Methods and systems for managing an avatar identity in a metaverse system
The method and system for managing avatar identities in metaverse systems through verification and secure sharing address the challenge of unauthorized access, enhancing security and authentication in 5G networks.
Patent Information
- Application Number
- PCT/KR2025/003801
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-26
- Filing Date
- 2025-03-25
- Publication Date
- 2025-10-02
AI Technical Summary
Current systems lack effective methods for managing and securing avatar identities in metaverse systems, particularly in 5G networks, leading to potential impersonation attacks and unauthorized access to digital identities.
A method and system for managing avatar identities in a metaverse system, involving a second entity that receives an application session establishment request, verifies the avatar identity against a repository, and securely shares the identity with metaverse servers and third-party entities, ensuring only authorized users can access and use the avatars.
This approach enhances security by verifying and authenticating avatar identities, preventing impersonation attacks and ensuring only authorized users can access and use avatars, thus securing digital identity management in metaverse systems.
Smart Images

Figure KR2025003801_02102025_PF_FP_ABST
Abstract
Description
METHODS AND SYSTEMS FOR MANAGING AN AVATAR IDENTITY IN A METAVERSE SYSTEM
[0001] Embodiments disclosed herein relate to wireless communication networks, and more particularly to methods and systems for managing an avatar identity in a metaverse system.
[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.
[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.
[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.
[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.
[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.
[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.
[0008] 5th generation (5G) or new radio (NR) mobile communications is recently gathering increased momentum with all the worldwide technical activities on the various candidate technologies from industry and academia. The candidate enablers for the 5G / NR mobile communications include massive antenna technologies, from legacy cellular frequency bands up to high frequencies, to provide beamforming gain and support increased capacity, new waveform (e.g., a new radio access technology (RAT)) to flexibly accommodate various services / applications with different requirements, new multiple access schemes to support massive connections, and so on.
[0009] In line with development of the communication systems, there is a need for methods and systems for managing an avatar identity in a metaverse system.
[0010] The principal object of embodiments herein is to disclose methods and systems for managing an avatar identity in a metaverse system.
[0011] Another object of the embodiments herein is to provide an authentication of a digital identification of a user.
[0012] Another object of the embodiments herein is to verify whether a user is allowed to use the digital identity.
[0013] Another object of the embodiments herein is to create a link between the Digital identities with a user identity and with a 3rdgeneration project partnership (3GPP) subscription in the Unified Data Management (UDM).
[0014] Another object of the embodiments herein is to securely share an avatar information (digital identity etc.) by a 5th generation core (5GC) to the metaverse servers or Application Function.
[0015] Another object of the embodiments herein is to securely share the avatar information by the third-party entity to the 5GC.
[0016] Another object of the embodiments herein is to store and manage the digital asset container by the 5GC and by the third-party entity.
[0017] Another object of the embodiments herein is to disclose methods and systems for binding the digital identity to a 3GPP subscription.
[0018] Another object of the embodiments herein is to disclose methods and systems for retrieving the digital ID / Avatar ID from the Digital Asset Container (DAC)
[0019] The technical subjects pursued in the disclosure may not be limited to the above mentioned technical subjects, and other technical subjects which are not mentioned may be clearly understood, through the following descriptions, by those skilled in the art to which the disclosure pertains.
[0020] Accordingly, the embodiments herein provide a method for managing an avatar identity in a metaverse system. The method includes receiving, by a second entity, an application session establishment request from a first entity for a user through an IP Management Subsystem (IMS) Application Server (AS). The application session establishment request comprises at least one of: at least one avatar identity and a token. The method further includes requesting, by the second entity, to retrieve an avatar representation from an avatar repository to verify the avatar identity in the application session establishment request matches with the avatar representation of the user stored in the avatar repository. The avatar representation includes at least one avatar identity. The method further includes sharing, by the second entity, the token and a user identity of the user received in the application session establishment request along with the request to retrieve the avatar representation. The method further includes receiving, by the second entity (104), a verification from the avatar repository, when the requesting user is allowed to use the provided avatar identity of the application session establishment request. The method further includes receiving, by the second entity, a response message comprising the avatar representation from the avatar repository, upon successful verification of the avatar identity along with the user identity received in the application session establishment request with a preconfigured avatar representation and a user profile information in the avatar repository.
[0021] Accordingly, the embodiments herein provide a method for managing an avatar identity in a metaverse system, wherein the method includes receiving, by a first entity, an application session establishment request from a user equipment (UE) to access at least one of: a metaverse service and an avatar communication service. The application session establishment request comprises at least one of: at least one avatar identity and a token. The method further includes sending, by the first entity, an avatar request of the user to a core network by invoking a service operation. The method further includes receiving by the first entity, a response message from the core network through an avatar repository based on the avatar request of the user. The response message comprises at least one avatar identity is used to check for a user identity and a user identity tokens whether the user is already authenticated for accessing at least one of: the metaverse service and the avatar communication service. The at least one avatar identity is retrieved by the avatar repository for the corresponding user identity and a UE identity. The method further includes verifying by the first entity, the received avatar identity received in the application session establishment request through the UE is the same as the avatar identity received in the response message from the core network. The method further includes sending by the first entity, at least one of: a metaverse service response and an avatar communication service response, with at least one of: a requested service and a success indication to the UE when the received avatar identity from the application session establishment request through the UE is the same as the avatar identity received in the response message from the core network.
[0022] Accordingly, the embodiments herein provide a method for managing an avatar identity in a metaverse system. The method includes receiving by a second entity, an avatar request of a user from a core network to access a metaverse service. The avatar request of the user includes at least one of: at least one avatar identity and a token. The method further includes requesting by the second entity, to retrieve an avatar representation from an avatar repository; wherein the avatar representation comprises at least one of: an avatar identity, a digital painting, and a digitally purchased item. The method further includes verifying by the second entity, whether the avatar identity in the avatar repository for the requesting user matches with the avatar identity of the avatar request of the user. The method further includes validating by the second entity, that the requesting user with a user identity is allowed to use the provided avatar identity based on the verification. The method further includes retrieving by the second entity, the requested avatar representation based on the validation. The method further includes sending, by the second entity, a response message to a first entity. The response message comprises at least one of: an internet protocol (IP) address where the avatar is stored, a time period, the avatar identity, and success indication.
[0023] Accordingly, the embodiments herein provide a second entity, including a processor, a memory, a transceiver; and an avatar identity managing controller, coupled with the processor and the memory. The processor is configured to receive an application session establishment request from a first entity for a user through an IP Management Subsystem (IMS) Application Server (AS). The application session establishment request comprises at least one of: at least one avatar identity and a token. The processor is further configured to request to retrieve an avatar representation from an avatar to verify avatar identity in the application session establishment request matches with the avatar representation of the user stored in the avatar repository wherein the avatar representation comprises at least one of: at least one token and at least one avatar identity. The processor is further configured to share the token and a user identity of the user received in the application session establishment request along with the request to retrieve the avatar representation. The processor is further configured to receive a verification from the avatar repository, when the requesting user is allowed to use the provided avatar identity of the application session establishment request. The processor is further configured to receive a response message comprising the avatar representation from the avatar repository, upon successful verification of the avatar identity along with the user identity received in the application session establishment request with a preconfigured avatar representation and a user profile information in the avatar repository.
[0024] Accordingly, the embodiments herein provide a first entity, including a processor, a memory, a transceiver; and an avatar identity managing controller, coupled with the processor and the memory. The processor is configured to receive an application session establishment request from a user equipment (UE) to access at least one of: a metaverse service and an avatar communication service. The application session establishment request comprises at least one of: at least one avatar identity. The processor is further configured to send an avatar request of the user to a core network by invoking a service operation. The processor is further configured to receive a response message from the core network through an avatar repository based on the avatar request of the user. The response message comprises at least one avatar identity is used to check for a user identity and a user identity token whether the user is already authenticated for accessing at least one of: the metaverse service and the avatar communication service by the avatar repository for the corresponding user identity and a UE identity. The processor is further configured to verify the received avatar identity received in the application session establishment request through the UE is the same as the avatar identity received in the response message from the core network. The processor is further configured to send at least one of: a metaverse service response and an avatar communication service response, with at least one of a requested service and a success indication to the UE when the received avatar identity from the application session establishment request through the UE is the same as the avatar identity received in the response message from the core network.
[0025] Accordingly, the embodiments herein provide a second entity, including a processor, a memory, a transceiver, and an avatar identity managing controller, coupled with the processor and the memory. The processor is configured to receive an avatar request of a user from a core network to access at least one of: a metaverse service and an avatar communication service. The avatar request of the user comprises at least one avatar identity and a token. The processor is further configured to request to retrieve an avatar representation from an avatar repository; wherein the avatar representation comprises at least one of: an avatar identity, a digital painting, and a digitally purchased item. The processor is further configured to verify by checking whether the avatar identity in the avatar repository for the requesting user matches with the avatar request of the user. The processor is further configured to validate that the requesting user with a user identity is allowed to use the provided avatar identity based on the verification. The processor is further configured to retrieve the requested avatar representation based on the validation. The processor is configured to send a response message to a first entity; wherein the response message comprises at least one of: an internet protocol (IP) address where the avatar is stored, a time period, the avatar identity, and success indication.
[0026] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating at least one embodiment and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the scope thereof, and the embodiments herein include all such modifications.
[0027] The present disclosure provides an effective and efficient method for methods and systems for managing an avatar identity in a metaverse system. Advantageous effects obtainable from the disclosure may not be limited to the above mentioned effects, and other effects which are not mentioned may be clearly understood, through the following descriptions, by those skilled in the art to which the disclosure pertains.
[0028] Embodiments herein are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the following illustrated drawings. Embodiments herein are illustrated by way of examples in the accompanying drawings, and in which:
[0029] FIG. 1 shows a schematic overview of a system 100 for managing an avatar identity, according to embodiments as disclosed herein;
[0030] FIG. 2A shows a flowchart for a method 200 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein;
[0031] FIG. 2B depicts a flowchart of a method 250 to receive the application session establishment request from the first entity for the user by the second entity, according to embodiments as disclosed herein;
[0032] FIG. 3 shows an example sequence diagram 300 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein;
[0033] FIG. 4 shows a schematic overview of a system 400 for managing an avatar identity, according to embodiments as disclosed herein;
[0034] FIG. 5 shows a flowchart for a method 500 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein;
[0035] FIG. 6 shows an example sequence diagram 600 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein;
[0036] FIG. 7 shows a schematic overview of a system 700 for managing an avatar identity in a metaverse system, according to embodiments as disclosed herein;
[0037] FIG. 8 shows a flowchart for a method 800 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein;
[0038] FIG. 9 an example sequence diagram for the process of retrieving the avatar from the AAA server by the metaverse provider, according to embodiments as disclosed herein;
[0039] FIG. 10 depicts an example sequence diagram for managing the avatar identity by mapping the avatar identity with 3GPP subscription, and updating the UDM record accordingly, according to embodiments as disclosed herein;
[0040] FIG. 11 depicts an example sequence diagram for managing the avatar identity by retrieving the avatar by the metaverse provider from the UDM, according to embodiments as disclosed herein;
[0041] FIG. 12 depicts an example sequence diagram for managing the avatar identity by performing user authentication and authorization using OAuth Mechanism, according to embodiments as disclosed herein;
[0042] FIG. 13 depicts an example sequence diagram for managing the avatar identity by retrieving the digital identity from a third-party entity, according to embodiments as disclosed herein;
[0043] FIG. 14 depicts an example sequence diagram for managing the avatar identity by verifying the digital identity by the network, according to embodiments as disclosed herein; and
[0044] FIG. 15 depicts an architecture to support IMS avatar communication without DC, according to embodiments as disclosed herein.
[0045] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.
[0046] For the purposes of interpreting this specification, the definitions (as defined herein) will apply and whenever appropriate the terms used in singular will also include the plural and vice versa. It is to be understood that the terminology used herein is for the purposes of describing particular embodiments only and is not intended to be limiting. The terms "comprising", "having" and "including" are to be construed as open-ended terms unless otherwise noted.
[0047] The words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.,", "i.e.," are merely used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein using the words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.,", "i.e.," is not necessarily to be construed as preferred or advantageous over other embodiments.
[0048] Embodiments herein may be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which may be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by firmware. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the disclosure.
[0049] It should be noted that elements in the drawings are illustrated for the purposes of this description and ease of understanding and may not have necessarily been drawn to scale. For example, the flowcharts / sequence diagrams illustrate the method in terms of the steps required for understanding aspects of the embodiments as disclosed herein. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein. Furthermore, in terms of the system, one or more components / modules which comprise the system may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
[0050] The accompanying drawings are used to help easily understand various technical features and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the present disclosure should be construed to extend to any modifications, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings and the corresponding description. Usage of words such as first, second, third etc., to describe components / elements / steps is for the purposes of this description and should not be construed as sequential ordering / placement / occurrence unless specified otherwise.
[0051] Within the third-generation project partnership (3GPP) Technical Specification Group Service and System Aspects (TSG SA), the main objective of 3GPP TSG SA WG1 (SA1) is to consider and study new and enhanced services, features, and capabilities and identify any corresponding stage 1 requirements to be met by 3GPP specifications. Currently, the 3GPP SA1 has studied multiple use cases and service requirements for 5thgeneration services (5GS) support of enhanced Extended Reality (XR)-based services, for the metaverse. In SA1, Rel-19 FS_Metaverse (TR 22.856) has studied the feasible use cases of localized mobile metaverse services and requirements of localized mobile metaverse services. Example use cases can be, but not limited to, localized mobile metaverse service, metaverse conference with user's digital identity, spatial mapping and localization service enabler, and avatar communications that requires system architecture enhancements for a 5G system to support mobile metaverse services. The study of mobile metaverse service indicates that the mobile metaverse services have distinct characteristics and have service aspects that are not present in any other immersive user services such as extended reality (XR) or virtual reality (VR) for today. Certain use cases specified in TR 22.856 (for example, use case 3, 24, 13, 15, 28 etc.) point out towards a need for security enhancement in mobile metaverse services.
[0052] In the mobile metaverse services, a real-time conversational user experience is highly desired for avatar communications. The new type of media file format, a media codec, and characteristics of those services need to be considered for representing the user's avatar in the network. Moreover, based on the different UE capabilities, various network entity deployments, network conditions, and based on the user's preferences, the avatar call may be dynamically converted to a video call, or a normal voice call. The transition between the avatar media call and the other type of calls including video call may be processed in the network in this respect as described in 3GPP TR 22.856.
[0053] For example, from a survey / study it is identified that around 1 billion people do not have a proof of identity and there comes the initiative from GSMA on the proposal for a digital identity or an avatar identity. As detailed in the Annex B of 3GPP TR 22.856, an EU digital identity wallet has been proposed. The EU digital identity wallet is intended to allow European citizens to safely save their documents and personal information in a manner that complies with privacy regulations, as well as to give the data owners full control how the data is used (who can access it), and to track how it has been used. The information stored in the wallet could have general utility in many circumstances, even outside of the country in which the information was issued. Examples given are driver's licenses, medical records or certification such as university degree titles. It is acknowledged that people need to establish their identity in many ways. The process is currently complex, as each activity requires different credentials and as the form of credentials vary, identification requires different processes. Having a single digital identity wallet will simplify these processes. The goal of the program is to bring the following benefits:
[0054] a. To support the ability of every person eligible for a national identity card to have a digital identity that is recognized anywhere in the European union (EU);
[0055] b. To provide a simple and a safe way to control the amount of information to be shared with the services that require the sharing of information;
[0056] c. To allow a mobile phone applications and other devices to support a means to:
[0057] a. provide identity services on-line and off-line;
[0058] b. store and exchange information provided by a government body, e.g. name, surname, date of birth, nationality; and
[0059] c. use the information as confirmation of the right to reside, to work, or to study in a particular member state.
[0060] The mobile metaverse media may support multiple users, there can be multiple devices accessing the network for better XR experience and the device and / or the UE can be bounded with multiple users. Given different use cases, the data associated with the avatars of users is generated and stored on different mobile metaverse servers. For example, a user uses life-like avatars for e-commerce and cartoonish avatars for gaming. Network operators enabling users to obtain diverse mobile metaverse services should support avatar management as a value-added service. For example, network operators can leverage their existing connections to extensive mobile metaverse servers and provide access to avatars across these servers acting as a proxy server.
[0061] For the avatar based real time communication, the 5G system should be able to identify the subscriber who has the right to use an avatar in mobile metaverse services as defined in [R-7.2.3-003] of 3GPP TS 22.156.
[0062] Currently, the subscription data of the user is stored at per user equipment (UE) granularity in the Unified Data Management (UDM). However, when multiple users are accessing the devices using their digital representations and / or when there are multiple devices belonging to the same user, there is a need to identify whether the user is allowed to use a particular digital identity for the metaverse service and whether the user is allowed for certain access / service in the metaverse technology in order to prevent a malicious user using the service that are allowed only for a particular user and / or an authenticated user. Therefore, there is a binding required between the 3GPP subscription and the real user and his / her avatar ID to ensure the metaverse service is only allowed to a valid user.
[0063] In mobile metaverse services, such as metaverse conference, the user and user's digital representations, and multiple devices which belong to the same user should be identified and authenticated. In such cases, it is required to bind the external authentication of the digital identity with 3GPP subscription.
[0064] During the avatar communication, the avatar may not correspond to the user (who is claiming as the real user), making it possible for a user to use a victim's device and thus victim's avatar, to initiate the avatar communication. Also, the avatar storage doesn't verify whether the avatar belongs to the user or not. Whether the UE can access, retrieve and / or use an avatar should be based on the authentication and authorization by the 5GS. A failure to ensure that only authenticated and authorized parties can access, retrieve, and / or use an Avatar may result in impersonation attacks.
[0065] Examples of scenarios / cases where security analysis can be required are as follows:
[0066] a. To verify whether the user is allowed to use the digital identity (e.g., avatar) for a metaverse service.
[0067] b. To create the linking of the digital identity (e.g., avatar) with 3GPP subscription in the UDM.
[0068] c. To authorize and authenticate the user(s) associated with digital identity(s) and protect the user's sensitive information sharing to and from a third-party service provider.
[0069] d. The way the 5GS authorizes and exposes the avatar information to the metaverse server.
[0070] e. To securely share and authorize the same avatar for multiple services between multiple metaverse servers.
[0071] f. To securely store and manage the digital asset container for the avatar communication.
[0072] Hence, there is a need in art for solutions which will overcome the above-mentioned drawbacks, among others.
[0073] Embodiments herein disclose a method for managing an avatar identity in a metaverse system, wherein the method includes receiving, by a second entity, an application session establishment request from a first entity for a user through an IP Management Subsystem (IMS) Application Server (AS). The method further includes requesting to retrieve an avatar representation from an avatar repository to verify the avatar identity received in the application session establishment request matches with the avatar representation of the user stored in the avatar repository. The method further includes receiving, by the second entity, a verification from the avatar repository, when the requesting user is allowed to use the provided avatar identity and receiving, a response message comprising the avatar representation from the avatar repository, upon successful verification of the avatar identity.
[0074] Embodiments herein disclose methods and systems for managing an avatar identity in a metaverse system. Embodiments herein disclose methods and systems for verifying whether a user is allowed to use an avatar identity (digital identity). Embodiments herein disclose methods and systems for creating a link between the avatar identity with user identity and with 3GPP subscription in the Unified data management (UDM). Embodiments herein disclose methods and systems for securely sharing avatar information by a 5thgeneration core network (5GC) to metaverse servers. Embodiments herein disclose methods and systems for securely sharing avatar information by a third-party entity to the 5GC. Embodiments herein disclose methods and systems for storing and managing the digital asset container by the 5GC and by the third-party entity. Embodiments herein disclose methods and systems for creating a link in between the avatar identity to a 3rdgeneration project partnership (3GPP) subscription.
[0075] Embodiments herein address security of IP Multimedia Core Network Subsystem (IMS) based Avatar Communication. The embodiments herein achieve methods and systems for managing an avatar identity in a metaverse system.
[0076] In TR 23.700-77, conclusion is reached to support the network-based avatar communication by media capability invocation. Specifically, the avatar representations are stored in a Base Avatar Repository (BAR), and a user equipment sends the avatar identity to the extended reality Application Server (XR AS). A media function (MF) entity or XR AS downloads the avatar representation from the Base Avatar Repository (BAR) based on the avatar identity.
[0077] In an embodiment herein, the XR Application Server is responsible for service control related to avatar communication, including avatar representation management, access control, avatar communication session media control, and so on. The Base Avatar Repository is used to store and retrieve the avatar representations. The BAR can be inside the PLMN, e.g. a new network function, or outside the PLMN, e.g. a webserver of the 3rd party provider.
[0078] The solution in the embodiments herein proposes security procedures to verify avatar identity, and authorize the UE / IMS entity (i.e., MF or XR AS) that accesses the avatar representations, preventing the unauthorized UE / IMS entities from accessing the avatar representations and thus impersonating the IMS caller / callee.
[0079] The avatar communication can be unidirectional or bidirectional. In this solution, only unidirectional avatar communication is described. When bidirectional avatar communication is used, UE2 also performs the operation same as UE1 described in the procedure.
[0080] Referring now to the drawings, and more particularly to FIGS. 1 through 15, where similar reference characters denote corresponding features consistently throughout the figures, there are shown embodiments.
[0081] FIG. 1 shows a schematic overview of a system 100 for managing an avatar identity, according to embodiments as disclosed herein. The system 100 can be, for example, but is not limited, to a fourth-generation wireless network, a fifth-generation wireless network, Open Radio Access Network (ORAN), a sixth generation (6G) network or the like. The system 100 includes a first entity 102, a second entity 104, an IP Management Subsystem (IMS) Application Server (AS) 114, an avatar repository 116, and a user equipment (UE) 118. The first entity 102 can be, for example, but is not limited to, an extended reality application server (XR AS), an application function (AF) entity, and an Authentication, Authorization, and Accounting (AAA) Server. The second entity 112 can be, for example, but is not limited to at least one of: a Network Exposure Function (NEF) entity, a media function (MF) entity, and a media resource function (MRF) entity.
[0082] In an embodiment herein, the system 100 may be implemented on, for example, but not limited to devices with immersive experience, such as an augmented reality (AR) device, a virtual reality (VR) device or an extended reality (XR) device. The devices may include but are not limited to, a laptop, a smart phone, a desktop computer, a notebook, a Device-to-Device (D2D) device, a vehicle to everything (V2X) device, a foldable phone, a smart TV, a tablet, a television, a connected car, an immersive device, an internet of things (IOT) device, or any other device that can communicate using the wireless network.
[0083] In an embodiment herein, the second entity 104 comprises a processor 106, an avatar identity managing controller 108, a transceiver 112, and a memory 110. In an embodiment herein, the avatar identity managing controller 108 is a part of the processor 106, where the avatar identity managing controller 108 communicates with the entities (client and servers) through the transceiver 112. In another embodiment herein, the avatar identity managing controller 108 is outside the processor 106 but the avatar identity managing controller 108 is in communication with the processor 106, where the avatar identity managing controller 108 communicates with the first entity 102, the avatar repository 116 through the transceiver 112. In another embodiment herein, the avatar identity managing controller 108 is outside the processor 106, and the avatar identity managing controller 108 works separately from the processor 106, where the avatar identity managing controller 108 communicates with the first entity 102 through the transceiver 112.
[0084] In an embodiment herein, the memory 110 is configured to store instructions to be executed by the processor 106. The memory 110 can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory 110 may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memory 110 is configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).
[0085] The processor 106 may include one or more processor(s). The one or more processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor 106 may include multiple cores and is configured to execute the instructions stored in the memory 110.
[0086] In an embodiment, the transceiver 112 includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver 112 is configured to communicate internally between internal hardware components of the second entity 104 and with external devices via one or more networks.
[0087] In an embodiment herein, the avatar repository 116 may include at least one of: a base avatar repository (BAR), and a Digital Asset Container (DAC). The avatar repository 116 may be located in but is not limited to: a network function (NF) entity, a Unified data management (UDM) entity, a User Authentication Function (UAF) entity, user information database function (UIDF) entity, and a user database (UDB). The BAR stores and retrieves an avatar model, the BAR is located in at least one of: inside a new network function entity for example a PLMN, and outside a network function entity. The outside the network function entity includes, but is not limited to, a webserver managed by a third-party provider.
[0088] In another embodiment, the BAR and the UAF can interchangeably take the role as proposed in other alternatives of this document.
[0089] In an embodiment herein, the DAC is used for storing and retrieving an avatar metadata including avatar representation from a fifth-generation core (5GC) network. The DAC is located in at least one of: internal to a new network function entity, as a part of a network function, a XR application server, a web server within an IMS and a 5GC. The network function entity may include but is not limited to a Home Subscriber Server (HSS), a Unified data management (UDM) entity, IP Multimedia Subsystem (IMS) entity, and an application server (AS). The DAC may be located outside the network function comprising a webserver managed by a third-party provider.
[0090] In an embodiment herein, the UE 118 chooses an avatar identity from the avatar identity list and generates a token. The token may include, but is not limited to an avatar identity, an issuer (a UE identity), a subject (a media function entity type (MF type) or XR AS type), an audience (a base avatar repository type (BAR type), and an expiration time. The UE 118 generates the token based on a private key that corresponds to a certificate of the UE 118. The generation of the signature in the token can be referred to clause 5 of IETF RFC 7515
[0012] . The UE certificate used for media plane protection can be reused.
[0091] In an embodiment herein, the first entity 102 receives an application session establishment request from the UE 118. The application session establishment request may include, but is not limited to, an avatar identity and the token. The procedure for the application session establishment may be an avatar animation negotiation procedure.
[0092] In an embodiment herein, the first entity 102 may include, but is not limited to, the XR Application Server (XR AS): The XR Application Server is responsible for service control related to avatar communication, including avatar communication session media control and so on.
[0093] In an embodiment herein the first entity 102 determines whether the received avatar identity is in the avatar identity list of the UE 118. If the avatar identity received by the first entity 102 is equal to one of the avatar identity in the avatar identity list of the UE 118, the first entity 102 sends the application session establishment request to the second entity 104. Otherwise, if the avatar identity is not found in the avatar identity list of the UE 118, the first entity 102 may send an error message to the UE 118. The first entity 102 may also check whether the token is a valid token or an expired token.
[0094] In an embodiment herein, if the first entity 102 does not have the avatar identity list of the UE 118, the first entity 102 retrieves the avatar identity list of the UE 118 from the avatar repository 116.
[0095] In an embodiment herein, an avatar metadata includes an avatar representation stored in a file, which can be accessed, for example via a universal resource locator (URL). The avatar metadata, or a reference of the avatar metadata (e.g. identifier), is associated per subscriber or per user identifier of a subscriber. The avatar representation corresponds to a 2 dimensional or a three-dimensional model of a face, full body, or a portion of the body. An additional metadata can be associated with the avatar representation as part of the avatar metadata, e.g. format, resolution, access / usage rights & conditions, date of creation, licensing, etc.
[0096] In an embodiment herein, the avatar metadata is addressable via the avatar identity. The avatar identity can be, but is not limited to, an integer, string, a Universally Unique Identifier (UUID), or a Uniform Resource Identifier (URI) including a uniform Resource Name (URN) or the URL. Retrieving means such as application Programming Interfaces (APIs), can be used to retrieve the avatar metadata based on the Avatar-identity from a predefined server or the avatar repository 116 (e.g. the DAC).It an embodiment herein, the Avatar-identity are associated per subscriber or per associated subscriber's User Identity in the IMS HSS (i.e. assuming multiple User Identities per subscriber, e.g. personal and / or professional).
[0097] In an embodiment herein, when an avatar related context is created in the DAC and associated with an avatar identity, the avatar identity is configured on the UE 118 that may use the particular avatar. The configuration is done via mechanisms out of the scope of 3GPP such as configured by the certificate authority or by the identity provider etc.
[0098] In an embodiment herein, the second entity 104 sends a request through the avatar identity managing controller 108 to download the avatar representation from the avatar repository 116. The avatar representation may include parameters of a token, a user identity of the user, and an avatar identity related to the user identity. The avatar identity received in the application session establishment request is also shared to the avatar repository 116.
[0099] In an embodiment herein, the avatar repository 116 verifies the token provided by the second entity 104. The avatar repository 116 verifies a certificate related to the UE 118 based on a certificate fingerprint. The avatar repository receives the certificate fingerprint with at least one token of the application session establishment request. The avatar repository 116 verifies the avatar identity in the application session establishment request after verifying the certificate related to the UE, Specifically, the avatar repository 116 checks whether the received audience type in the token of the application session establishment request matches the audience type of the avatar repository 116, the subject in the token of the application session establishment request matches the MF type of the second entity 104. The second entity 104 also verifies whether the token is a valid token or an expired token, where the token has reached the expiration time. In an embodiment herein, whether the avatar identity in the avatar repository for the requesting user matches with the avatar identity of the application session establishment request.
[0100] In an embodiment herein, the second entity 104 receives a response message including the avatar representation from the avatar repository, upon successful verification of the avatar identity along with the user identity received in the application session establishment request with a preconfigured avatar representation and a user profile information in the avatar repository 116. The response message has a success indication that the avatar identity along with the user identity received in the application session establishment request from the UE is the same as the avatar identity received in the response message through the avatar repository 116.
[0101] In an embodiment herein, the second entity 104 receives a response message including at least one error code, indicating that the token verification or the verification of the certificate for the avatar identity has failed.
[0102] In an embodiment herein, the 5GC network provides a link between the digital identity with the 3GPP subscription and the 5GC network requests the certification authority or the avatar identity provider to provide the avatar identity for verification and updating the UDM record. In an embodiment herein, the digital identity provider can be the third-party entity.
[0103] The embodiments herein provide a solution to prevent the UE 118 from providing the avatar identity belonging to other UEs, the solution proposes to verify whether the avatar identity provided by the UE 118 is in the UE's Avatar identity list. To prevent the second entity 104 from downloading the wrong avatar representation based on other UE's Avatar identity, the solution requires the second entity 104 to download the avatar representation based on the token received from the UE 118. A real-time user with the 3GPP subscription and the avatar identity associated with the real-time user is linked together to ensure the metaverse service is only allowed to a valid user.
[0104] FIG. 2A shows a flowchart for a method 200 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein. At step 202, the second entity 104 receives the application session establishment request from the first entity 102 for the user through an IP Management Subsystem (IMS) Application Server (AS). The application session establishment request includes at least one of: the at least one avatar identity and the token. At step 204, the second entity 104 requests the avatar repository 116 to retrieve an avatar representation to verify the avatar identity in the application session establishment request matches with the avatar representation of the user stored in the avatar repository 116. The avatar representation may include but is not limited to at least one avatar identity. The token and a user identity of the user received in the application session establishment request is shared along with the request to retrieve the avatar representation by the second entity 104. At step 206, the avatar repository 116 verifies the certificate related to the UE 118 based on the certificate fingerprint. The avatar repository 116 receives the certificate fingerprint with the at least one token of the application session establishment request. The avatar repository 116 verifies the avatar identity of the application session establishment request after verifying the certificate related to the UE 118. The avatar repository 116 checks whether the avatar identity in the avatar repository 116 for the requesting user matches with the avatar identity of the application session establishment request. The avatar repository 116 also verifies whether the token is the valid token or the expired token. At step 208, the second entity 104 receives the verification from the avatar repository 116, when the requesting user is allowed to use the provided avatar identity of the application session establishment request. At step 210, the second entity 104 receives the response message including the avatar representation from the avatar repository, upon successful verification of the avatar identity along with the user identity received in the application session establishment request with a preconfigured avatar representation and a user profile information in the avatar repository 116. The response message includes a success indication verifying the avatar identity received from the application session establishment request through the UE 118 is the same as the avatar identity received in the response message through the avatar repository. At step 212, the second entity 104 receives the response message including at least one error code, indicating that the token verification or the verification of the certificate for the avatar identity has failed in case the avatar identity along with the user identity received in the application session establishment request is not the same as the preconfigured avatar representation and a user profile information in the avatar repository 116.
[0105] The various actions in method 200 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 2A may be omitted.
[0106] FIG. 2B depicts a flowchart of a method 250 to receive the application session establishment request from the first entity for the user by the second entity, according to embodiments as disclosed herein. Before the second entity 104 receives the application session establishment request from the first entity, the method includes the following steps, at step 220, the first entity 102 receives the application session establishment request from the user equipment (UE) 118 to access at least one of: the metaverse service and the avatar communication service. At step 222, the first entity 102 determines whether the received avatar identity is in the list of avatar identities of the UE 118. At step 224, the first entity 102 authorizes the application session establishment request from the UE 118, if the received avatar identity is equal to at least one of the avatar identity in the allowed list of avatar identities of the UE 118. At 226, the first entity 102 sends the application session establishment request to the second entity 104 through an IP Management Subsystem (IMS) Application Server (AS), therefore, the second entity 104 receives application session establishment request from the first entity for the user.
[0107] The various actions in method 250 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 2B may be omitted.
[0108] FIG. 3 shows an example sequence diagram 300 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein. At step 302, Bootstrap data channel (BDC) is established. Through the BDC, the UE 118 receives the avatar identity list. At step 304, Application data channel (ADC) is established. At step 306, the UE 118 chooses the avatar identity from the list of the avatar identity and generates the token. At step 308, the XR AS 334 receives the avatar identity and the token from the UE 118 during Avatar animation negotiation procedure. At 310, the XR AS 334 determines whether the received avatar identity is in the list of the avatar identity of the UE 118. If the received avatar identity is equal to one of the avatar identity in the list of the avatar identity of the UE 118, Steps 312 is executed. Otherwise, the XR AS 334 may send an error message to the UE 118. If the XR AS 334 does not have the list of the avatar identity of the UE 118, the XR AS 334 retrieves the list of the avatar identity of the UE 118 from the BAR 336. The XR AS 334 may also check whether the token is the valid token or the expired token. At step 312, the XR AS 334 sends the avatar identity and the token to the IMS AS 330. At step 314, the IMS AS 330 sends the avatar identity and the token to the MF or the MRF 332. At step 316, the MF 332, requests the BAR 336 to download the avatar representation from the BAR 336, including parameters of the token and the avatar identity. At step 318, the BAR 336 verifies the token provided by the MF 332. Specifically, BAR 336 checks whether the audience matches its own type, the subject is the MF type 332, the token is not expired. The BAR 336 also checks whether the avatar identity in the request equals that in the token. Note that before verifying the token, the BAR 336 can also verify the certificate of the UE based on the certificate fingerprints. The certificate fingerprint is sent to XR AS 334 during the Avatar animation negotiation procedure and then sent to the BAR 336 along with the token. At step 320, the BAR 336 sends the avatar representation downloading response message to the MF 332. If the verification in step 318 is passed, the message includes the avatar representation, otherwise the message includes the error code, indicating that the token verification or the verification of the certificate fails.
[0109] FIG. 4 shows a schematic overview of a system 400 for managing an avatar identity, according to embodiments as disclosed herein. The system 400 can be, for example, but is not limited, to a fourth-generation wireless network, a fifth-generation wireless network, Open Radio Access Network (ORAN), a sixth generation (6G) network or the like. The system 400 includes a first entity 404, a core network 402, an avatar repository 116, and the user equipment (UE) 118. The first entity 402 can be, for example, but is not limited to, an extended reality application server (XR AS) and an application function (AF) entity.
[0110] In an embodiment herein, the UE 118 may be implemented on, for example, but not limited to devices with immersive experience, such as an augmented reality (AR) device, the virtual reality (VR) device or the extended reality (XR) device. The devices may include but are not limited to, the laptop, the smart phone, the desktop computer, the notebook, the Device-to-Device (D2D) device, the vehicle to everything (V2X) device, the foldable phone, the smart TV, the tablet, the television, the connected car, the immersive device, the internet of things (IOT) device, or any other device that can communicate using the wireless network.
[0111] In an embodiment herein, the first entity 404 comprises a processor 406, an avatar identity managing controller 408, a transceiver 412, and a memory 410. In an embodiment herein, the avatar identity managing controller 408 is a part of the processor 406, where the avatar identity managing controller 408 communicates with the entities (client and servers) through the transceiver 412. In another embodiment herein, the avatar identity managing controller 408 is outside the processor 406 but the avatar identity managing controller 408 is in communication with the processor 406, where the avatar identity managing controller 108 communicates with the UE 118, the avatar repository 116 through the transceiver 412. In another embodiment herein, the avatar identity managing controller 408 is outside the processor 406, and the avatar identity managing controller 408 works separately from the processor 406, where the avatar identity managing controller 408 communicates with the UE 118 through the transceiver 412.
[0112] In an embodiment herein, the memory 410 is configured to store instructions to be executed by the processor 406. The memory 410 can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory 410 may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memory 410 is configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).
[0113] The processor 406 may include one or more processor(s). The one or more processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as the graphics processing unit (GPU), the visual processing unit (VPU), and / or the AI-dedicated processor such as the neural processing unit (NPU). The processor 406 may include multiple cores and is configured to execute the instructions stored in the memory 410.
[0114] In an embodiment, the transceiver 412 includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver 412 is configured to communicate internally between internal hardware components of the first entity 404 and with external devices via one or more networks.
[0115] In an embodiment herein, the avatar repository 416 may include at least one of: the base avatar repository (BAR), and the Digital Asset Container (DAC). In an embodiment herein, the avatar repository 416 may be located in, but is not limited to: the network function (NF) entity, the Unified data management (UDM) entity, the User Authentication Function (UAF) entity, user information database function (UIDF) entity, and the user database (UDB). The BAR stores and retrieves the avatar model, the BAR is located in at least one of: inside a new network function entity for example the PLMN, and outside a network function entity. The outside the network function entity includes, but is not limited to, a webserver managed by a third-party provider.
[0116] In an embodiment herein, the DAC is used for storing and retrieving an avatar metadata including avatar representation from a fifth-generation core (5GC) network. The DAC is located in at least one of: internal to a new network function entity, as a part of a network function, a XR application server, a web server within an IMS and a 5GC. The network function entity may include but is not limited to a Home Subscriber Server (HSS), a Unified data management (UDM) entity, IP Multimedia Subsystem (IMS) entity, and an application server (AS). The DAC may be located outside the network function comprising a webserver managed by a third-party provider.
[0117] In an embodiment herein, the first entity 404 receives the application session establishment request from the user equipment (UE) 118 to access at least one of: the metaverse service and the avatar communication service. The application session establishment request includes at least one of: at least one avatar identity and a token. The application session establishment request may include an IP address and a UE-identity identifying the terminal through which services are accessed. The AF-identity, an External-Identity-Provider-identity identifying a 3rd party identity service provider though which user utilizing the service can be authenticated. The UE 118 may additionally include the session-identity and other possible parameters in the application session establishment request message.
[0118] In an embodiment herein, the UE 118 chooses the avatar identity from a list of allowed avatar identities. The UE 118 generates the token. The token comprises at least one of the avatar identity, an issuer identity, a subject containing at least one of a media function (MF) type and an extended reality application server (XR AS) type, an audience type, a user identity, a UE identity, a service type, and an expiration time. The token is generated based on a UE's private key corresponding to a certificate associated with the UE 118.
[0119] In an embodiment herein, the first entity 404 sends the avatar request of the user through the avatar identity managing controller 408 to the core network 402 by invoking a service operation. The first entity 404 may invoke a Nnef_UEId_Get service operation for translating the UE's Private IP address to the identity of the UE. The avatar request of the user to the core network 402 includes the received IP Address and user identity in the request message. In an embodiment herein, the NEF of the core network 402 translates the private internet protocol (IP) address of the UE 118 to the identity of the UE. Alternatively, the first entity 404 identifies a home network based on the received identity of the UE.
[0120] In an embodiment herein, the NEF of the core network 402 sends a request to retrieve the avatar identity to the avatar repository 116. The NEF of the core network retrieves the user identity from the session identity received in the avatar request of the userfrom the UDM of the avatar repository 116. The UDM may directly communicate with the UE 118.
[0121] In an embodiment herein, the User-identity is the identity uniquely identifying the user. The session-identity is a randomly generated identity for the session, which can be used if the User-Identity needs to be hidden until identity verification. The user-identity and the Session-identity are especially useful when multiple users are present behind the UE 118.
[0122] In an embodiment herein, the UDM in the core network may send the request to retrieve the avatar identity to the UAF. The request message includes the User Identity, the AF identity, a user identity, a UE identity, a service type, and other possible parameters. In an embodiment herein, the UAF is pre-configured with the digital identity for the users. In an embodiment herein, based on the request from the UDM and the first entity 404, the UDM retrieves the avatar identity from at least one of: an external AAA, a certification Authority (CA), the UAF, and the third-party entity.
[0123] In an embodiment herein, the UAF sends the response message to the UDM. The response message includes the avatar identity allowed for the user whose avatar identity is received and additionally includes the user identity token if the user is already authenticated for the metaverse service. The response message may include at least one avatar identity that is used to check for the mapping of allowed avatar identity for the corresponding user identity and a user identity token, for whether the user is already authenticated for accessing the at least one of: the metaverse service and the avatar communication service On receiving the response message, the UDM forwards the response message to the NEF of the core network 402. The response message includes the avatar identity allowed for the user whose identity is received and additionally includes the user identity token if the user is already authenticated for the metaverse service. The NEF of the core network forwards the response message to the first entity 404.
[0124] In an embodiment herein, the avatar repository 116 is internal to the core network 402, that is the avatar repository is located in at least one of the UDM and the UAF. In an embodiment herein, the avatar repository 116 is outside the core network 402, including a webserver managed by a third-party provider.
[0125] In an embodiment herein, the first entity 404 receives the response message from the core network 402 through the avatar repository 116 based on the avatar request of the user. The response message comprises at least one avatar identity that is used to check for the user identity and the user identity token whether the user is already authenticated for accessing the metaverse service. The at least one avatar identity is retrieved by the avatar repository 116.
[0126] In an embodiment herein, the first entity 404 verifies the received avatar identity received from the application session establishment request through the UE 118 is the same as the avatar identity received in the response message through the avatar repository 116.
[0127] In an embodiment herein, the first entity 404 sends at least one of: a metaverse service response and an avatar communication service response, with at least one of: a requested service and a success indication to the UE when the received avatar identity from the application session establishment request through the UE is the same as the avatar identity received in the response message through from the core network (402).
[0128] In an embodiment herein, the first entity 404 sends a metaverse service response with at least one error code, indicating that the token verification or the verification of the certificate for the avatar identity has failed.
[0129] FIG. 5 shows a flowchart for a method 500 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein. At step 502, the first entity 404 receives the application session establishment request from a user equipment (UE) to access at least one of: the metaverse service and the avatar communication service. The application session establishment request includes at least one of: at least one avatar identity and a token. At step 504, the first entity 404 sends the avatar request of the user to the core network 402 by invoking a service operation. At step 506, the NEF of the core network translates the private internet protocol (IP) address of the UE to the identity of the UE 118. The first entity 404 may identify the home network based on the received identity of the UE 118. At step 508, the core network 402 may retrieve through a Unified data management (UDM), the user identity from the session identity received in the application session establishment request. At step 510, the UDM of the core network 402 may send the avatar request of the user to the UAF. The UAF is pre-configured with the avatar identity for the users. In an embodiment herein, the UDM retrieves the avatar identity from at least one of an external authentication server or a certification Authority (CA) At step 512, the UAF may send the response message to the UDM. The response message comprises at least one avatar identity is used to check for the user identity and a user identity token whether the user is already authenticated for accessing the metaverse service. At step 514, the UDM may send the response message to the NEF on receiving the response message from the UAF. At step 516, the NEF may send the response message to the first entity 404 on receiving the response message from the UDM. The first entity 404 may receive the response message from the core network 402 through an avatar repository 116 based on the avatar request of the user. The response message includes at least one avatar identity is used to check for the user identity and a user identity token whether the user is already authenticated for accessing at least one of: the metaverse service and the avatar communication service. The avatar identity is retrieved by the avatar repository (116) for the corresponding user identity and a UE identity. At step 518, the first entity 404 verifies the received avatar identity received from the application session establishment request through the UE is the same as the avatar identity received in the response message through the avatar repository. At step 520, the first entity 404 sends the metaverse service response with at least one of: a requested service and a success indication to the UE 118 when the received avatar identity received from the application session establishment request through the UE 118 is the same as the avatar identity received in the response message through the avatar repository.
[0130] The various actions in method 500 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 5 may be omitted.
[0131] FIG. 6 shows an example sequence diagram 600 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein. In step 612, the UE 118 sends the application session establishment request to the application function (AF) 610 to access the metaverse services. The application session establishment request may include the IP address or the UE-identity identifying the terminal through which services are accessed, the AF-identity, the External-Identity-Provider-identity identifying a 3rd party identity service provider though which user utilizing the service can be authenticated. The UE 118 may additionally include the session-identity service type, AF ID, digital ID, user ID and / or anonymous user IDin the application session establishment request message. At step 614, upon receiving the application session establishment request, the AF 610 may invoke Nnef_UEId_Get service operation for translating the UE's Private IP address to the identity of the UE 118. The AF 610 includes the received IP Address and user identity in the request message. At step 616, the NEF 608 translates the IP address to the identity of the UE 118. Alternatively, the AF 610 identifies the home network based on the received the identity of the UE 118. In step 618, the NEF 608 sends a request to retrieve the avatar identity to the UDM 606. The request message includes the UE identity, the user identity, the session identity and other possible parameters. At step 620, the UDM 606 retrieves the user identity from the session identity received. This may include UDM 606 communicating with the UE 118. In an embodiment herein, the user-identity is an identity uniquely identifying the user. The session-identity is a randomly generated identity for the session, which can be used if the user identity needs to be hidden until identity verification. The user-identity and the session-identity are especially useful when multiple users are present behind the UE 118. At step 622, the UDM 606 sends the request to retrieve the avatar identity to the User Authentication Function (UAF). At step 624, the UAF 604 is pre-configured with the avatar identity for the users. In an embodiment herein, based on the request from the AF 610 and the UDM 606, the UDM 606 retrieves the digital identity from the external AAA or the certification Authority (CA). At step 626, the UAF 604 sends the response message to the UDM 606. The response message includes the avatar identity allowed for the user whose identity is received and additionally includes the user identity token if the user is already authenticated for the metaverse service. At step 628, on receiving the response message, the UDM 606 forwards the response message to the NEF 608. The response message includes the avatar identity allowed for the user whose identity is received and additionally includes the user identity token if the user is already authenticated for the metaverse service. At step 630, on receiving the response message, the NEF 608 forwards the message to the AF 610. The response message includes the avatar identity allowed for the user whose identity is received and additionally includes the user identity token if the user is already authenticated for the metaverse service. At step 632, the AF 610 verifies that the avatar identity received from the UE 118 in the session establishment message is the same as the one network provided via the NEF 608. If the avatar identity in the application session establishment message is the same as in the response, the AF 610 provides the service to the requesting user. In step 634, the AF 610 sends the metaverse service response to the UE 118 with the requested service and / or success indication.
[0132] FIG. 7 shows a schematic overview of a system 700 for managing an avatar identity in a metaverse system, according to embodiments as disclosed herein. The system 700 can be, for example, but is not limited to a fourth-generation wireless network, a fifth-generation wireless network, Open Radio Access Network (ORAN), a sixth generation (6G) network or the like. The system 700 includes a first entity 702, a second entity 704, a core network 714, the avatar repository 116, and the user equipment (UE) 118. The first entity 702 can be, for example, but is not limited to, an extended reality application server (XR AS), and an application function (AF). The second entity 112 can be, for example, but is not limited to at least one of: an Authentication, Authorization, and Accounting (AAA) Server.
[0133] In an embodiment herein, the system 700 may be implemented on, for example, but not limited to devices with immersive experience, such as an augmented reality (AR) device, a virtual reality (VR) device or an extended reality (XR) device. The devices may include but are not limited to, a laptop, a smart phone, a desktop computer, a notebook, a Device-to-Device (D2D) device, a vehicle to everything (V2X) device, a foldable phone, a smart TV, a tablet, a television, a connected car, an immersive device, an internet of things (IOT) device, or any other device that can communicate using the wireless network.
[0134] In an embodiment herein, the second entity 704 comprises a processor 706, an avatar identity managing controller 708, a transceiver 712, and a memory 710. In an embodiment herein, the avatar identity managing controller 708 is a part of the processor 706, where the avatar identity managing controller 708 communicates with the entities (client and servers) through the transceiver 712. In another embodiment herein, the avatar identity managing controller 708 is outside the processor 706 but the avatar identity managing controller 708 is in communication with the processor 706, where the avatar identity managing controller 708 communicates with the first entity 702, the avatar repository 116 through the transceiver 712. In another embodiment herein, the avatar identity managing controller 708 is outside the processor 706, and the avatar identity managing controller 708 works separately from the processor 706, where the avatar identity managing controller 708 communicates with the first entity 102 through the transceiver 112.
[0135] In an embodiment herein, the memory 710 is configured to store instructions to be executed by the processor 706. The memory 710 can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory 710 may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memory 710 is configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).
[0136] The processor 706 may include one or more processor(s). The one or more processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor 106 may include multiple cores and is configured to execute the instructions stored in the memory 710.
[0137] In an embodiment, the transceiver 712 includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver 712 is configured to communicate internally between internal hardware components of the second entity 704 and with external devices via one or more networks.
[0138] In an embodiment herein, the avatar repository 116 may include at least one of: a base avatar repository (BAR), and a Digital Asset Container (DAC). The avatar repository 116 may be located in but is not limited to: a network function (NF) entity, a Unified data management (UDM) entity, a User Authentication Function (UAF) entity, user information database function (UIDF) entity, and a user database (UDB). The BAR stores and retrieves an avatar model, the BAR is located in at least one of: inside a new network function entity for example a PLMN, and outside a network function entity. The outside the network function entity includes, but is not limited to, a webserver managed by a third-party provider.
[0139] In an embodiment herein, the DAC is used for storing and retrieving an avatar metadata including avatar representation from a fifth-generation core (5GC) network. The DAC is located in at least one of: internal to a new network function entity, as a part of a network function, a XR application server, a web server within an IMS and a 5GC. The network function entity may include but is not limited to a Home Subscriber Server (HSS), a Unified data management (UDM) entity, IP Multimedia Subsystem (IMS) entity, and an application server (AS). The DAC may be located outside the network function comprising a webserver managed by a third-party provider.
[0140] In an embodiment herein, the first entity 702 receives the application session establishment request from the UE 118 to access metaverse services. The application session establishment request further includes a UE identity identifying a terminal through which the service is accessed, the avatar identity, a user identity, and other possible parameters. In an embodiment herein, the first entity 702 authorizes the application session establishment request from the UE 118.
[0141] In an embodiment herein, the first entity 702 may send the application session establishment request to a Network Exposure Function (NEF) of the core network 714. In an embodiment herein the NEF of the core network 714 identifies the home network by sending the application session establishment request to the User Authentication Function (UAF) in the core network 714. The UAF redirects the application session establishment request to the second entity 704.
[0142] In an embodiment herein, the second entity 704 may receive an avatar request of a user from the core network to access a metaverse service. The avatar request of a user request includes at least one avatar identity and a token.
[0143] In an embodiment herein, the second entity 704 may request the avatar repository 116 to retrieve an avatar representation. The avatar representation comprises at least one of: an avatar identity, a digital painting, and a digitally purchased item. The avatar repository may be an integral part of the second entity 704, that may be an external to the core network 714. The second entity may be the AAA server.
[0144] In an embodiment herein, the second entity 704 may verify by checking whether the avatar identity in the avatar repository 116 for the requesting user matches with the avatar identity of the avatar request of the user. The avatar repository 116 verifies whether the token is a valid token or an expired token. The avatar repository 116 validates that the requesting user is allowed to use the provided avatar identity based on the verification.
[0145] In an embodiment herein, the second entity 704 may retrieve the requested avatar representation based on the validation and send a response message to a first entity 702. The response message includes at least one of: an internet protocol (IP) address where the avatar is stored, a time period, the avatar identity, and success indication.
[0146] FIG. 8 shows a flowchart for a method 800 for managing the avatar identity in the metaverse system, according to embodiments as disclosed herein. At step 802, the first entity 702 receives the application session establishment request from the UE 118 to access metaverse services. The application session establishment request further includes a UE identity identifying a terminal through which the service is accessed, the avatar identity, a user identity, and other possible parameters. At step 804, the first entity 702 authorizes the application session establishment request from the UE 118. At step 806, the first entity 702 may send the avatar request of the user to a Network Exposure Function (NEF) of the core network 714. In an embodiment herein the NEF of the core network 714 identifies the home network by sending the avatar request of the user to the User Authentication Function (UAF) in the core network 714. The UAF redirects the avatar request of the user to the second entity 704. At step 808, the second entity 704 may receive an avatar request from the user from the core network to access at least one of: the metaverse service and the avatar communication service. The application session establishment request includes at least one avatar identity and a token. At step 810, the second entity 704 may request the avatar repository 116 to retrieve an avatar representation. The avatar representation includes at least one of and an avatar identity, a digital painting, and a digitally purchased item. The avatar repository 116 may be an integral part of the second entity 704, that may be an external to the core network 714. The second entity may be the AAA server. At step 812, the second entity 704 may verify by checking whether the avatar identity in the avatar repository 116 for the requesting user matches with the avatar identity of the application session establishment request. The avatar repository 116 verifies whether the token is a valid token or an expired token. The avatar repository 116 validates that the requesting user with the user identity received in the avatar request of the user is allowed to use the provided avatar identity based on the verification. At step 814, the second entity 704 may retrieve the requested avatar representation based on the validation and send a response message to a first entity 702. The response message includes at least one of: an internet protocol (IP) address where the avatar is stored, the avatar identity, and a success indication.
[0147] The various actions in method 800 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 8 may be omitted.
[0148] FIG. 9 an example sequence diagram for the process of retrieving the avatar from the AAA server by the metaverse provider, according to embodiments as disclosed herein. At step 902, the UE 118 sends the application session establishment request to the application function (AF) 610 to access Metaverse services. The application session establishment request may include UE identity identifying the terminal through which services are accessed, the avatar identity / digital identity, the user identity, and other possible parameters. On receiving the user's avatar request, in step 904, the AF 610 authorizes the request from the UE 118 and sends the application session establishment request to the NEF 608. The application session establishment request includes the received UE identity, the avatar identity / Digital identity, the service type, the user identity and other possible messages in the request message. In step 906, the NEF 608 identifies the home network based on, e.g. UE-identity sends the application session establishment request to the UAF 604. The NEF 608 includes the received UE identity and the avatar identity / Digital identity, the service type, the user identity and other possible messages in the request message. On receiving the User's avatar request from the NEF 608, in step 908, the UAF 604 forwards / redirects the request to the third party or external AAA server 901. The message includes the received UE identity and the avatar identity / digital identity, the service type, the user identity and other possible messages in the request message. In step 910, the AAA server 901 checks its records and validates if the requesting user is allowed to use the provided digital identity. On successful verification, the AAA server 901 retrieves the avatar for the requesting user. In step 912, the AAA server 901 sends the response message to the UAF 604. The response message includes the Avatar information (IP address where the avatar is stored, the time period and other possible parameters). On receiving the response message, in step 914, the UAF 604 forwards the message to the NEF 608. The response message includes the Avatar information (IP address where the avatar is stored, the time period and other possible parameters). On receiving the response message, in step 916, the NEF 608 forwards the response message to the AF 906. The response message includes the Avatar information (IP address where the avatar is stored, the time period, digital ID, a success indication). On receiving the user's Avatar Response, in step 918, the AF 906 stores the avatar information in its database for future use. In step 920, the AF 906 sends the metaverse service response with the avatar identity / digital identity. After this, the user could use the avatar communication to get the metaverse service.
[0149] In an embodiment herein, on receiving the session establishment request from the UE, the AF can directly send a request message to the AAA server and / or digital identity provider to check its database, and to retrieve the digital identity of the requesting user's avatar representation.
[0150] FIG. 10 depicts an example sequence diagram for managing the avatar identity by mapping the avatar identity with 3GPP subscription, and updating the UDM record accordingly, according to embodiments as disclosed herein. In step 0, the UE 118 is pre-configured with credentials for accessing 3GPP network, for biometric verification of the user(s) and optionally with credentials for accessing digital-identities and / or Avatars. The UE 118 may also be preconfigured with the avatar identity(s) of user(s) for obtaining the metaverse services. Alternatively, digital-identity(s) and / or avatar identities of the users are only configured in the metaverse servers or external identity provider's servers. In step 1, a primary authentication is performed as described in clause 6.1 in 3GPP TS 33.501 and the UE 118 is authenticated with the 3GPP core network. Further, the users behind the UEs are authenticated using UE methods for user authentication. The result of the user authentication is stored in 5GC (e.g. UAF, UDM). In step 2, the UE 118 sends a binding request to the UAF 604 directly (e.g. over data path) or via the AMF 602 (e.g., over NAS) to store UE 118 / User-identity to Digital-identity / Avatar identity mapping into UDM 606. Alternatively, the request for binding is to create an association of UE 118 / User-identity with result of user-authentication and / or a previously used Digital-identity / Avatar identity stored at a 3rd party identity provider. In this message, the UE 118 includes its UE-identity, User-identity of the user who is requesting the metaverse service and / or the digital-identity of the avatar for which association is to be created. The request may additionally include the identity of an external identity provider who manages user's Digital-ID and / or Avatar ID. Upon receiving the binding request from the UE 118, in step 3, the UAF 604 checks the user authentication status (i.e. whether user authentication is already performed for the requesting UE 118). If the authentication is already performed, then step 5 is performed. In an embodiment herein, the UAF 604 can be collocated with AMF 602 and / or SMF and / or other existing 5GC network entities. In step 4a and 4b, if the user authentication was not performed before, the network and the UE 118 perform the user authentication. In step 5, the UAF 604 sends a request to the external identity provider with the request to associate and / or map UE 118 and / or User with its Digital identity / Avatar. This message includes the UE identity, User identity, result of user-authentication and optionally the digital-Id identifying a specific Avatar. It may additionally include the service type and other possible parameters. In step 6, the external identity provider checks its database and retrieves the digital identity of the requesting user's avatar representation and provides it to the UAF 604 in response message. Alternatively, it validates if the user is allowed to use a specific avatar and provides the digital identity associated with it to the UAF 604. Alternatively, it validates if the user is allowed to use a specific digital-identity and responds with a confirmation message. The external identity provider may perform user-authentication before responding to the UAF 604. The response may optionally include the service-type for which the given avatar is valid. In an embodiment herein, the external identity provider could be a certification authority (CA). Upon receiving the response from the external identity provider, in step 7, the UAF 604 may check whether the digital identity provided by the external identity provider and the digital identity received in the binding request are same. The UAF 604 then initiates the binding update request to the UDM 606. This message includes the UE identity, user identity, external provider identity and the digital identity of the avatar. Upon receiving the user binding request from the UAF 604, in step 8, the UDM 606 performs the mapping of the identities received with the 3GPP subscription. UDM 606 updates its record respectively. In an embodiment herein, the UDM 606 record includes the mapping of digital identity, User identity, UE identity, external Provider identity, optional service-type and / or service name associated with avatar identity / digital-identity and the subscription data. On successfully updating its record, in step 9, the UDM 606 sends the user binding response to the UAF 604. This message includes the acknowledgement and / or the success indication. On successfully receiving the user binding response from the UDM 606, in step 10, the UAF 604 sends the user binding response to the UE 118 via the AMF 602 (NAS message). This message includes the acknowledgement and / or the success indication.
[0151] Embodiments herein use the terms 'Digital identity' and 'Avatar identity' interchangeably to represent the identification of any digital representation and / or avatar.
[0152] Creating Digital identity mapping with 3GPP subscription and updates UDM 606 record:
[0153] In this alternative, the UE 118 sends the digital identity and user information to the UDM 606 using a NAS message and the UDM 606 requests the CA / Digital identity provider (via NEF) to provide the digital identity for verification. Once the verification is successful (i.e., the digital identity received from the UE 118 is the same as the digital identity provided by the CA / Digital identity provider / external identity provider), the UDM 606 updates its record by creating a mapping of the user identity, Digital identity with the 3GPP subscription.
[0154] In another embodiment herein, the external user identity binding is created with the digital identity and the 3GPP subscription and updates the UDM 606 record.
[0155] Avatar retrieval by the metaverse provider from the UDM 606:
[0156] FIG. 11 depicts an example sequence diagram for managing the avatar identity by retrieving the avatar by the metaverse provider from the UDM, according to embodiments as disclosed herein. In step 1, the UE 118 sends a session establishment request to the application function (AF) 610 to access Metaverse services. The message may include UE identity identifying the terminal through which services are accessed, Avatar identity / Digital identity, User identity, User authentication result and other possible parameters. On receiving the user's avatar request, in step 2, the AF 610 sends the user's Avatar Request message to the NEF 608. The AF 610 includes the received UE identity and the avatar identity / Digital identity, Service type, user identity and other possible messages in the request message. In step 3, the NEF 608 identifies the home network based on, e.g. UE-identity and sends the user's Avatar Request message to the UDM 606. The NEF 608 includes the received UE identity and the avatar identity / Digital identity, Service type, user identity and other possible message in the request message. In step 4, the UDM 606 checks the record and validates whether the user is allowed to use the received Digital identity. If yes, the UDM 606 retrieves the binding details for the requesting user. In an embodiment herein, the UDM 606 has the mapping of the user identity with the digital identity and External provider identity. In another embodiment herein, the user identity is mapped with the digital identity and 3GPP subscription at the UDM 606 records. In an embodiment herein, the UDM 606 verifies whether the received Digital identity is allowed for a user by checking the configuration data. In another embodiment herein, the UDM 606 verifies whether the received Digital identity is allowed for a user by checking the NRF stored information. In step 5, the UDM 606 sends the User's avatar information in response to the NEF 608. This message includes the IP address where the avatar is saved, allowed time period and additional avatar information etc. In step 6, the NEF 608 forwards the User's avatar response to the AF 610. This message includes the IP address where the avatar is saved, allowed time period and additional avatar information. On receiving the avatar information from the 5GC network (UDM 606) via NEF 608, in step 7, the AF 610 stores the avatar information binding with the user for future use. On successfully receiving the avatar information, in step 8, the AF 610 sends the session establishment Response to the UE 118. This message includes the User identity and the Avatar identity / Digital identity.
[0157] Digital identity verification by the AF / metaverse server:
[0158] User Authentication and Authorization using OAuth Mechanism:
[0159] FIG. 12 depicts an example sequence diagram for managing the avatar identity by performing user authentication and authorization using OAuth Mechanism, according to embodiments as disclosed herein. In step 1, the Metaverse Server configures the profiles required for UE 118 / User registration, authentication, and authorization purpose in the 5GC. The Metaverse Server sends the user Profile, Avatar information, AF identity, service identity as part of pre-configuration to be stored at the 5GC. In an embodiment herein, in step 2, optionally, the NRF stores the configuration information. In an embodiment herein, at step 3, the NRF forwards the configuration information to the home PLMN UDM 606. The received user Profile, Avatar information, AF identity, service identity is stored at the UDR. In another embodiment herein, the UE 118 has been pre-configured or has discovered the address (e. g. IP address, FQDN, URI) of the Metaverse server, UE Identifier is available, and the UE 118 has been authorized to communicate with the Metaverse server. These steps can happen as part of the AS / Metaverse Server discovery procedure. In another embodiment herein, in step 4, the UDM 606 stores the configuration data received from the NRF. In an embodiment herein, the UAF 604 stores the configuration data received from the NRF. In step 5, the user initiates registration procedure / PDU session modification request / User access request. The UE 118 / User provides at least one of the UE 118 IP Address, UE MAC Address, UE Identifier (SUPI or GPSI or MSISDN or GUTI), the AF / Application Server identity. At the 5G core network, in steps 6-9, the UDM 606 or the NRF or the UAF 604 verifies the received at least one of the UE IP Address, UE MAC Address, UE Identifier (SUPI or GUTI or GPSI or MSISDN), AF / Application server identity, User identity against the stored configuration profiles. In an embodiment herein, if the verification check is performed at the UDM 606, the UDM 606 sends the access grant to the NRF. In another embodiment herein, if the anonymous user identity is received, in step 5, the NRF / UDM 606 retrieves the real user identity from the UAF 604. After successful verification, in steps 10-11, the NRF generates an access token for the user and sends the access token and the corresponding Digital identity / Avatar identity to the user in the registration request response / PDU session modification response / User access response. In another embodiment herein, once access is granted for the user, the NRF assigns one Digital identity / Avatar identity for the authorized user to be used in the Metaverse / Avatar communication. The NRF sends the Registration Request / PDU session modification / User Access / Authentication / Authorization Response to the User. This message includes the Access token, Digital identity / Avatar identity, and other possible parameters. In an embodiment herein, it optionally provides the Avatar identity / Digital identity validity / expiry time to the user. In step 12, the user gets authenticated and authorized using the access token for the metaverse service.
[0160] In an embodiment herein, the block chain-based solutions can be applied for the user authentication and authorization. The token could be the Bitcoins for accessing the 5G service and / or the application.
[0161] Management of Digital asset container by the third party:
[0162] In this alternative, it is the third party storing and managing the digital asset container. Upon receiving the access request from the user, the 5GC retrieves the digital identity from the third party and verifies if the user is allowed to use the claiming digital / Avatar identity.
[0163] It is assumed that between the UE 118 and the AF, the TLS session is established, and the messages are shared over a protected interface.
[0164] In another embodiment herein, it is assumed that the TLS is established between the UE 118 and the third party. In another embodiment herein, the TLS could be established between the AF and the third-party entity.
[0165] FIG. 13 depicts an example sequence diagram for managing the avatar identity by retrieving the digital identity from a third-party entity, according to embodiments as disclosed herein. In step 0, the UE 118 is in possession of the private key and the certificate. In an embodiment herein, the Key Management Server (operator managed / third party provided) configures UE 118 with the certificate and private key as part of UE 118 configuration and / or in the UICC. In an embodiment herein, the Certificate Authority (CA) / Registration Authority (RA) (operator managed / third party provided) configures the UE 118 with the certificate and private key as part of UE 118 pre- configuration and / or in the UICC. In step 1, the third-party entity / server has the private key and the certificate. Additionally, the third-party entity is pre-configured with the digital asset container. In step 2, either the TLS is established using the server-side certificate or the UE 118 side certificate-based authentication. The message exchanged between the UE 118 and the third-party entity and / or the application server can be based on the TLS based Protection. In step 3, the TLS session is established between the UE 118 and the third-party entity. In an embodiment herein, the sensitive information's like the user Authentication / Authorization Results, Digital / Avatar identity and / or the authentication data parameters can be shared to the respective entities once the TLS is successfully established. In step 4, the UE 118 is authenticated and / or authorized using the procedure detailed in TS 33.501. Once the user decides to access the application, in step 5, the user sends the access request and / or authentication / authorization request to the 5GC network entity. In an embodiment herein, the User sends the access request and / or authentication / authorization request to the UAF 604 (User Authentication Function). On receiving the access request and / or Authentication / Authorization request from the user, in step 6, the UAF 604 verifies whether the UE 118 is already Authenticate and authorized. If yes, then step 7 is performed. If not, the UAF 604 first performs the UE 118 authentication and authorization procedure. In step 7, the UAF 604 sends the Digital identity retrieval request to the third party. This message includes the user identity, AF identity, UE identity, and other possible parameters. In an embodiment herein, the UAF 604 sends the Digital identity retrieval request via the NEF to the third-party entity / server. On receiving the Digital identity request from the UAF 604 / NEF, in steps 8-9, the third-party entity / server / AAA-server check the pre-configured data. If the digital identity is available for the received user identity, the third party retrieves the digital identity and provides it to the UAF 604 directly or via NEF in the digital identity retrieval response message. Additionally, it includes the Digital identity validity time / expiry time. On receiving the Digital identity response from the third part entity, in steps 10-11, the UAF 604 verifies whether the digital identity provided by the third-party entity is the same as the digital identity received from the UE 118 for the particular user identity. If the Digital identity matches, the UAF 604 sends the access request and / or Authentication / Authorization response to the user. This message includes the expiry time / Digital identity validity and the access token to access the application.
[0166] In an embodiment herein, the user sensitive information and the Avatar specific information for a user needs to be exposed in a secured channel to and from the third party.
[0167] In an embodiment herein, the SUPI and the corresponding user identity mapping can be provided to the AMF 602 once the user authentication is successful. In another embodiment herein, the mapping of User identity and the digital identity can be provided to the AMF 602 after the successful digital identity authentication.
[0168] In an embodiment herein, the AMF, the UAF 604, the UDM 606, the UDB (user data base), the UIDF (user information database function), the third party shall be provided with the mapping of UE identity (SUPI / GPSI) and the corresponding user identity.
[0169] In another embodiment herein, the user identity is stored at a user identity provider within or outside the 5G core network.
[0170] Complete flow of digital identity verification by the network:
[0171] FIG. 14 depicts an example sequence diagram for managing the avatar identity by verifying the digital identity by the network, according to embodiments as disclosed herein. In this alternative, in step 0, the user Identities and the Digital Identities are pre-configured at the network. The network entities such as UAF 604 (User Authentication Function) and / or UIDF (user information database function) and / or UDB (user database). In an embodiment herein, the UAF / UDB / UIDF can be collocated with any of the existing 5G core network entities. In another embodiment herein, either the User Identity provider or the digital Identity provider and / or the NRF and / or the third party can configure the user information / user Identity / digital identity to the UAF / UIDF / UDB. In this alternative, in step 1, it is assumed that the user / UE 118 is authenticated successfully with the network and the third party. Once the user authentication is successful via the UE 118, in step 2, the network (UAF / UDM / NEF) exposes the user authentication results to the third party. In this message the network provides the user identity mapping with the UE 118 identity to the third party. In step 3, the UE 118 sends the service request and / or the access request on behalf of the user to the Application function (AF) / metaverse server. This message includes the digital identity and optionally includes the user identity. This service / access request can be sent as part of an application session establishment by sending an A-KID. On receiving the service request / the access request from the UE 118, in step 4, the AF sends the digital identity request and / or the digital identity Authentication request to the network (UAF / NEF) to verify whether the requesting user is allowed to use the digital identity for the metaverse service. In this message, the AF also includes its identity (AF ID). In an embodiment herein, if the user identity is not provided by the UE 118, the AF retrieves the user identity from the network by providing the received digital identity from the UE 118 to the network. If an anonymous user identity has been provided by the UE 118 in the session establishment / service / access request, the AF forwards the anonymous user identity to the network. On receiving the digital identity request from the AF, in step 5, the UAF 604 verifies whether the user is authenticated. If the user is authenticated, the UAF 604 verifies whether the user is an authorized user to use the digital identity / the avatar identity for the metaverse services. In an embodiment herein, the network optionally verifies whether the digital identity can be used by the user for the requesting AF.
[0172] In another embodiment herein, the UAF / UIDF / any other new entity / any existing 5G network entities can perform the verification of digital identity by retrieving the user identity for the received digital identity.
[0173] In an embodiment herein, as part of the user Authentication and authorization procedure, the UAF / UDM / UDR / UIDF can be configured with user information and based on the successful authentication, the UAF / UDM / UDR / UIDF can be updated with the corresponding UE identity and user identity mapping.
[0174] Network is pre-configured with digital identities:
[0175] If the user authentication is successful for the received user identity, in step 6, the UAF 604 fetches the digital identity for the corresponding user identity from the configured data. In an embodiment herein, the UAF 604 may fetch the corresponding digital identity from the UDB / UIDF / any other possible 5G core network entity. In another embodiment herein, herein, the digital asset container can be maintained at the 5GC (UAF). In an embodiment herein, the UDM / UDR can be enhanced to maintain the user profile information, user identity and digital identity mapping.
[0176] In another embodiment, any new NF and / or UIDF can maintain the user profile information and the user identity and the digital identity mapping with the 3GPP subscription.
[0177] Network fetches the digital identity from NRF / AAA-S / 3rd party:
[0178] On checking the user authentication, in step 7, if the user is an authenticated user, the UAF / UIDF sends a digital identity request to the NRF and / or AAA-S / Digital identity provider and / or CA and / or RA and / or 3rd party. In an embodiment herein, the NRF can be configured by the digital identity provider with a user identity and corresponding allowed digital identity. On receiving the digital identity request from the UAF / UIDF / any 5G network entity, the NRF and / or AAA-S / Digital identity provider and / or 3rd party fetches the digital identity for the received user identity from the configured data and provides it to the UAF 604 / UIDF / any 5G network entity in the digital identity response message. On receiving / fetching the digital identity, in step 8, the UAF 604 / UIDF verifies whether the fetched digital identity is the same as the digital identity provided by the AF (received in session establishment / service request / access request message from the UE 118). Upon successful verification, in step 9, the UAF 604 / UIDF sends the Digital identity authentication response message to the AF / metaverse server. This message includes the result of authentication / digital identity verification (success or failure), expiry time, and optionally provides the digital identity. In an embodiment herein, if the AF is outside the trust domain, the NEF exposure API is reused here. On receiving the digital identity authentication response from the network, in step 10, the AF sends the session establishment response / access response / service response to the UE 118. By this check, it is verified that the user he / she claims is authorized to use the digital identity for the metaverse services.
[0179] FIG. 15 depicts an architecture to support IMS avatar communication without DC, according to embodiments as disclosed herein. The modules described herein are well-known modules for IMS communication. The purpose of the FIG. 15 is to describe the avatar repository as the DAC 1514 or the BAR storing the avatar representations.
[0180] The UE-A 118 may send session establishment / service request / access request message to the IMS AS 1506 through a Proxy Call Session Control Function (P-CSCF) 1502 and a Serving - Call Session Control Function (S-CSCF) 1504. The P-CSCF 1502 acts as the ingress and egress point to and from a service provider's IMS domain with respect to the IMS client. The S-CSCF 1504 is the primary node in the IMS responsible for session control. Subscribers will be allocated a S-CSCF 1504 for the duration of their IMS registration in order to facilitate routing of SIP messages as part of service establishment procedures. The IMS AS 1506 is a standardized architectural framework for delivering IP multimedia services. The at least one avatar identity is associated per subscriber, per associated subscriber's user identity, and per service in an IP Multimedia Subsystem Home Subscriber Server (IMS HSS) 1508. The IMS AS 1506 sends the avatar identity and the token to the MF 1512. The MF 1512 requests the DAC 1514 to download the avatar representation from the DAC 1514, including parameters of the token and the avatar identity. The avatar identity can be retrieved from the 5GC new entity and / or an existing entity and / or from an external third-party entity. The DAC 1514 can be used for storing and retrieving the avatar representation (for e.g., Avatar identity / digital identity) from 5GC network. DAC can be internal to the PLMN, e.g. a new network function (e.g., UAF, UDB, UIDF), or part of a network function (HSS, UDM, IMS AS,), a XR application server or a web server within the IMS and / or 5GC network; or DAC can be external to the PLMN where a third party entity stores the avatar representation, e.g. a webserver and the avatar identity / digital identity can be retrieved from the external DAC.
[0181] In an embodiment, the UAF / any new 5G entity / BAR (Base avatar repository) situated inside the PLMN are configured with avatar information.
[0182] In another embodiment, the third party / BAR (Base Avatar Repository) is configured with avatar information and third party / BAR situated outside the PLMN provides the avatar representation to the 5G core network. An IMS-AGW 1510 is an IMS Access gateway complimenting the P-CSCF 1502 function to broaden the range of devices that can access the IMS. A transition gateway 1518 (TrGW) sits on the media path for the session establishment request leaving the service provider's IMS network. The primary role of the TrGW 1518 is to facilitate interworking between two different domains which may be using different addressing schemes, codecs etc. An Interconnection Border Control Function (IBCF) (1516) offers boundary control between various service provider networks, providing IMS network security in terms of signaling information. The IBCF 1516 is a SIP (Session Initiation Protocol) ALG (Application-Level Gateway) which is designed to facilitate interconnection between two service provider domains. Here the IBCF 1516 and TrGW provides an interconnection between the UE-A 118 to a UE-B 1522 through the IMS communication network. The IMS network is terminated through the terminating IMS network 1520, for connecting to the UE -B 1522. The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.
[0183] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.
[0184] The embodiments disclosed herein describe methods and systems for managing an avatar identity in a metaverse system. Therefore, it is understood that the scope of the protection is extended to such a program and in addition to a computer readable means having a message therein, such computer readable storage means contain program code means for implementation of one or more steps of the method, when the program runs on a server or mobile deviceor any suitable programmable device. The method is implemented in at least one embodiment through or together with a software program written in e.g., Very high-speed integrated circuit Hardware Description Language (VHDL), another programming language, or implemented by one or more VHDL or several software modules being executed on at least one hardware device. The hardware device can be any kind of portable device that can be programmed. The device may also include means which could be e.g., hardware means like e.g., an ASIC, or a combination of hardware and software means, e.g., an ASIC and an FPGA, or at least one microprocessor and at least one memory with software modules located therein. The method embodiments described herein could be implemented partly in hardware and partly in software. Alternatively, the invention may be implemented on different hardware devices, e.g., using a plurality of CPUs.
[0185] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of embodiments and examples, those skilled in the art will recognize that the embodiments and examples disclosed herein can be practiced with modification within the scope of the embodiments as described herein.
Claims
1.A method performed by a first entity in a communication system, the method comprising:receiving, from a second entity, an avatar representation downloading request message;performing a verification of a token associated with a user equipment (UE); andtransmitting, to the second entity, an avatar representation downloading response message,wherein the avatar representation downloading request comprises at least one of information on an avatar identifier (ID) or information on the token associated with the UE.2.The method of claim 1,wherein the first entity comprises at least one of a base avatar repository (BAR) or digital asset container (DAC),wherein the second entity comprises a media function (MF), andwherein the at least one of the BAR or the DAC is capable of being inside a public local mobile network (PLMN) or outside the PLMN.3.The method of claim 1,wherein the at least one of the information on the avatar ID or the information on the token is transmitted from a third entity to the second entity via an IP multimedia subsystem (IMS) application server (IMS AS), andwherein the avatar representation downloading response message comprises at least one of an avatar representation or an error code.4.The method of claim 1, further comprising:identifying whether the avatar ID in the avatar representation downloading request message equals to that in the token,wherein the avatar ID is associated per subscriber or per associated subscriber's user identity.5.A method performed by a second entity in a communication system, the method comprising:transmitting, to a first entity, an avatar representation downloading request message; andreceiving, from the first entity, an avatar representation downloading response message,wherein a verification of a token associated with a user equipment (UE) is performed by the first entity, andwherein the avatar representation downloading request comprises at least one of information on an avatar identifier (ID) or information on the token associated with the UE.6.The method of claim 5,wherein the first entity comprises at least one of a base avatar repository (BAR) or digital asset container (DAC),wherein the second entity comprises a media function (MF), andwherein the at least one of the BAR or the DAC is capable of being inside a public local mobile network (PLMN) or outside the PLMN.7.The method of claim 5, further comprising:receiving, from a third entity via an IP multimedia subsystem (IMS) application server (IMS AS), the at least one of the information on the avatar ID or the information on the token,wherein the avatar representation downloading response message comprises at least one of an avatar representation or an error code,wherein whether the avatar ID in the avatar representation downloading request message equals to that in the token is identified by the first entity, andwherein the avatar ID is associated per subscriber or per associated subscriber's user identity.8.A first entity in a communication system, the first entity comprising:a transceiver; andat least one processor coupled with the transceiver and configured to:receive, from a second entity, an avatar representation downloading request message,perform a verification of a token associated with a user equipment (UE), andtransmit, to the second entity, an avatar representation downloading response message,wherein the avatar representation downloading request comprises at least one of information on an avatar identifier (ID) or information on the token associated with the UE.9.The first entity of claim 8,wherein the first entity comprises at least one of a base avatar repository (BAR) or digital asset container (DAC),wherein the second entity comprises a media function (MF), andwherein the at least one of the BAR or the DAC is capable of being inside a public local mobile network (PLMN) or outside the PLMN.10.The first entity of claim 8,wherein the at least one of the information on the avatar ID or the information on the token is transmitted from a third entity to the second entity via an IP multimedia subsystem (IMS) application server (IMS AS), andwherein the avatar representation downloading response message comprises at least one of an avatar representation or an error code.11.The first entity of claim 8, wherein the at least one processor is further configured to:identify whether the avatar ID in the avatar representation downloading request message equals to that in the token,wherein the avatar ID is associated per subscriber or per associated subscriber's user identity.12.A second entity in a communication system, the second entity comprising:a transceiver; andat least one processor coupled with the transceiver and configured to:transmit, to a first entity, an avatar representation downloading request message, andreceive, from the first entity, an avatar representation downloading response message,wherein a verification of a token associated with a user equipment (UE) is performed by the first entity, andwherein the avatar representation downloading request comprises at least one of information on an avatar identifier (ID) or information on the token associated with the UE.13.The second entity of claim 12,wherein the first entity comprises at least one of a base avatar repository (BAR) or digital asset container (DAC),wherein the second entity comprises a media function (MF), andwherein the at least one of the BAR or the DAC is capable of being inside a public local mobile network (PLMN) or outside the PLMN.14.The second entity of claim 12, wherein the at least one processor is further configured to:receive, from a third entity via an IP multimedia subsystem (IMS) application server (IMS AS), the at least one of the information on the avatar ID or the information on the token,wherein the avatar representation downloading response message comprises at least one of an avatar representation or an error code.15.The second entity of claim 12,wherein whether the avatar ID in the avatar representation downloading request message equals to that in the token is identified by the first entity, andwherein the avatar ID is associated per subscriber or per associated subscriber's user identity.
Citation Information
Patent Citations
System And Method For Generating An Avatar And Provides It To An External Metaverse Platform To Update The Avatar And Provide NFT For The Updated Avatar
KR102432248B1
User authentication method using avata and user device for implementing the same
KR102586118B1
Metaverse personalized content creation and authentication method and apparutus and system therefor
KR102627728B1
KR20230036386A
Cited By
Unmanned aerial vehicle identity anonymization and security data outsourcing method and system
CN121750382A