Apparatus, method and computer program
By providing an indication to user equipment to obtain and manage consent information, the network entity addresses the challenge of resource owner consent management in CAPIF-8 interface, ensuring secure and efficient access to personal information resources.
Patent Information
- Application Number
- PCT/EP2025/069035
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-03
- Filing Date
- 2025-07-03
- Publication Date
- 2026-01-08
AI Technical Summary
Existing communication systems lack efficient mechanisms for managing resource owner consent in Common Application Interface (CAPIF)-8 interface, particularly in managing interactions between resource owner functions and authorization functions for personal information access.
A network entity provides an indication to user equipment via a uniform resource identifier to obtain pending consent request information, and based on this information, the user equipment obtains and provides consent information to the network entity, facilitating the issuance of access tokens.
This approach ensures seamless and standardized management of resource owner consent, enabling secure and efficient access to personal information resources while adhering to regulatory requirements.
Smart Images

Figure EP2025069035_08012026_PF_FP_ABST
Abstract
Description
[0001] TITLE
[0002] APPARATUS, METHOD AND COMPUTER PROGRAM
[0003] TECHNICAL FIELD
[0004] Various embodiments of this disclosure relate generally to methods, apparatus and computer programs, and in particular - but not exclusively - to resource owner consent management, such as resource owner consent management in Common Application Interface (API) Framework (CAPIF)-8 interface.
[0005] BACKGROUND
[0006] A communication system can be seen as a facility that enables communication sessions between two or more communication devices, or provides communication devices access to a network, a mobile or wireless communication network is one example of a communication network, a communication device may be provided with a service by an application server.
[0007] A mobile or wireless communication network may operate in accordance with standard(s), such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of mobile or wireless communication network that operate in accordance with 3GPP standards are generally referred to as 4G (4th Generation) networks, 5G (5th Generation) network, 5G-Advanced networks and 6G networks.
[0008] SUMMARY
[0009] Some embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the various example embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure. For example, it should be appreciated that further aspects may be provided by the combination of any two or more of the various aspects described herein.
[0010] 2 In a first aspect, there is provided an apparatus comprising a network entity, the apparatus comprising means for receiving an access token request from a second network entity, in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from the network entity, receiving consent information from the user equipment via the uniform resource indicator and providing an access token to the second network entity based on the consent information.
[0011] The apparatus may comprise means for receiving a request from the user equipment for a subscription to consent requests for the user equipment and providing a response to the request to the user equipment, the response comprising an identifier of the subscription.
[0012] The indication may comprise an identifier of the user equipment.
[0013] The indication may further comprise the identifier of the subscription.
[0014] The apparatus may comprise means for receiving, in response to the indication, a request for the pending consent request in-formation from the user equipment and providing the pending consent request information to the user equipment in response.
[0015] The indication may comprise the pending consent request information.
[0016] The network entity may comprise an authorization function and the second network entity may comprise an application function.
[0017] The application function may comprise an application programming interface invoker.
[0018] In a second aspect, there is provided a user equipment comprising means for receiving an indication at the user equipment via a uniform re-source identifier to cause the user equipment to obtain pending consent request information from a network entity, based on the pending consent request information, obtaining consent information and providing the consent information to the network entity via the uniform resource indicator.
[0019] The apparatus may comprise means for providing a request to a network entity for a subscription to consent requests for the user equipment and receiving a response to the request to the user equipment, the response comprising an identifier of the subscription.
[0020] The indication may comprise an identifier of the user equipment and wherein obtaining the pending consent request information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the pending consent request information from the network entity in response.
[0021] The indication may further comprise the identifier of the subscription.
[0022] The indication may comprise the pending consent request information.
[0023] The network entity may comprise an authorization function.
[0024] In a third aspect, there is provided a method comprising receiving an access token request from a second network entity, in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from the network entity, receiving consent information from the user equipment via the uniform resource indicator and providing an access token to the second network entity based on the consent information.
[0025] The method may comprise receiving a request from the user equipment for a subscription to consent requests for the user equipment and providing a response to the request to the user equipment, the response comprising an identifier of the subscription.
[0026] The indication may comprise an identifier of the user equipment.
[0027] The indication may further comprise the identifier of the subscription.
[0028] The method may comprise receiving, in response to the indication, a request for the pending consent request information from the user equipment and providing the pending consent request information to the user equipment in response.
[0029] The indication may comprise the pending consent request information.
[0030] The method may be performed at an apparatus comprising a network entity. The network entity may comprise an authorization function and the second network entity may comprises an application function.
[0031] The application function may comprise an application programming interface invoker.
[0032] In a fourth aspect, there is provided a method comprising receiving an indication at a user equipment via a uniform re-source identifier to cause the user equipment to obtain pending consent request information from a network entity, based on the pending consent request information, obtaining consent information and providing the consent information to the network entity via the uniform resource indicator.
[0033] The method may comprise providing a request to a network entity for a subscription to consent requests for the user equipment and receiving a response to the request to the user equipment, the response comprising an identifier of the subscription. The indication may comprise an identifier of the user equipment and wherein obtaining the pending consent request information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the pending consent request information from the network entity in response.
[0034] The indication may further comprise the identifier of the subscription.
[0035] The indication may comprise the pending consent request information.
[0036] The network entity may comprise an authorization function.
[0037] In a fifth aspect, there is provided an apparatus comprising a network entity., the apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform a method according to the third aspect.
[0038] In a sixth aspect, there is provided a user equipment comprising at least one processor, and at least one memory storing instructions, wherein the instructions, when executed by the at least one processor cause the user equipment at least to perform a method according to the fourth aspect.
[0039] In a seventh aspect, there is provided a non-transitory computer readable medium comprising instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the third aspect.
[0040] In an eighth aspect, there is provided a non-transitory computer readable medium comprising program instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the fourth aspect.
[0041] In a nineth aspect, there is an apparatus comprising a network entity, the apparatus comprising means for receiving an access token request from a second network entity, in response to receiving the access token request, providing an indication to a user equipment via non-access stratum signalling to cause the us-er equipment to obtain pending consent request information from the network entity, receiving consent information from the user equipment and providing an access token to the second network entity based on the consent information.
[0042] The indication may comprise an identifier of the user equipment.
[0043] The indication may comprise an identifier of a subscription to consent requests for the user equipment. The apparatus may comprise means for receiving, in response to the indication, a request for the pending consent request in-formation from the user equipment and providing the pending consent request information to the user equipment in response.
[0044] The indication may comprise the pending consent request information.
[0045] The network entity may comprise an authorization function. The second network entity may comprise an application function.
[0046] The application function may comprise an application programming interface invoker.
[0047] In a tenth aspect, there is provided a user equipment comprising means for receiving an indication at the user equipment via non-access stratum signalling to cause the user equipment to obtain pending consent request information from the network entity, based on the one pending consent request information, obtaining consent information and providing the consent information to the network entity.
[0048] The indication may comprise an identifier of the user equipment and wherein obtaining the pending consent re-quest information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the consent request information from the network entity in response.
[0049] The indication may comprise an identifier of a subscription to consent requests for the user equipment.
[0050] The indication may comprise the pending consent request information.
[0051] The network entity may comprise an authorization function.
[0052] In an eleventh aspect, there is provided a method comprising receiving an access token request from a second network entity, in response to receiving the access token request, providing an indication to a user equipment via non-access stratum signalling to cause the user equipment to obtain pending consent request information from the network entity, receiving consent information from the user equipment and providing an access token to the second network entity based on the consent information.
[0053] The indication may comprise an identifier of the user equipment.
[0054] The indication may comprise an identifier of a subscription to consent requests for the user equipment.
[0055] The method may comprise receiving, in response to the indication, a request for the pending consent request in-formation from the user equipment and providing the pending consent request information to the user equipment in response. The indication may comprise the pending consent request information.
[0056] The network entity may comprise an authorization function. The second network entity may comprise an application function.
[0057] The application function may comprise an application programming interface invoker.
[0058] In a twelfth aspect, there is provided a method comprising receiving an indication at the user equipment via non-access stratum signalling to cause the user equipment to obtain pending consent request information from the network entity, based on the one pending consent request information, obtaining consent information and providing the consent information to the network entity.
[0059] The indication may comprise an identifier of the user equipment and wherein obtaining the pending consent re-quest information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the consent request information from the network entity in response.
[0060] The indication may comprise an identifier of a subscription to consent requests for the user equipment.
[0061] The indication may comprise the pending consent request information.
[0062] The network entity may comprise an authorization function.
[0063] In a thirteenth aspect, there is provided an apparatus comprising a network entity., the apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform a method according to the eleventh aspect.
[0064] In a fourteenth aspect, there is provided a user equipment comprising at least one processor, and at least one memory storing instructions, wherein the instructions, when executed by the at least one processor cause the user equipment at least to perform a method according to the twelfth aspect.
[0065] In a fifteenth aspect, there is provided a non-transitory computer readable medium comprising instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the eleventh aspect.
[0066] In a sixteenth aspect, there is provided a non-transitory computer readable medium comprising program instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the twelfth aspect. In a seventeenth aspect, there is provided an apparatus comprising a network entity, the apparatus comprising means for receiving an access token request from a second network entity, in response to receiving the access token request, providing an indication to a user equipment to cause the user equipment to obtain pending consent request information from the network entity, receiving consent information from the user equipment and providing an access token to the second network entity based on the consent information.
[0067] The indication may be provided to the user equipment via non-access stratum signaling.
[0068] The indication may be provided to the user equipment via a uniform resource indicator.
[0069] The indication may comprise an identifier of a subscription to consent requests for the user equipment and an identifier of the user equipment.
[0070] The apparatus may comprise means for receiving, in response to the indication, a request for the pending consent request information from the user equipment and providing the pending consent request information to the user equipment in response.
[0071] The indication may comprise pending consent request information.
[0072] The network entity may comprise an authorization function. The second network entity may comprise an application function.
[0073] The application function may comprise an application programming interface invoker.
[0074] In an eighteenth aspect, there is provided a user equipment comprising means for receiving an indication at the user equipment to cause the user equipment to obtain pending consent request information from the network entity, based on the pending consent request information, obtaining con-sent information and providing the consent information to the network entity.
[0075] The indication may be received at the user equipment via non-access stratum signaling.
[0076] The indication may be received at the user equipment via a uniform resource indicator.
[0077] The indication may comprise the identifier of the subscription and an identifier of the user equipment and wherein obtaining the pending consent request information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the pending consent request information from the network entity in response. The indication may comprise the pending consent request information.
[0078] The network entity may comprise an authorization function.
[0079] In a nineteenth aspect, there is provided a method comprising receiving an access token request from a second network entity, in response to receiving the access token request, providing an indication to a user equipment to cause the user equipment to obtain pending consent request information from the network entity, receiving consent information from the user equipment and providing an access token to the second network entity based on the consent information.
[0080] The indication may be provided to the user equipment via non-access stratum signaling.
[0081] The indication may be provided to the user equipment via a uniform resource indicator.
[0082] The indication may comprise an identifier of a subscription to consent requests for the user equipment and an identifier of the user equipment.
[0083] The method may comprise receiving, in response to the indication, a request for the pending consent request information from the user equipment and providing the pending consent request information to the user equipment in response.
[0084] The indication may comprise pending consent request information.
[0085] The network entity may comprise an authorization function. The second network entity may comprise an application function.
[0086] The application function may comprise an application programming interface invoker.
[0087] In a twentieth aspect, there is provided a method comprising receiving an indication at a user equipment to cause the user equipment to obtain pending consent request information from the network entity, based on the pending consent request information, obtaining consent information and providing the consent information to the network entity.
[0088] The indication may be received at the user equipment via non-access stratum signaling.
[0089] The indication may be received at the user equipment via a uniform resource indicator.
[0090] The indication may comprise the identifier of the subscription and an identifier of the user equipment and wherein obtaining the pending consent request information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the pending consent request information from the network entity in response.
[0091] The indication may comprise the pending consent request information.
[0092] The network entity may comprise an authorization function.
[0093] In a twenty-first aspect, there is provided an apparatus comprising a network entity., the apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform a method according to the nineteenth aspect.
[0094] In a twenty-second aspect, there is provided a user equipment comprising at least one processor, and at least one memory storing instructions, wherein the instructions, when executed by the at least one processor cause the user equipment at least to perform a method according to the twentieth aspect.
[0095] In a twenty-third aspect, there is provided a non-transitory computer readable medium comprising instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the nineteenth aspect.
[0096] In a twenty-fourth aspect, there is provided a non-transitory computer readable medium comprising program instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the twentieth aspect.
[0097] Some embodiments of the invention are defined in the dependent claims.
[0098] In the above, many different aspects have been described. As previously noted, it should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above (or otherwise in this disclosure).
[0099] Various other aspects are also described in the following detailed description and in the claims.
[0100] BRIEF DESCRIPTION OF THE FIGURES
[0101] Some embodiments will be described, by way of non-limiting and illustrative example only, with reference to the figures, in which:
[0102] Fig. 1 shows an example of a communication network to which examples disclosed herein may be applied;
[0103] Fig. 2 shows a schematic diagram of example CAPIF architecture;
[0104] Fig. 3 shows a flowchart of an example of a method; Fig. 4 shows a flowchart of an example of a method;
[0105] Fig. 5 shows a flowchart of an example of a method;
[0106] Fig. 6 shows a flowchart of an example of a method;
[0107] Fig. 7 show an example of a signaling flow diagram;
[0108] Fig. 8 shows a flowchart of an example of a method;
[0109] Fig. 9 shows a flowchart of an example of a method;
[0110] Fig. 10 show an example of a signaling flow diagram; and
[0111] Fig. 11 shows an example of an apparatus.
[0112] DETAILED DESCRIPTION
[0113] The following embodiments are provided by way of non-limiting and illustrative example. Although the specification may refer to “an”, “one”, or “some” embodiments) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s), or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it intended such feature, structure, or characteristic may be applied in connection with other embodiments (whether or not explicitly described).
[0114] It shall be understood that although the terms “first,” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.
[0115] For the purposes of this disclosure, the phrases “at least one of A or B”, “at least one of A and B”, and “A and / or B” means (A), (B), or (A and B). For the purposes of this disclosure, the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).
[0116] As used herein, the term “or” refers to a non-exclusive “or” unless otherwise indicated (e.g., use of “or else” or “or in the alternative”).
[0117] As used herein, unless stated explicitly, performing a respective feature, step, or functionality “in response to A” does not indicate that the respective feature, step, or functionality is performed immediately after “A” occurs as one or more intervening features, steps, or functionalities may be performed (at least in part) between an occurrence of the respective feature, step, or function and “A”. Analogously, performing a respective feature, step, or functionality “based on A” does not indicate that the respective feature, step, or functionality is performed solely based on “A” as the respective feature, step, or functionality may be further based on one or more other features, steps, or functionalities in addition to “A”.
[0118] Embodiments described herein may be implemented in a communication network, such as any of the following radio access technologies (RATs): Worldwide Interoperability for Micro-wave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, and enhanced LTE (eLTE), 5G (also called NR), or any future RAT such as 6G. Moreover, communication within the communication network may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), and / or Discrete Fourier Transform spread OFDM (DFT-s-OFDM).
[0119] As used herein, the term “network device” or “network node” refers to a node in a communication network via which user equipment may access the network and / or which is configured to control radio communication and managing radio resources within a cell. The network node or network device may be referred to as a base station (BS), an access point (AP) or an access node. The network device may be, depending on the applied technology, for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node, a non-terrestrial network (NTN) or nonground network device, such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, or an aircraft network device.
[0120] Moreover, in connection of split radio access network (RAN), the network device may refer to a centralised unit (CU) of a base station and / or a distributed unit (DU) of a base station. An interface between CU and DU may be referred to as an F1 interface in NR. In the split RAN architecture, node operations may be carried out, at least partly, in the central / centralized unit, CU, (e.g. server, host or node) operationally coupled to the DU, (e.g. a radio head / node). One CU may control one or more DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some embodiments, the DUs may comprise e.g. a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the CU may comprise the layers above RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) and an internet protocol (IP) layers. Other functional splits are possible too. In practice, any processing task may be performed in either the CU or the DU and the boundary where the responsibility is shifted between the CU and the DU may depend on the applied implementation.
[0121] The term “terminal device” refers to any end device that may be configured to perform wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), or a Mobile Station (MS). The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, USB dongles, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like.
[0122] A term “resource”, as used herein, may refer to radio resources in time domain, in frequency domain, in space domain, and / or in code domain. Some examples of resources may include, e.g., a physical resource block (PRB), a radio frame, a subframe, a time slot, a subband, a frequency region, a sub-carrier, a beam, etc. The term “transmission” and / or “reception” may refer to wirelessly transmitting and / or receiving via a wireless propagation channel on radio resources.
[0123] Fig. 1 illustrates an example of a communication network to which examples disclosed herein may be applied. The communication network or a cellular communication network may comprise a network node 110 configured to provide one or more cells, such as cell 100, and a network node 112 configured to provide one or more other cells, such as cell 102. Each cell may, for example, be a macro cell, a micro cell, femto, or a pico cell. The cell may define a coverage area or a service area of the corresponding access node.
[0124] The network node (110, 112) may be configured to provide a user
[0125] 13 equipment (UE) 120 (one or more UEs) with wireless access to the communication network. The wireless access may comprise downlink (DL) communication from the network node (110, 112) to the UE 120 and uplink (UL) communication from the UE 120 to the network node (110, 112). Examples of uplink channels may comprise physical uplink control channel (PUCCH) for transmitting control information and physical uplink shared channel (PUSCH) for transmitting data towards the network. Examples of downlink channels may comprise physical downlink control channel (PDCCH) for transmitting control information and physical downlink shared channel (PDSCH) for transmitting data towards the user equipment.
[0126] There may be a plurality of UEs (120, 122) in the system. Each of the plurality of UEs may be served by the same or by different network nodes (110, 112). UE may be configured with dual connectivity (DC), wherein the UE, for example UE 120, may be connected to multiple network nodes (110, 112). The UEs (120, 122) may communicate with each other, in case device-to-device (D2D) communication interface is established between them via a so-called sidelink (SL). Such D2D communications may be referred to as machine-to-machine, peer-to-peer (P2P) communications, or vehicle- to-vehicle (V2V), for example.
[0127] In the case of multiple network nodes in the communication network, the network nodes may be connected to each other via an interface. LTE specifications, for example, refer to such an interface as an X2 interface. An interface between an LTE node and a 5G node, or between two 5G nodes may be called an Xn interface.
[0128] The network nodes 110 and 112 may be further connected via another interface to a core network 116 of the communication network. The LTE specifications specify the core network as an evolved packet core (EPC), and the core network may comprise a plurality of entites (e.g. a mobility management entity (MME) and a gateway node). The MME may handle mobility of terminal devices in a tracking area encompassing a plurality of cells and handle signalling connections between the terminal devices and the core network. The gateway node may handle data routing in the core network and to / from the terminal devices. The 5G specifications specify the core network as a 5G core (5GC). The 5GC may, for example, comprise an access and mobility management function (AMF) and a user plane function / gateway (UPF) and other functions. The AMF may handle termination of non-access stratum (NAS) signalling, NAS ciphering & integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. The UPF node may, for example, support packet routing and forwarding, packet inspection and quality of service (QoS) handling.
[0129] Fig. 2 shows an example representation of Resource owner-aware Northbound API Access (RNAA) as supported by CAPIF architecture.
[0130] An example CAPIF architecture comprises functional entities, such as a resource owner function (ROF) and an authorization function. CAPIF-8 relates to the interactions between ROF and an authorization function.
[0131] The resource owner function (ROF) is a functional entity that enables providing authorization for accessing personal information resources (e.g., the location, network activity). Under some jurisdictions, sharing personal information resources with an API invoker requires explicit opt-in by the resource owner (also referred to as subscriber) to authorize access to its personal information resources. This process is called consent capture. Consent capture may be achieved with a client application, such as the ROF, on or implemented at least in part by the resource owner's UE, and the resource owner (e.g., user) allowing or denying access by the API invoker to the personal information resources via the ROF.
[0132] While capturing the consent, the ROF may be provided with a purpose of data processing, indicating what the API invoker intends to do with the personal information resources of the resource owner. The resource owner may grant access to personal information resources based on the purpose (e.g., fraud detection) but deny access for other purposes (e.g., advertising).
[0133] An authorization function (which may be located in the CAPIF core function (CCF)) is a functional entity which, among other things, captures the consent (also referred to as authorization) through the ROF to allow an API invoker accessing services that require personal information processing. When receiving consent from the ROF, the authorization function may provide the API invoker with the authorization information (also referred to as an access token), which is used to access the resource owner's resources. Once consent is received from a resource owner (e.g., user), an access token is granted to the API Invoker to utilize the service from an API exposing function (AEF).
[0134] The API Invoker sends an access token request (or OAuth access token request) to the authorization function (CCF). The access token request may include the resource owner ID. If the resource is associated with a subscriber, the resource owner ID is specified as the Global Public Subscriber Identity (GPSI) of the corresponding subscriber.
[0135] The communication between the authorization function (in CCF) and ROF
[0136] 15 over CAPIF-8 is not defined in Rel-18, but is being defined in Rel-19. There is an outstanding question of how to manage the consent of the resource owner through communication between the resource owner and the authorization function in the CCF.
[0137] Fig. 3 shows an example of a method. The method may be performed at an apparatus (e.g., an apparatus comprising a network entity). The network entity may, for example, comprise a network function, such as the application function of a CCF. The network entity may, for example, be configured to implement at least in part a network function, such as the application function of a CCF.
[0138] At 301 , the method comprises receiving an access token request from a second network entity.
[0139] At 302, the method comprises, in response to receiving the access token request, providing an indication to a user equipment to cause the user equipment to obtain pending consent request information from the network entity.
[0140] At 303, the method comprises receiving consent information from the user equipment.
[0141] At 304, the method comprises providing an access token to the second network entity based on the consent information.
[0142] Fig. 4 shows an example of a method. The method may be performed at a UE. The UE may, for example, comprise a ROF. The UE may, for example, be configured to implement at least in part a ROF.
[0143] At 401 the method comprises receiving an indication at the user equipment to cause the user equipment to obtain pending consent request information from the network entity.
[0144] At 402, the method comprises, based on the pending consent request information, obtaining consent information.
[0145] At 403, the method comprises providing the consent information to the network entity.
[0146] The indication may be provided from the network entity to the ROF of the UE and the consent information may be provided from the ROF to the network entity. Consent information may be obtained from the resource owner as described above. The second network entity may, for example, comprise an application function, such as an API invoker. The second network entity may, for example be configured to implement at least in part an application function, such as an API invoker.
[0147] A method as described with reference to Fig. 3 may comprise providing the indication to the user equipment via a uniform resource identifier. The method may comprise receiving consent information from the user equipment via a uniform resource indicator.
[0148] The method may comprise receiving a request from the user equipment for a subscription to consent requests for the user equipment and providing a response to the request to the user equipment, the response comprising an identifier of the subscription. For example, a ROF may subscribe for pending consent requests with an Authorization Function.
[0149] In an embodiment, ROF Consent T rigger is triggered via Subscription Notification. A Subscription Notification is an example of an indication as described above with reference to Figs. 3 and 4.
[0150] Upon Access Token Request from API Invoker (and based on optional notification criteria set by the resource owner), the Authorization Function notifies the ROF.
[0151] The notification optionally includes the consent information of the API Invoker. That is, the indication may comprise the pending consent request information.
[0152] Alternatively, or in addition, the indication may comprise an identifier of the UE (resourceOwnerlD) and / or an identifier of the subscription (subscriptionlD). If the notification doesn’t contain consent information, ROF may fetch the pending consent request information (also referred to as consent requests) from an Authorization Function.
[0153] The UE (or ROF of the UE) may provide the consent information (e.g., consent responses) to the URI provided by Authorization Function.
[0154] Fig. 5 shows an example of a method as described with reference to Fig.
[0155] 3 where the indication is provided via a URI. The method may, for example, be performed at an apparatus comprising a network entity. The network entity may, for example, comprise a network function, such as for example, the application function of a CCF. The network entity may, for example, be configured to implement at least in part a network function, such as for example, the application function of a CCF
[0156] At 501 , the method comprises receiving an access token request from a second network entity.
[0157] At 502, the method comprises, in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier (URI) to cause the user equipment to obtain pending consent request information from the network entity.
[0158] At 503, the method comprises receiving consent information from the user
[0159] 17 equipment via the URL
[0160] At 504, the method comprises providing an access token to the second network entity based on the consent information.
[0161] Fig. 6 shows an example of a method as described with reference to Fig. 4 where the indication is received via a URL The method may, for example, be performed at a UE. The UE may, for example, comprise a ROF. The UE may, for example, be configured to implement at least in part a ROF.
[0162] At 601 the method comprises receiving an indication at the user equipment via a uniform resource identifier (URI) to cause the user equipment to obtain pending consent request information from the network entity.
[0163] At 602, the method comprises, based on the pending consent request information, obtaining consent information.
[0164] In 603, the method comprises providing the consent information to the network entity via the URL
[0165] Fig. 7 shows a signalling flow between a Resource Owner, a ROF, an Authorization Function of a CCF and an API Invoker according to an embodiment.
[0166] At 1 , the ROF is successfully registered in CCF.
[0167] At 2, the API Invoker is onboarded successfully with CCF.
[0168] At 3, the ROF subscribes with Authorization function (CCF) for resource owner consent requests notifications using SubscribeForConsent Request.
[0169] At 4, the ROF receives 200 Ok and the subscriptionlD.
[0170] At 5, the ROF waits for the notifications from CCF.
[0171] At 6, the API Invoker sends an access token request to CCF.
[0172] At 7, the CCF notifies the ROF using Notify Event comprising resource- OwnerlD and subscriptionlD. ROF gets the pending consent information from CCF.
[0173] At alternative 8, the CCF sends notification to ROF including the consent request information.
[0174] At 9 and 10, a Consent capture window is presented to the resource owner (e.g., via a web browser or application frontend). The Consent capture window may include the Purpose with other details, and the resource owner provides the consent to ROF.
[0175] At 11 , the ROF posts the consent to URI accessible to CCF.
[0176] At 12 and 13, the CCF stores the consent locally or at a repository service (e.g., UDM / UDR via NEF) and then provides the access token to API Invoker.
[0177] The method may comprise providing an indication to the user equipment
[0178] 18 via non-access stratum signalling. The method may comprise receiving consent information from the user equipment via non-access stratum signalling.
[0179] A method as described with reference to Fig. 5 may comprise providing the indication to the UE via non-access stratum (NAS) signalling. The method may comprise receiving consent information from the user equipment via a NAS sigalling.
[0180] In an embodiment, a ROF Consent may be triggered via NAS. The ROF may subscribe for the pending consent request information with an Authorization Function.
[0181] In an embodiment, upon receiving an Access Token Request from an API Invoker, the Authorization Function wakes up ROF via AMF using a NAS signalling message.
[0182] The NAS signalling message may optionally include the consent information of API Invoker. That is, the indication may comprise the pending consent request information.
[0183] Alternatively, or in addition, the indication may comprise an identifier of the UE (resourceOwnerlD) and / or an identifier of the subscription (subscriptionlD). If the notification doesn’t contain consent information, ROF may fetch the pending consent request information (also referred to as consent requests) from an Authorization Function and provide the consent information via NAS sigalling.
[0184] Fig. 8 shows an example of a method as described with reference to Fig.
[0185] 3 where the indication is provided via non-access stratum signalling. The method may be performed at an apparatus (e.g., an apparatus comprising a network entity). The network entity may, for example, comprise a network function, such as for example, the application function of a CCF. The network entity may, for example, be configured to implement at least in part a network function, such as for example, the application function of a CCF.
[0186] At 801 , the method comprises receiving an access token request from a second network entity.
[0187] At 802, the method comprises, in response to receiving the access token request, providing an indication to a user equipment via non-access stratum signalling to cause the user equipment to obtain pending consent request information from the network entity.
[0188] At 803, the method comprises receiving consent information from the user equipment.
[0189] At 804, the method comprises providing an access token to the second
[0190] 19 network entity based on the consent information.
[0191] Fig. 9 shows an example of a method as described with reference to Fig.
[0192] 4 where the indication is received via non-access stratum signalling. The method may, for example, be performed at a UE. The UE may, for example, comprise a ROF. The UE may, for example, be configured to implement at least in part a ROF.
[0193] At 901 , the method comprises receiving an indication at the user equipment via non-access stratum signalling to cause the user equipment to obtain pending consent request information from the network entity.
[0194] At 902, the method comprises, based on the pending consent request information, obtaining consent information.
[0195] At 903, the method comprises providing the consent information to the network entity.
[0196] Fig. 10 shows a signalling flow between a Resource Owner, a ROF, AMF, NEF, an Authorization Function of a CCF and an API Invoker according to an embodiment.
[0197] At 1 , the ROF is successfully registered in the CCF.
[0198] At 2, the API Invoker is onboarded successfully with the CCF.
[0199] At 3, the API Invoker sends an access token request to the CCF.
[0200] At 4a, the CCF sends the wakeup request to the NEF.
[0201] At 4b, the NEF fetches the AMF address associated with resourceOwn- erlD from the UDM.
[0202] At 5, the NEF sends a wakeup request message to the AMF.
[0203] At 6, the AMF forwards the wakeup request message to the ROF using NAS signalling (the wakeup message is an example of the indication).
[0204] At 7, 8 and 9, wakeup responses are sent back to the AMF (via NAS), NEF, and CCF.
[0205] 10 corresponds to 7b, 7c and 9 to 13 of Fig. 9.
[0206] The following comprises a description of example services which may be used for the management of resource owner consent.
[0207] A: Subscribe For Consent Request / Response:
[0208] This service operation is used by a resource owner function to subscribe for consent requests destined to it from Authorization Function (in CCF).
[0209] The parameters in the Subscription Request may include:
[0210] • resourceOwnerld, • notificationDestinationUri where the event notification to be delivered to, and
[0211] • capif event type CONSENT_PENDING.
[0212] • notificationTimeConstraints (Optional) indicating the time in which the resource owner should not be requested with notifications for capturing the consent
[0213] • consentnotificationZoneConstraints (Optional) indicating geographical zones in which the resource owner should not be requested for capturing the consent
[0214] • subscriptionDuration (Optional) indicating the time for which the subscription holds. Upon expiration time, no further notification can be sent to the resource owner.
[0215] A Response (from the Authorization Function to the ROF) includes the information about success or failure of the service operation, and if the operation was successful, a subscriptionlD.
[0216] B: Notify Event:
[0217] This service operation allows Authorization function (in CCF) to notify the ROF about the pending Consents (e.g., pending consent information). The parameters included in this message may follow the resourceOwnerConsentlnformation structure defined below.
[0218] The notification event may carry just the resource owner id and the subscriptionlD.
[0219] Thereby ROF can explicitly fetch the pending consents from the authorization function (in CCF). Alternatively, if the notification event contains the resourceOwnerCon- sentlnformation, ROF doesn’t need to query the pending consents explicitly.
[0220] C: Unsubscribe For Consent Request:
[0221] This service operation may be used by a resource owner function to unsubscribe to CONSENT_PENDING event from Authorization function (in CCF).
[0222] The parameters of this unsubscribe request may include:
[0223] ■ subscriptionlD or
[0224] ■ resourceOwnerld and
[0225] ■ capif event type CONSENT_PENDING.
[0226] D: Get Pending Consent Request / Response:
[0227] This service operation may be used by resource owner function to get from the Authorization Function (in CCF) the pending consent requests associated with it.
[0228] Get Pending Consent Request contains resource owner ID and I or subscription ID to get the pending consent request details associated to the resource owner from authorization function.
[0229] Get Pending Consent Response contains ResourceOwnerConsentlnformation structure and URI in which ROF can post its granted / rejected consent records. E: Post / Report Consent:
[0230] This service operation may be used by resource owner function to post consent to the Authorization Function URI based on consent requests received beforehand.
[0231] Post / report consent may comprise ResourceOwnerConsentlnformation structure.
[0232] F: Wakeup Request:
[0233] This service operation may be used by an Authorization Function (in CCF) to wake up the resource owner function in the UE (taking into account notification restrictions provided by the resource owner during the subscription procedure) via the AMF (NAS signalling). This service operation may be supported by AMF.
[0234] If the wakeup request carries just the resource owner id and the subscrip- tionlD, ROF can explicitly fetch the pending consent requests from Authorization Function using Get Pending Consent Request. Alternatively, if the wakeup request contains the ResourceOwnerConsentlnformation, ROF doesn’t need to query the pending consent requests explicitly from Authorization function.
[0235] G: Retrieve Consent Request / Response:
[0236] This service operation may be used by ROF to retrieve the Consents records that have been granted by it earlier. The API request may include specific subscrip- tionlD or Resource Information or API Invoker Information or resourceOwnerld.
[0237] The operation response indicates success or failure of the service operation. If successful, the ResourceOwnerConsentlnformation is included in the API response.
[0238] H: Update Consent Request / Response:
[0239] This service operation may used by ROF to update the Consents records (for example, Resource Information) that have been granted by it earlier. The request may include specific subscriptionlD and ResourceOwnerConsentlnformation.
[0240] The operation response indicates success or failure of the service operation.
[0241] I: Revoke Consent Request / Response:
[0242] This service operation may be used by ROF to revoke the consent that was already provided. The ResourceOwnerConsentlnformation is included in the API request.
[0243] The response may indicate success or failure of the operation. If the revocation is successful in the CCF, there must be a Token revocation mechanism in place to invalidate API invoker access to personal information protected by an AEF. Resource owner consent information structure
[0244] The following Information Elements may define a resource owner consent information structure:
[0245] ResourceOwnerConsentlnformation
[0246] Consentinformation
[0247] ConsentGranted SHALL BE included in the Post / Report Consent API invocation by ROF on Authorization Function. If ConsentGranted is FALSE then Resourceinformation is not included.
[0248] Resourceinformation
[0249] The above operations may use ResourceOwnerConsentlnformation structure commonly. The parameters of it are filled by the sender of the messages as applicable.
[0250] Fig. 11 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). In an example, the at least one memory and the instructions (e.g. a computer program code, software), are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof).
[0251] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with embodiments described herein.
[0252] As used herein, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessors), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0253] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may, for example, be at least in part external to apparatus 10 but accessible to apparatus 10.
[0254] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM).
[0255] For example, the apparatus 10 is a terminal device, such as a UE. As another example, the apparatus is comprised in such a terminal device, e.g. as a chipset configured to control the terminal device. The apparatus 10 may be caused or configured to perform at least the method of Figs. 4, 6, 9 and / or any one or more of the embodiments described herein.
[0256] As another example, the apparatus 10 is a network entity. In another embodiment, the apparatus is comprised in such a network entity, e.g. as a chipset configured to control the network entity. The apparatus 10 may be caused or configured to perform at least the method of Figs. 3, 5 or 8 and / or any one or more of the embodiments described herein.
[0257] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity. In some embodiments, the entity is configured to perform at least the method of Figs. 3 to 6, or 8 or 9, and / or any one or more of the embodiments described.
[0258] The apparatus 10 comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.
[0259] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.
[0260] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C]”, is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.
[0261] Even though this disclosure has been described above with reference to non-limiting and illustrative examples according to the accompanying figures, it is clear that the scope of this disclosure is not restricted thereto - but can be modified in many different ways. As technology advances, it will become apparent to a person skilled in art as to how the disclosure can be further implemented and / or modified in various ways. Further, it is clear to a person skilled in the art that the embodiments described herein may, but are not required to, be combined in various ways with other embodiments described herein. APPENDIX A
[0262] The following includes an example 3GPP contribution according to some embodiments of this disclosure.
[0263] 1. Introduction
[0264] If Consent is the applicable legal basis for processing of personal data, resource owners must actively agree through an affirmative action (opt in). How Consent can be captured depends on the concrete use case and on the laws of the jurisdictions which govern the use case. Even though Consent can be obtained through a variety of methods and techniques (e.g., ticking a box on a website or writing / accepting a letter confirming the grant for processing personal data), having the Consent captured during runtime is a well-established approach, as have been studied in RNAA.
[0265] 2. Reason for Change
[0266] KI#1 states that it is needed to study "I low consent of the resource owner can be managed through communication between the resource owner and authorization function in the CAPIF core function ” . This solution proposes the service operations and related information flows to capture the Consent from the resource owner.
[0267] 3. Proposal
[0268] It is proposed to agree the new key issue for 3GPP TR 23.700-22 VO.3.0.
[0269] 6.1 Mapping of solutions to key issues
[0270] Table 6.1-1 Mapping of Solutions to Key Issues
[0271] 6.z Solution #Y: Consent capture
[0272] 6.z.1 Solution description
[0273] 6.Z.1.1 General
[0274] Under some legislations around the globe, sharing personal information with an API invoker implies explicit opt-in by the Resource Owner (RO) to authorize access to its personal information resources (e.g., location). This process is called Consent capture which is performed e.g., while having a client application on the RO's device, and the RO allowing or denying the resource access. Even though Consent can be captured through a variety of methods and techniques (e.g., ticking a box on a website or writing / ac- cepting a letter confirming the grant for processing personal data), having the Consent captured during runtime is a well-established approach for some scenarios in which the so-called resource owner grants or denies the invoker’s access request [6],
[0275] While capturing the Consent during runtime, the RO is presented the so-called Purpose (of data processing), indicating what the API invoker intends to do with the personal information resources of the RO (e.g., read location for spatial analytics or read network activity for fraud detection). In turn, the RO may grant access to personal information resources based on the Purpose, for instance: grant access to personal information resources for fraud detection but deny access for other Purposes (e.g., advertising).
[0276] 6.z.1 .2 Consent capture procedure
[0277] Figure 6.Z.1-1 presents the procedure for capturing and storing the Consent using RNAA.
[0278] Pre-condition:
[0279] 1. The API invoker is onboarded as in clause 8.1 in 3GPP TS 23.222 [2] and has received an API invoker identity.
[0280] 28
[0281]
[0282] Figure 6.Z.1-1 : Consent Capture in RNAA
[0283] 1. ROF registers with the CCF providing Identity and Security information while subscribing at the same time to CAPIF events about Pending Consent requests (see Table 8.8.6-1) including relevant Event Criteria and Notification reception information (containing a callback URI). Optional information as time or zone constraints for notifying the RO or subscription duration could be present while subscribing.
[0284] Editor's Note: The details of the ROF registration procedure are FFS
[0285] 2. The API invoker sends an obtain service API authorization request to the CAPIF core function for obtaining permission to access the service API by including the API invoker identity information and any information required for authentication of the API invoker. If processing of personal data is foreseen, the API invoker includes in the request information about the Purpose and the targeted resources and operations to be performed on those resources.
[0286] Editor's Note: Authorization details need to be provided by SA3
[0287] 3. The CCF validates the authentication of the API invoker (using authentication information) and checks whether the API invoker is permitted to access the requested resources, i.e., checks if a Consent record for the signalled Purpose is already in place. If the Consent for accessing the requested resources for the signalled Purpose is already granted, the information flow continues in step 7 of Figure 6.Z.1-1.
[0288] NOTE 1 : The authentication process is specified in clause 6.5.2 of 3GPP TS 33.122 [3],
[0289] NOTE 2: Whether the CCF is allowed to hold / cache Consent records depends on local regulations. 4a.1 If the Consent needs to be captured from the RO, and the notification criteria are met, the CCF sends event notifications to the ROF. The Event identifier IE indicates that there are Pending Consent requests that require RO’s attention. The Event content could carry a retrieval URL
[0290] 4a.2 ROF can explicitly fetch the Pending Consent request information (including among others API invoker identity, Purpose, Scope) using the retrieval URI and present that information to the RO (step 6).
[0291] 4b.1 Alternatively, the Event content in the Event notification could directly carry the Pending Consent request information (including among others API invoker identity, Purpose, Scope).
[0292] 5. ROF sends an Event notification acknowledgement to the CCF.
[0293] 6. Consent capture request presented to the RO (e.g., via a web browser or application frontend) showing the Purpose with other details and the RO grants or deny the Consent.
[0294] NOTE 3 : The details of the interaction between RO and ROF for capturing the Consent are considered out-of-scope of 3GPP.
[0295] 7. ROF triggers the storage of the result of the interaction RO-ROF for capturing the Consent with the CCF.
[0296] NOTE 3 : If the CCF is a suitable place for storing Consent information is FFS.
[0297] 8. If the RO grants the Consent for accessing personal information resources, the authorization information to access the service APIs is sent to the API invoker in the obtain service API authorization response.
[0298] 9. The service API invocation takes place considering the authorization information received in the previous step.
[0299] 6.Z.1 .3 Enhancement to clause 8.8.1 of 3GPP TS 23.222
[0300] The new content is highlighted (in bold).
[0301]
[0302] 6.Z.1 .4 Enhancement to clause 8.8.6 of 3GPP TS 23.222
[0303] The new content is highlighted (in bold). 6.Z.1.4 Enhancement to clause 10.4.1 of 3GPP TS 23.222
[0304] The new content is highlighted (in bold).
[0305] 32 6.z.2 Architecture Impacts
[0306] None.
[0307] 6.z.3 Corresponding APIs
[0308] Editor's note: Whether new or enhanced APIs are required in support of this solution is in scope of SA3.
[0309] 6.z.4 Solution evaluation
[0310] Editor's note: This clause provides an evaluation of the solution. The evaluation should include the descriptions of the impacts to existing architectures.
[0311] 33
Claims
WE CLAIM:1 . An apparatus comprising a network entity, the apparatus comprising means for: receiving an access token request from a second network entity; in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from the network entity; receiving consent information from the user equipment via the uniform resource indicator; and providing an access token to the second network entity based on the consent information.
2. The apparatus according to claim 1 , comprising means for receiving a request from the user equipment for a subscription to consent requests for the user equipment; and providing a response to the request to the user equipment, the response comprising an identifier of the subscription.
3. The apparatus according to claim 1 or claim 2, wherein the indication comprises an identifier of the user equipment.
4. The apparatus according to claim 3 when dependent on claim 2, wherein the indication further comprises the identifier of the subscription.
5. The apparatus according to claim 3 or claim 4, comprising means for receiving, in response to the indication, a request for the pending consent request information from the user equipment and providing the pending consent request information to the user equipment in response.
346. The apparatus according to claim 1 or claim 2, wherein the indication comprises the pending consent request information.
7. The apparatus according to any of claims 1 to 6, wherein the network entity comprises an authorization function and the second network entity comprises an application function.
8. The apparatus according to claim 7, wherein the application function comprises an application programming interface invoker.
9. A user equipment comprising means for: receiving an indication at the user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from a network entity; based on the pending consent request information, obtaining consent information; and providing the consent information to the network entity via the uniform resource indicator.
10. The apparatus according to claim 9, comprising means for providing a request to a network entity for a subscription to consent requests for the user equipment; and receiving a response to the request to the user equipment, the response comprising an identifier of the subscription.11 . The user equipment according to claim 9 or claim 10, wherein the indication comprises an identifier of the user equipment and wherein obtaining the pending consent request information comprises providing, in response to the indication, a request for the pending consent request information to the network entity and receiving the pending consent request information from the network entity in response.
12. The apparatus according to claim 11 when dependent on claim 10, wherein the indication further comprises the identifier of the subscription.
13. The apparatus according to claim 9, wherein the indication comprises the pending consent request information.
14. The apparatus according to any of claims 9 to 13, wherein the network entity comprises an authorization function.
15. An apparatus comprising a network entity, the apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving an access token request from a second network entity; in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from the network entity; receiving consent information from the user equipment via the uniform resource indicator; and providing an access token to the second network entity based on the consent information.
16. A user equipment, the user equipment comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to perform: receiving an indication at the user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from a network entity; based on the pending consent request information, obtaining consent information; and providing the consent information to the network entity via the uniform resource indicator.
17. A method, comprising: receiving an access token request from a second network entity; in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from the network entity; receiving consent information from the user equipment via the uniform resource indicator; and providing an access token to the second network entity based on the consent information.
18. A method, comprising: receiving an indication at a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from a network entity; based on the pending consent request information, obtaining consent information; and providing the consent information to the network entity via the uniform resource indicator.
19. A computer program product comprising program instructions which, when the program is executed by an apparatus, cause the apparatus to perform: receiving an access token request from a second network entity; in response to receiving the access token request, providing an indication to a user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from the network entity; receiving consent information from the user equipment via the uniform resource indicator; and providing an access token to the second network entity based on the consent information.
20. A computer program product comprising program instructions which, when the program is executed by an apparatus, cause the apparatus to perform:receiving an indication at the user equipment via a uniform resource identifier to cause the user equipment to obtain pending consent request information from a network entity; based on the pending consent request information, obtaining con- sent information; and providing the consent information to the network entity via the uniform resource indicator.38