Terminals and communication methods
Patent Information
- Application Number
- JP2024541300
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-08-15
- Publication Date
- 2026-10-01
- Estimated Expiration
- 2042-08-15
AI Technical Summary
【0010】 開示の技術によれば、ネットワークにおいて、リソース保持者のリソースにアクセスするための認証手順を簡素化することができる。
Smart Images

Figure 0007927854000001 
Figure 0007927854000002 
Figure 0007927854000003
Abstract
Description
Technical Field
[0001] The present invention relates to a terminal and a communication method in a communication system. Background Art
[0002] In 3GPP (registered trademark) (3rd Generation Partnership Project), a radio communication system called 5G or NR (New Radio) (hereinafter, this radio communication system is referred to as "5G" or "NR") is being studied to achieve further increase in system capacity, further increase in data transmission rate, further reduction in delay in radio sections, and the like. In 5G, various radio technologies are being studied to satisfy the requirement that the delay in the radio section is 1 ms or less while achieving a throughput of 10 Gbps or more.
[0003] In NR, a network architecture including 5GC (5G Core Network) corresponding to EPC (Evolved Packet Core), which is the core network in the LTE (Long Term Evolution) network architecture, and NG-RAN (Next Generation - Radio Access Network) corresponding to E-UTRAN (Evolved Universal Terrestrial Radio Access Network), which is RAN (Radio Access Network) in the LTE network architecture, is being studied (e.g., Non-Patent Document 1).
[0004] Further, for example, an architecture in which a Northbound interface between NEF (Network Exposure Function) and AF (Application Function) in a 5G system is configured by CAPIF (Common API Framework) is being studied (e.g., Non-Patent Document 2 and Non-Patent Document 3). Related Art Documents [Non-patent literature]
[0005] [Non-Patent Document 1] 3GPP TS 23.501 V17.5.0(2022-06) [Non-Patent Document 2] 3GPP TS 29.522 V17.6.0(2022-06) [Non-Patent Document 3] 3GPP TS 23.222 V17.6.0(2022-06) [Non-Patent Document 4] 3GPP TR 23.700-95 V1.4.0(2022-07) [Overview of the project] [Problems that the invention aims to solve]
[0006] The 3GPP core network opens its API (Application Program Interface) to external applications, allowing third-party applications to call the API. Furthermore, CAPIF is being considered to allow resource owners to authorize API calls to the core network. Resource owners can register in advance with the API exposing function or authorization function, and at the necessary time, the API exposing function or authorization function can access the resource owner to inquire about the permission to call the API.
[0007] Furthermore, SNA (Subscriber-aware northbound API access) applications (see Non-Patent Document 4) extend CAPIF to allow resource owner clients to authorize API calls to the core network. However, when an UE directly accesses another UE's resources using an SNA application, if the MNO (Mobile Network Operator) and the authorization server are independent, negotiation will be required among the three parties: the MNO, the UE, and the authorization server, which is expected to complicate the process.
[0008] This invention has been made in view of the above points, and aims to simplify the authentication procedure for accessing the resources of a resource holder in a network. [Means for solving the problem]
[0009] According to the disclosed technology, the device includes a transmitting unit that sends a request for the use of an API (Application Program Interface) to a first server, a receiving unit that receives a notification from the first server to redirect to the URI (Uniform Resource Identifier) of a second server, and a control unit that accesses the second server and performs authentication using an authentication method specified by the second server. The control unit grants the second server authorization for the first server to access the user information of its device, the receiving unit receives a notification from the second server to redirect to the URI of the first server, the control unit accesses the first server, obtains authorization for the request from the first server, and provides a terminal that accesses the resource holder's resources via the API. [Effects of the Invention]
[0010] According to the disclosed technology, authentication procedures for accessing resources held by resource holders can be simplified within a network. [Brief explanation of the drawing]
[0011] [Figure 1] This is a diagram illustrating an example of a communication system. [Figure 2] This diagram illustrates an example of a communication system in a roaming environment. [Figure 3] This diagram illustrates an example of an API call. [Figure 4] This figure illustrates an example of an API call in an embodiment of the present invention. [Figure 5] This is a sequence diagram illustrating an example of an API call in an embodiment of the present invention. [Figure 6] This figure shows an example of the functional configuration of a base station 10 and a network node 30 in an embodiment of the present invention. [Figure 7] This figure shows an example of the functional configuration of terminal 20 in an embodiment of the present invention. [Figure 8] This figure shows an example of the hardware configuration of the base station 10 and terminal 20 in an embodiment of the present invention. [Figure 9] This figure shows an example of the configuration of a vehicle 2001 in an embodiment of the present invention. [Modes for carrying out the invention]
[0012] Embodiments of the present invention will be described below with reference to the drawings. Note that the embodiments described below are examples, and the embodiments to which the present invention is applied are not limited to those described below.
[0013] In the operation of the wireless communication system according to the embodiments of the present invention, existing technologies may be used as appropriate. However, such existing technologies include, for example, existing LTE, but are not limited to existing LTE. Furthermore, the term "LTE" as used herein has a broad meaning that includes LTE-Advanced and LTE-Advanced and later methods (e.g., NR), or wireless LAN (Local Area Network), unless otherwise specified.
[0014] Also, in the embodiments of the present invention, the expression that a radio parameter or the like is "configured" may mean that a predetermined value is pre-configured in advance, or may mean that a radio parameter notified from the network node 30 or the terminal 20 is set.
[0015] FIG. 1 is a diagram for explaining an example of a communication system. As shown in FIG. 1, the communication system includes a UE that is the terminal 20 and a plurality of network nodes 30. In the following description, it is assumed that one network node 30 corresponds to each function, but one network node 30 may implement a plurality of functions, or a plurality of network nodes 30 may implement one function. In addition, the "connection" described below may be a logical connection or a physical connection.
[0016] A RAN (Radio Access Network) is a network node 30 having a radio access function, may include the base station 10, and is connected to a UE, an AMF (Access and Mobility Management Function) and a UPF (User plane function). The AMF is a network node 30 having functions such as termination of a RAN interface, termination of a NAS (Non-Access Stratum), registration management, connection management, reachability management, and mobility management. The UPF is a network node 30 having functions such as a PDU (Protocol Data Unit) session point for the outside interconnected with a DN (Data Network), packet routing and forwarding, and user plane QoS (Quality of Service) handling. The UPF and the DN constitute a network slice. In the radio communication system according to the embodiments of the present invention, a plurality of network slices are constructed.
[0017] The AMF is connected to the UE, the RAN, the Session Management Function (SMF), the Network Slice Selection Function (NSSF), the Network Exposure Function (NEF), the Network Repository Function (NRF), the Unified Data Management (UDM), the Authentication Server Function (AUSF), the Policy Control Function (PCF), and the Application Function (AF). The AMF, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF and AF are network nodes 30 interconnected via respective service-based interfaces, namely Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf and Naf.
[0018] SMF is a network node 30 that has functions such as session management, IP (Internet Protocol) address allocation and management for UEs, DHCP (Dynamic Host Configuration Protocol) functionality, ARP (Address Resolution Protocol) proxy, and roaming functionality. NEF is a network node 30 that has the function of notifying other NFs (Network Functions) of capabilities and events. NSSF is a network node 30 that has functions such as selecting the network slice to which the UE connects, determining the allowed NSSAI (Network Slice Selection Assistance Information), determining the NSSAI to be set, and determining the AMF set to which the UE connects. PCF is a network node 30 that has the function of controlling network policy. AF is a network node 30 that has the function of controlling application servers. NRF is a network node 30 that has the function of discovering NF instances that provide services. UDM is a network node 30 that manages subscriber data and authentication data. UDM is connected to UDR (User Data Repository) which holds the said data.
[0019] Figure 2 is a diagram illustrating an example of a communication system in a roaming environment. As shown in Figure 2, the network consists of a terminal 20 (UE) and multiple network nodes 30. Hereafter, one network node 30 will be assumed to correspond to each function, however, one network node 30 may implement multiple functions, or multiple network nodes 30 may implement one function. Furthermore, the "connection" described below may be a logical connection or a physical connection.
[0020] The RAN is a network node 30 with wireless access capabilities and is connected to the UE, AMF, and UPF. The AMF is a network node 30 with functions such as RAN interface termination, NAS termination, registration management, connection management, reachability management, and mobility management. The UPF is a network node 30 interconnected with the DN and has functions such as external PDU session point, packet routing and forwarding, and user plane QoS handling. The UPF and DN constitute a network slice. In the wireless communication network according to the embodiment of the present invention, multiple network slices are constructed.
[0021] AMF is connected to UE, RAN, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, AF, and SEPP (Security Edge Protection Proxy). AMF, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, and AF are network nodes 30 that are interconnected via interfaces based on their respective services: Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.
[0022] SMF is a network node 30 with functions such as session management, UE IP address assignment and management, DHCP functionality, ARP proxy, and roaming functionality. NEF is a network node 30 with the function of notifying other NFs of capabilities and events. NSSF is a network node 30 with functions such as selecting the network slice to which the UE connects, determining the allowed NSSAI, determining the NSSAI to be configured, and determining the AMF set to which the UE connects. PCF is a network node 30 with the function of controlling network policy. AF is a network node 30 with the function of controlling application servers. NRF is a network node 30 with the function of discovering NF instances that provide services. SEPP is an opaque proxy that filters control plane messages between PLMNs (Public Land Mobile Networks). vSEPP shown in Figure 2 is SEPP in the visited network, and hSEPP is SEPP in the home network.
[0023] As shown in Figure 2, the UE is in a roaming environment connected to the RAN and AMF in the VPLMN (Visited PLMN). The VPLMN and HPLMN (Home PLMN) are connected via vSEPP and hSEPP. The UE can communicate with the HPLMN's UDM, for example, via the VPLMN's AMF.
[0024] The 3GPP core network opens up its API (Application Program Interface) to external applications, allowing third-party applications to call the API. Furthermore, by extending CAPIF (Common API Framework), it is being considered that resource owners will be able to authorize API calls to the core network. Resource owners can register in advance with either the API exposing function or the authorization function, and at the necessary time, the API exposing function or authorization function can access the resource owner to inquire about the permission to call the API.
[0025] Figure 3 is a diagram illustrating an example of an API call. As shown in Figure 3, the CAPIF core function 30A receives the application pre-registration sent from the API invoker 20A and authenticates and authorizes the third-party application. The API provider function 30B receives the core network API call sent from the API invoker and opens the API to the authenticated and authorized external application.
[0026] Furthermore, as shown in Figure 3, the resource owner client 20B can authorize API calls from the core network via the authorization function 30E. The authorization function 30E registers with the API provider function 30B. After registration, the API provider function 30B can access the authorization function 30E at the necessary time to check whether or not the API call is permitted.
[0027] The API caller 20A may be, for example, an application on a terminal, and may have the ability to support authentication by providing an API caller identifier, the ability to support mutual authentication with CAPIF core function 30A, the ability to obtain authentication when accessing a service API, the ability to discover information related to a service API, and the ability to call a service API.
[0028] Furthermore, the CAPIF core function 30A may have, for example, the ability to support mutual authentication with the API caller 20A, the ability to authenticate the API caller 20A when accessing the service API, the ability to publish and store information related to the service API, the ability to control access to the service API based on policies set by the PLMN operator, the ability to record service API call logs and provide service API call logs to the approval body, the ability to charge based on service API call logs, the ability to monitor service API calls, the ability to add and remove API callers 20A, the ability to support access to logs for audits to detect misuse, for example, and the ability to publish information related to the service API together with other CAPIF core functions through connections between CAPIFs.
[0029] Furthermore, the API provision function 30B, the API publishing function 30C, and the API management function 30D may be functions or nodes belonging to a single API provider.
[0030] Furthermore, the API provisioning function 30B is a provider that provides service APIs and may have the ability to authenticate the API caller 20A based on information provided by the CAPIF core function 30A, the ability to verify the authentication provided by the CAPIF core function 30A, and the ability to record logs of service API calls in the CAPIF core function 30A.
[0031] Furthermore, the API disclosure function 30C may have the ability to disclose information relating to the service APIs owned by the API provider to the CAPIF core function 30A.
[0032] The API management function 30D is a function that causes the API provider to manage the service API, and may have the ability to audit service API call logs received from the CAPIF core function 30A, monitor events reported from the CAPIF core function 30A, set policies for the API provider in the CAPIF core function 30A, monitor the status of the service API, add and delete API callers 20A, and register and maintain the registration information of the API provider in the CAPIF core function 30A.
[0033] The CAPIF core function 30A, API provision function 30B, API publication function 30C, and API management function 30D may each be configured as a network node 30, or for example, the API provision function 30B, API publication function 30C, and API management function 30D may be configured as a single network work node 30. Furthermore, the API caller 20A, resource holder client 20B, and authorization function 30E may be, for example, communication devices such as terminals or servers, or other communication devices.
[0034] Furthermore, SNA (Subscriber-aware northbound API access) applications extend CAPIF to allow resource owner clients to authorize API calls to the core network.
[0035] Figure 4 is a diagram illustrating an example of an API call in an embodiment of the present invention. As shown in Figure 4, it is assumed that a Subscriber-aware northbound API access (SNA) application allows a UE to directly access the resources of another UE. Also, as shown in Figure 4, UE20A, the API caller, belongs to MNO (Mobile network operator) 2, and UE20B, the resource holder, belongs to MNO1, and it is assumed that access occurs between UEs with different MNOs.
[0036] UE20B, the resource holder, grants authorization to the authorization server 30E to access the resource. UE20A, the API caller, sends the authorization request necessary for API use to the authorization server.
[0037] The authorization server 30E may correspond to the authorization function 30E shown in Figure 3. The authorization server 30E may belong to MNO1 or MNO2. The resource holder UE20B may correspond to the resource holder client 20B shown in Figure 3. The API caller UE20A may correspond to the API caller 20A shown in Figure 3. MNO1 and MNO2 may correspond to the CAPIF core function 30A shown in Figure 3.
[0038] Here, both UE20A, the API caller, and UE20B, the resource holder, need to be authenticated. 3GPP has an authentication mechanism that uses subscriber information from its own network to authenticate users. Examples of such mechanisms include GBA (Generic Bootstrapping Architecture) and AKMA (Authentication and Key Management for Applications).
[0039] The authentication mechanism defined by 3GPP, as described above, typically authenticates users by exchanging authentication information between the UE and the MNO. However, if there are UEs belonging to different MNOs, and the MNO and the authorization server are independent, or if the authorization server belongs to one of the MNOs, negotiation will be required among the three parties: the MNO, the UE, and the authorization server, which is expected to complicate the process.
[0040] Therefore, the OpenID Connect framework may be applied to CAPIF to simplify authentication interactions when multiple entities are involved. In the actual authentication process, an authentication method defined by the MNO may be used. An ID token may be provided to the authorization server to allow access to the UE's information.
[0041] Figure 5 is a sequence diagram illustrating an example of an API call in an embodiment of the present invention. UE20A may correspond to the API caller 20A shown in Figure 3. The authorization server 30E may correspond to the authorization function 30E shown in Figure 3. The authentication server 30A may correspond to the CAPIF core function 30A shown in Figure 3.
[0042] In step S100, the authorization server 30E and the authentication server 30A begin registering and coordinating with each other. Step S100 is a procedure required only the first time.
[0043] In step S101, the UE20A, which has not yet been authenticated, sends the authorization request necessary for the API request to the authorization server 30E. Note that even if the UE20A has an access token, if it is not authenticated, the authentication procedure may be executed.
[0044] In the subsequent step S102, the authorization server 30E sends a notification to the UE20A that redirects it to the authentication server 30A's URI (Uniform Resource Identifier). This notification may include, for example, the following parameters.
[0045] response_type=code scope=openid client_id = ID of the authorization server redirext_uri=URI of the authentication server state = specific state
[0046] In the following step S103, UE20A accesses the specified redirection URI.
[0047] In the following step S104, UE20A and authentication server 30A perform authentication using the authentication method specified by the MNO's authentication server 30A.
[0048] In the following step S105, the authentication server 30A obtains authorization from the UE20A (end user) for the authorization server 30E to access the end user's user information.
[0049] In the following step S106, the authentication server 30A sends a notification to the UE20A that redirects it to the authorization server's URI.
[0050] In the following step S107, UE20A accesses the specified redirection URI.
[0051] In the following step S108, the authorization server 30E requests an ID token from the authentication server 30A. In the following step S109, the authentication server 30A sends the ID token to the authorization server 30E. In the following step S110, the authorization server 30E verifies the ID token and completes the authentication of UE20A.
[0052] Next, UE20A receives authorization for an API request from the authorization server 30E, and can access the resource holder's resources through that API.
[0053] As demonstrated in the above embodiment, authentication can be easily performed even when subscribers belonging to different MNOs call the API. Furthermore, even if an OAuth access token is illegally read and leaked, security is improved because the UE possessing that access token will not be able to access the resource unless authenticated.
[0054] In other words, it can simplify the authentication process for accessing resources held by resource owners within a network.
[0055] (Device configuration) Next, we will describe an example of the functional configuration of the base station 10, network node 30, and terminal 20 that perform the processes and operations described above. The base station 10, network node 30, and terminal 20 include the functions to perform the embodiments described above. However, the base station 10, network node 30, and terminal 20 may each have only some of the functions in the embodiments.
[0056] <Base station 10 and network node 30> Figure 6 shows an example of the functional configuration of a base station 10 and a network node 30. As shown in Figure 6, the base station 10 has a transmitting unit 110, a receiving unit 120, a setting unit 130, and a control unit 140. The functional configuration shown in Figure 6 is merely an example. The functional classifications and names of the functional units can be anything as long as they can perform the operations according to the embodiment of the present invention. The network node 30 may have the same functional configuration as the base station 10. Furthermore, a network node 30 having multiple different functions on the system architecture may be composed of multiple network nodes 30 separated by function.
[0057] The transmitting unit 110 includes the function of generating a signal to be transmitted to the terminal 20 or other network node 30 and transmitting the signal by wire or wireless. The receiving unit 120 includes the function of receiving various signals transmitted from the terminal 20 or other network node 30 and obtaining information from the received signal, for example, higher layer information. A communication unit including the transmitting unit 110 and the receiving unit 120 may be configured.
[0058] The configuration unit 130 stores pre-configured configuration information and various configuration information to be transmitted to the terminal 20 in a storage device, and reads it from the storage device as needed. The contents of the configuration information include, for example, information related to service APIs in the network.
[0059] As described in the embodiment, the control unit 140 performs processing related to the configuration of service APIs in the network. The control unit 140 also performs processing related to communication with the terminal 20. The signal transmission function of the control unit 140 may be included in the transmission unit 110, and the signal reception function of the control unit 140 may be included in the reception unit 120.
[0060] <Terminal 20> Figure 7 shows an example of the functional configuration of terminal 20. As shown in Figure 7, terminal 20 has a transmitting unit 210, a receiving unit 220, a setting unit 230, and a control unit 240. The functional configuration shown in Figure 7 is merely an example. The functional classifications and names of the functional units can be anything as long as they can perform the operations according to the embodiment of the present invention. Furthermore, the communication device that becomes the resource holder 20 may have a functional configuration similar to that of terminal 20.
[0061] The transmitting unit 210 creates a transmission signal from the transmission data and transmits the transmission signal wirelessly. The receiving unit 220 wirelessly receives various signals and obtains signals from higher layers from the received physical layer signals. The receiving unit 220 also has the function of receiving NR-PSS, NR-SSS, NR-PBCH, DL / UL control signals or reference signals transmitted from the network node 30. A communication unit including the transmitting unit 210 and the receiving unit 220 may be configured.
[0062] The configuration unit 230 stores various configuration information received from the network node 30 by the receiving unit 220 in its storage device and reads it from the storage device as needed. The configuration unit 230 also stores pre-configured configuration information. The content of the configuration information is, for example, information related to service APIs in the network.
[0063] The control unit 240 performs processing related to the configuration of service APIs in the network, as described in the embodiment. The signal transmission function of the control unit 240 may be included in the transmission unit 210, and the signal reception function of the control unit 240 may be included in the reception unit 220.
[0064] (Hardware configuration) The block diagrams (Figures 6 and 7) used in the description of the above embodiments show functional units. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method of realizing each functional block is not particularly limited. That is, each functional block may be realized using one device that is physically or logically coupled, or it may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wired or wireless connections). A functional block may be realized by combining the one or more devices with software.
[0065] Functions include, but are not limited to, judgment, decision, judgment, calculation, calculation, processing, derivation, investigation, exploration, confirmation, reception, transmission, output, access, resolution, selection, selection, establishment, comparison, assumption, expectation, assumption, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating (mapping), and assigning. For example, a functional block (configuration part) that enables transmission is called a transmitting unit or transmitter. As mentioned above, the method of implementation is not particularly limited.
[0066] For example, the network node 30, terminal 20, etc. in one embodiment of the present disclosure may function as a computer that processes the wireless communication method of the present disclosure. Figure 8 is a diagram showing an example of the hardware configuration of a base station 10 and terminal 20 according to one embodiment of the present disclosure. The network node 30 may have a hardware configuration similar to that of the base station 10. The base station 10 and terminal 20 described above may be physically configured as a computer device including a processor 1001, a storage device 1002, an auxiliary storage device 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, etc.
[0067] In the following explanation, the term "device" can be replaced with "circuit," "device," "unit," etc. The hardware configuration of the base station 10 and terminal 20 may include one or more of the devices shown in the figure, or it may be configured without some of the devices.
[0068] Each function in the base station 10 and terminal 20 is realized by loading predetermined software (programs) onto hardware such as the processor 1001 and storage device 1002, which allows the processor 1001 to perform calculations, control communication by the communication device 1004, and control at least one of the reading and writing of data in the storage device 1002 and auxiliary storage device 1003.
[0069] The processor 1001 controls the entire computer, for example, by running an operating system. The processor 1001 may consist of a central processing unit (CPU) that includes interfaces with peripheral devices, control devices, arithmetic units, registers, etc. For example, the control unit 140, control unit 240, etc., described above may be implemented by the processor 1001.
[0070] Furthermore, the processor 1001 reads programs (program code), software modules, or data from at least one of the auxiliary storage device 1003 and the communication device 1004 into the storage device 1002, and executes various processes accordingly. The program used is one that causes a computer to execute at least a part of the operations described in the above embodiment. For example, the control unit 140 of the base station 10 shown in Figure 6 may be implemented by a control program stored in the storage device 1002 and operated by the processor 1001. Also, for example, the control unit 240 of the terminal 20 shown in Figure 7 may be implemented by a control program stored in the storage device 1002 and operated by the processor 1001. Although the above processes have been described as being executed by one processor 1001, they may be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may be implemented by one or more chips. The program may be transmitted from the network via a telecommunications line.
[0071] The storage device 1002 is a computer-readable recording medium and may consist of at least one of the following: ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), RAM (Random Access Memory), etc. The storage device 1002 may also be called a register, cache, main memory, etc. The storage device 1002 can store executable programs (program code), software modules, etc., for implementing a communication method according to one embodiment of this disclosure.
[0072] The auxiliary storage device 1003 is a computer-readable recording medium and may consist of at least one of the following: an optical disc such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disc, a digital multipurpose disc, a Blu-ray® disc), a smart card, flash memory (e.g., a card, a stick, a key drive), a floppy® disk, a magnetic strip, etc. The above-mentioned storage medium may also be a database, server, or other suitable medium that includes at least one of the storage device 1002 and the auxiliary storage device 1003.
[0073] The communication device 1004 is hardware (transceiver / receiver device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as a network device, network controller, network card, communication module, etc. The communication device 1004 may include high-frequency switches, duplexers, filters, frequency synthesizers, etc., to implement at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, the transmit / receive antenna, amplifier section, transmit / receive section, transmission path interface, etc., may be implemented by the communication device 1004. The transmit / receive section may be implemented with physically or logically separated transmitting and receiving sections.
[0074] The input device 1005 is an input device that accepts input from an external source (e.g., a keyboard, mouse, microphone, switch, button, sensor, etc.). The output device 1006 is an output device that outputs to an external source (e.g., a display, speaker, LED lamp, etc.). The input device 1005 and the output device 1006 may be configured as an integrated unit (e.g., a touch panel).
[0075] Furthermore, each device, such as the processor 1001 and the storage device 1002, is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus, or different buses may be configured for each device.
[0076] Furthermore, the base station 10 and terminal 20 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a PLD (Programmable Logic Device), and an FPGA (Field Programmable Gate Array), and some or all of each functional block may be realized by such hardware. For example, the processor 1001 may be implemented using at least one of these hardware components.
[0077] Figure 9 shows an example of the configuration of vehicle 2001. As shown in Figure 9, vehicle 2001 comprises a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a shift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021-2029, an information service unit 2012, and a communication module 2013. Each aspect / embodiment described in this disclosure may be applied to a communication device mounted on vehicle 2001, for example, to the communication module 2013.
[0078] The drive unit 2002 consists of, for example, an engine, a motor, or a hybrid of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also called a handle) and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel, which is operated by the user.
[0079] The electronic control unit 2010 consists of a microprocessor 2031, memory (ROM, RAM) 2032, and communication ports (IO ports) 2033. Signals from various sensors 2021 to 2029 installed in the vehicle 2001 are input to the electronic control unit 2010. The electronic control unit 2010 may also be called an ECU (Electronic Control Unit).
[0080] Signals from various sensors 2021-2029 include current signals from current sensor 2021 which senses motor current, front and rear wheel rotation speed signals obtained by rotation speed sensor 2022, front and rear wheel air pressure signals obtained by air pressure sensor 2023, vehicle speed signals obtained by vehicle speed sensor 2024, acceleration signals obtained by acceleration sensor 2025, accelerator pedal depression signals obtained by accelerator pedal sensor 2029, brake pedal depression signals obtained by brake pedal sensor 2026, shift lever operation signals obtained by shift lever sensor 2027, and detection signals obtained by object detection sensor 2028 for detecting obstacles, vehicles, pedestrians, etc.
[0081] The Information Services Unit 2012 consists of various devices for providing (outputting) various types of information such as driving information, traffic information, and entertainment information, including a car navigation system, audio system, speakers, television, and radio, and one or more ECUs that control these devices. The Information Services Unit 2012 uses information acquired from external devices via a communication module 2013, etc., to provide various multimedia information and multimedia services to the occupants of the vehicle 2001. The Information Services Unit 2012 may include input devices that accept input from the outside (e.g., keyboard, mouse, microphone, switch, button, sensor, touch panel, etc.) and output devices that perform output to the outside (e.g., display, speaker, LED lamp, touch panel, etc.).
[0082] The driver assistance system unit 2030 consists of various devices that provide functions to prevent accidents or reduce the driver's workload, such as millimeter-wave radar, LiDAR (Light Detection and Ranging), cameras, positioning locators (e.g., GNSS), map information (e.g., high-definition (HD) maps, autonomous vehicle (AV) maps, etc.), gyro systems (e.g., IMU (Inertial Measurement Unit), INS (Inertial Navigation System), etc.), AI (Artificial Intelligence) chips, and AI processors, as well as one or more ECUs that control these devices. The driver assistance system unit 2030 also sends and receives various information via the communication module 2013 to realize driver assistance functions or autonomous driving functions.
[0083] The communication module 2013 can communicate with the microprocessor 2031 and components of the vehicle 2001 via its communication port. For example, the communication module 2013 sends and receives data via its communication port 2033 to the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axle 2009, the microprocessor 2031 and memory (ROM, RAM) 2032 in the electronic control unit 2010, and sensors 2021-29 provided in the vehicle 2001.
[0084] The communication module 2013 is a communication device that can be controlled by the microprocessor 2031 of the electronic control unit 2010 and can communicate with external devices. For example, it can send and receive various types of information to and from external devices via wireless communication. The communication module 2013 may be located either inside or outside the electronic control unit 2010. The external device may be, for example, a base station or a mobile station.
[0085] The communication module 2013 may transmit at least one of the following to an external device via wireless communication: signals from the various sensors 2021-2028 input to the electronic control unit 2010, information obtained based on said signals, and information based on input from an external source (user) obtained via the information service unit 2012. The electronic control unit 2010, the various sensors 2021-2028, the information service unit 2012, etc., may also be called input units that accept input. For example, the PUSCH transmitted by the communication module 2013 may include information based on the above input.
[0086] The communication module 2013 receives various information (traffic information, signal information, inter-vehicle information, etc.) transmitted from an external device and displays it on the information service unit 2012 provided in the vehicle 2001. The information service unit 2012 may also be called an output unit, which outputs information (for example, outputs information to devices such as displays and speakers based on the PDSCH (or data / information decoded from the PDSCH) received by the communication module 2013). The communication module 2013 also stores the various information received from the external device in memory 2032, which is available to the microprocessor 2031. Based on the information stored in memory 2032, the microprocessor 2031 may control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axles 2009, sensors 2021-2029, etc., provided in the vehicle 2001.
[0087] (Summary of the embodiments) As described above, according to the embodiment of the present invention, a terminal is provided that accesses the resources of a resource holder via the API, comprising: a transmitting unit that transmits a request related to the use of an API (Application Program Interface) to a first server; a receiving unit that receives a notification from the first server to redirect to the URI (Uniform Resource Identifier) of a second server; and a control unit that accesses the second server and performs authentication using an authentication method specified by the second server. The control unit grants the second server authorization for the first server to access the user information of its device, the receiving unit receives a notification from the second server to redirect to the URI of the first server, and the control unit accesses the first server, obtains authorization for the request from the first server.
[0088] The above configuration allows for simplified authentication even when subscribers belonging to different MNOs call the API. Furthermore, even if an OAuth access token is illegally read and leaked, security is improved because the UE possessing that access token will not be able to access the resource unless authenticated. In other words, the authentication procedure for accessing resources held by resource owners can be simplified within the network.
[0089] The first server performs authorization independently of the MNO (Mobile Network Operator) to which its device belongs, and the second server may have the CAPIF core function (Common API Framework core function) of the MNO to which its device belongs. This configuration allows for easy authentication even when subscribers belonging to different MNOs call the API.
[0090] The control unit may perform authentication processing if it holds an access token and its own device is not authenticated. This configuration allows for easy authentication even when subscribers belonging to different MNOs call the API. Furthermore, even if an OAuth access token is illegally read and leaked by someone, security is improved because the UE holding the access token will not be able to access the resource unless it is authenticated.
[0091] The notification redirecting to the URI of the second server may include at least the ID of the first server and the URI of the second server. This configuration allows for simplified authentication even when subscribers belonging to different MNOs call the API.
[0092] The MNO to which the device belongs and the MNO to which the resource holder belongs may be different. This configuration allows for easy authentication even when subscribers belonging to different MNOs call the API.
[0093] Furthermore, according to an embodiment of the present invention, a communication method is provided in which a terminal performs the following steps: sending a request related to the use of an API (Application Program Interface) to a first server; receiving a notification from the first server to redirect to the URI (Uniform Resource Identifier) of a second server; accessing the second server and performing authentication using an authentication method specified by the second server; granting the second server authorization for the first server to access user information of its device; receiving a notification from the second server to redirect to the URI of the first server; and accessing the first server, obtaining authorization for the request from the first server, and accessing the resource holder's resources via the API.
[0094] The above configuration allows for simplified authentication even when subscribers belonging to different MNOs call the API. Furthermore, even if an OAuth access token is illegally read and leaked, security is improved because the UE possessing that access token will not be able to access the resource unless authenticated. In other words, the authentication procedure for accessing resources held by resource owners can be simplified within the network.
[0095] (Supplement to the embodiment) While embodiments of the present invention have been described above, the disclosed invention is not limited to such embodiments, and those skilled in the art will understand various modifications, alterations, alternatives, substitutions, etc. Specific numerical examples have been used to facilitate understanding of the invention, but unless otherwise specified, these numerical values are merely examples, and any appropriate values may be used. The division of items in the above description is not essential to the present invention, and matters described in two or more items may be combined as needed, and matters described in one item may be applied to matters described in another item (as long as they do not contradict each other). The boundaries of functional units or processing units in the functional block diagram do not necessarily correspond to the boundaries of physical parts. The operation of multiple functional units may be physically performed by one part, or the operation of one functional unit may be physically performed by multiple parts. Regarding the processing procedures described in the embodiments, the order of processing may be changed as long as it does not contradict each other. For the convenience of explaining the processing, the base station 10 and terminal 20 have been described using functional block diagrams, but such devices may be implemented in hardware, software, or a combination thereof. The software operated by the processor of the base station 10 according to an embodiment of the present invention and the software operated by the processor of the terminal 20 according to an embodiment of the present invention may be stored in random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, registers, hard disk (HDD), removable disk, CD-ROM, database, server, or any other suitable storage medium.
[0096] Furthermore, the notification of information is not limited to the embodiments / models described herein and may be carried out by other methods. For example, the notification of information may be carried out by physical layer signaling (e.g., DCI (Downlink Control Information), UCI (Uplink Control Information)), upper layer signaling (e.g., RRC (Radio Resource Control) signaling, MAC (Medium Access Control) signaling), broadcast information (MIB (Master Information Block), SIB (System Information Block)), other signals, or combinations thereof. Also, RRC signaling may be called RRC messages, and may be, for example, RRC Connection Setup messages, RRC Connection Reconfiguration messages, etc.
[0097] Each aspect / embodiment described in this disclosure includes LTE (Long Term Evolution), LTE-A (LTE-Advanced), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), 6th generation mobile communication system (6G), xth generation mobile communication system (xG) (xG (where x is, for example, an integer or decimal)), FRA (Future Radio Access), NR (new Radio), New radio access (NX), Future generation radio access (FX), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), and IEEE This may apply to at least one system utilizing 802.20, UWB (Ultra-WideBand), Bluetooth®, or other appropriate systems, and to next-generation systems extended, modified, created, or defined based thereon. It may also apply to a combination of multiple systems (for example, a combination of at least one of LTE and LTE-A with 5G).
[0098] The processing procedures, sequences, flowcharts, etc., of each aspect / embodiment described herein may be reordered, provided they are consistent with each other. For example, the methods described herein present various step elements in an exemplary order and are not limited to that specific order.
[0099] In this specification, specific operations performed by the base station 10 may, in some cases, be performed by its upper node. In a network consisting of one or more network nodes having a base station 10, it is clear that various operations performed for communication with the terminal 20 can be performed by the base station 10 and at least one of the other network nodes (for example, an MME or S-GW, but not limited to these). Although the above example illustrates the case where there is one other network node besides the base station 10, the other network node may be a combination of multiple other network nodes (for example, an MME and an S-GW).
[0100] In particular, the authorization server 30E may be combined with network nodes that have functions other than authorization (for example, an edge application server or edge enabler server with edge computing capabilities).
[0101] The information or signals described in this disclosure may be output from a higher layer (or lower layer) to a lower layer (or higher layer). They may also be input and output via multiple network nodes.
[0102] Input and output information may be stored in a specific location (e.g., memory) or managed using a management table. Input and output information may be overwritten, updated, or appended to. Output information may be deleted. Input information may be transmitted to other devices.
[0103] The determination in this disclosure may be made by a value represented by one bit (0 or 1), by a boolean value (true or false), or by a numerical comparison (for example, a comparison with a predetermined value).
[0104] Software should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, and so on, whether they are called software, firmware, middleware, microcode, hardware description languages, or by any other name.
[0105] Furthermore, software, instructions, information, etc., may be transmitted and received via a transmission medium. For example, if software is transmitted from a website, server, or other remote source using at least one of wired technology (such as coaxial cable, fiber optic cable, twisted pair, or digital subscriber line (DSL)) and wireless technology (such as infrared or microwave), then at least one of these wired and wireless technologies is included in the definition of a transmission medium.
[0106] The information, signals, etc. described in this disclosure may be represented using any of the various different techniques. For example, the data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.
[0107] In addition, terms used in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings. For example, at least one of the channel and symbol may be a signal (signaling). Also, a signal may be a message. Furthermore, a component carrier (CC) may be called a carrier frequency, cell, frequency carrier, etc.
[0108] The terms “system” and “network” as used in this disclosure are interchangeable.
[0109] Furthermore, the information, parameters, etc., described in this disclosure may be expressed using absolute values, relative values from a given value, or other corresponding information. For example, wireless resources may be indicated by an index.
[0110] The names used for the parameters described above are not restrictive in any way. Furthermore, the formulas and other expressions using these parameters may differ from those expressly disclosed in this disclosure. Various channels (e.g., PUCCH, PDCCH, etc.) and information elements can be identified by any suitable name, and therefore, the various names assigned to these various channels and information elements are not restrictive in any way.
[0111] In this disclosure, terms such as "base station (BS)", "wireless base station", "base station equipment", "fixed station", "NodeB", "eNodeB (eNB)", "gNodeB (gNB)", "access point", "transmission point", "reception point", "transmission / reception point", "cell", "sector", "cell group", "carrier", and "component carrier" may be used interchangeably. Base stations may also be referred to by terms such as macrocell, small cell, femtocell, and picocell.
[0112] A base station can house one or more (e.g., three) cells. If a base station houses multiple cells, the entire coverage area of the base station can be divided into several smaller areas, each of which may also be provided with communication services by a base station subsystem (e.g., a Remote Radio Head (RRH)). The terms “cell” or “sector” refer to part or all of the coverage area of at least one of the base station and / or base station subsystems that provide communication services in that coverage.
[0113] In this disclosure, the transmission of information by a base station to a terminal may be interpreted as the base station instructing the terminal to perform information-based control or operation.
[0114] In this disclosure, terms such as "Mobile Station (MS)," "user terminal," "User Equipment (UE)," and "terminal" may be used interchangeably.
[0115] A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or several other appropriate terms.
[0116] At least one of the base station and the mobile station may be called a transmitting device, a receiving device, a communication device, etc. At least one of the base station and the mobile station may also be a device mounted on a mobile body, the mobile body itself, etc. The mobile body refers to a movable object, and its speed of movement is arbitrary. This also includes the case when the mobile body is stationary. The mobile body includes, but is not limited to, vehicles, transport vehicles, automobiles, motorcycles, bicycles, connected cars, excavators, bulldozers, wheel loaders, dump trucks, forklifts, trains, buses, handcarts, rickshaws, ships and other watercraft, airplanes, rockets, satellites, drones (registered trademark), multicopters, quadcopters, balloons, and items mounted on them. The mobile body may also be a mobile body that moves autonomously based on operation commands. It may be a vehicle (e.g., a car, an airplane, etc.), an unmanned mobile body (e.g., a drone, an autonomous vehicle, etc.), or a robot (manned or unmanned). Furthermore, at least one of the base station and the mobile station may include devices that do not necessarily move during communication operations. For example, at least one of the base station and the mobile station may be an IoT (Internet of Things) device such as a sensor.
[0117] Furthermore, the term "base station" in this disclosure may be interpreted as "user terminal." For example, the various aspects / embodiments of this disclosure may be applied to a configuration in which communication between a base station and a user terminal is replaced with communication between multiple terminals 20 (which may be called, for example, D2D (Device-to-Device), V2X (Vehicle-to-Everything), etc.). In this case, the terminals 20 may have the functions that the base station 10 has. Also, terms such as "uplink" and "downlink" may be interpreted as terms corresponding to terminal-to-terminal communication (for example, "side"). For example, uplink channel, downlink channel, etc., may be interpreted as side channel.
[0118] Similarly, the term "user terminal" in this disclosure may be replaced with "base station." In this case, the base station may be configured to have the same functions as the user terminal described above.
[0119] As used in this disclosure, the terms “determining” and “determining” may encompass a wide variety of actions. “Determining” may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiry (e.g., searching in a table, database, or other data structure), and ascertaining. “Determining” may also include, for example, receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, and accessing (e.g., accessing data in memory). Furthermore, "judgment" and "decision" can include considering something as having been "judged" or "decided" after resolving, selecting, choosing, establishing, comparing, etc. In other words, "judgment" and "decision" can include considering something as having been "judged" or "decided" after some action. Also, "judgment (decision)" can be reinterpreted as "assuming," "expecting," or "considering."
[0120] The terms “connected,” “coupled,” or any variation thereof, mean any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are “connected” or “coupled” with each other. The coupling or connection between elements may be physical, logical, or a combination thereof. For example, “connection” may be reinterpreted as “access.” As used in this disclosure, two elements may be considered to be “connected” or “coupled” with each other using at least one of one or more wires, cables, and printed electrical connections, and, in some non-limiting and non-exclusive examples, electromagnetic energy having wavelengths in the radio frequency domain, microwave domain, and optical (both visible and invisible) domain.
[0121] The reference signal can also be abbreviated as RS (Reference Signal), and may be called a pilot depending on the applicable standard.
[0122] In this disclosure, the phrase "based on" does not mean "based solely on" unless otherwise specified. In other words, the phrase "based on" means both "based solely on" and "based at least on."
[0123] Any reference to elements using the designations “first,” “second,” etc., as used in this disclosure does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient way to distinguish between two or more elements. Accordingly, references to the first and second elements do not imply that only two elements may be employed, or that the first element must precede the second element in any way.
[0124] In the configuration of each of the above devices, "means" may be replaced with "part," "circuit," "device," etc.
[0125] Where the terms “include,” “including,” and variations thereof are used in this disclosure, these terms are intended to be inclusive, as is the term “comprising.” Furthermore, the term “or” as used in this disclosure is not intended to mean exclusive OR.
[0126] In this disclosure, if articles are added through translation, such as a, an, and the in English, this disclosure may include the fact that the noun following these articles is plural.
[0127] In this disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "combine" may be interpreted similarly to "different."
[0128] Each aspect / embodiment described herein may be used individually, in combination, or switched between as needed during implementation. Furthermore, notification of specific information (e.g., notification that "X is") is not limited to explicit notification, but may also be implicit (e.g., by not providing such notification).
[0129] Although the present disclosure has been described in detail above, it will be clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the intent and scope of the present disclosure as defined by the claims. Therefore, the descriptions in the present disclosure are illustrative and not intended to be restrictive in any way. [Explanation of Symbols]
[0130] 10 base station 110 Transmitter 120 Receiver 130 Setting section 140 Control Unit 20 devices 210 Transmitter 220 Receiver 230 Setting section 240 Control Unit 30 network nodes 1001 Processor 1002 Storage device 1003 Auxiliary storage device 1004 Communication device 1005 Input device 1006 Output device
Claims
1. A transmission unit that sends requests related to the use of an API (Application Program Interface) to the first server, A receiving unit that receives a notification from the first server to redirect to the URI (Uniform Resource Identifier) of the second server, The system includes a control unit that accesses the second server and performs authentication using an authentication method specified by the second server, The control unit grants the second server authorization for the first server to access the user information of its device. The receiving unit receives a notification from the second server to redirect to the URI of the first server, The control unit is a terminal that accesses the first server, obtains authorization for the request from the first server, and accesses the resource holder's resources via the API.
2. The first server performs authorization independently of the MNO (Mobile Network Operator) to which its device belongs. The terminal according to claim 1, wherein the second server has the CAPI core function (Common API Framework core function) of the MNO to which its device belongs.
3. The terminal according to claim 1, wherein the control unit holds an access token and performs authentication processing if the device is not authenticated.
4. The terminal according to claim 1, wherein the notification redirecting to the URI of the second server includes at least the ID of the first server and the URI of the second server.
5. The terminal according to claim 1, wherein the MNO to which the device belongs and the MNO to which the resource holder belongs are different.
6. The procedure for sending a request related to the use of an API (Application Program Interface) to the first server, A procedure for receiving a notification from the first server to redirect to the URI (Uniform Resource Identifier) of the second server, A procedure for accessing the second server and performing authentication using the authentication method specified by the second server, A procedure for the first server to grant the second server authorization to access user information of its own device, A procedure for receiving a notification from the second server to redirect to the URI of the first server, A communication method in which a terminal performs the following steps: access the first server, obtain authorization for the request from the first server, and access the resource holder's resources via the API.
Citation Information
Patent Citations
Communication method and device
CN111935757A