcarriers included in an RB may also be determined based on numerology.

[0168] The time domain of an RB may include one or more symbols and may have a length of one slot, one minislot, one subframe, or one TTI. One TTI, one subframe, etc. may each be composed of one or more resource blocks.

[0169] Note that one or more RBs may also be called a physical resource block (PRB), a sub-carrier group (SCG), a resource element group (REG), a PRB pair, an RB pair, or the like.

[0170] Furthermore, a resource block may be composed of one or more resource elements (REs). For example, one RE may be a radio resource region of one subcarrier and one symbol.

[0171] A Bandwidth Part (BWP) (which may also be referred to as a fractional bandwidth) may represent a subset of contiguous common resource blocks (RBs) for a given numerology on a given carrier, where the common RBs may be identified by their index relative to a common reference point of the carrier. PRBs may be defined in a given BWP and numbered within that BWP.

[0172] The BWP may include a BWP for UL (UL BWP) and a BWP for DL ​​(DL BWP). One or more BWPs may be configured for a UE within one carrier.

[0173] At least one of the configured BWPs may be active, and the UE may not expect to transmit or receive a given signal / channel outside the active BWP. Note that the terms "cell," "carrier," etc. in this disclosure may be read as "BWP."

[0174] The above-described structures of radio frames, subframes, slots, minislots, symbols, etc. are merely examples. For example, the number of subframes included in a radio frame, the number of slots per subframe or radio frame, the number of minislots included in a slot, the number of symbols and RBs included in a slot or minislot, the number of subcarriers included in an RB, the number of symbols in a TTI, the symbol length, the cyclic prefix (CP) length, etc. may be changed in various ways.

[0175] In this disclosure, where articles are added by translation, such as a, an, and the in English, the disclosure may include that the nouns following these articles are in the plural form.

[0176] In the present disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "coupled" may also be interpreted in the same way as "different."

[0177] Each aspect / embodiment described in this disclosure may be used alone, in combination, or switched depending on the implementation. Furthermore, notification of predetermined information (e.g., notification that "X is true") is not limited to being done explicitly, but may be done implicitly (e.g., by not notifying the predetermined information).

[0178] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure. [Explanation of symbols]

[0179] 10 base station 110 Transmitter 120 Receiver 130 Setting section 140 Control Unit 20 terminals 210 Transmitter 220 Receiving unit 230 Setting Section 240 Control Unit 30 network nodes 35 Authorization Server 40 Resource Holder Client 50 databases 60 External Servers 1001 processor 1002 Storage device 1003 Auxiliary storage device 1004 Communication equipment 1005 Input Device 1006 Output Device 2001 Vehicle 2002 Drive unit 2003 Steering Section 2004 accelerator pedal 2005 brake pedal 2006 Shift Lever 2007 front wheel 2008 rear wheel 2009 Axle 2010 Electronic Control Unit 2012 Information Services Department 2013 Communication Module 2021 Current Sensor 2022 RPM Sensor 2023 Air Pressure Sensor 2024 Vehicle speed sensor 2025 Acceleration Sensor 2026 Brake pedal sensor 2027 Shift lever sensor 2028 Object Detection Sensor 2029 Accelerator pedal sensor 2030 Driving Assistance Systems Department 2031 microprocessor 2032 memory (ROM, RAM) 2033 Communication port (IO port)

Claims

1. a control unit that determines whether an event that satisfies a condition for revoking authorization for an API call has occurred; a transmission unit that transmits a request to revoke authorization for calling the API to a network node device when it is determined that the event has occurred; A communication device comprising:

2. The condition is at least one of a plurality of conditions including a condition related to an application state, a condition related to time, a condition related to a location, a condition related to communication quality, and a condition related to wireless quality. The communication device according to claim 1 .

3. a receiving unit that receives a request to revoke authorization for an API call from a communication device that has detected an event that satisfies a condition for revoking authorization for the API call; a control unit that executes a process of canceling authorization for calling the API based on the request; A network node device comprising:

4. The control unit deletes the access permission information used to call the API from a database, or makes the access permission information unusable. The network node device according to claim 3 .

5. determining whether an event has occurred that satisfies a condition for revoking authorization for the API call; When it is determined that the event has occurred, transmitting a request to the network node device to revoke authorization for calling the API; An authorization control method performed by a communication device.

6. receiving a request to revoke authorization for an API call from a communication device that has detected an event that satisfies a condition for revoking authorization for the API call; Based on the request, execute a process to revoke authorization for calling the API. An authorization control method executed by a network node device.

Citation Information

Patent Citations

  • UE capabilities provisioning and retrieval in cellular networks

    US20190239064A1