Onboarding renewal in the common application programming interface (API) framework
The secure session with a CAPIF core function enables dynamic renewal of API invoker onboarding, addressing vulnerabilities and ensuring continuous service availability in telecommunications systems.
Patent Information
- Application Number
- PCT/IB2025/051468
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-15
- Filing Date
- 2025-02-12
- Publication Date
- 2025-08-21
AI Technical Summary
Current telecommunications systems lack a dynamic and secure method for renewing the onboarding process of application programming interface (API) invokers, leading to vulnerabilities and service disruptions during the offboarding and new onboarding process.
Implementing a secure session with a common API framework (CAPIF) core function to enable API invokers to send onboarding update requests for renewal, allowing for the validation and update of onboarding information without losing the API invoker profile, and providing advance notifications for expiration.
Ensures continuous service availability by allowing secure and dynamic renewal of API invoker onboarding, reducing vulnerabilities and service disruptions.
Smart Images

Figure IB2025051468_21082025_PF_FP_ABST
Abstract
Description
ONBOARDING RENEWAL IN THE COMMON APPLICATION PROGRAMMING INTERFACE (API) FRAMEWORK TECHNOLOGICAL FIELD
[0001] The present disclosure relates generally to telecommunications and, in particular, to procedures for application programming interface (API) invoker onboarding and renewal in the common API framework. BACKGROUND
[0002] A telecommunications system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications path. A telecommunications system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.
[0003] In a wireless telecommunications system at least a part of a communication session between at least two stations occurs over a wireless link. Examples of wireless systems comprise public land mobile networks (PLMN), satellite based communication systems and different wireless local networks, for example wireless local area networks (WLAN). Some wireless systems can be divided into cells, and are therefore often referred to as cellular systems.
[0004] A user can access the telecommunications system by means of an appropriate communication device or terminal. A communication device of a user may be referred to as user equipment (UE) or user device. A communication device is provided with an appropriate signal receiving and transmitting apparatus for enabling communications, for example enabling access to a communication network or communications directly with other users. The communication device may access a carrier provided by a station, forexample a base station of a cell, and transmit and / or receive communications on the carrier.
[0005] The telecommunications system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. One example of a telecommunications system is the Universal Mobile Telecommunications System (UMTS). Other examples of telecommunications systems are Long-Term Evolution (LTE), LTE Advanced and the so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP). BRIEF SUMMARY
[0006] Example implementations of the present disclosure are directed to telecommunications and, in particular, to procedures for application programming interface (API) invoker onboarding and renewal in the common API framework. The present disclosure includes, without limitation, the following example implementations.
[0007] Some example implementations provide an apparatus to implement an application programming interface (API) invoker, the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: establish a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; send an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receive an onboarding update response message from the CAPIF core function based on the renewal.
[0008] Some example implementations provide an apparatus to implement an application programming interface (API) invoker, the apparatus comprising: means for establishing a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboardinginformation; means for sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and means for receiving an onboarding update response message from the CAPIF core function based on the renewal.
[0009] Some example implementations provide a method implemented at an application programming interface (API) invoker, the method comprising: establishing a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receiving an onboarding update response message from the CAPIF core function based on the renewal.
[0010] Some example implementations provide a computer-readable storage medium implemented at an application programming interface (API) invoker, the computer- readable storage medium being non-transitory and having instructions stored therein that, in response to execution by at least one processing circuitry, causes an apparatus to at least: establish a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; send an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receive an onboarding update response message from the CAPIF core function based on the renewal.
[0011] Some example implementations provide an apparatus to implement a common application programming interface (API) framework (CAPIF) core function, the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: establish a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receive an onboarding update request message including the onboarding information from the API invoker; validate the onboarding update request message and the onboarding based on the onboarding information; perform a renewal ofthe onboarding based on the onboarding update request message; and send an onboarding update response message to the API invoker based on the renewal.
[0012] Some example implementations provide an apparatus to implement a common application programming interface (API) framework (CAPIF) core function, the apparatus comprising: means for establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; means for receiving an onboarding update request message including the onboarding information from the API invoker; means for validating the onboarding update request message and the onboarding based on the onboarding information; means for performing a renewal of the onboarding based on the onboarding update request message; and means for sending an onboarding update response message to the API invoker based on the renewal.
[0013] Some example implementations provide a method implemented at a common application programming interface (API) framework (CAPIF) core function, the method comprising: establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receiving an onboarding update request message including the onboarding information from the API invoker; validating the onboarding update request message and the onboarding based on the onboarding information; performing a renewal of the onboarding based on the onboarding update request message; and sending an onboarding update response message to the API invoker based on the renewal.
[0014] Some example implementations provide a computer-readable storage medium implemented at a common application programming interface (API) framework (CAPIF) core function, the computer-readable storage medium being non-transitory and having instructions stored therein that, in response to execution by at least one processing circuitry, causes an apparatus to at least: establish a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receive an onboarding update request message including the onboarding information from the API invoker; validate the onboarding update request message and the onboarding based on the onboarding information; perform a renewal of theonboarding based on the onboarding update request message; and send an onboarding update response message to the API invoker based on the renewal.
[0015] These and other features, aspects, and advantages of the present disclosure will be apparent from a reading of the following detailed description together with the accompanying figures, which are briefly described below. The present disclosure includes any combination of two, three, four or more features or elements set forth in this disclosure, regardless of whether such features or elements are expressly combined or otherwise recited in a specific example implementation described herein. This disclosure is intended to be read holistically such that any separable features or elements of the disclosure, in any of its aspects and example implementations, should be viewed as combinable unless the context of the disclosure clearly dictates otherwise.
[0016] It will therefore be appreciated that this Brief Summary is provided merely for purposes of summarizing some example implementations so as to provide a basic understanding of some aspects of the disclosure. Accordingly, it will be appreciated that the above described example implementations are merely examples and should not be construed to narrow the scope or spirit of the disclosure in any way. Other example implementations, aspects and advantages will become apparent from the following detailed description taken in conjunction with the accompanying figures which illustrate, by way of example, the principles of some described example implementations. BRIEF DESCRIPTION OF THE FIGURE(S)
[0017] Having thus described example implementations of the disclosure in general terms, reference will now be made to the accompanying figures, which are not necessarily drawn to scale, and wherein:
[0018] FIG. 1 illustrates a telecommunications system that includes one or more public land mobile networks (PLMNs) coupled to one or more external data networks, according to some example implementations of the present disclosure;
[0019] FIG. 2 illustrates a deployment of a PLMN, according to some example implementations;
[0020] FIG. 3 more particularly depicts aspects of the deployment of FIG. 2, according to some example implementations;
[0021] FIG. 4 illustrates a functional model for the common application programming interface (API) framework (CAPIF), according to some example implementations;
[0022] FIG. 5 is a signaling chart of security procedures for API invoker onboarding and renewal, according to some example implementations;
[0023] FIG. 6 illustrates an onboarding renewal security flow, according to some example implementations;
[0024] FIGS. 7A and 7B are flowcharts illustrating various steps in a method implemented at API invoker, according to various example implementations
[0025] FIGS. 8A, 8B, 8C, 8D, 8E and 8F are flowcharts illustrating various steps in a method implemented at a CAPIF core function, according to various example implementations; and
[0026] FIG. 9 illustrates an apparatus according to some example implementations. DETAILED DESCRIPTION
[0027] Some implementations of the present disclosure will now be described more fully hereinafter with reference to the accompanying figures, in which some, but not all implementations of the disclosure are shown. Indeed, various implementations of the disclosure may be embodied in many different forms and should not be construed as limited to the implementations set forth herein; rather, these example implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Like reference numerals refer to like elements throughout.
[0028] Unless specified otherwise or clear from context, references to first, second or the like should not be construed to imply a particular order. A feature described as being above another feature (unless specified otherwise or clear from context) may instead be below, and vice versa; and similarly, features described as being to the left of another feature else may instead be to the right, and vice versa. Also, while reference may be made herein to quantitative measures, values, geometric relationships or the like, unless otherwise stated, any one or more if not all of these may be absolute or approximate toaccount for acceptable variations that may occur, such as those due to engineering tolerances or the like.
[0029] As used herein, unless specified otherwise or clear from context, the “or” of a set of operands is the “inclusive or” and thereby true if and only if one or more of the operands is true, as opposed to the “exclusive or” which is false when all of the operands are true. Thus, for example, “[A] or [B]” is true if [A] is true, or if [B] is true, or if both [A] and [B] are true. Further, the articles “a” and “an” mean “one or more,” unless specified otherwise or clear from context to be directed to a singular form. Furthermore, it should be understood that unless otherwise specified, the terms “data,” “content,” “digital content,” “information,” and similar terms may be at times used interchangeably. The term “network” may refer to a group of interconnected computers including clients and servers; and within a network, these computers may be interconnected directly or indirectly by various means including via one or more switches, routers, gateways, access points or the like.
[0030] Reference may be made herein to terms specific to a particular system, architecture or the like, but it should be understood that example implementations of the present disclosure may be equally applicable to any of a number of systems, architectures and the like. For example, reference may be made to 3GPP technologies such as Global System for Mobile Communications (GSM), UMTS, LTE, LTE Advanced, 5G NR, 5G Advanced and 6G; however, it should be understood that example implementations of the present disclosure may be equally applicable to non-3GPP technologies such as IEEE 802, Bluetooth and Bluetooth Low Energy.
[0031] Further, as used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry); (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); or (c) hardware circuit(s) and / or processor(s), such as a microprocessor(s) or aportion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0032] The above definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0033] FIG. 1 illustrates a telecommunications system 100 according to various example implementations of the present disclosure. The telecommunications system generally includes one or more telecommunications networks. As shown, for example, the system includes one or more public land mobile networks (PLMNs) 102 coupled to one or more other external data networks 104 – notably including a wide area network (WAN) such as the Internet. Each of the PLMNs includes a core network (CN) 106 backbone such as the Evolved Packet Core (EPC) of LTE, the 5G core network (5GC) or the like; and each of the core networks and the Internet are coupled to one or more radio access networks (RANs) 108, air interfaces or the like that implement one or more radio access technologies (RATs). As used herein, a “network device” refers to any suitable device at a network side of a telecommunications network. Examples of suitable network devices are described in greater detail below.
[0034] In addition, the system includes one or more radio units that may be varyingly known as user equipment (UE) 110, terminal device, terminal equipment, mobile station or the like. The UE is generally a device configured to communicate with a network device or a further UE in a telecommunication network. The UE may be a portable computer (e.g., laptop, notebook, tablet computer), mobile phone (e.g., cell phone, smartphone), wearable computer (e.g., smartwatch), or the like. In other examples, the UE may be an Internet of Things (IoT) device, an industrial IoT (IIoT device), a vehicle equipped with a vehicle-to-everything (V2X) communication technology, or the like. In some examples, as referenced by 3GPP, the UE may be a narrowband IoT (NB-IoT)device, an enhanced machine-type communication (eMTC) device, a reduced capability (RedCap) device, an ambient IoT device, or the like.
[0035] In operation, these UEs may be configured to connect to one or more of the RANs 108 according to their particular radio access technologies to thereby access a particular CN 106 of a PLMN 102, or to access one or more of the external data networks 104 (e.g., the Internet). The external data network may be configured to provide Internet access, operator services, 3rd party services, etc. For example, the International Telecommunication Union (ITU) has classified 5G mobile network services into three categories: enhanced mobile broadband (eMBB), ultra-reliable and low-latency communications (URLLC), and massive machine type communications (mMTC) or massive internet of things (MIoT).
[0036] Examples of radio access technologies include 3GPP radio access technologies such as GSM, UMTS, LTE, LTE Advanced, 5G NR, 5G Advanced, and 6G. Other examples of radio access technologies include IEEE 802 technologies such as IEEE 802.11 (Wi-Fi), IEEE 802.15 (including 802.15.1 (WPAN / Bluetooth), 802.15.4 (Zigbee) and 802.15.6 (WBAN)), Bluetooth, Bluetooth Low Energy (BLE), ultra wideband (UWB), and the like. Generally, a radio access technology may refer to any 2G, 3G, 4G, 5G, 6G or higher generation mobile communication technology and their different versions, as well as to any other wireless radio access technology that may be arranged to interwork with such a mobile communication technology to provide access to the CN 106 of a mobile network operator (MNO).
[0037] In various examples, a RAN 108 may be configured as one or more macrocells, microcells, picocells, femtocells or the like. The RAN may generally include one or more radio access nodes that are configured to interact with UEs 110. In various examples, a radio access node may be referred to as a base station (BS), access point (AP), base transceiver station (BTS), Node B (NB), evolved NB (eNB), macro BS, NB (MNB) or eNB (MeNB), home BS, NB (HNB) or eNB (HeNB), next generation NB (gNB), enhanced gNB (en-gNB), next generation eNB (ng-eNB), or the like. The RAN may include some type of network controlling / governing entity responsible for control of the radio access nodes. The network controlling / governing entity and radio access node may be separate or integrated into a single apparatus. The network controlling / governingentity may include processing circuity configured to carry out various management functions, etc. The processing circuity may be associated with a memory, computer- readable storage medium or database for maintaining information required in the management functions.
[0038] A RAN 108 may be centralized or distributed. In various examples, components of a RAN may be interconnected by Ethernet, Gigabit Ethernet, Asynchronous Transfer Mode (ATM), optical fiber, dark fiber, passive wavelength division multiplexing (WDM), WDM passive optical network (WDM-PON), optical transport network (OTN), time sensitive networking (TSN) and / or any other data link layer network, possibly including radio links. The RAN may be connected to a CN 106 through one or more gateways, network functions or the like.
[0039] As will be appreciated, a PLMN 102 may be deployed in a number of different manners. In a 4G LTE deployment, the EPC is the CN 106, and the evolved UMTS terrestrial radio access network (E-UTRAN) is the RAN 108; and the E-UTRAN includes one or more eNBs (radio access nodes) configured to connect UEs 110 to the E- UTRAN to thereby access the EPC. FIG. 2 illustrates a deployment 200, such as a 5G or 6G deployment. As shown, the 5GC 202 is the CN, and the next generation (NG) radio access network (NG-RAN) 204 is the RAN; and the NG-RAN includes one or more gNBs 206 (radio access nodes) configured to connect UEs 208 to the NG-RAN to thereby access the 5GC. The term ‘gNB’ in 5G may correspond to the eNB in 4G LTE.
[0040] Some 4G LTE and 5G deployments are considered standalone (SA) deployments. Other deployments combine 4G LTE and 5G technologies, and are referred to as non-standalone (NSA) deployments. In some deployments, the E-UTRAN includes one or more ng-eNBs that are configured to communicate with the 5GC, and that may also be configured to communicate with one or more gNBs. Similarly, in another deployment, the NG-RAN may include one or more en-gNBs that are configured to communicate with the EPC, and that may also be configured to communicate with one or more eNBs. In various instances, a single UE 110, a dual-mode or multimode UE, may support multiple (two or more) RANs—thereby being configured to connect to multiple RANs, such as 4G LTE and 5G.
[0041] FIG. 3 more particularly depicts aspects of the deployment 200 for a MNO, according to some example implementations. As shown, the deployment includes the 5GC 202, and NG-RAN 204 with one or more gNBs 206 configured to connect UEs 208 to the NG-RAN to thereby access the 5GC. The 5GC may include a number of network functions (NFs) divided between the control plane and the user plane. In particular, the 5GC may include, for example, an access and mobility management function (AMF) 302, a session management function (SMF) 304, a user plane function (UPF) 306, a network exposure function (NEF) 308, and / or an application function (AF) 310. Other examples of suitable NFs include a network repository function (NRF), a network slice selection function (NSSF), a policy control function (PCF), a unified data management (UDM), or the like. Also shown is a server hosting an application, referred to as application server (AS) 312.
[0042] In the control plane, the AMF 302 is configured to provide UE-based authentication, authorization, mobility management, etc. The SMF 304 is configured to provide various functionality including session management (SM), UE Internet Protocol (IP) address allocation and management, selection and control of UPF(s) 306, control part of policy enforcement and Quality of Service (QoS), lawful intercept, termination of SM parts of NAS messages, Downlink Data Notification (DNN), roaming functionality, handle local enforcement to apply QoS for Service Level Agreements (SLAs), charging data collection and charging interface, etc. If the UE 208 has multiple sessions, different SMFs may be allocated to each session to manage them individually and possibly provide different functionalities per session.
[0043] The UPF 306 supports various user plane operations and functionalities, such as packet routing and forwarding, traffic handling (e.g., QoS enforcement), an anchor point for intra-RAT / inter-RAT mobility (when applicable), packet inspection and policy rule enforcement, lawful intercept (UP collection), traffic accounting and reporting, etc. The UPF is the point of interconnect between the 5GC and at least one external data network (DN) 316 (i.e., point of ingress or egress for a DN), and routes packets to and from the DN. The DN may be configured to provide Internet access, operator services, 3rd party services, etc. The
[0044] The AF 310 may interact with the 5GC 202 to enable the deployment of specific services and applications. The AF communicates with other NFs to request and manage network resources, ensuring that the network adapts to the requirements of different applications and services. The NEF 308 allows authorized third-party applications and services to access specific network functions and services in a controlled manner. The NEF enables the exposure of network capabilities to external entities, fostering innovation and the development of new services.
[0045] In some deployments, such as deployment 200, operations of the gNB 206 or other radio access node may be carried out, at least partly, in a central / centralized unit (CU), such as a server, host or node, operationally coupled to a distributed unit (DU), such as a radio head / node. It is also possible that node operations may be distributed among a plurality of servers, hosts or nodes. It should also be understood that the distribution of work between 5GC 202 (or other CN) operations and gNB (or other radio access node) operations may vary depending on implementation.
[0046] A 5G network architecture may be based on a so-called CU-DU split. One gNB-CU (central node) may control one or more gNB-DUs. The gNB-CU may control a plurality of spatially separated gNB-DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some example implementations, however, the gNB-DUs (also called DU) may include, for example, a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the gNB-CU (also called a CU) may include the layers above the RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC), and an internet protocol (IP) layer. Other functional splits are also possible. It is considered that a skilled person is familiar with the open systems interconnection (OSI) model and the functionalities within each layer.
[0047] In some example implementations, the server or CU may generate a virtual network through which the server communicates with the radio node. In general, virtual networking may involve a process of combining hardware and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Such virtual network may provide flexible distribution of operations between the server and the radio head / node. In practice, any digital signal processing taskmay be performed in either the CU or the DU, and the boundary where the responsibility is shifted between the CU and the DU may be selected according to implementation.
[0048] In 3GPP, the common application programming interface (API) Framework (CAPIF) defines a standardized set of interfaces and protocols for NFs to expose their capabilities to external applications and other NFs. The CAPIF defines common API structures, data formats, and communication protocols for various NFs, and enables different applications and NFs to interact with each other, regardless of their implementation details. The CAPIF provides mechanisms (e.g., publish service APIs, authorization, logging, charging) to support service API operations. It enables one or more API invokers to discover and communicate with service APIs from API providers.
[0049] FIG. 4 illustrates a functional model 400 for the CAPIF. As shown, the CAPIF may be hosted within a PLMN trust domain 402 including a MNO’s PLMN 102 or a stand-alone non-public network (SNPN). An API invoker 404 requests access to a NF’s capabilities through CAPIF APIs. The API invoker may be provided by a third-party application provider who has a SLA with the MNO. An API invoker may reside outside or within the same trust domain as the PLMN.
[0050] In the PLMN trust domain, the CAPIF includes a CAPIF core function (CCF) 406 and an API provider domain 408, and the API provider domain includes an API exposing function (AEF) 410, API publishing function (APF) 412, and API management function (AMF) 414 (together known as API provider domain functions).
[0051] The CAPIF core function 406 performs onboarding and offboarding of API invokers 404. The CAPIF core function handles authentication, authorization, and routing of API requests from API invokers. It verifies the API invoker’s identity, checks permissions, and directs the request to an appropriate API exposing function within the network function. The API exposing function 410 is the provider of service APIs, and serves as a service communication entry point of the service API to the API invokers. The API publishing function 412 enables an API provider to publish service APIs information in order to enable the discovery of service APIs by the API invoker, and the API management function 414 enables administration of service APIs by the API provider.
[0052] As also shown, the CAPIF includes a number of reference points between the various entities. The API invoker 404 within the PLMN trust domain 402 interacts withthe CAPIF core function 406 via CAPIF-1, and interacts with the API exposing function 410 via CAPIF-2. The API invoker from outside the PLMN trust domain interacts with the CAPIF core function via CAPIF-1e, and interacts with the API exposing function via CAPIF-2e. The API exposing function, the API publishing function 412 and the API management function 414 of the API provider domain 408 interacts with the CAPIF core function via respective ones of CAPIF-3, CAPIF-4 and CAPIF-5.
[0053] The CAPIF may be implemented in any of a number of different manners. In some examples, the API invoker 404 may be implemented by an AF 310, an AS 312, a service capability server (SCS) or the like. Likewise, in some examples, the CAPIF core function 406 and API provider domain functions (API exposing function 410, API publishing function 412, API management function 414) may be implemented by a NEF 308, a service capability exposure function (SCEF) or the like.
[0054] Before an API invoker 404 is authorized to invoke a service API using the CAPIF, the API invoker needs to be known to the CAPIF core function 406. In this regard, as indicated above, the CAPIF core function is responsible for onboarding the API invoker. Onboarding is a registration process that enables the API invoker to subsequently access the CAPIF and the service APIs. The onboarding may include the provisioning of onboarding information, which may optionally include an API Invoker’s onboard secret (onboard_secret). As currently specified, the registration process is a one- time registration process, with the onboarding typically valid for a long time (although the onboarding may optionally include an expiry time). The onboard secret may also remain valid as long as the API invoker is registered, which may create some undesirable vulnerability.
[0055] From the API invoker side, the only current way to renew an onboarding is to initiate an offboarding from the CAPIF core function 406, and then initiate a new onboarding with the CAPIF core function. The procedure may be triggered by the API invoker 404 over CAPIF-1 or CAPIF-1e, but offboarding from the CAPIF core function makes the API invoker no longer a recognized user of the CAPIF core function. By current standards not having a dynamic renewal in which the service may continue without offboarding, a number of issues may be created. In particular, for example, theAPI invoker may be unable to continue to use the service during the offboarding and new onboarding renewal process.
[0056] Example implementations of the present disclosure therefore provide a service that may be triggered by the API invoker 404 for renewal of its onboarding at the CAPIF core function 406. This may include renewal or update of the API invoker’s onboard registration, onboard secret, and / or API invoker enrollment details information (e.g., API list, API invoker information). According to example implementations, the API invoker may renew its onboarding, which may include updated API invoker enrollment details information, without loss of the API invoker profile (API invoker context information) at the already registered at the CAPIF core function. Example implementations may also provide a CAPI event (e.g., API_INVOKER_ONBOARDING_DUE_TO_EXPIRE), which may be subscribed by the API invoker to receive advance notification about expiration of its onboarding.
[0057] Some example implementations of the present disclosure therefore provide an API invoker 404 and a CAPIF core function 406 with which the API invoker is onboarded from an onboarding based on onboarding information. The API invoker and the CAPIF core function may be configured to establish a secure session. The API invoker may be configured to send an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding, and the CAPIF core function may be configured to receive the onboarding update request message from the API invoker. In various examples, the onboarding update request message may include API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, such as API invoker information and / or a list of API(s) being enrolled for the renewal. Additionally or alternatively, the onboarding update request message may include a request for an onboard secret for the renewal, and / or a proposed expiration time for the renewal.
[0058] The CAPIF core function 406 may be configured to validate the onboarding update request message and the onboarding based on the onboarding information, and perform a renewal of the onboarding based on the onboarding update request message. In various examples depending on the onboarding update request message, renewal of the onboarding may include the CAPIF core function configured to update the API invokerenrollment details information at the CAPIF core function. Additionally or alternatively, renewal of the onboarding may include the CAPIF core function configured to generate the onboard secret based on the request.
[0059] In some examples, the CAPIF core function 406 may be configured to determine an expiration time for the renewal based on an internal policy of the CAPIF core function. In examples in which the onboarding update request message inclues a proposed expiration time for the renewal, the CAPIF core function may be configured to determine the expiration time based on the proposed expiration time and / or the internal policy of the CAPIF core function.
[0060] After performing the renewal of the onboarding, the CAPIF core function 406 may be configured to send an onboarding update response message to the API invoker based on the renewal, and the API invoker 404 may be configured to receive the onboarding update response message. The onboarding update response message may include the API invoker enrollment details information as updated, and / or the onboard secret generated by the CAPIF core function based on the request. Additionally or alternatively, the onboarding update response message may include the expiration time for the renewal, determined at the CAPIF core function based on the proposed expiration time and / or internal policy of the CAPIF core function.
[0061] In some examples, the CAPIF core function 406 may be further configured to determine an advance notification time that is before expiration of the onboarding, and send an advance notification regarding expiration of the onboarding. The API invoker 404 may be configued to receive the advance notification regarding expiration of the onboarding, and send the onboarding update request message based on the advance notification, before expiration of the onboarding. As indicated above, in some examples, this advance notification may be provided by a CAPIF event (e.g., API_INVOKER_ONBOARDING_DUE_TO_EXPIRE), which may be subscribed by the API invoker.
[0062] To further illustrate some example implementations of the present disclosure, FIG. 5 is a signaling chart 500 of security procedures for API invoker onboarding and renewal. As shown at step 501, the API invoker 404 obtains onboarding enrollment information from the API provider domain 408, which may be used to authenticate andestablish secure transport layer security (TLS) communication with the CAPIF core function 406 during the onboarding. The enrollment information may include, for example, information regarding the CAPIF core function (e.g., address, root certification authority (CA) certificate). The enrollment information may also include an onboarding credential (also at times referred to as an enrollment credential), such as an access token (e.g. OAuth 2.0 access token).
[0063] As shown at step 502, the API invoker 404 and the CAPIF core function 406 establish a secure session based on TLS (server-side certificate authentication), and the API invoker uses the enrollment information obtained in step 501 to establish the TLS session with the CAPIF core function.
[0064] After successful establishment of the TLS session, the API invoker 404 at step 503 sends an onboard API invoker request message to the CAPIF core function 406. The onboard API invoker request message carries the onboarding credential (e.g., access token) obtained in step 501. The API invoker may also generate a key pair {private key, public key}, and provide the public key in the onboard API invoker request. Additionally, the onboard API invoker request message may include a list of one or more APIs the API invoker is requesting to access.
[0065] The CAPIF core function 406 at step 504 performs a validation of the onboarding credential, and that the onboard API invoker request message includes necessary information for onboarding the API invoker 404. If the validation is successful, the CAPIF core function provisions or otherwise generates an API invoker profile, such as in the manner specified in 3GPP TS 23.222. The API invoker profile may include an assigned API invoker identity (ID), and and a list of API(s) and / or type(s) of APIs that the API invoker can access.
[0066] The CAPIF core function 406 may also create an API invoker certificate for the assigned API invoker ID and public key (or the API invoker certificate may be issued by a third party and provided in the onboard API invoker request message). This certificate may be used by the API invoker for subsequent authentication procedures with the CAPIF core function and may be used for establishing a secure connection and authentication with the API exposing function 410. In this regard, the API invoker profile may also contain a selected method for AEF authentication and authorization between theAPI invoker and the API exposing function. The CAPIF core function may also optionally generate an onboard secret, such as for CAPIF-2e security. The onboard secret value may remain the same during the lifetime of the onboarding, and may be bound to the CAPIF core function specific API invoker ID.
[0067] The CAPIF core function 406 at step 505 responds to the API invoker 404 with an onboard API invoker response message. The onboard API invoker response message may include onboarding information from the API invoker profile, which may include information to allow the API invoker to be authenticated and to obtain authorization for service APIs. In particular, for example, the onboard API invoker response message may include CAPIF core function assigned API invoker ID, AEF authentication and authorization information (if generated in step 504), API invoker’s certificate, and the API invoker onboard secret (if generated by the CAPIF core function). The onboard API invoker response message may also include the list of API(s) and / or type(s) of APIs that the API invoker can access.
[0068] During lifetime of the onboarding, the API invoker 404 at step 506 sends an onboarding update request message (OnboardingUpdateRequest) to renew its onboarding with the CAPIF core function 406. The onboarding update request message may include the API invoker ID (APIInvokerID), and onboarding information (OnboardingInformation) received by the API invoker at step 505. The onboarding update request message may also include API invoker enrollment details information or parameters for update, such as API invoker information (ApiInvokerInformation) and / or a list of API(s) being enrolled for the renewal (APIList). Additionally or alternatively, the onboarding update request message may include a request for the CAPIF core function to generate a new onboard secret (GenerateOnBoardSecret=True / False), and / or a proposed expiration time (ProposedExpirationTIme).
[0069] The CAPIF core function 406 receives the onboarding update request message, and validates the onboarding update request message and the onboarding based on the onboarding information. If the onboarding update request message is validated, the CAPIF core function performing a renewal of the onboarding based on the onboarding update request message, as shown at 507a, 507b, 507c. In this regard, the CAPIF core function may at step 507a generate a new onboard secret when the onboarding updaterequest message includes the relevant request, which may be expressed by setting GenerateOnBoardSecret to True. If GenerateOnBoardSecret is not received or set to False, an existing onboard secret (if previously generated) may be reused.
[0070] Additionally or alternatively, the CAPIF core function 406 may at step 507b calculate a new expiration time for the renewal. When the onboarding update request message includes a ProposedExpirationTime, the CAPIF core function may calculate a negotiated expiration time based on the proposed expiration time and / an internal policy. When the onboarding update request message does not include a proposed expiration time, the CAPIF core function may still calculate an expiration time of the renewal based on its internal policy. And as shown at step 507c, the CAPIF core function may update any API invoker enrollment details information or parameters included in the onboarding update request message (e.g., ApiInvokerInformation, APIList).
[0071] The CAPIF core function 406 then at step 508 sends an onboarding update response message (OnboardingUpdateResponse) to the API invoker 404. The onboarding update response message may include a status of the onboarding / renewal (OnboardingStatus), the onboarding information (OnboaringInformation), and any API invoker enrollment details information or parameters included in the onboarding update request message (e.g., ApiInvokerInformation, APIList). The onboarding update response message may also include the new expiration time.
[0072] FIG. 6 illustrates an onboarding renewal security flow 600, according to some example implementations. As shown at block 602, as a pre-requisite to onboarding renewal, the API invoker 404 and the CAPIF core function 406 may be provisioned with the necessary onboarding enrollment information for the API Invoker, and the API invoker wants to renew its onboarding, such as its API registration and / or onboard secret. Initially, as shown at 604 and 606, the API invoker attempts to establish a secure connection with the CAPIF core function. If the onboarding session cannot be secured, the session may be released and the onboarding renewal flow ends.
[0073] If the session is secured, the API invoker 404 requests renewal of its onboarding using an onboarding update request message (OnboardingUpdateResponse) that includes onboarding information, as shown at block 608.
[0074] The CAPIF core function 406 receives the onboarding update request message, and validates the onboarding update request message and the onboarding based on the onboarding information, as shown at blocks 610 and 612. If the onboarding update request message is valid, the CAPIF core function creates and returns an onboarding update response message (OnboardingUpdateResponse) based on the renewal, as shown at block 614. If the CAPIF core function cannot validate the onboarding update request message, the CAPIF core function may reject the renewal request, and return the onboarding update response message that contains an error response to the API Invoker instead, as shown at block 616. Following return of the onboarding update response message (either successful or unsuccessful), the secure session is torn down and the onboarding security flow ends, as shown at block 618.
[0075] FIGS. 7A and 7B are flowcharts illustrating various steps in a method 700 implemented at an API invoker, according to various example implementations. The method includes establishing a secure session with a CAPIF core function with which the API invoker is onboarded from an onboarding based on onboarding information, as shown at block 702 of FIG. 7A. The method includes sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding, as shown at block 704. And the method includes receiving an onboarding update response message from the CAPIF core function based on the renewal, as shown at block 706.
[0076] In some examples, the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0077] In some examples, the onboarding update request message further includes a request for an onboard secret for the renewal, and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
[0078] In some examples, the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
[0079] In some examples, the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expiration time or an internal policy of the CAPIF core function.
[0080] In some examples, method further comprises receiving an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, as shown at block 708 of FIG. 7B. In some of these examples, the onboarding update request message is sent at block 704 based on the advance notification.
[0081] FIGS. 8A – 8F are flowcharts illustrating various steps in a method 800 implemented at a CAPIF core function, according to various example implementations. The method includes establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information, as shown at block 802 of FIG. 8A. The method includes receiving an onboarding update request message including the onboarding information from the API invoker, as shown at block 804. The method includes validating the onboarding update request message and the onboarding based on the onboarding information, as shown at block 806. The method includes performing a renewal of the onboarding based on the onboarding update request message, as shown at block 808. And the method includes sending an onboarding update response message to the API invoker based on the renewal, as shown at block 810.
[0082] In some examples, the onboarding update request message further includes API invoker enrollment details information. In some of these examples, performing the renewal at block 808 includes updating the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated, as shown at block 812 of FIG. 8B.
[0083] In some examples, the onboarding update request message further includes a request for an onboard secret for the renewal. In some of these examples, performing the renewal at block 808 includes generating the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated, as shown at block 814 of FIG. 8C.
[0084] In some examples, performing the renewal at block 808 includes determining an expiration time for the renewal based on an internal policy of the CAPIF core function, as shown at block 816 of FIG. 8D. In some of these examples, the onboarding update response message includes the expiration time.
[0085] In some examples, the onboarding update request message further includes a proposed expiration time for the renewal, performing at block 808 the renewal includes determining expiration time for the renewal based on at least one of the proposed expiration time or an internal policy of the CAPIF core function, as shown at block 818 of FIG. 8E.
[0086] In some examples, method 800 further includes determining an advance notification time that is before expiration of the onboarding, as shown at block 820 of FIG. 8F. The method in some of these examples also includes sending an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, as shown at block 822. And in some of these examples, the onboarding update request message is received at block 804 based on the advance notification.
[0087] According to example implementations of the present disclosure, a telecommunications system 100 or PLMN 102, and its components such as a UE 110, CN 106, RAN 108, 5GC 202, NG-RAN 204, gNB 206, UE 208, AMF 302, SMF 304, UPF 306, NEF 308, AF 310, AS 312, API invoker 404 and / or CAPIF core 406 function may be implemented by various means. Means for implementing the system and its components may include hardware, firmware, software, or combinations thereof. In some examples, one or more apparatuses may be configured to function as or otherwise implement the system and its components shown and described herein. In examples involving more than one apparatus, the respective apparatuses may be connected to or otherwise in communication with one another in a number of different manners, such as directly or indirectly via a wired or wireless network or the like.
[0088] According to some example implementations, at least some of the method 700 described with respect to FIGS. 7A and 7B may be carried out by an apparatus comprising means for performing functions corresponding steps of the method. Similarly, at least some of the method 800 described with respect to FIGS. 8A-8F may be carriedout by an apparatus comprising means for performing functions corresponding steps of the method. Examples of a suitable apparatus may include an API invoker, CAPIF core function, a NF (e.g., NEF, AF, AS, SCS, SCEF) or any suitable apparatus, such as a server, host or node.
[0089] FIG. 9 illustrates an apparatus 900 in which means for performing various functions includes hardware, alone or under direction of one or more computer programs from a computer-readable storage medium or other memory, such as computer memory, according to some example implementations of the present disclosure. The apparatus may include one or more of each of a number of components such as, for example, processing circuitry 902 connected to computer-readable storage medium or other memory 904.
[0090] The processing circuitry 902 may be composed of one or more processors alone or in combination with one or more computer-readable storage media. The processing circuitry is generally any piece of computer hardware that is capable of processing information such as, for example, data, computer programs and / or other suitable electronic information. The processing circuitry is composed of a collection of electronic circuits some of which may be packaged as an integrated circuit or multiple interconnected integrated circuits (an integrated circuit at times more commonly referred to as a “chip”). The processing circuitry may be configured to execute computer programs, which may be stored onboard the processing circuitry or otherwise stored in the memory 904 (of the same or another apparatus).
[0091] The processing circuitry 902 may be a number of processors, a multi-core processor or some other type of processor, depending on the particular implementation. Further, the processing circuitry may be implemented using a number of heterogeneous processor systems in which a main processor is present with one or more secondary processors on a single chip. As another illustrative example, the processing circuitry may be a symmetric multi-processor system containing multiple processors of the same type. In yet another example, the processing circuitry may be embodied as or otherwise include one or more ASICs, FPGAs or the like. Thus, although the processing circuitry may be capable of executing a computer program to perform one or more functions, the processing circuitry of various examples may be capable of performing one or more functions without the aid of a computer program. In either instance, the processingcircuitry may be appropriately programmed to perform functions or operations according to example implementations of the present disclosure.
[0092] The memory 904 is generally any piece of computer hardware that is capable of storing information such as, for example, data, computer programs, instructions 906 (e.g., computer-readable program code) and / or other suitable information either on a temporary basis and / or a permanent basis. The memory may include volatile and / or non- volatile memory, and may be fixed or removable. Examples of suitable memory include recording media, random access memory (RAM), read-only memory (ROM), a hard drive, a flash memory, a thumb drive, a removable computer diskette, an optical disk or some combination thereof.
[0093] The memory 904 is a non-transitory device capable of storing information. One example of a suitable memory is a computer-readable storage medium, which is distinguishable from a computer-readable transmission medium capable of carrying information from one location to another. Examples of suitable computer-readable transmission media comprise electronic carrier signals, telecommunications signals, software distribution packages, or some combination thereof. As used herein, the term “non-transitory” is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM versus ROM). A computer-readable medium as described herein generally refers to a computer-readable storage medium or computer-readable transmission medium. A computer-readable medium is any entity or device capable in which information, such as one or more computer programs or portions thereof, may be stored and carried.
[0094] In addition to the memory 904 (e.g., computer-readable storage medium), the processing circuitry 902 may also be connected to one or more interfaces for displaying, transmitting and / or receiving information. The interfaces may include a communications interface 908 and / or one or more user interfaces (e.g., display, user input interface). The communications interface may be configured to transmit and / or receive information, such as to and / or from other apparatus(es), network(s) or the like. The communications interface may be configured to transmit and / or receive information by physical (wired) and / or wireless communications links. Examples of suitable communication interfaces include a network interface controller (NIC), wireless NIC (WNIC) or the like.
[0095] Execution of the instructions 906 by the processing circuitry 902, or storage of the instructions in the memory 904, supports combinations of operations for implementing example implementations of the present disclosure. In this manner, an apparatus 900 may comprise at least one processing circuitry and at least one memory coupled to the at least one processing circuitry, where the at least one processing circuitry is configured to execute instructions stored in the at least one memory. It will also be understood that one or more functions, and combinations of functions, may be implemented by special purpose hardware-based computer systems and / or processing circuitry which perform the specified functions, or combinations of special purpose hardware and program code instructions.
[0096] Some example implementations of the present disclosure may also be carried out in the form of a computer process defined by one or more computer programs or portions thereof. Example implementations of the present disclosure may be carried out by executing at least one portion of a computer program comprising instructions. The computer program may be in source code form, object code form, or in some intermediate form. The computer program may be stored in a computer-readable medium that is readable by a computer, processing circuitry or other suitable apparatus. As indicated above, for example, the computer program may be stored in a memory, such as a computer-readable storage medium. Additionally or alternatively, for example, the computer program may be stored in a computer-readable transmission medium. The coding of software for carrying out example implementations of the present disclosure is well within the scope of a person of ordinary skill in the art.
[0097] As will be appreciated, any suitable instructions may be loaded onto a computer, a processing circuitry or other programmable apparatus from a memory or a computer-readable medium (e.g., computer-readable storage medium, computer-readable transmission medium) to produce a particular machine, such that the particular machine becomes a means for implementing the functions specified herein. The instructions may also be stored in a computer-readable medium that can direct a computer, a processing circuitry or other programmable apparatus to function in a particular manner to thereby generate a particular machine or particular article of manufacture. In some examples, the instructions stored in the computer-readable medium may produce an article ofmanufacture, where the article of manufacture becomes a means for implementing functions described herein. The instructions may be retrieved from a computer-readable medium and loaded into a computer, processing circuitry or other programmable apparatus to configure the computer, processing circuitry or other programmable apparatus to execute operations to be performed on or by the computer, processing circuitry or other programmable apparatus.
[0098] Retrieval, loading and execution of instructions comprising program code instructions may be performed sequentially such that one instruction is retrieved, loaded and executed at a time. In some example implementations, retrieval, loading and / or execution may be performed in parallel such that multiple instructions are retrieved, loaded, and / or executed together. Execution of the program code instructions may produce a computer-implemented process such that the instructions executed by the computer, processing circuitry or other programmable apparatus provide operations for implementing functions described herein.
[0099] As explained above and reiterated below, the present disclosure includes, without limitation, the following example implementations.
[0100] Clause 1. An apparatus to implement an application programming interface (API) invoker, the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: establish a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; send an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receive an onboarding update response message from the CAPIF core function based on the renewal.
[0101] Clause 2. The apparatus of clause 1, wherein the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0102] Clause 3. The apparatus of clause 1 or clause 2, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
[0103] Clause 4. The apparatus of any of clauses 1 to 3, wherein the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
[0104] Clause 5. The apparatus of any of clauses 1 to 4, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 6. The apparatus of any of clauses 1 to 5, wherein at least one processing circuitry is configured to execute the instructions to cause the apparatus to further receive an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, and wherein the onboarding update request message is sent based on the advance notification.
[0105] Clause 7. An apparatus to implement an application programming interface (API) invoker, the apparatus comprising: means for establishing a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; means for sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and means for receiving an onboarding update response message from the CAPIF core function based on the renewal.
[0106] Clause 8. The apparatus of clause 7, wherein the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0107] Clause 9. The apparatus of clause 7 or clause 8, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
[0108] Clause 10. The apparatus of any of clauses 7 to 9, wherein the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
[0109] Clause 11. The apparatus of any of clauses 7 to 10, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 12. The apparatus of any of clauses 7 to 11, wherein apparatus further comprises means for receiving an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, and wherein the onboarding update request message is sent based on the advance notification.
[0110] Clause 13. A method implemented at an application programming interface (API) invoker, the method comprising: establishing a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receiving an onboarding update response message from the CAPIF core function based on the renewal.
[0111] Clause 14. The method of clause 13, wherein the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0112] Clause 15. The method of clause 13 or clause 14, wherein the onboarding update request message further includes a request for an onboard secret for the renewal,and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
[0113] Clause 16. The method of any of clauses 13 to 15, wherein the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
[0114] Clause 17. The method of any of clauses 13 to 16, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 18. The method of any of clauses 13 to 17, wherein method further comprises receiving an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, and wherein the onboarding update request message is sent based on the advance notification.
[0115] Clause 19. A computer-readable storage medium implemented at an application programming interface (API) invoker, the computer-readable storage medium being non-transitory and having instructions stored therein that, in response to execution by at least one processing circuitry, causes an apparatus to at least: establish a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; send an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receive an onboarding update response message from the CAPIF core function based on the renewal.
[0116] Clause 20. The computer-readable storage medium of clause 19, wherein the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0117] Clause 21. The computer-readable storage medium of clause 19 or clause 20, wherein the onboarding update request message further includes a request for an onboardsecret for the renewal, and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
[0118] Clause 22. The computer-readable storage medium of any of clauses 19 to 21, wherein the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
[0119] Clause 23. The computer-readable storage medium of any of clauses 19 to 22, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 24. The computer-readable storage medium of any of clauses 19 to 23, wherein computer-readable storage medium has further instructions stored therein that, in response to execution by the at least one processing circuitry, causes the apparatus to further receive an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, and wherein the onboarding update request message is sent based on the advance notification.
[0120] Clause 25. An apparatus comprising means for performing the method of any of clauses 13 to 18.
[0121] Clause 26. A computer-readable medium comprising computer-readable program code that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 13 to 18.
[0122] Clause 27. A computer-readable storage medium comprising computer- readable program code that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 13 to 18.
[0123] Clause 28. A computer program comprising computer-readable program code that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 13 to 18.
[0124] Clause 29. An apparatus to implement a common application programming interface (API) framework (CAPIF) core function, the apparatus comprising: at least onememory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: establish a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receive an onboarding update request message including the onboarding information from the API invoker; validate the onboarding update request message and the onboarding based on the onboarding information; perform a renewal of the onboarding based on the onboarding update request message; and send an onboarding update response message to the API invoker based on the renewal.
[0125] Clause 30. The apparatus of clause 29, wherein the onboarding update request message further includes API invoker enrollment details information, the apparatus caused to perform the renewal includes the apparatus caused to update the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0126] Clause 31. The apparatus of clause 29 or clause 30, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, the apparatus caused to perform the renewal includes the apparatus caused to generate the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated.
[0127] Clause 32. The apparatus of any of clauses 29 to 31, wherein the apparatus caused to perform the renewal includes the apparatus caused to determine an expiration time for the renewal based on an internal policy of the CAPIF core function, and the onboarding update response message includes the expiration time.
[0128] Clause 33. The apparatus of any of clauses 29 to 32, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the apparatus caused to perform the renewal includes the apparatus caused to determine expiration time for the renewal based on at least one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 34. The apparatus of any of clauses 29 to 33, wherein at least one processing circuitry is configured to execute the instructions to cause the apparatus to further at least: determine an advance notification time that is before expiration of the onboarding; andsend an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, and wherein the onboarding update request message is received based on the advance notification.
[0129] Clause 35. An apparatus to implement a common application programming interface (API) framework (CAPIF) core function, the apparatus comprising: means for establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; means for receiving an onboarding update request message including the onboarding information from the API invoker; means for validating the onboarding update request message and the onboarding based on the onboarding information; means for performing a renewal of the onboarding based on the onboarding update request message; and means for sending an onboarding update response message to the API invoker based on the renewal.
[0130] Clause 36. The apparatus of clause 35, wherein the onboarding update request message further includes API invoker enrollment details information, the means for performing the renewal includes means for updating the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0131] Clause 37. The apparatus of clause 35 or clause 36, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, the means for performing the renewal includes means for generating the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated.
[0132] Clause 38. The apparatus of any of clauses 35 to 37, wherein the means for performing the renewal includes means for determining an expiration time for the renewal based on an internal policy of the CAPIF core function, and the onboarding update response message includes the expiration time.
[0133] Clause 39. The apparatus of any of clauses 35 to 38, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the means for performing the renewal includes means for determining expiration time for the renewal based on at least one of the proposed expiration time or an internal policy of the CAPIF core function.Clause 40. The apparatus of any of clauses 35 to 39, wherein apparatus further comprises: means for determining an advance notification time that is before expiration of the onboarding; and means for sending an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, and wherein the onboarding update request message is received based on the advance notification.
[0134] Clause 41. A method implemented at a common application programming interface (API) framework (CAPIF) core function, the method comprising: establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receiving an onboarding update request message including the onboarding information from the API invoker; validating the onboarding update request message and the onboarding based on the onboarding information; performing a renewal of the onboarding based on the onboarding update request message; and sending an onboarding update response message to the API invoker based on the renewal.
[0135] Clause 42. The method of clause 41, wherein the onboarding update request message further includes API invoker enrollment details information, performing the renewal includes updating the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0136] Clause 43. The method of clause 41 or clause 42, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, performing the renewal includes generating the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated.
[0137] Clause 44. The method of any of clauses 41 to 43, wherein performing the renewal includes determining an expiration time for the renewal based on an internal policy of the CAPIF core function, and the onboarding update response message includes the expiration time.
[0138] Clause 45. The method of any of clauses 41 to 44, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and performing the renewal includes determining expiration time for the renewal based on atleast one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 46. The method of any of clauses 41 to 45, wherein method further comprises: determining an advance notification time that is before expiration of the onboarding; and sending an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, and wherein the onboarding update request message is received based on the advance notification.
[0139] Clause 47. A computer-readable storage medium implemented at a common application programming interface (API) framework (CAPIF) core function, the computer-readable storage medium being non-transitory and having instructions stored therein that, in response to execution by at least one processing circuitry, causes an apparatus to at least: establish a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receive an onboarding update request message including the onboarding information from the API invoker; validate the onboarding update request message and the onboarding based on the onboarding information; perform a renewal of the onboarding based on the onboarding update request message; and send an onboarding update response message to the API invoker based on the renewal.
[0140] Clause 48. The computer-readable storage medium of clause 47, wherein the onboarding update request message further includes API invoker enrollment details information, the apparatus caused to perform the renewal includes the apparatus caused to update the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
[0141] Clause 49. The computer-readable storage medium of clause 47 or clause 48, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, the apparatus caused to perform the renewal includes the apparatus caused to generate the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated.
[0142] Clause 50. The computer-readable storage medium of any of clauses 47 to 49, wherein the apparatus caused to perform the renewal includes the apparatus caused todetermine an expiration time for the renewal based on an internal policy of the CAPIF core function, and the onboarding update response message includes the expiration time.
[0143] Clause 51. The computer-readable storage medium of any of clauses 47 to 50, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the apparatus caused to perform the renewal includes the apparatus caused to determine expiration time for the renewal based on at least one of the proposed expiration time or an internal policy of the CAPIF core function. Clause 52. The computer-readable storage medium of any of clauses 47 to 51, wherein computer-readable storage medium has further instructions stored therein that, in response to execution by the at least one processing circuitry, causes the apparatus to further at least: determine an advance notification time that is before expiration of the onboarding; and send an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, and wherein the onboarding update request message is received based on the advance notification.
[0144] Clause 53. An apparatus comprising means for performing the method of any of clauses 41 to 46.
[0145] Clause 54. A computer-readable medium comprising computer-readable program code that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 41 to 46.
[0146] Clause 55. A computer-readable storage medium comprising computer- readable program code that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 41 to 46.
[0147] Clause 56. A computer program comprising computer-readable program code that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 41 to 46.
[0148] Many modifications and other implementations of the disclosure set forth herein will come to mind to one skilled in the art to which the disclosure pertains having the benefit of the teachings presented in the foregoing description and the associated figures. Therefore, it is to be understood that the disclosure is not to be limited to the specific implementations disclosed and that modifications and other implementations are intended to be included within the scope of the appended claims. Moreover, although theforegoing description and the associated figures describe example implementations in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative implementations without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as may be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.
Claims
WHAT IS CLAIMED IS:
1. An apparatus to implement an application programming interface (API) invoker, the apparatus comprising: means for establishing a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; means for sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and means for receiving an onboarding update response message from the CAPIF core function based on the renewal.
2. The apparatus of claim 1, wherein the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
3. The apparatus of claim 1 or claim 2, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
4. The apparatus of any of claims 1 to 3, wherein the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
5. The apparatus of any of claims 1 to 4, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expirationtime or an internal policy of the CAPIF core function.
6. The apparatus of any of claims 1 to 5, wherein apparatus further comprises means for receiving an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, and wherein the onboarding update request message is sent based on the advance notification.
7. A method implemented at an application programming interface (API) invoker, the method comprising: establishing a secure session with a common API framework (CAPIF) core function with which the API invoker is onboarded from an onboarding based on onboarding information; sending an onboarding update request message including the onboarding information to the CAPIF core function for a renewal of the onboarding; and receiving an onboarding update response message from the CAPIF core function based on the renewal.
8. The method of claim 7, wherein the onboarding update request message further includes API invoker enrollment details information for update of the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
9. The method of claim 7 or claim 8, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, and the onboarding update response message includes the onboard secret generated by the CAPIF core function based on the request.
10. The method of any of claims 7 to 9, wherein the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on an internal policy of the CAPIF core function.
11. The method of any of claims 7 to 10, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the onboarding update response message includes an expiration time for the renewal, determined at the CAPIF core function based on at least one of the proposed expiration time or an internal policy of the CAPIF core function.
12. The method of any of claims 7 to 11, wherein method further comprises receiving an advance notification regarding expiration of the onboarding, before expiration of the onboarding and at an advance notification time determined at the CAPIF core function, and wherein the onboarding update request message is sent based on the advance notification.
13. An apparatus to implement a common application programming interface (API) framework (CAPIF) core function, the apparatus comprising: means for establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; means for receiving an onboarding update request message including the onboarding information from the API invoker; means for validating the onboarding update request message and the onboarding based on the onboarding information; means for performing a renewal of the onboarding based on the onboarding update request message; and means for sending an onboarding update response message to the API invoker based on the renewal.
14. The apparatus of claim 13, wherein the onboarding update request message further includes API invoker enrollment details information, the means for performing the renewal includes means for updating the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
15. The apparatus of claim 13 or claim 14, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, the means for performing the renewal includes means for generating the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated.
16. The apparatus of any of claims 13 to 15, wherein the means for performing the renewal includes means for determining an expiration time for the renewal based on an internal policy of the CAPIF core function, and the onboarding update response message includes the expiration time.
17. The apparatus of any of claims 13 to 16, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and the means for performing the renewal includes means for determining expiration time for the renewal based on at least one of the proposed expiration time or an internal policy of the CAPIF core function.
18. The apparatus of any of claims 13 to 17, wherein apparatus further comprises: means for determining an advance notification time that is before expiration of the onboarding; and means for sending an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, and wherein the onboarding update request message is received based on the advance notification.
19. A method implemented at a common application programming interface (API) framework (CAPIF) core function, the method comprising: establishing a secure session with an API invoker onboarded with the CAPIF core function from an onboarding based on onboarding information; receiving an onboarding update request message including the onboarding information from the API invoker; validating the onboarding update request message and the onboarding based on the onboarding information; performing a renewal of the onboarding based on the onboarding update request message; and sending an onboarding update response message to the API invoker based on the renewal.
20. The method of claim 19, wherein the onboarding update request message further includes API invoker enrollment details information, performing the renewal includes updating the API invoker enrollment details information at the CAPIF core function, and the onboarding update response message includes the API invoker enrollment details information as updated.
21. The method of claim 19 or claim 20, wherein the onboarding update request message further includes a request for an onboard secret for the renewal, performing the renewal includes generating the onboard secret based on the request, and the onboarding update response message includes the onboard secret as generated.
22. The method of any of claims 19 to 21, wherein performing the renewal includes determining an expiration time for the renewal based on an internal policy of the CAPIF core function, and the onboarding update response message includes the expiration time.
23. The method of any of claims 19 to 22, wherein the onboarding update request message further includes a proposed expiration time for the renewal, and performing the renewal includes determining expiration time for the renewal based on at least one of the proposed expiration time or an internal policy of the CAPIF core function.
24. The method of any of claims 19 to 23, wherein method further comprises: determining an advance notification time that is before expiration of the onboarding; and sending an advance notification regarding expiration of the onboarding, before the expiration of the onboarding and at the advance notification time, and wherein the onboarding update request message is received based on the advance notification.
Citation Information
Cited By
Systems and methods for providing a unified application programming interface proxy supporting multiple endpoints for multiple users
US20250158987A1