Secure avatar registration and management

The method addresses secure avatar registration and management in 5G systems by using biometric templates and encryption, ensuring only authorized users can access avatars, enhancing security and efficiency in metaverse environments.

WO2025177260A1PCT designated stage Publication Date: 2025-08-28NOKIA TECHNOLOGIES OY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051977
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-25
Filing Date
2025-02-24
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

Existing systems face challenges in securely identifying and managing avatars in metaverse environments, particularly in 5G systems, ensuring that only the actual owner can use and authorize access rights to avatars, and determining the digital rights associated with these avatars.

Method used

Implementing a method for secure avatar registration and management through mechanisms such as biometric templates, symmetric hashing functions, and encryption using pre-shared keys, which associate user identification features with avatar identifiers and manage digital rights within network entities like UDM and AMF.

Benefits of technology

Enables efficient and secure communication and processing for avatar registration, ensuring that only authorized users can access and manage avatars, supporting multiple avatars per user and handling scenarios without USIM, while maintaining privacy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051977_28082025_PF_FP_ABST
    Figure IB2025051977_28082025_PF_FP_ABST
Patent Text Reader

Abstract

There are provided measures for secure avatar registration and management. Such measures exemplarily comprise receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Title

[0002] SECURE AVATAR REGISTRATION AND MANAGEMENT

[0003] Field

[0004] Various example embodiments relate to secure avatar registration and management. More specifically, various example embodiments exemplarily relate to measures (including methods, apparatuses and computer program products) for realizing secure avatar registration and management.

[0005] The present specification generally relates to avatars for digital environments such as meta verse environments.

[0006] An avatar may represent a user in metaverse environments such as 3rdGeneration Partnership Project (3GPP) 5thGeneration (5G) metaverse. In such metaverse, each user can have avatars created for various use cases. Avatar is very sensitive and privacy critical entity for which it is to be ensured that only the actual owner (and registered user) of the avatar is able to use and give access rights to third parties to use the avatar. Thus, avatars may be associated with digital rights. The digital rights comprise the rights of ownership and / or usage of a 2D / 3D graphics representation of the avatar by one or more persons each associated with e.g. a mobile subscription. The digital rights thus enable a person with usage rights to an avatar to use that avatar as their representation in a metaverse environment, for example using an application on their user equipment (UE), another UE, or a universal subscriber identity module (USIM)-less device.

[0007] Here, a UE is a terminal or mobile equipment (ME) comprising a USIM. A mobile equipment is any device capable of connecting via a radio interface to a public land mobile network (PLMN), such as a mobile phone, that may comprise a USIM. A USIM stores information on a user’s mobile subscription, providing support for authentication, authorization, encryption, and integrity protection of data transmitted via the radio interface.

[0008] In this context, it is demanded that such metaverse systems involving usage of avatars, e.g. a 5G system or a successor system providing such metaverse technology is enabled to identify avatars and associate avatars with respective subscribers (i.e. owners of the avatars) and to authorize avatars to be used in mobile metaverse services.

[0009] Hence, the problem arises that, to enable authorizing, in a 5G or successor system, a user of a UE to use a particular avatar as their representation in a metaverse environment, a mechanism is needed enabling to determine whether the user’s avatar corresponds to one of avatars with digital rights known to the 5G (or beyond) system, for example based on visual appearance or other attributes of the user’s avatar and the known avatars, and if the determination is positive, to further determine whether the user has usage rights to the known avatar.

[0010] Hence, there is a need to provide for secure avatar registration and management and in particular for registering the digital rights of an avatar.

[0011] Summary

[0012] Various example embodiments aim at addressing at least part of the above issues and / or problems and drawbacks.

[0013] Various aspects of example embodiments are set out in the appended claims.

[0014] According to an exemplary aspect, there is provided a method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0015] According to an exemplary aspect, there is provided a method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request.

[0016] According to an exemplary aspect, there is provided a method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0017] According to an exemplary aspect, there is provided a method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0018] According to an exemplary aspect, there is provided an apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, means for associating a user identification feature with an avatar identifier of said avatar, means for storing said user identification feature, said avatar identifier, and said information on said avatar, and means for transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0019] According to an exemplary aspect, there is provided an apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, means for decrypting said avatar registration request utilizing said first key, and means for transmitting, towards a second network entity, said decrypted avatar registration request.

[0020] According to an exemplary aspect, there is provided an apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0021] According to an exemplary aspect, there is provided an apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. According to an exemplary aspect, there is provided an apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating circuitry configured to associate a user identification feature with an avatar identifier of said avatar, storing circuitry configured to store said user identification feature, said avatar identifier, and said information on said avatar, and transmitting circuitry configured to transmit, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0022] According to an exemplary aspect, there is provided an apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting circuitry configured to decrypt said avatar registration request utilizing said first key, and transmitting circuitry configured to transmit, towards a second network entity, said decrypted avatar registration request.

[0023] According to an exemplary aspect, there is provided an apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0024] According to an exemplary aspect, there is provided an apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0025] According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0026] According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request.

[0027] According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0028] According to an exemplary aspect, there is provided an apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0029] According to an exemplary aspect, there is provided a computer program product comprising computer-executable computer program code which, when the program is run on a computer (e.g. a computer of an apparatus according to any one of the aforementioned apparatus-related exemplary aspects of the present disclosure), is configured to cause the computer to carry out the method according to any one of the aforementioned method-related exemplary aspects of the present disclosure.

[0030] Such computer program product may comprise (or be embodied) a (tangible) computer- readable (storage) medium or the like on which the computer-executable computer program code is stored, and / or the program may be directly loadable into an internal memory of the computer or a processor thereof.

[0031] Any one of the above aspects enables an efficient and secured communication and processing in relation to avatar registration to thereby solve at least part of the problems and drawbacks identified in relation to the prior art. By way of example embodiments, there is provided secure avatar registration and management. More specifically, by way of example embodiments, there are provided measures and mechanisms for realizing secure avatar registration and management.

[0032] Thus, improvement is achieved by methods, apparatuses and computer program products enabling / realizing secure avatar registration and management.

[0033] Brief description of the drawings

[0034] In the following, the present disclosure will be described in greater detail by way of nonlimiting examples with reference to the accompanying drawings, in which

[0035] FIG. 1 is a block diagram illustrating an apparatus according to example embodiments,

[0036] FIG. 2 is a block diagram illustrating an apparatus according to example embodiments,

[0037] FIG. 3 is a block diagram illustrating an apparatus according to example embodiments,

[0038] FIG. 4 is a block diagram illustrating an apparatus according to example embodiments,

[0039] FIG. 5 is a block diagram illustrating an apparatus according to example embodiments,

[0040] FIG. 6 is a block diagram illustrating an apparatus according to example embodiments,

[0041] FIG. 7 is a schematic diagram of a procedure according to example embodiments,

[0042] FIG. 8 is a schematic diagram of a procedure according to example embodiments,

[0043] FIG. 9 is a schematic diagram of a procedure according to example embodiments,

[0044] FIG. 10 is a schematic diagram of a procedure according to example embodiments, FIG. 11 shows a schematic diagram of signaling sequences according to example embodiments,

[0045] FIG. 12 shows a schematic diagram of symmetric hashing concept,

[0046] FIG. 13 shows a schematic diagram of signaling sequences according to example embodiments, and

[0047] FIG. 14 is a block diagram alternatively illustrating apparatuses according to example embodiments.

[0048] Detailed description

[0049] The present disclosure is described herein with reference to particular non-limiting examples and to what are presently considered to be conceivable embodiments. A person skilled in the art will appreciate that the disclosure is by no means limited to these examples, and may be more broadly applied.

[0050] It is to be noted that the following description of the present disclosure and its embodiments mainly refers to specifications being used as non-limiting examples for certain exemplary network configurations and deployments. Namely, the present disclosure and its embodiments are mainly described in relation to 3GPP specifications being used as non-limiting examples for certain exemplary network configurations and deployments. As such, the description of example embodiments given herein specifically refers to terminology which is directly related thereto. Such terminology is only used in the context of the presented non-limiting examples, and does naturally not limit the disclosure in any way. Rather, any other communication or communication related system deployment, etc. may also be utilized as long as compliant with the features described herein.

[0051] Hereinafter, various embodiments and implementations of the present disclosure and its aspects or embodiments are described using several variants and / or alternatives. It is generally noted that, according to certain needs and constraints, all of the described variants and / or alternatives may be provided alone or in any conceivable combination (also including combinations of individual features of the various variants and / or alternatives).

[0052] As used herein, "at least one of the following: " and "at least one of " and similar wording, where the list of two or more elements are joined by "and" or "or", mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0053] According to example embodiments, in general terms, there are provided measures and mechanisms for (enabling / realizing) secure avatar registration and management.

[0054] In brief, according to example embodiments, a management service to handle avatar related services of a user and avatar registration mechanisms either via an access and mobility management function (AMF) using non-access stratum (NAS) keys or via a unified data management (UDM) using a pre-shared long key K are provided. In addition, keys based on biometric identifiers or templates or other biometric related information may be utilized. In this way, example embodiments are applicable also to no USIM-cases and to roaming scenarios.

[0055] According to such example embodiments, different biometric identifiers may be utilized to associate different avatars with a same user.

[0056] According to example embodiments, a unique avatar identifier (ID) is created and stored in association with information indicative of the owning (associated) user. The information indicative of the owning (associated) user may be device information (corresponding to a registering device), subscriber information (corresponding to a registering subscriber), or information provided by the registering entity or generated based on such information provided by the registering entity. Such information provided by the registering entity may include biometric templates and (symmetric) hashing functions. Such information generated based on such information provided by the registering entity may include quick response (QR) codes or bar codes including at least part of the information provided by the registering entity and / or being indicative of at least part of the information provided by the registering entity.

[0057] Such QR code or bar code may be generated as part of a successful registration and may be provided as part of a successful registration response. Other (graphical) representations other than QR codes or bar codes being able to be indicative of at least part of the information provided by the registering entity and to thus serve as a kind of identification may be used instead.

[0058] According to further example embodiments, a successful registration of an avatar, which is initiated by a subscriber (corresponding to a user), is considered as an implicit userconsent to allow a 5thGeneration system (5GS) (or successor, or similar) to maintain the mapping or association between the subscriber and the registered avatar(s).

[0059] According to example embodiments of one option, the avatar registration and mapping mechanism is configured via UDM in 5GS through some or all of the following summarized steps: a long-term key K is pre-shared at both a UE (as an example of a terminal) and the UDM, the UE sends an avatar registration request which is encrypted with the key K and contains a device ID and avatar details to an avatar management service (AMS), and the AMS forwards this message to an UDM for decryption and authorization, the UDM decrypts and authenticates the registration request message with the key K and sends the authentication response to the AMS, and the AMS assigns a unique avatar ID for the avatar and maps it to the subscriber.

[0060] According to example embodiments of another option, the avatar registration and mapping mechanism is configured via an AMF in 5GS through some or all of the following summarized steps: a UE sends an avatar registration request encrypted with NAS encryption keys and containing biometric templates and symmetric hashing functions to the AMF, the AMF uses the NAS keys to check the integrity and decrypt the message and forwards the avatar registration request to an AMS, the AMS may generate and registers a unique avatar ID and stores the biometric templates of the user and generates a QR / bar code for a new avatar registration which is forwarded to the AMF, and the AMF forwards the QR / bar code to the UE as an avatar registration response (the QR code enables the user to use the registered avatar also on a different UE than its own UE (or the registering UE), or on a device not containing a USIM).

[0061] Example embodiments are specified below in more detail.

[0062] FIG. 1 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a network node or entity 10 such as an avatar management service entity (or a network node or entity providing such functionality) comprising a receiving circuitry 11, an associating circuitry 12, a storing circuitry 13, and a transmitting circuitry 14. The receiving circuitry 11 receives, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar. The associating circuitry 12 associates a user identification feature with an avatar identifier of said avatar. The storing circuitry 13 stores said user identification feature, said avatar identifier, and said information on said avatar. The transmitting circuitry 14 transmits, towards said first network entity, an avatar registration response including information indicative of said avatar identifier. FIG. 7 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 1 may perform the method of FIG. 7 but is not limited to this method. The method of FIG. 7 may be performed by the apparatus of FIG. 1 but is not limited to being performed by this apparatus.

[0063] As shown in FIG. 7, a procedure according to example embodiments comprises an operation of receiving (S71), from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, an operation of associating (S72) a user identification feature with an avatar identifier of said avatar, an operation of storing (S73) said user identification feature, said avatar identifier, and said information on said avatar, and an operation of transmitting (S74), towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0064] FIG. 2 is a block diagram illustrating an apparatus according to example embodiments. In particular, FIG. 2 illustrates a variation of the apparatus shown in FIG. 1. The apparatus according to FIG. 2 may thus further comprise a generating circuitry 21, and / or a checking circuitry 22.

[0065] In an embodiment at least some of the functionalities of the apparatus shown in FIG. 1 (or 2) may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes.

[0066] According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and an exemplary method according to example embodiments may comprise an operation of transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, and an operation of receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key.

[0067] According to further example embodiments, said second network entity is a unified data management entity or an authentication server function entity.

[0068] According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of generating said avatar identifier.

[0069] According to further example embodiments, said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier.

[0070] According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0071] According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0072] According to further example embodiments, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0073] According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of generating said avatar identifier.

[0074] According to further example embodiments, said avatar registration request includes said avatar identifier.

[0075] According to further example embodiments, said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function. According to a variation of the procedure shown in FIG. 7, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements.

[0076] According to a variation of the procedure shown in FIG. 7, exemplary details of the transmitting operation (S74) are given, which are inherently independent from each other as such. Such exemplary transmitting operation (S74) according to example embodiments may comprise an operation of generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0077] According to further example embodiments, said code is at least one of the following: a bar code, or a quick response code.

[0078] According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0079] FIG. 3 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a network node or entity 30 such as an access and mobility management function entity (or a network node or entity providing such functionality) comprising a receiving circuitry 31, a decrypting circuitry 32, and a transmitting circuitry 33. The receiving circuitry 31 receives, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key. The decrypting circuitry 32 decrypts said avatar registration request utilizing said first key. The transmitting circuitry 33 transmits, towards a second network entity, said decrypted avatar registration request. FIG. 8 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 3 may perform the method of FIG. 8 but is not limited to this method. The method of FIG. 8 may be performed by the apparatus of FIG. 3 but is not limited to being performed by this apparatus.

[0080] As shown in FIG. 8, a procedure according to example embodiments comprises an operation of receiving (S81), from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, an operation of decrypting (S82) said avatar registration request utilizing said first key, and an operation of transmitting (S83), towards a second network entity, said decrypted avatar registration request.

[0081] FIG. 4 is a block diagram illustrating an apparatus according to example embodiments. In particular, FIG. 4 illustrates a variation of the apparatus shown in FIG. 3. The apparatus according to FIG. 4 may thus further comprise an encrypting circuitry 41, a verifying circuitry 42, a generating circuitry 43, and / or an adding circuitry 44.

[0082] In an embodiment at least some of the functionalities of the apparatus shown in FIG. 3 (or 4) may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes.

[0083] According to a variation of the procedure shown in FIG. 8, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, an operation of encrypting said avatar registration response utilizing said first key, and an operation of transmitting, towards said first network entity, said encrypted avatar registration response.

[0084] According to a variation of the procedure shown in FIG. 8, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of verifying integrity of said avatar registration response utilizing said first key.

[0085] According to a variation of the procedure shown in FIG. 8, exemplary additional operations are given, which are inherently independent from each other as such. According to such variation, an exemplary method according to example embodiments may comprise an operation of generating said avatar identifier, and an operation of adding said avatar identifier to said decrypted avatar registration request.

[0086] According to further example embodiments, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0087] According to further example embodiments, said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0088] According to further example embodiments, said code is at least one of the following: a bar code, or a quick response code.

[0089] According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0090] According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0091] According to further example embodiments, said first network entity is an access and mobility management function entity.

[0092] According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0093] FIG. 5 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a terminal 50 such as a user equipment comprising a transmitting circuitry 51 and a receiving circuitry 52. The transmitting circuitry 51 transmits, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key. The receiving circuitry 52 receives, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. FIG. 9 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 5 may perform the method of FIG. 9 but is not limited to this method. The method of FIG. 9 may be performed by the apparatus of FIG. 5 but is not limited to being performed by this apparatus.

[0094] As shown in FIG. 9, a procedure according to example embodiments comprises an operation of transmitting (S91), towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and an operation of receiving (S92), from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0095] In an embodiment at least some of the functionalities of the apparatus shown in FIG. 5 may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes. According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0096] According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0097] According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0098] FIG. 6 is a block diagram illustrating an apparatus according to example embodiments. The apparatus may be a terminal 60 such as a user equipment comprising a transmitting circuitry 61 and a receiving circuitry 62. The transmitting circuitry 61 transmits, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key. The receiving circuitry 62 receives, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. FIG. 10 is a schematic diagram of a procedure according to example embodiments. The apparatus according to FIG. 6 may perform the method of FIG. 10 but is not limited to this method. The method of FIG. 10 may be performed by the apparatus of FIG. 6 but is not limited to being performed by this apparatus.

[0099] As shown in FIG. 10, a procedure according to example embodiments comprises an operation of transmitting (S101), towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and an operation of receiving (SI 02), from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0100] In an embodiment at least some of the functionalities of the apparatus shown in FIG. 6 may be shared between two physically separate devices forming one operational entity. Therefore, the apparatus may be seen to depict the operational entity comprising one or more physically separate devices for executing at least some of the described processes.

[0101] According to further example embodiments, said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0102] According to further example embodiments, said code is at least one of the following: a bar code, or a quick response code. According to further example embodiments, said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0103] According to further example embodiments, said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0104] According to further example embodiments, said first network entity is an access and mobility management function entity.

[0105] According to further example embodiments, said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0106] Example embodiments outlined and specified above are explained below in more specific terms. FIG. 11 shows a schematic diagram of signaling sequences according to example embodiments, and in particular illustrates an example processing of an avatar registration via a UDM according to example embodiments of the one option mentioned above.

[0107] Initially, a UE (as an example of a terminal) is primarily authenticated, and NAS and access stratum (AS) security contexts are established.

[0108] As part or as a result of this authentication procedure, a pre-shared long term key K is available on both sides, the UE and the UDM.

[0109] In case of no-USIM scenarios, in the lack of such authentication procedure and consequently of the availability of pre-shared long term key K, biometric based keys Kb can be considered instead of K. In such scenarios, such biometric based keys Kb or bases for deprival of such biometric based keys Kb would thus be exchanged beforehand.

[0110] According to example embodiments of the one option, an AMS is provided and responsible for generating unique avatar IDs and mapping the unique avatar IDs to subscriber(s) / user(s). There can be a l:n mapping, where one user can have multiple avatars for different purposes.

[0111] According to example embodiment, the UE is preconfigured with the connectivity information of such AMS.

[0112] In a step 1 of FIG. 11 , according to example embodiments of the one option, the UE transmits an avatar registration request to the AMS. One user can register multiple avatars using this procedure. However, at-a-time, only one avatar can be registered. In other words, one avatar registration request is for requesting registration of one avatar. If the UE has an avatar created, it needs to register the avatar in AMS. Heretofore, the avatar registration request is encrypted with (or utilizing) the mentioned key K. According to example embodiments, the avatar registration request contains a device ID (corresponding to the requesting device) and avatar details. The avatar details include, for example, a purpose of the avatar, a list of third parties requesting the avatar service, etc. A table defining information elements (IE) representing (and included in) the avatar details is included below and discussed afterwards.

[0113]

[0114] Avatar_details can comprise IES like encrypted 2D / 3D images and visual perspectives representing the avatar, privacy preferences of avatar (like minimum distance requirement from other avatars (e.g. in meters)), a name given by the user to the avatar, etc.

[0115] With NAS and AS security context being established, the encryption keys from one of these security contexts (preferably NAS security context) can be used to encrypt these details.

[0116] The purpose of the avatar can be an enumerated value indicating, for example:

[0117] Official Meetings and conferences: 0

[0118] Gaming: 1

[0119] - Shopping: 2

[0120] Religious: 3, etc.

[0121] For example, the user performing this avatar registration may want to have one avatar with formal attire for official work, one fancy look for gaming, a cool look for shopping, and one avatar for religious pilgrimage kind of augmented reality (AR) / virtual reality (VR) experience, etc. For this, the user can register multiple avatars, each with different purpose, and a different look and feel depending on the venue where the avatars needs to appear in the virtual world.

[0122] Along with the images, a hashed value can be included to allow consuming applications / services to ensure that the data is not modified anywhere in transit or at rest. In a step 2 of FIG. 11 , according to example embodiments of the one option, the AMS forwards the avatar registration request (message) to the UDM for decryption and authorization.

[0123] In steps 3 and 4 of FIG. 11, according to example embodiments of the one option, the UDM gets the key Kb corresponding to the device ID (e.g. under consideration of the AS / NAS keys) and decrypts and authenticates the avatar registration request (message).

[0124] In a step 5 of FIG. 11, according to example embodiments of the one option, once decrypted, the UDM sends a (successful) authentication response (message) with the device ID, subscriber information, and the avatar details.

[0125] In a step 6 of FIG. 11, according to example embodiments of the one option, the AMS, once having received the (successful) authentication response, assigns a unique avatar ID and creates a mapping of the avatar (ID) with the device ID and the subscriber information.

[0126] In a step 7 of FIG. 11 , according to example embodiments of the one option, the AMS stores the mapping and the avatar details.

[0127] In a step 8 of FIG. 11, according to example embodiments of the one option, the registration response is shared (transmitted towards the UE) with a status. If the authentication is failed from the UDM, the registration response contains an error status. In the case of successful registration, the avatar ID is passed to device with the registration response.

[0128] Once the registration is successful, the avatar can be uniquely identified, and a mapping between the avatar and the subscriber / user is established in the 5GS. This enables subsequent authentication of the avatar. According to example embodiments, a successful registration of the avatar, which is initiated by the subscriber, is considered as an implicit user-consent to allow the 5GS to maintain the mapping between the subscriber and avatar(s).

[0129] FIG. 13 shows a schematic diagram of signaling sequences according to example embodiments, and in particular illustrates an example processing of an avatar registration via an AMF according to example embodiments of the another option mentioned above.

[0130] Example embodiments of the another option are applicable also to roaming scenarios as well as no-USIM scenarios. According to these example embodiments, there is no need to preconfigure the AMS at the UE, since the avatar registration request (message) is transmitted to (and routed via) an AMF. Here, the AMS is assumed to be in the home network. According to these example embodiments, NAS keys are used for protecting the registration request.

[0131] Initially, a UE (as an example of a terminal) is primarily authenticated, and NAS and AS security contexts are established.

[0132] In a step 1 of FIG. 13, according to example embodiments of the another option, an avatar registration request is sent from the UE to the AMF. This procedure is required for every new avatar created by a user. One user may have multiple such avatars.

[0133] The avatar registration request includes biometric templates and a list of symmetric hashing functions supported by the UE. Each avatar can be registered with each biometric template. Multiple hashing functions may be supported by UEs.

[0134] FIG. 12 shows a schematic diagram of symmetric hashing concept, and in particular illustrates generation of biometric encryption and integrity keys (Kbenc and Kbint) from biometric templates using symmetric hashing functions. The biometric templates are shared by the user during the registration procedure along with the symmetric hashing functions (with the avatar registration request). The 5G network stores these templates and map the templates to a unique digital avatar ID, as discussed later with respect to steps 7 to 10 of FIG. 13.

[0135] Known feature extraction algorithms to form biometric template are, for example, ISEF Egde detection and CANNY Edge Detection And SIFT Based Algorithm.

[0136] With respect to the symmetric hashing functions, it is noted that a small change in the input (missing information, noise, or a change in the order of the input etc.) can cause a significant change in the hash value. A certain class of hash functions can, however, be formulated that are invariant to the order in which the input pattern is presented to the hash function. Such hash functions are known as order-independent or symmetric hash functions.

[0137] Consider an input sequence X = x 1x2x3. . .xn and the following two hash functions (examples)

[0138] If the order of the input is changed to X = x2x3xn. . .xl, the first hash function (1) yields a different hash value (different from the result of the original input sequence X = x 1x2x3. . .xn), whereas the result of the second hash function (2) which is a symmetric hash function remains unchanged.

[0139] Similar hash functions (such as function (2)) that are symmetric can be generated. Moreover, arbitrary combinations of more than one (symmetric) hash function yield new (symmetric) hash functions. Thus, a whole family of symmetric hash functions can be achieved by combining elementary symmetric hash functions.

[0140] Returning to step 1 of FIG. 13, according to example embodiments of the another option, the avatar registration request is encrypted using NAS encryption keys and integrity protected using NAS integrity keys. These keys are derived as per legacy NAS security context establishment procedures.

[0141] In steps 2 and 3 of FIG. 13, according to example embodiments of the another option, once the AMF receives the avatar registration request message, the AMF uses the NAS keys to check integrity of the avatar registration request message and to decrypt the avatar registration request message.

[0142] According to example embodiments of the another option, the AMF may generate and maintain unique avatar IDs (optional step 4 of FIG. 13). However, the preferred alternative is generation and maintenance of avatar IDs by the AMS as is later on discussed with respect to step 6 of FIG. 13.

[0143] In a step 5 of FIG. 13, according to example embodiments of the another option, the (decrypted) avatar registration request is forwarded by the AMF to the AMS, which may be an entity in the core network.

[0144] According to example embodiments, the (decrypted) avatar registration request includes biometric templates and a list of symmetric hashing functions supported by the UE. The (decrypted) avatar registration request may further include a unique digital asset ID identifying a digital asset container. If, in optional step 4 of FIG. 13, a unique avatar ID was generated, this may be included as well.

[0145] In a step 6 of FIG. 13, according to example embodiments of the another option, the AMS generates the unique avatar ID, which is preferred over the optional step 4 of FIG. 13 as mentioned above.

[0146] In a step 7 of FIG. 13, according to example embodiments of the another option, the AMS registers / s tores the unique avatar ID.

[0147] In a step 8 of FIG. 13, according to example embodiments of the another option, the AMS stores the received biometric template(s). In a step 9 of FIG. 13, according to example embodiments of the another option, the AMS checks for supported symmetric hashing functions. In particular, the AMS may check if the symmetric hashing functions supported by the UE are secure enough and are supported by the AMS or not, which might lead (upon negative result) to an error being sent in step 12 of FIG. 13.

[0148] In a step 10 of FIG. 13, according to example embodiments of the another option, the AMS generates a QR / bar code for this new avatar registration. The generated QR / bar code contains information about the unique avatar ID and the symmetric hashing functions (e.g. fnl and fn2 in FIG. 12) to be used to ensure that the user is able to securely access the avatar. A QR / bar code reader at UE can decode this if needed.

[0149] In a step 11 of FIG. 13, according to example embodiments of the another option, the AMS sends an avatar registration response to the AMF. The avatar registration response includes the QR / bar code.

[0150] In a step 12 of FIG. 13, according to example embodiments of the another option, the AMF forwards this avatar registration response including the QR / bar code to the UE. The avatar registration response is prepared using the NAS encryption and integrity keys.

[0151] Once the registration is successful, the avatar can be uniquely identified, the user is enabled to access its avatars from different UEs, as long as the QR / bar code is retained. This enables subsequent authentication of the avatar.

[0152] According to example embodiments, a successful registration of the avatar, which is initiated by the subscriber, is considered as an implicit user-consent to allow the 5GS to maintain the mapping between the subscriber and avatar(s).

[0153] The above-described procedures and functions may be implemented by respective functional elements, processors, or the like, as described below. In the foregoing exemplary description of the network entity, only the units that are relevant for understanding the principles of the disclosure have been described using functional blocks. The network entity may comprise further units that are necessary for its respective operation. However, a description of these units is omitted in this specification. The arrangement of the functional blocks of the devices is not construed to limit the disclosure, and the functions may be performed by one block or further split into sub-blocks.

[0154] When in the foregoing description it is stated that the apparatus, i.e. network node or entity (or some other means) is configured to perform some function, this is to be construed to be equivalent to a description stating that a (i.e. at least one) processor or corresponding circuitry, potentially in cooperation with computer program code stored in the memory of the respective apparatus, is configured to cause the apparatus to perform at least the thus mentioned function. Also, such function is to be construed to be equivalently implementable by specifically configured circuitry or means for performing the respective function (i.e. the expression “unit configured to" is construed to be equivalent to an expression such as “means for”).

[0155] In FIG. 14, an alternative illustration of apparatuses according to example embodiments is depicted. As indicated in FIG. 14, according to example embodiments, the apparatus (network node or entity) 10’ (corresponding to the network node or entity 10) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. Further, according to example embodiments, the apparatus (network node or entity) 30’ (corresponding to the network node or entity 30) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. Further, according to example embodiments, the apparatus (network node or entity) 50’ (corresponding to the network node or entity 50) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. Further, according to example embodiments, the apparatus (network node or entity) 60’ (corresponding to the network node or entity 60) comprises a processor 141, a memory 142 and an interface 143, which are connected by a bus 144 or the like. The apparatuses 10, 30, 50, 60 may be connected via link 145 with another apparatus (the interface of the another apparatus), e.g., another of the apparatuses 10, 30, 50, 60.

[0156] The processor 141 and / or the interface 143 may also include a modem or the like to facilitate communication over a (hardwire or wireless) link, respectively. The interface 143 may include a suitable transceiver coupled to one or more antennas or communication means for (hardwire or wireless) communications with the linked or connected device(s), respectively. The interface 143 is generally configured to communicate with at least one other apparatus, i.e. the interface thereof.

[0157] The memory 142 may store respective programs assumed to include program instructions or computer program code that, when executed by the respective processor, enables the respective electronic device or apparatus to operate in accordance with the example embodiments.

[0158] In general terms, the respective devices / apparatuses (and / or parts thereof) may represent means for performing respective operations and / or exhibiting respective functionalities, and / or the respective devices (and / or parts thereof) may have functions for performing respective operations and / or exhibiting respective functionalities.

[0159] When in the subsequent description it is stated that the processor (or some other means) is configured to perform some function, this is to be construed to be equivalent to a description stating that at least one processor, potentially in cooperation with computer program code stored in the memory of the respective apparatus, is configured to cause the apparatus to perform at least the thus mentioned function. Also, such function is to be construed to be equivalently implementable by specifically configured means for performing the respective function (i.e. the expression “processor configured to [cause the apparatus to] perform xxx-ing” is construed to be equivalent to an expression such as “means for xxx-ing”).

[0160] According to example embodiments, an apparatus representing the network node or entity 10 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar (thus the apparatus comprising corresponding means for receiving), to perform associating a user identification feature with an avatar identifier of said avatar (thus the apparatus comprising corresponding means for associating), to perform storing said user identification feature, said avatar identifier, and said information on said avatar (thus the apparatus comprising corresponding means for storing), and to perform transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier (thus the apparatus comprising corresponding means for transmitting).

[0161] According to example embodiments, an apparatus representing the network node or entity 30 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key (thus the apparatus comprising corresponding means for receiving), to perform decrypting said avatar registration request utilizing said first key (thus the apparatus comprising corresponding means for decrypting), and to perform transmitting, towards a second network entity, said decrypted avatar registration request (thus the apparatus comprising corresponding means for transmitting).

[0162] According to example embodiments, an apparatus representing the network node or entity 50 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key (thus the apparatus comprising corresponding means for transmitting) and to perform receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key (thus the apparatus comprising corresponding means for receiving).

[0163] According to example embodiments, an apparatus representing the network node or entity 60 comprises at least one processor 141, at least one memory 142 including computer program code, and at least one interface 143 configured for communication with at least another apparatus. The processor (i.e. the at least one processor 141, with the at least one memory 142 and the computer program code) is configured to perform transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key (thus the apparatus comprising corresponding means for transmitting) and to perform receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key (thus the apparatus comprising corresponding means for receiving).

[0164] For further details regarding the operability / functionality of the individual apparatuses, reference is made to the above description in connection with any one of FIGs. 1 to 13, respectively. For the purpose of the present disclosure as described herein above, it should be noted that

[0165] - method steps likely to be implemented as software code portions and being run using a processor at a network server or network entity (as examples of devices, apparatuses and / or modules thereof, or as examples of entities including apparatuses and / or modules therefore), are software code independent and can be specified using any known or future developed programming language as long as the functionality defined by the method steps is preserved;

[0166] - generally, any method step is suitable to be implemented as software or by hardware without changing the idea of the embodiments and its modification in terms of the functionality implemented;

[0167] - method steps and / or devices, units or means likely to be implemented as hardware components at the above-defined apparatuses, or any module(s) thereof, (e.g., devices carrying out the functions of the apparatuses according to the embodiments as described above) are hardware independent and can be implemented using any known or future developed hardware technology or any hybrids of these, such as MOS (Metal Oxide Semiconductor), CMOS (Complementary MOS), BiMOS (Bipolar MOS), BiCMOS (Bipolar CMOS), ECL (Emitter Coupled Logic), TTL (Transistor-Transistor Logic), etc., using for example ASIC (Application Specific IC (Integrated Circuit)) components, FPGA (Field-programmable Gate Arrays) components, CPLD (Complex Programmable Logic Device) components or DSP (Digital Signal Processor) components;

[0168] - devices, units or means (e.g. the above-defined network entity or network register, or any one of their respective units / means) can be implemented as individual devices, units or means, but this does not exclude that they are implemented in a distributed fashion throughout the system, as long as the functionality of the device, unit or means is preserved;

[0169] - an apparatus like the user equipment and the network entity / network register may be represented by a semiconductor chip, a chipset, or a (hardware) module comprising such chip or chipset; this, however, does not exclude the possibility that a functionality of an apparatus or module, instead of being hardware implemented, be implemented as software in a (software) module such as a computer program or a computer program product comprising executable software code portions for execution / being run on a processor;

[0170] - a device may be regarded as an apparatus or as an assembly of more than one apparatus, whether functionally in cooperation with each other or functionally independently of each other but in a same device housing, for example.

[0171] In general, it is to be noted that respective functional blocks or elements according to above-described aspects can be implemented by any known means, either in hardware and / or software, respectively, if it is only adapted to perform the described functions of the respective parts. The mentioned method steps can be realized in individual functional blocks or by individual devices, or one or more of the method steps can be realized in a single functional block or by a single device.

[0172] Generally, any method step is suitable to be implemented as software or by hardware without changing the idea of the present disclosure. Devices and means can be implemented as individual devices, but this does not exclude that they are implemented in a distributed fashion throughout the system, as long as the functionality of the device is preserved. Such and similar principles are to be considered as known to a skilled person.

[0173] Software in the sense of the present description comprises software code as such comprising code means or portions or a computer program or a computer program product for performing the respective functions, as well as software (or a computer program or a computer program product) embodied on a tangible medium such as a computer-readable (storage) medium having stored thereon a respective data structure or code means / portions or embodied in a signal or in a chip, potentially during processing thereof.

[0174] The present disclosure also covers any conceivable combination of method steps and operations described above, and any conceivable combination of nodes, apparatuses, modules or elements described above, as long as the above-described concepts of methodology and structural arrangement are applicable. In view of the above, there are provided measures for secure avatar registration and management. Such measures exemplarily comprise receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0175] Even though the disclosure is described above with reference to the examples according to the accompanying drawings, it is to be understood that the disclosure is not restricted thereto. Rather, it is apparent to those skilled in the art that the present disclosure can be modified in many ways without departing from the scope of the inventive idea as disclosed herein.

[0176] Among others, the following Items are covered by the above disclosure:

[0177] Item 1. A method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0178] Item 2. The method according to Item 1 , wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the method further comprises transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key.

[0179] Item 3. The method according to Item 2, wherein said second network entity is a unified data management entity or an authentication server function entity.

[0180] Item 4. The method according to Item 2 or 3, further comprising generating said avatar identifier.

[0181] Item 5. The method according to any of Items 2 to 4, wherein said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier.

[0182] Item 6. The method according to any of Items 2 to 5, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0183] Item 7. The method according to any of Items 2 to 5, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0184] Item 8. The method according to Item 1, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template. Item 9. The method according to Item 8, further comprising generating said avatar identifier.

[0185] Item 10. The method according to Item 8, wherein said avatar registration request includes said avatar identifier.

[0186] Item 11. The method according to any of Items 8 to 10, wherein said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function.

[0187] Item 12. The method according to any of Items 8 to 11, further comprising checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements.

[0188] Item 13. The method according to any of Items 8 to 12, wherein in relation to said transmitting, the method further comprises generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0189] Item 14. The method according to Item 13, wherein said code is at least one of the following: a bar code, or a quick response code.

[0190] Item 15. The method according to any of Items 1 to 14, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0191] Item 16. A method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request.

[0192] Item 17. The method according to Item 16, further comprising receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, encrypting said avatar registration response utilizing said first key, and transmitting, towards said first network entity, said encrypted avatar registration response.

[0193] Item 18. The method according to Item 17, further comprising verifying integrity of said avatar registration response utilizing said first key.

[0194] Item 19. The method according to Item 17 or 18, further comprising generating said avatar identifier, and adding said avatar identifier to said decrypted avatar registration request.

[0195] Item 20. The method according to any of Items 17 to 19, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0196] Item 21. The method according to Item 20, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0197] Item 22. The method according to Item 21, wherein said code is at least one of the following: a bar code, or a quick response code.

[0198] Item 23. The method according to any of Items 16 to 22, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0199] Item 24. The method according to any of Items 16 to 22, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0200] Item 25. The method according to any of Items 16 to 24, wherein said first network entity is an access and mobility management function entity.

[0201] Item 26. The method according to any of Items 16 to 25, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0202] Item 27. A method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0203] Item 28. The method according to Item 27, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0204] Item 29. The method according to Item 27, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0205] Item 30. The method according to any of Items 27 to 29, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0206] Item 31. A method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0207] Item 32. The method according to Item 31, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0208] Item 33. The method according to Item 32, wherein said code is at least one of the following: a bar code, or a quick response code. Item 34. The method according to any of Items 31 to 33, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0209] Item 35. The method according to any of Items 31 to 33, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0210] Item 36. The method according to any of Items 31 to 35, wherein said first network entity is an access and mobility management function entity.

[0211] Item 37. The method according to any of Items 31 to 36, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0212] Item 38. An apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, means for associating a user identification feature with an avatar identifier of said avatar, means for storing said user identification feature, said avatar identifier, and said information on said avatar, and means for transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0213] Item 39. The apparatus according to Item 38, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the apparatus further comprises means for transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, means for receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key.

[0214] Item 40. The apparatus according to Item 39, wherein said second network entity is a unified data management entity or an authentication server function entity.

[0215] Item 41. The apparatus according to Item 39 or 40, further comprising means for generating said avatar identifier.

[0216] Item 42. The apparatus according to any of Items 39 to 41, wherein said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier.

[0217] Item 43. The apparatus according to any of Items 39 to 42, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0218] Item 44. The apparatus according to any of Items 39 to 42, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0219] Item 45. The apparatus according to Item 38, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0220] Item 46. The apparatus according to Item 45, further comprising means for generating said avatar identifier.

[0221] Item 47. The apparatus according to Item 45, wherein said avatar registration request includes said avatar identifier.

[0222] Item 48. The apparatus according to any of Items 45 to 47, wherein said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function.

[0223] Item 49. The apparatus according to any of Items 45 to 48, further comprising means for checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements.

[0224] Item 50. The apparatus according to any of Items 45 to 49, further comprising means for generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0225] Item 51. The apparatus according to Item 50, wherein said code is at least one of the following: a bar code, or a quick response code.

[0226] Item 52. The apparatus according to any of Items 38 to 51, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0227] Item 53. An apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, means for decrypting said avatar registration request utilizing said first key, and means for transmitting, towards a second network entity, said decrypted avatar registration request.

[0228] Item 54. The apparatus according to Item 53, further comprising means for receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, means for encrypting said avatar registration response utilizing said first key, and means for transmitting, towards said first network entity, said encrypted avatar registration response.

[0229] Item 55. The apparatus according to Item 54, further comprising means for verifying integrity of said avatar registration response utilizing said first key.

[0230] Item 56. The apparatus according to Item 54 or 55, further comprising means for generating said avatar identifier, and means for adding said avatar identifier to said decrypted avatar registration request.

[0231] Item 57. The apparatus according to any of Items 54 to 56, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0232] Item 58. The apparatus according to Item 57, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0233] Item 59. The apparatus according to Item 58, wherein said code is at least one of the following: a bar code, or a quick response code.

[0234] Item 60. The apparatus according to any of Items 53 to 59, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network. Item 61. The apparatus according to any of Items 53 to 59, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0235] Item 62. The apparatus according to any of Items 53 to 61, wherein said first network entity is an access and mobility management function entity.

[0236] Item 63. The apparatus according to any of Items 53 to 62, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0237] Item 64. An apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key. Item 65. The apparatus according to Item 64, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0238] Item 66. The apparatus according to Item 64, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0239] Item 67. The apparatus according to any of Items 64 to 66, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0240] Item 68. An apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0241] Item 69. The apparatus according to Item 68, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0242] Item 70. The apparatus according to Item 69, wherein said code is at least one of the following: a bar code, or a quick response code.

[0243] Item 71. The apparatus according to any of Items 68 to 70, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0244] Item 72. The apparatus according to any of Items 68 to 70, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0245] Item 73. The apparatus according to any of Items 68 to 72, wherein said first network entity is an access and mobility management function entity.

[0246] Item 74. The apparatus according to any of Items 68 to 73, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0247] Item 75. An apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating circuitry configured to associate a user identification feature with an avatar identifier of said avatar, storing circuitry configured to store said user identification feature, said avatar identifier, and said information on said avatar, and transmitting circuitry configured to transmit, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0248] Item 76. The apparatus according to Item 75, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the apparatus further comprises transmitting circuitry configured to transmit, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, receiving circuitry configured to receive, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key. Item 77. The apparatus according to Item 76, wherein said second network entity is a unified data management entity or an authentication server function entity.

[0249] Item 78. The apparatus according to Item 76 or 77, further comprising generating circuitry configured to generate said avatar identifier.

[0250] Item 79. The apparatus according to any of Items 76 to 78, wherein said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier.

[0251] Item 80. The apparatus according to any of Items 76 to 79, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0252] Item 81. The apparatus according to any of Items 76 to 79, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0253] Item 82. The apparatus according to Item 75, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0254] Item 83. The apparatus according to Item 82, further comprising generating circuitry configured to generate said avatar identifier.

[0255] Item 84. The apparatus according to Item 82, wherein said avatar registration request includes said avatar identifier. Item 85. The apparatus according to any of Items 82 to 84, wherein said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function.

[0256] Item 86. The apparatus according to any of Items 82 to 85, further comprising checking circuitry configured to check said at least one symmetric hashing function for compatibility and / or compliance with security requirements.

[0257] Item 87. The apparatus according to any of Items 82 to 86, further comprising generating circuitry configured to generate a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0258] Item 88. The apparatus according to Item 87, wherein said code is at least one of the following: a bar code, or a quick response code.

[0259] Item 89. The apparatus according to any of Items 75 to 88, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0260] Item 90. An apparatus comprising receiving circuitry configured to receive, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting circuitry configured to decrypt said avatar registration request utilizing said first key, and transmitting circuitry configured to transmit, towards a second network entity, said decrypted avatar registration request.

[0261] Item 91. The apparatus according to Item 90, further comprising receiving circuitry configured to receive, from said second network entity, an avatar registration response including information indicative of an avatar identifier, encrypting circuitry configured to encrypt said avatar registration response utilizing said first key, and transmitting circuitry configured to transmit, towards said first network entity, said encrypted avatar registration response.

[0262] Item 92. The apparatus according to Item 91, further comprising verifying circuitry configured to verify integrity of said avatar registration response utilizing said first key.

[0263] Item 93. The apparatus according to Item 91 or 92, further comprising generating circuitry configured to generate said avatar identifier, and adding circuitry configured to add said avatar identifier to said decrypted avatar registration request.

[0264] Item 94. The apparatus according to any of Items 91 to 93, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0265] Item 95. The apparatus according to Item 94, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0266] Item 96. The apparatus according to Item 95, wherein said code is at least one of the following: a bar code, or a quick response code.

[0267] Item 97. The apparatus according to any of Items 90 to 96, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0268] Item 98. The apparatus according to any of Items 90 to 96, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0269] Item 99. The apparatus according to any of Items 90 to 98, wherein said first network entity is an access and mobility management function entity.

[0270] Item 100. The apparatus according to any of Items 90 to 99, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0271] Item 101. An apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0272] Item 102. The apparatus according to Item 101, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0273] Item 103. The apparatus according to Item 101, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0274] Item 104. The apparatus according to any of Items 101 to 103, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0275] Item 105. An apparatus comprising transmitting circuitry configured to transmit, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving circuitry configured to receive, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0276] Item 106. The apparatus according to Item 105, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0277] Item 107. The apparatus according to Item 106, wherein said code is at least one of the following: a bar code, or a quick response code. Item 108. The apparatus according to any of Items 105 to 107, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0278] Item 109. The apparatus according to any of Items 105 to 107, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0279] Item 110. The apparatus according to any of Items 105 to 109, wherein said first network entity is an access and mobility management function entity.

[0280] Item 111. The apparatus according to any of Items 105 to 110, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0281] Item 112. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

[0282] Item 113. The apparatus according to Item 112, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the instructions, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key.

[0283] Item 114. The apparatus according to Item 113, wherein said second network entity is a unified data management entity or an authentication server function entity.

[0284] Item 115. The apparatus according to Item 113 or 114, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating said avatar identifier. Item 116. The apparatus according to any of Items 113 to 115, wherein said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier.

[0285] Item 117. The apparatus according to any of Items 113 to 116, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0286] Item 118. The apparatus according to any of Items 113 to 116, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0287] Item 119. The apparatus according to Item 112, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0288] Item 120. The apparatus according to Item 119, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating said avatar identifier.

[0289] Item 121. The apparatus according to Item 119, wherein said avatar registration request includes said avatar identifier.

[0290] Item 122. The apparatus according to any of Items 119 to 121, wherein said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function.

[0291] Item 123. The apparatus according to any of Items 119 to 122, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements.

[0292] Item 124. The apparatus according to any of Items 119 to 123, wherein in relation to said transmitting, the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0293] Item 125. The apparatus according to Item 124, wherein said code is at least one of the following: a bar code, or a quick response code.

[0294] Item 126. The apparatus according to any of Items 112 to 125, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference. Item 127. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request.

[0295] Item 128. The apparatus according to Item 127, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, encrypting said avatar registration response utilizing said first key, and transmitting, towards said first network entity, said encrypted avatar registration response.

[0296] Item 129. The apparatus according to Item 128, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: verifying integrity of said avatar registration response utilizing said first key.

[0297] Item 130. The apparatus according to Item 128 or 129, wherein the instructions, when executed by the at least one processor, cause the apparatus at least to perform: generating said avatar identifier, and adding said avatar identifier to said decrypted avatar registration request.

[0298] Item 131. The apparatus according to any of Items 128 to 130, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

[0299] Item 132. The apparatus according to Item 131, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier.

[0300] Item 133. The apparatus according to Item 132, wherein said code is at least one of the following: a bar code, or a quick response code.

[0301] Item 134. The apparatus according to any of Items 127 to 133, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0302] Item 135. The apparatus according to any of Items 127 to 133, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0303] Item 136. The apparatus according to any of Items 127 to 135, wherein said first network entity is an access and mobility management function entity.

[0304] Item 137. The apparatus according to any of Items 127 to 136, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0305] Item 138. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0306] Item 139. The apparatus according to Item 138, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0307] Item 140. The apparatus according to Item 138, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0308] Item 141. The apparatus according to any of Items 138 to 140, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

[0309] Item 142. An apparatus comprising at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

[0310] Item 143. The apparatus according to Item 142, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier. Item 144. The apparatus according to Item 143, wherein said code is at least one of the following: a bar code, or a quick response code.

[0311] Item 145. The apparatus according to any of Items 142 to 144, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network.

[0312] Item 146. The apparatus according to any of Items 142 to 144, wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

[0313] Item 147. The apparatus according to any of Items 142 to 146, wherein said first network entity is an access and mobility management function entity.

[0314] Item 148. The apparatus according to any of Items 142 to 147, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference. Item 149. A computer program product comprising computer-executable computer program code which, when the program is run on a computer, is configured to cause the computer to carry out the method according to any one of Item 1 to 16, 16 to 26, 27 to 30, or 31 to 37.

[0315] Item 150. The computer program product according to Item 149, wherein the computer program product comprises a computer-readable medium on which the computerexecutable computer program code is stored, and / or wherein the program is directly loadable into an internal memory of the computer or a processor thereof.

[0316] List of acronyms and abbreviations

[0317] 3GPP 3rd Generation Partnership Project

[0318] 5G 5th Generation

[0319] 5GS 5th Generation system

[0320] AMF access and mobility management function

[0321] AMS avatar management service

[0322] AR augmented reality

[0323] AS access stratum

[0324] ID identifier

[0325] IE information elements

[0326] ME mobile equipment

[0327] NAS non-access stratum

[0328] PLMN public land mobile network

[0329] QR quick response

[0330] UDM unified data management

[0331] UE user equipment

[0332] USIM universal subscriber identity module

[0333] VR virtual reality

Claims

Claims1. A method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, associating a user identification feature with an avatar identifier of said avatar, storing said user identification feature, said avatar identifier, and said information on said avatar, and transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

2. The method according to claim 1, wherein said avatar registration request includes a device identifier of a device requesting said registering said avatar, said avatar registration request is encrypted utilizing a first key, and the method further comprises transmitting, towards a second network entity, a decryption request for decrypting said avatar registration request, wherein said decryption request includes said avatar registration request, and receiving, from said second network entity, a decryption response, wherein said decryption response includes said user identification feature and said information on said avatar as a result of decryption utilizing said first key.

3. The method according to claim 2, wherein said second network entity is a unified data management entity or an authentication server function entity, and / or wherein the method further comprises generating said avatar identifier, and / or wherein said user identification feature is at least one of the following: said device identifier, or subscriber information obtained based on said device identifier.

4. The method according to any of claims 2 to 3, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network, or wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

5. The method according to claim 1, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

6. The method according to claim 5, further comprising generating said avatar identifier, or wherein said avatar registration request includes said avatar identifier.

7. The method according to any of claims 5 to 6, wherein said user identification feature is at least one of the following: said at least one biometric template, or said at least one symmetric hashing function, and / or wherein the method further comprises checking said at least one symmetric hashing function for compatibility and / or compliance with security requirements.

8. The method according to any of claims 5 to 7, wherein in relation to said transmitting, the method further comprises generating a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier, wherein optionally said code is at least one of the following: a bar code, ora quick response code.

9. The method according to any of claims 1 to 8, wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

10. A method comprising receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, decrypting said avatar registration request utilizing said first key, and transmitting, towards a second network entity, said decrypted avatar registration request.

11. The method according to claim 10, further comprising receiving, from said second network entity, an avatar registration response including information indicative of an avatar identifier, encrypting said avatar registration response utilizing said first key, and transmitting, towards said first network entity, said encrypted avatar registration response.

12. The method according to claim 11, further comprising verifying integrity of said avatar registration response utilizing said first key, and / or wherein the method further comprises generating said avatar identifier, and adding said avatar identifier to said decrypted avatar registration request.

13. The method according to any of claims 11 to 12, wherein said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template.

14. The method according to claim 13, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier, wherein optionally said code is at least one of the following: a bar code, or a quick response code.

15. The method according to any of claims 10 to 14, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network, or wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

16. The method according to any of claims 10 to 15, wherein said first network entity is an access and mobility management function entity, and / or wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, ora device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, or a data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

17. A method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, and receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

18. A method comprising transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, andreceiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

19. The method according to claim 18, wherein said avatar registration response including said information indicative of said avatar identifier includes a code indicative of said avatar identifier and of said at least one symmetric hashing function as said information indicative of said avatar identifier, wherein optionally said code is at least one of the following: a bar code, or a quick response code.

20. The method according to any of claims 17 to 19, wherein said first key is a pre-shared long term key made available during establishment of a communication session of said device to a core network of a mobile network, or wherein said first key is a biometric based key made available during establishment of a communication session of said device to a core network of a mobile network.

21. The method according to any of claims 17 to 20, wherein said first network entity is an access and mobility management function entity, and / or wherein said information on said avatar includes at least one of the following: a device identifier of a device requesting said registering said avatar, or a device-side avatar identifier of said avatar, or a name of said avatar, or a usage purpose of said avatar, or a format of a graphical and / or visual representation of said avatar, or an image hashing algorithm used for hashing images constituting said graphical and / or visual representation of said avatar, or said images constituting said graphical and / or visual representation of said avatar, ora data type of said graphical and / or visual representation of said avatar, or a download address of said images constituting said graphical and / or visual representation of said avatar, or information on a social distancing privacy preference.

22. An apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, means for associating a user identification feature with an avatar identifier of said avatar, means for storing said user identification feature, said avatar identifier, and said information on said avatar, and means for transmitting, towards said first network entity, an avatar registration response including information indicative of said avatar identifier.

23. An apparatus comprising means for receiving, from a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, and wherein said avatar registration request is encrypted utilizing a first key, means for decrypting said avatar registration request utilizing said first key, and means for transmitting, towards a second network entity, said decrypted avatar registration request.

24. An apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes a device identifier of a device requesting said registering said avatar, and said avatar registration request is encrypted utilizing a first key, andmeans for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

25. An apparatus comprising means for transmitting, towards a first network entity, an avatar registration request for registering an avatar for a user, wherein said avatar registration request includes information on said avatar, said avatar registration request includes at least one biometric template and at least one symmetric hashing function for derivation of at least one second key from said at least one biometric template, and said avatar registration request is encrypted utilizing a first key, and means for receiving, from said first network entity, an avatar registration response including information indicative of said avatar identifier, wherein said avatar registration response is encrypted utilizing said first key.

Citation Information

Patent Citations

  • Method and system to prove identity of owner of an avatar in virtual world

    US20100153722A1

  • System and method of storing data

    US20130205135A1

  • Avatar management system, avatar management method, program, and computer-readable recording medium

    US20230136394A1