Spatial anchor association with multiple service providers
A spatial anchor management system with authorization tokens and enhanced access tokens addresses the issue of unauthorized alterations by enforcing strict security policies, ensuring secure and reliable management of spatial anchors for multiple service providers.
Patent Information
- Application Number
- PCT/CN2024/110325
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-07
- Publication Date
- 2026-02-12
AI Technical Summary
Existing systems lack a secure and efficient mechanism for multiple service providers to manage spatial anchors, leading to unauthorized alterations of service information and lack of authorization control in spatial anchor management.
Implementing a spatial anchor management system involving first and second spatial anchor management nodes, an authentication and authorization node, and a spatial anchor management server, utilizing authorization tokens and enhanced access tokens to enforce strict security policies, ensuring only authorized service providers can perform CRUD operations on spatial anchors.
Ensures secure and reliable management of spatial anchors by enforcing strict security policies, preventing unauthorized alterations and maintaining accurate service information, while reducing signaling overhead.
Smart Images

Figure CN2024110325_12022026_PF_FP_ABST
Abstract
Description
SPATIAL ANCHOR ASSOCIATION WITH MULTIPLE SERVICE PROVIDERSTECHNICAL FIELD
[0001] Various example embodiments described herein generally relate to communication technologies, and more particularly, to devices, methods, apparatuses and computer readable mediums for spatial anchor management by multiple service providers.BACKGROUND
[0002] Certain abbreviations that may be found in the description and / or in the figures are herewith defined as follows:
[0003] 3GPP 3rd Generation Partnership Project
[0004] AEF API Exposing Function
[0005] API Application Programming Interface
[0006] CAPIF Common API Framework
[0007] CCF CAPIF Core Function
[0008] CRUD Create Retrieve Update Delete
[0009] LM Location Management
[0010] NF Network Function
[0011] SA Spatial Anchor
[0012] SEAL Service Enabler Architecture Layer for Verticals
[0013] SIM SEAL Identity Management
[0014] UE User Equipment
[0015] URI Uniform Resource Identifier
[0016] VAL Vertical Application Layer
[0017] Metaverse is considered as a three dimension (3D) digital world which uses virtual reality, augmented reality and other digital and semiconductor technologies to allow people to have immersive experiences like in the physical world. Metaverse services can be created for events, activities, shops, malls, entertainment venues, scenic spots or the like which enables companies to run businesses online. Such services in the digital world are provided at specific locations and thus are called localized services. The localized services can be associated with specific places (3D locations in the physical world) , and the association between these places and service information is termed a spatial anchor. Localized service providers can use spatial anchors to associate application content and services with location information which can be managed by the 3GPP system. In turn, spatial anchors can be used by application clients to discover and access application content and services in a location aware fashion.SUMMARY
[0018] A brief summary of exemplary embodiments is provided below to provide basic understanding of some aspects of various embodiments. It should be noted that this summary is not intended to identify key features of essential elements or define scopes of the embodiments, and its sole purpose is to introduce some concepts in a simplified form as a preamble for a more detailed description provided below.
[0019] In a first aspect, an example embodiment of a first spatial anchor management node is provided. The first spatial anchor management node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the first spatial anchor management node at least to receive, from a second spatial anchor management node, an authorization request for a spatial anchor management operation on a spatial anchor owned by the first spatial anchor management node, to validate the authorization request received from the second spatial anchor management node, and to send, to the second spatial anchor management node, an authorization token for the spatial anchor management operation on the spatial anchor.
[0020] In a second aspect, an example embodiment of a second spatial anchor management node is provided. The second spatial anchor management node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the second spatial anchor management node at least to send, to a first spatial anchor management node, an authorization request for a spatial anchor management operation on a spatial anchor owned by the first spatial anchor management node, to receive, from the first spatial anchor management node, an authorization token for the spatial anchor management operation, to send, to an authentication and authorization node, an access token request for the spatial anchor along with the authorization token, to receive, from the authentication and authorization node, an enhanced access token for the spatial anchor, and to send, to a spatial anchor management server, a request for performing the spatial anchor management operation along with the enhanced access token for the spatial anchor.
[0021] In a third aspect, an example embodiment of an authentication and authorization node is provided. The authentication and authorization node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the authentication and authorization node at least to receive, from a second spatial anchor management node, an access token request for a spatial anchor owned by a first spatial anchor management node along with an authorization token issued by the first spatial anchor management node, to validate the access token request and the authorization token, and to send, to the second spatial anchor management node, an enhanced access token for the second spatial anchor management node to access the spatial anchor.
[0022] In a fourth aspect, an example embodiment of a spatial anchor management server is provided. The spatial anchor management server may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the spatial anchor management server at least to receive, from a first spatial anchor management node, a spatial anchor creation request comprising an authorization policy preconfigured for a spatial anchor, to create the spatial anchor in response to the spatial anchor creation request, to send, to the first spatial anchor management node, a spatial anchor creation response indicating successful creation of the spatial anchor, and to provide, to an authentication and authorization node, information of the spatial anchor comprising the preconfigured authorization policy.
[0023] In a fifth aspect, an example embodiment of a first spatial anchor management node is provided. The first spatial anchor management node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the first spatial anchor management node at least to send, to a spatial anchor management server, a spatial anchor creation request comprising an authorization policy preconfigured for a spatial anchor, and to receive, from the spatial anchor management server, a spatial anchor creation response indicating success creation of the spatial anchor.
[0024] In a sixth aspect, an example embodiment of a first spatial anchor management node is provided. The first spatial anchor management node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the first spatial anchor management node at least to send, to a spatial anchor management server, a spatial anchor creation request, to receive, from the spatial anchor management server, a spatial anchor creation response indicating success creation of a spatial anchor, and to provide, to an authentication and authorization node, information of the spatial anchor comprising an authorization policy preconfigured for the spatial anchor.
[0025] In a seventh aspect, an example embodiment of an authentication and authorization node is provided. The authentication and authorization node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the authentication and authorization node at least to receive, from a first spatial anchor management node or a spatial anchor management server, information of a spatial anchor owned by the first spatial anchor management node, the spatial anchor information comprising an authorization policy preconfigured for the spatial anchor, and to update profile of the first spatial anchor management node with the received spatial anchor information.
[0026] In an eighth aspect, an example embodiment of a second spatial anchor management node is provided. The second spatial anchor management node may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the second spatial anchor management node at least to send, to an authentication and authorization node, an access token request for a spatial anchor management operation on a spatial anchor owned by a first spatial anchor management node, to receive, from the authentication and authorization node, an enhanced access token for the spatial anchor management operation on the spatial anchor, and to send, to a spatial anchor management server, a request for performing the spatial anchor management operation on the spatial anchor along with the access token.
[0027] Example embodiments of methods, apparatuses and computer readable media are also provided, which generally correspond to the above-described example embodiments of the first to eighth aspects, and a repetitive description thereof is omitted here for convenience.
[0028] Other features and advantages of the example embodiments of the present disclosure will also be apparent from the following description of specific embodiments when read in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of example embodiments of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Some example embodiments will now be described, by way of non-limiting examples, with reference to the accompanying drawings.
[0030] Fig. 1 illustrates an on-network functional architecture for providing service enabler architecture layer for verticals (SEAL) services.
[0031] Fig. 2 illustrates a procedure for creating a spatial anchor.
[0032] Fig. 3 illustrates a procedure for managing a spatial anchor according to example embodiments of the present disclosure.
[0033] Fig. 4 illustrates a procedure for managing a spatial anchor according to example embodiments of the present disclosure.
[0034] Fig. 5 illustrates a procedure for managing a spatial anchor according to example embodiments of the present disclosure.
[0035] Fig. 6 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0036] Fig. 7 illustrates an apparatus according to example embodiments of the present disclosure.
[0037] Fig. 8 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0038] Fig. 9 illustrates an apparatus according to example embodiments of the present disclosure.
[0039] Fig. 10 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0040] Fig. 11 illustrates an apparatus according to example embodiments of the present disclosure.
[0041] Fig. 12 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0042] Fig. 13 illustrates an apparatus according to example embodiments of the present disclosure.
[0043] Fig. 14 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0044] Fig. 15 illustrates an apparatus according to example embodiments of the present disclosure.
[0045] Fig. 16 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0046] Fig. 17 illustrates an apparatus according to example embodiments of the present disclosure.
[0047] Fig. 18 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0048] Fig. 19 illustrates an apparatus according to example embodiments of the present disclosure.
[0049] Fig. 20 illustrates a method for managing a spatial anchor according to example embodiments of the present disclosure.
[0050] Fig. 21 illustrates an apparatus according to example embodiments of the present disclosure.
[0051] Fig. 22 illustrates a device according to example embodiments of the present disclosure.
[0052] Fig. 23 illustrates a device according to example embodiments of the present disclosure.
[0053] Fig. 24 illustrates a device according to example embodiments of the present disclosure.
[0054] Throughout the drawings, same or similar reference numbers indicate same or similar elements. A repetitive description on the same elements would be omitted.DETAILED DESCRIPTION
[0055] Herein below, some example embodiments are described in detail with reference to the accompanying drawings. The following description includes specific details for the purpose of providing a thorough understanding of various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well known circuits, techniques and components are shown in block diagram form to avoid obscuring the described concepts and features.
[0056] Service enabler architecture layer for verticals (SEAL) is an enabling layer architecture which provides a set of common services towards a vertical application layer (VAL) , including for example location management, group management, configuration management, identity management, key management, network resource management, and so forth. Fig. 1 illustrates an on-network functional model 100 for SEAL. As shown in Fig. 1, in the vertical application layer, VAL client (s) 112 and VAL server (s) 130 provide vertical application services to users, and they communicate with each other over a VAL-UU reference point using a wireless communication network e.g., a 3GPP network system 120. In the SEAL, SEAL client (s) 114 and SEAL server (s) 140 provide SEAL services to the vertical application layer (and also to non-vertical applications if any) , and they communicate with each other over a SEAL-UU reference point using the 3GPP network system 120. The SEAL client 114 may provide the service enabler layer support functions to the VAL client 112 over a SEAL-C reference point. The VAL server 130 may communicates with the SEAL server 140 over the SEAL-Sreference point. The SEAL server 140 may communicate with the 3GPP network system 120 using 3GPP interfaces e.g., T8, N33.
[0057] The VAL client 112 and the SEAL client 114 may reside in user equipment (UE) 110. The VAL server 130 may reside in another UE or outside UE. In an example, the VAL server 130 may reside in an application server e.g., a metaverse application server, or in a network function node of a core network e.g., 5G Core (5GC) . The SEAL server 140 may reside in a network function node of the core network, or in an application server external to the core network.
[0058] In an example, the VAL client 112 may use the SEAL client 114 to manage spatial anchors for the metaverse applications over the SEAL-C reference point. Similarly, the VAL server 130 may use the SEAL server 140 to manage spatial anchors for the metaverse applications over SEAL-Sreference point. The SEAL-UU interface may be enhanced to provide management of spatial anchors between the SEAL client 114 and the SEAL server 140. Generally, spatial anchor management may involve operations to create, retrieve, update and delete (CRUD) spatial anchors.
[0059] Here the SEAL is described as an example architecture for providing the spatial anchor management services, but example embodiments disclosed herein are not limited to the SEAL architecture. In an example, a network function (NF) for the core network may be implemented to provide services to create / retrieve / update / delete spatial anchors, and such NF may be called spatial anchor management NF (SAMNF) . UE, application servers or other core network NFs (such as, but not limited to access and mobility management function (AMF) , session management function (SMF) , and so on) may interact with the SAMNF to use the spatial anchor management services.
[0060] Fig. 2 illustrates an example procedure 200 for creating association of spatial anchor with location for metaverse applications. The service is provided by a SEAL server 204 (e.g., a SEAL location management (LM) server) and consumed by a VAL server 202 (or a SEAL client) . As shown in Fig. 2, the VAL server 202 (or the SEAL client) may send at 210 a request message to the SEAL server 204 to create association of the spatial anchor with the location. The request may include VAL server identity, position of the anchor and application service identifier, security credentials, spatial anchor service area. The request may include service information of the product to be associated with the spatial anchor, access control rules defining which entities are permitted to discover and access the spatial anchor, and customer premise information (e.g. a residence, office, or shop) . The request may also include spatial anchor discoverable visibility levels like universal to facilitate shared spatial anchor discovery. The universal discoverable visibility level defines the spatial anchor is discoverable for any user.
[0061] The SEAL server 204 may authorize the VAL server 202 (or the SEAL client) . If the requestor is authorized, then the SEAL server 204 may create the association between the spatial anchor and the location, and store the information as received in the request message. The SEAL server 204 may create identity for the spatial anchor and send at 220 a response back to the VAL server 202 (or the SEAL client) including the spatial anchor identity for a successful case. If the SEAL server 204 fails to create the spatial anchor association, it may include failure cause in the response message.
[0062] A spatial anchor can be created by a service provider operating a VAL server (or SEAL client) as discussed above, and other service providers may want to create (e.g., add) / retrieve / update / delete their respective service information in the spatial anchor with an authorization from the spatial anchor owner. For example, a shopping mall owner may create a spatial anchor representing restaurant, and other service providers running restaurant services in the shopping mall (e.g., KFC, Pizza Hut, Mc-Donalds etc. ) may want to add their service information in the spatial anchor. Multiple service providers can use the spatial anchor management service to perform create / retrieve / update / delete (CRUD) operations on the same spatial anchor for their services. In this use case, a security mechanism is needed to ensure appropriate management operations on the spatial anchor by multiple service providers either owning or not owning the spatial anchor. For example, service providers can be permitted / prevented to perform CRUD operations on the spatial anchor owned by another service provider for their services, and one application service provider cannot alter other application service providers’ service information in the spatial anchor.
[0063] Fig. 3 illustrates an example procedure 300 for managing a spatial anchor according to example embodiments of the present disclosure. The procedure 300 may be performed at a first spatial anchor (SA) management node 302, a second spatial anchor management node 304, an authentication and authorization node 306, and a spatial anchor management server 308. The first and second spatial anchor management nodes 302, 304 may be also referred to as spatial anchor management client node, which interact with the spatial anchor management server 308 to carry out management operations including for example CRUD operations on spatial anchors. The spatial anchor management server 308 provides server side functionalities of the spatial anchor management service, the first and second spatial anchor management nodes 302, 304 provide client side functionalities of the spatial anchor management service. In an example, the spatial anchor management server 308 may be a SEAL server, a spatial anchor management NF (SAMNF) in the core network, or an application server. The first and second spatial anchor management nodes 302, 304 each may be a VAL server, a SEAL client, other NFs (such as AMF, SMF, and so on) in the core network, or an application server (e.g., a metaverse application server) . In the present disclosure, the SEAL server / client may refer to any SEAL application that supports metaverse services.
[0064] The authentication and authorization node 306 can apply a security mechanism to ensure secure management of the spatial anchors by multiple service providers. In an example, in case common application programming interface frame (CAPIF) is used between the SEAL server in the spatial anchor management server 308 and the VAL server in the spatial anchor management clients 302, 304, the authentication and authorization node 306 may comprise a CAPIF core function (CCF) . In this case, the SEAL server acts as an application programming interface (API) exposing function (AEF) , and the VAL server acts as an API invoker. The CCF may choose an appropriate CAPIF-2e security method for mutual authentication and protection of the SEAL server -VAL server interface. In another example, a SEAL identity management (SIM) server (SIM-S) may be used in place of CAPIF to provide VAL user authentication and SEAL service authorization functions.
[0065] At the beginning of the procedure 300, it is assumed that the first spatial anchor management node 302 and the second spatial anchor management node 304 are onboarded / registered to the authentication and authorization node 306 and have their certificates stored at the authentication and authorization node 306. For example, the first spatial anchor management node 302 and the second spatial anchor management node 304 may register their VAL IDs and VAL service IDs with the authentication and authorization node 306, and a private-public key pair may be generated for each of the first spatial anchor management node 302 and the second spatial anchor management node 304 during the onboarding / registration. The public key may be stored at the authentication and authorization node 306, and the private key may be maintained by the first spatial anchor management node 302 and the second spatial anchor management node 304.
[0066] Referring to Fig. 3, at 310, the first spatial anchor management node 302 is authenticated with the authentication and authorization node 306 and receives an access token for creation of a spatial anchor from the authentication and authorization node 306. Then the first spatial anchor management node 302 may send a spatial anchor creation request along with the access token to the spatial anchor management server 308 at 312. For example, a shopping mall owner may want to create a spatial anchor representing restaurant. The spatial anchor creation request may include identity of the first spatial anchor management node 302 (e.g., VAL server identity) , position of the anchor and vertical application service identifier, spatial anchor service area. The request may also include information of the service (e.g., the restaurant service) or product to be associated with the spatial anchor, access control rules defining which entities are permitted to discover and access the spatial anchor, and customer premise information (e.g. a residence, office, or shop) . The spatial anchor creation request may also include spatial anchor discoverable visibility levels like universal to facilitate shared spatial anchor discovery. The universal discoverable visibility level defines the spatial anchor is discoverable for any user. In some example embodiments, the spatial anchor creation request may include more or less information than described above.
[0067] If the access token is validated at the spatial anchor management server 308, the spatial anchor management server 308 may create at 314 the spatial anchor and store the information received in the spatial anchor creation request. The spatial anchor management server 308 may create identity (ID) for the spatial anchor. At 316, the spatial anchor management server 308 may send a spatial anchor creation response including the spatial anchor ID to the first spatial anchor management node 302.
[0068] At 318, the second spatial anchor management node 304 (or a service provider owning the second spatial anchor management node 304) may discover the spatial anchor created by the first spatial anchor management node 302. Consider the shopping mall example, where a restaurant service provider (e.g., KFC) with a headset or UE receiving the metaverse application service may discover the spatial anchor created by the shopping mall owner if the spatial anchor visibility level is marked as discoverable for all users during the creation process. In an example, the second spatial anchor management node 304 may get details of the spatial anchor from the spatial anchor management server 308. Then the restaurant service provider may decide to add its service information to the spatial anchor.
[0069] At 320, the second spatial anchor management node 304 may send an authorization request to the spatial anchor owner, i.e., the first spatial anchor management node 302 in the example. The authorization request may indicate to the first spatial anchor management node 302 that the second spatial anchor management node 304 wants to perform a management operation e.g., one or more of CRUD operations on the spatial anchor owned by the first spatial anchor management node 302. The authorization request may include identity of the second spatial anchor management node 304 (source ID) , identity of the first spatial anchor management node 302 (destination ID) , the spatial anchor ID, and an API name that the second spatial anchor management node 304 requests to invoke for the spatial anchor management operation. For example, the second spatial anchor management node 304 may invoke the API to create / add a new service in the spatial anchor, update a service in the spatial anchor, retrieve a service in the spatial anchor, or delete a service in the spatial anchor. The authorization request may also include service information to be managed in the spatial anchor by the second spatial anchor management node 304. For example, the service information may indicate name or ID of the service provider, VAL service ID, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc. The authorization request may also include any other information relating to the service to be created / retrieved / updated / deleted in the spatial anchor.
[0070] The first spatial anchor management node 302 (the shopping mall owner) may check if the second spatial anchor management node 304 (the service provider e.g., KFC) is authorized for the requested spatial anchor management service and validate the authorization request at 322. In an example, the first spatial anchor management node 302 may pop up a window showing content of the authorization request to the human owner. The human owner may click on an accept button or a rejection button in the window to accept or reject the authorization request. The first spatial anchor management node 302 may validate the authorization request based on the human owner’s input. In another example, the first spatial anchor management node 302 may maintain a list of service providers that are allowed to manage the spatial anchor. The list may also include information of management operations that the service providers are permitted to perform on the spatial anchor. In an example, the list may also include service information e.g., service position, service type, VAL service ID or the like that are permitted to be added and managed in the spatial anchor. The first spatial anchor management node 302 may check the list to determine whether to approve or refuse the authorization request.
[0071] If the authorization request is successfully validated, the first spatial anchor management node 302 may generate an authorization token for the second spatial anchor management node 304 and transmit the authorization token in an authorization request response message to the second spatial anchor management node 304 at 324. In an example, the authorization token may include the identity of the second spatial anchor management node 304 (the source ID) , the identity of the first spatial anchor management node 302 (the destination ID) , the spatial anchor ID, the spatial anchor management operation or the API name authorized for the second spatial anchor management node 304 to perform or invoke, and the service information that the second spatial anchor management node 304 is authorized to manage in the spatial anchor. For example, the service information may include name or ID of the service provider, VAL service ID, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc. The authorization token may also include additional information e.g., expiry time of the token. The authorization token may have a format understandable by the authentication and authorization node 306. The first spatial anchor management node 302 may sign the authorization token with the private key which was established when the first spatial anchor management node 302 was onboarded / registered with the authentication and authorization node 306.
[0072] After receiving the authorization token from the first spatial anchor management node 302, the second spatial anchor management node 304 may send an access token request along with the authorization token to the authentication and authorization node 306 at 326. The access token request may indicate the identity of the second spatial anchor management node 304 (the API invoker / spatial anchor management client) , the identity of the first spatial anchor management node 302 (the spatial anchor owner) , and the spatial anchor ID. The access token request may include a scope field indicating the requested scope from the access token request. For example, the scope field may indicate the spatial anchor management operation (e.g., one or more of CRUD operations) or the API requested to perform / invoke. The access token request may also include the service information requested to be managed in the spatial anchor. For example, the service information may indicate name or ID of the service provider, VAL service ID, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc. It is worth noting that the above information included in the access token request should be identical to or consistent with that included in the authorization token received from the first spatial anchor management node 302.
[0073] At 328, the authentication and authorization node 306 may validate the authorization token and the access token request received from the second spatial anchor management node 304. As mentioned above, the authorization token is signed with the private key of the first spatial anchor management node 302. The authentication and authorization node 306 may verify the signature of the authorization token using the public key of the first spatial anchor management node 302 stored at the authentication and authorization node 306. The private-public key pair was established during the onboarding / registration phase of the first spatial anchor management node 302 with the authentication and authorization node 306. If the verification is successful, the authentication and authorization node 306 may validate the access token request by comparing it with content of the authorization token. If the information included in the access token request is identical to or consistent with the information included in the authorization token, the access token request is successfully validated. If the information included in the access token request is different from the information included in the authorization token, for example, if the spatial anchor management operation indicated in the access token request is different from that authorized in the authorization token, the validation is failed.
[0074] If the validation at 322 is successful, the authentication and authorization node 306 may generate an enhanced access token for the second spatial anchor management node 304 and send the enhanced access token to the second spatial anchor management node 304 at 330. The enhanced access token may include information of the entity issuing the token (the authentication and authorization node 306 in the example, e.g., CCF or SIM-S) , the authorization scope associated with the token (e.g., the spatial anchor management operation or the API allowed to perform / invoke) , the entity to which the token is issued (the second spatial anchor management node 304 in the example) , the expiry time of the token, and the like. Compared with a legacy access token, the enhanced access token may further contain service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor. For example, the service information may indicate the spatial anchor ID, the spatial anchor owner (the first spatial anchor management node 302 in the example) , the service provider name or ID, VAL service ID, service position, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc. In this way, a strict security policy may be enforced to ensure that the service providers can be authorized to manage their own service in the spatial anchor, and the service providers cannot alter other service providers’ service information in the spatial anchor.
[0075] After receiving the enhanced access token, the second spatial anchor management node 304 may send a request for performing a spatial anchor management operation along with the enhanced access token to the spatial anchor management server 308 at 332. The spatial anchor management request may indicate the requested spatial anchor management operation (e.g., one or more of CRUD operations) and service information relating to the spatial anchor management operation (i.e., service information to be created / retrieved / updated / deleted in the spatial anchor) . The spatial anchor management server 308 may validate the enhanced access token and the spatial anchor management request. Upon successful validation, the spatial anchor management server 308 may carry out the requested spatial anchor management operation at 334.
[0076] If the spatial anchor management operation is successfully carried out at 334, the spatial anchor management server 308 may send a spatial anchor management response to the second spatial anchor management node 304 at 336 indicating the successful completion of the spatial anchor management operation. If the spatial anchor management server 308 fails to carry out the spatial anchor management operation at 334, the spatial anchor management server 308 may include failure cause in the spatial anchor management response sent to the second spatial anchor management node 304.
[0077] In the example procedure 300 discussed above, before invoking the API to perform the spatial anchor management operation on the spatial anchor with regard to the service information, the second spatial anchor management node 304 obtains the authorization token from the first spatial anchor management node 302 who owns the spatial anchor and the enhanced access token from the authentication and authorization node 306. The authorization token and the enhanced access token each can restrict the spatial anchor management operations that the second spatial anchor management node 304 is authorized to perform on the spatial anchor. In addition, the authorization token and the enhanced access token each contain the service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor. In this way, a strict security policy may be enforced in the spatial anchor management service to ensure secure and reliable spatial anchor management operations by multiple service providers either owning or not owning the spatial anchor. For example, service providers can be permitted / prevented to perform particular operations on the spatial anchor owned by another service provider for their services, and one application service provider cannot alter other application service providers’ service information in the spatial anchor.
[0078] Fig. 4 illustrates an example procedure 400 for managing a spatial anchor according to example embodiments of the present disclosure. The procedure 400 may be also performed at the first spatial anchor (SA) management node 302, the second spatial anchor management node 304, the authentication and authorization node 306, and the spatial anchor management server 308. Some operations in the procedure 400 may be similar to those in the procedure 300 and such operations will be described below in a simple way.
[0079] Referring to Fig. 4, at 410, the first spatial anchor management node 302 is authenticated with the authentication and authorization node 306 and receives an access token for creation of a spatial anchor from the authentication and authorization node 306. Then the first spatial anchor management node 302 may send a spatial anchor creation request along with the access token to the spatial anchor management server 308 at 412. The spatial anchor creation request may include identity of the first spatial anchor management node 302, position of the anchor and vertical application service identifier, spatial anchor service area, service information to be associated with the spatial anchor, access control rules defining which entities are permitted to discover and access the spatial anchor, and customer premise information (e.g. a residence, office, or shop) . The spatial anchor creation request may also include spatial anchor discoverable visibility levels like universal to facilitate shared spatial anchor discovery. The universal discoverable visibility level defines the spatial anchor is discoverable for any user.
[0080] In an example, the first spatial anchor management node 302 may preconfigure an authorization policy (ies) for the spatial anchor requested to be created. The preconfigured authorization policy may specify which service providers are authorized to perform which operations on the spatial anchor. For example, the authorization policy may indicate one or more nodes, entities or functions (i.e., service providers) that are authorized to manage the spatial anchor. Optionally, the authorization policy may also specify a scope of spatial anchor management operations permitted for respective nodes, entities or functions to perform on the spatial anchor, and service information permitted for respective nodes, entities or functions to manage in the spatial anchor. For example, the shopping mall owner may request to create a spatial anchor representing restaurant and permit restaurant service providers such as KFC, Pizza Hut, Mc-Donalds in the shopping mall to add their services in the spatial anchor. Alternatively or additionally, the authorization policy may indicate one or more nodes, entities or functions (i.e., service providers) that are not permitted to manage the spatial anchor. The first spatial anchor management node 302 may include the preconfigured authorization policy in the spatial anchor creation request sent to the spatial anchor management server 308.
[0081] The spatial anchor management server 308 may validate the spatial anchor creation request and the access token and create the spatial anchor at 414. The spatial anchor management server 308 may create identity (ID) for the spatial anchor. Upon successful creation of the spatial anchor, the spatial anchor management server 308 may store the information received in the spatial anchor creation request and send a spatial anchor creation response including the spatial anchor ID to the first spatial anchor management node 302 at 416.
[0082] At 418, the spatial anchor management server 308 may provide information of the spatial anchor, including for example the spatial anchor ID, information of the spatial anchor owner, and the preconfigured authorization policy, to the authentication and authorization node 306. In another example, the first spatial anchor management node 302 may provide the spatial anchor information, including the spatial anchor ID, the spatial anchor owner information, and the preconfigured authorization policy, to the authentication and authorization node 306 at 420, and the operation 418 may be omitted. If the spatial anchor information including the authorization policy is provided from the first spatial anchor management node 302 to the authentication and authorization node 306, the first spatial anchor management node 302 may not provide the authorization policy in the spatial anchor creation request to the spatial anchor management server 308.
[0083] At 422, the authentication and authorization node 306 may update a profile of the first spatial anchor management node 302 stored at the authentication and authorization node 306 with the spatial anchor information including the authorization policy.
[0084] At 424, the second spatial anchor management node 304 (or a service provider owning the second spatial anchor management node 304) may discover the spatial anchor created by the first spatial anchor management node 302 and know about the service information associated with the spatial anchor, including for example position, service type, service description and the like. In an example, the second spatial anchor management node 304 may get details of the spatial anchor from the spatial anchor management server 308. The second spatial anchor management node 304 may or may not know about the owner of the spatial anchor (the first spatial anchor management node 302 or the service provider owning it) . Based on the service information associated with the spatial anchor, the second spatial anchor management node 304 (i.e., the service provider) may decide to add its service information to the spatial anchor.
[0085] At 426, the second spatial anchor management node 304 may send an access token request to the authentication and authorization node 306. The access token request may indicate identity of the second spatial anchor management node 304 (the API invoker / spatial anchor management client) , the spatial anchor ID, and optionally identity of the spatial anchor owner (the first spatial anchor management node 302 or the service provider owning it) if the second spatial anchor management node 304 knows about it. The access token request may include a scope field indicating the requested scope from the access token request. For example, the scope field may indicate the spatial anchor management operation (e.g., one or more of CRUD operations) or the API requested to perform / invoke. The access token request may also include the service information requested to be managed in the spatial anchor. For example, the service information may indicate name or ID of the service provider, VAL service ID, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc.
[0086] When the authentication and authorization node 306 receives the access token request, the authentication and authorization node 306 may retrieve the authorization policy present in the profile of the first spatial anchor management node 302 (the spatial anchor owner) and validate the access token request based on the authorization policy at 428. The authentication and authorization node 306 may maintain a mapping between the spatial anchors and their owners. If the access token request received from the second spatial anchor management node 304 does not indicate the spatial anchor owner, the authentication and authorization node 306 may retrieve the spatial anchor owner from the mapping based on the spatial anchor ID. Then the authentication and authorization node 306 may retrieve the spatial anchor owner’s profile and obtain the authorization policy preconfigured for the spatial anchor. If the authorization policy indicates that the second spatial anchor management node 304 is permitted to carry out the spatial anchor management operation on the spatial anchor with regard to the service information indicated in the access token request, the access token request is successfully validated, and the authentication and authorization node 306 may generate an enhanced access token for the second spatial anchor management node 304 and send the enhanced access token to the second spatial anchor management node 304 at 430. The enhanced access token may include information of the entity issuing the token (the authentication and authorization node 306 in the example, e.g., CCF or SIM-S) , the authorization scope associated with the token (e.g., the spatial anchor management operation or the API authorized to perform / invoke) , the entity to which the token is issued (the second spatial anchor management node 304 in the example) , the expiry time of the token, and the like. Compared with a legacy access token, the enhanced access token may further contain service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor. For example, the service information may indicate the spatial anchor ID, the spatial anchor owner (the first spatial anchor management node 302 in the example) , the service provider name or ID, VAL service ID, service position, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc.
[0087] After receiving the enhanced access token, the second spatial anchor management node 304 may send a request for performing a spatial anchor management operation along with the enhanced access token to the spatial anchor management server 308 at 432. The spatial anchor management request may indicate the requested spatial anchor management operation (e.g., one or more of CRUD operations) and service information relating to the spatial anchor management operation (i.e., service information to be created / retrieved / updated / deleted in the spatial anchor) . The spatial anchor management server 308 may validate the enhanced access token and the spatial anchor management request. Upon successful validation, the spatial anchor management server 308 may carry out the requested spatial anchor management operation at 434. For example, the spatial anchor management server 308 may create / retrieve / update / delete the service information indicated in the spatial anchor management request in the spatial anchor.
[0088] If the spatial anchor management operation is successfully carried out at 434, the spatial anchor management server 308 may send a spatial anchor management response to the second spatial anchor management node 304 at 436 indicating the successful completion of the spatial anchor management operation. If the spatial anchor management server 308 fails to carry out the spatial anchor management operation at 434, the spatial anchor management server 308 may include failure cause in the spatial anchor management response sent to the second spatial anchor management node 304.
[0089] In the example procedure 400 discussed above, the spatial anchor owner preconfigures the authorization policy for the spatial anchor at the authentication and authorization node 306. Then other service providers do not need to request the spatial anchor owner to issue an authorization token for each management operation on the spatial anchor. The other service providers can send the access token request without the authorization token to the authentication and authorization node 306, and the authentication and authorization node 306 can validate the access token request based on the authorization policy preconfigured for the spatial anchor. The procedure 400 can reduce the signaling overhead of the system.
[0090] Fig. 5 illustrates an example procedure 500 for managing a spatial anchor according to example embodiments of the present disclosure. The procedure 500 may be also performed at the first spatial anchor (SA) management node 302, the second spatial anchor management node 304, the authentication and authorization node 306, and the spatial anchor management server 308. The procedure 500 includes some operations similar to those in the procedure 400 discussed above with reference to Fig. 4. Below the description of the procedure 500 will focus on the different operations, and the similar operations will be described in a simple manner.
[0091] Referring to Fig. 5, at 510, the first spatial anchor management node 302 may register a callback uniform resource identifier (URI) with the authentication and authorization node 306. In an example, the first spatial anchor management node 302 may register the callback URI during or after onboarding with the authentication and authorization node 306. The callback URI is a string that designates a specific address where information can be sent to the first spatial anchor management node 302. For example, the authentication and authorization node 306 can write information in the callback URI, and the first spatial anchor management node 302 will receive the information. In another example, the authentication and authorization node 306 may send information to the first spatial anchor management node 302 in other ways, and the operation 510 may be omitted.
[0092] At 512, the first spatial anchor management node 302 is authenticated with the authentication and authorization node 306 and receives an access token for creation of a spatial anchor from the authentication and authorization node 306. Then the first spatial anchor management node 302 may send a spatial anchor creation request including a preconfigured authorization policy (ies) , along with the access token, to the spatial anchor management server 308 at 514. In this example, the authorization policy may specify that an explicit authorization from the spatial anchor owner is required for other service providers to perform management operations on the spatial anchor.
[0093] The spatial anchor management server 308 may validate the spatial anchor creation request and the access token and create the spatial anchor at 516. The spatial anchor management server 308 may create identity (ID) for the spatial anchor. Upon successful creation of the spatial anchor, the spatial anchor management server 308 may store the information received in the spatial anchor creation request and send a spatial anchor creation response including the spatial anchor ID to the first spatial anchor management node 302 at 518.
[0094] At 520, the spatial anchor management server 308 may provide information of the spatial anchor, including for example the spatial anchor ID, information of the spatial anchor owner, and the preconfigured authorization policy, to the authentication and authorization node 306. In another example, the first spatial anchor management node 302 may provide the spatial anchor information to the authentication and authorization node 306 at 522, and the operation 520 may be omitted. In this case, the first spatial anchor management node 302 may not provide the authorization policy in the spatial anchor creation request to the spatial anchor management server 308. At 524, the authentication and authorization node 306 may update a profile of the first spatial anchor management node 302 stored at the authentication and authorization node 306 with the spatial anchor information including the authorization policy.
[0095] The second spatial anchor management node 304 (or a service provider owning the second spatial anchor management node 304) may discover the spatial anchor created by the first spatial anchor management node 302 and know about the service information associated with the spatial anchor, including for example position, service type, service description and the like at 526. In an example, the second spatial anchor management node 304 may get details of the spatial anchor from the spatial anchor management server 308. The second spatial anchor management node 304 may or may not know about the owner of the spatial anchor (the first spatial anchor management node 302 or the service provider owning it) . Based on the service information associated with the spatial anchor, the second spatial anchor management node 304 (i.e., the service provider) may decide to add its service information to the spatial anchor.
[0096] At 528, the second spatial anchor management node 304 may send an access token request to the authentication and authorization node 306. The access token request may indicate identity of the second spatial anchor management node 304 (the API invoker / spatial anchor management client) , the spatial anchor ID, and optionally identity of the spatial anchor owner (the first spatial anchor management node 302 or the service provider owning it) if the second spatial anchor management node 304 knows about it. The access token request may include a scope field indicating the requested scope from the access token request. For example, the scope field may indicate the spatial anchor management operation (e.g., one or more of CRUD operations) or the API requested to perform / invoke. The access token request may also include the service information requested to be managed in the spatial anchor. For example, the service information may indicate name or ID of the service provider, VAL service ID, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc.
[0097] In response to the access token request, the authentication and authorization node 306 may retrieve and check the authorization policy present in the profile of the first spatial anchor management node 302 (the spatial anchor owner) at 530. The authentication and authorization node 306 may maintain a mapping between the spatial anchors and their owners. If the access token request received from the second spatial anchor management node 304 does not indicate the spatial anchor owner, the authentication and authorization node 306 may retrieve the spatial anchor owner from the mapping based on the spatial anchor ID. Then the authentication and authorization node 306 may retrieve the spatial anchor owner’s profile and obtain the authorization policy preconfigured for the spatial anchor. In the example, the authorization policy indicates that an explicit authorization from the spatial anchor owner is required for other service providers to perform management operations on the spatial anchor. Then the authentication and authorization node 306 decides to request an authorization from the first spatial anchor management node 302 (the spatial anchor owner) for the second spatial anchor management node 304.
[0098] At 532, the authentication and authorization node 306 may send a notification about an authorization request to the first spatial anchor management node 302. If the first spatial anchor management node 302 has registered the callback URI with the authentication and authorization node 306, the authentication and authorization node 306 may write the authorization request in the callback URI. If the first spatial anchor management node 302 has not yet registered any callback URI with the authentication and authorization node 306, the authentication and authorization node 306 may send an authorization request message in other ways to the first spatial anchor management node 302. The authorization request may include identity of the second spatial anchor management node 304 (source ID) , the spatial anchor ID, and information of the management operation (e.g., one or more of CRUD operations) or API that the second spatial anchor management node 304 requests to perform or invoke on the spatial anchor. The authorization request may also include service information to be managed in the spatial anchor by the second spatial anchor management node 304. For example, the service information may indicate name or ID of the service provider, VAL service ID, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc.
[0099] Upon receiving the notification about the authorization request, the first spatial anchor management node 302 (the shopping mall owner) may validate the authorization request at 534. The first spatial anchor management node 302 may check if the second spatial anchor management node 304 is authorized for the requested spatial anchor management operation with regard to the service information offered by it. In an example, the first spatial anchor management node 302 may maintain a list of service providers that are allowed to manage the spatial anchor. The list may also include information of management operations that the service providers are permitted to perform on the spatial anchor. In an example, the list may also include service information e.g., VAL service ID, service position, service type or the like that the service providers are permitted to manage in the spatial anchor. The first spatial anchor management node 302 may check the list to determine whether to approve or refuse the authorization request. In another example, the first spatial anchor management node 302 may pop up a window showing the notification to the human owner. The human owner may click on an accept button or a rejection button to accept or reject the authorization request. The first spatial anchor management node 302 may validate the authorization request based on the human owner’s input.
[0100] If the authorization request is successfully validated at 534, the first spatial anchor management node 302 may send an authorization response to the authentication and authorization node 306 at 536 indicating an authorization for the second spatial anchor management node 304. If the validation is failed, the first spatial anchor management node 302 may send an authorization rejection message indicating a failure cause to the authentication and authorization node 306 at 536.
[0101] In case the second spatial anchor management node 304 is successfully authorized, the authentication and authorization node 306 may generate an enhanced access token for the second spatial anchor management node 304 and send the enhanced access token to the second spatial anchor management node 304 at 538. The enhanced access token may include information of the entity issuing the token (the authentication and authorization node 306 in the example, e.g., CCF or SIM-S) , the authorization scope associated with the token (e.g., the spatial anchor management operation or the API authorized to perform / invoke) , the entity to which the token is issued (the second spatial anchor management node 304 in the example) , the expiry time of the token, and the like. Compared with a legacy access token, the enhanced access token may further contain service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor. For example, the service information may indicate the spatial anchor ID, the spatial anchor owner (the first spatial anchor management node 302 in the example) , the service provider name or ID, VAL service ID, service position, service type (e.g., sport, food, book, etc. ) , physical or internet service (website for the internet service) , service provider contact details, service timing, service description, etc.
[0102] After receiving the enhanced access token, the second spatial anchor management node 304 may send a request for performing a spatial anchor management operation along with the enhanced access token to the spatial anchor management server 308 at 540. The spatial anchor management request may indicate the requested spatial anchor management operation (e.g., one or more of CRUD operations) and service information relating to the spatial anchor management operation (i.e., service information to be created / retrieved / updated / deleted in the spatial anchor) . The spatial anchor management server 308 may validate the enhanced access token and the spatial anchor management request. Upon successful validation, the spatial anchor management server 308 may carry out the requested spatial anchor management operation at 542. For example, the spatial anchor management server 308 may create / retrieve / update / delete the service information indicated in the spatial anchor management request in the spatial anchor.
[0103] If the spatial anchor management operation is successfully carried out at 542, the spatial anchor management server 308 may send a spatial anchor management response to the second spatial anchor management node 304 at 544 indicating the successful completion of the spatial anchor management operation. If the spatial anchor management server 308 fails to carry out the spatial anchor management operation at 542, the spatial anchor management server 308 may include failure cause in the spatial anchor management response sent to the second spatial anchor management node 304.
[0104] In the example procedure 500 discussed above, the authorization policy preconfigured for the spatial anchor indicates that an explicit authorization from the spatial anchor owner is needed, hence the authentication and authorization node 306 requests the authorization from the spatial anchor owner before issuing an access token to other service providers. In an example, the spatial anchor may have multiple “owners” . For example, the spatial anchor may include service information from multiple service providers. When another service provider not owning the spatial anchor discovers the spatial anchor and want to add its service information in the spatial anchor, the authentication and authorization node 306 may request authorization from each of the multiple “owners” before issuing an access token to the service provider not owning the spatial anchor. In an example, the authorization policy preconfigured for the spatial anchor may be omitted, and the authentication and authorization node 306 may request authorization from the spatial anchor owner regardless which spatial anchor is requested for the management service.
[0105] Fig. 6 illustrates a method 600 according to example embodiments of the present disclosure. The method 600 may be carried out at a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above. In an example, the first spatial anchor management node 302 may be implemented with a VAL server or a SEAL client to carry out the method 600.
[0106] At the beginning of the method 600, it is assumed that the first spatial anchor management node 302 has created a spatial anchor with a spatial anchor management server e.g., the spatial anchor management server 308 discussed above. At 610, the first spatial anchor management node 302 may receive an authorization request from a second spatial anchor management node, e.g., the second spatial anchor management node 304 discussed above. The authorization request may indicate that the second spatial anchor management node 304 requests to perform a spatial anchor management operation on the spatial anchor owned by the first spatial anchor management node 302 with regard to a service provided by the second spatial anchor management node 304. The spatial anchor management operation may comprise for example creating / adding a service in the spatial anchor, retrieving a service in the spatial anchor, updating a service in the spatial anchor, or deleting a service in the spatial anchor. In an example, the authorization request may comprise information of an application programming interface (API) that is requested to be invoked by the second spatial anchor management node 304 for performing the spatial anchor management operation. Alternatively or additionally, the authorization request may comprise information of the service provided by the second spatial anchor management node 304 which is requested to be managed in the spatial anchor.
[0107] The first spatial anchor management node 302 may validate the authorization request received from the second spatial anchor management node 304 at 620.
[0108] If the authorization request is successfully validated, the first spatial anchor management node 302 may issue an authorization token to the second spatial anchor management node 304. The authorization token may indicate that the second spatial anchor management node 304 is authorized to perform the requested spatial anchor management operation on the spatial anchor owned by the first spatial anchor management node 302. In an example, the authorization token may be signed with a private key of the first spatial anchor management node 302. The private key may be established during onboarding / registration of the first spatial anchor management node 302 with an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above.
[0109] Fig. 7 illustrates an apparatus 700 according to example embodiments of the present disclosure. The apparatus 700 may be implemented at a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above, to carry out the method 600 discussed above with reference to Fig. 6. As shown in Fig. 7, the apparatus 700 may comprise a means 710 for performing the operation 610 in the method 600, a means 720 for performing the operation 620 in the method 600, and a means 730 for performing the operation 630 in the method 600. The means 710-730 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 610-630 in the method 600. Since the operations 610-630 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0110] Fig. 8 illustrates a method 800 according to example embodiments of the present disclosure. The method 800 may be carried out at a spatial anchor management client, e.g., the second spatial anchor management node 304 discussed above. In an example, the second spatial anchor management node 304 may be implemented with a VAL server or a SEAL client to carry out the method 800.
[0111] At the beginning of the method 800, it is assumed that the second spatial anchor management node 304 (the service provider, e.g., KFC) discovers a spatial anchor owned by another service provider e.g., the first spatial anchor management node 302 discussed above (e.g., the shopping mall owner) . The second spatial anchor management node 304 may get details of the spatial anchor from a spatial anchor management server, e.g., the spatial anchor management server 308 discussed above. For example, the spatial anchor represents restaurant services provided at the shopping mall. The second spatial anchor management node 304 decides to add its service information to the spatial anchor.
[0112] At 810, the second spatial anchor management node 304 may send an authorization request to the first spatial anchor management node 302 (the spatial anchor owner) . The authorization request may indicate that the second spatial anchor management node 304 requests to perform a spatial anchor management operation, e.g., one or more of CRUD operations, on the spatial anchor owned by the first spatial anchor management node 302 with regard to the service provided by the second spatial anchor management node 304. In an example, the authorization request may comprise information of an application programming interface (API) that is requested to be invoked by the second spatial anchor management node 304 for performing the spatial anchor management operation. Alternatively or additionally, the authorization request may comprise information of the service provided by the second spatial anchor management node 304 which is requested to be managed in the spatial anchor.
[0113] At 820, the second spatial anchor management node 304 may receive an authorization token from the first spatial anchor management node 302. The authorization token may comprise information of the spatial anchor management operation or the API that is authorized for the second spatial anchor management node 304 to perform or invoke. The authorization token may also comprise information of the service that is authorized for the second spatial anchor management node 304 to manage in the spatial anchor.
[0114] At 830, the second spatial anchor management node 304 may send the authorization token along with an access token request to an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above. The access token request may comprise, among others, information of the spatial anchor management operation (e.g., one or more of CRUD operations) that is requested to be performed on the spatial anchor, and the service information offered by the second spatial anchor management node 304 requested to be managed in the spatial anchor by the spatial anchor management operation.
[0115] At 840, the second spatial anchor management node 304 may receive an enhanced access token for the spatial anchor from the authentication and authorization node 306. The enhanced access token may comprise, among others, information of the spatial anchor management operation that is permitted to be performed on the spatial anchor, and the service information that is permitted to be managed in the spatial anchor.
[0116] At 850, the second spatial anchor management node 304 may send a request for performing the spatial anchor management operation on the spatial anchor with regard to the service information along with the enhanced access token to the spatial anchor management server 308. Then the second spatial anchor management node 304 may receive a response message from the spatial anchor management server 308 indicating whether the spatial anchor management operation is successfully performed on the spatial anchor.
[0117] Fig. 9 illustrates an apparatus 900 according to example embodiments of the present disclosure. The apparatus 900 may be implemented at a spatial anchor management client, e.g., the second spatial anchor management node 304 discussed above, to carry out the method 800 discussed above with reference to Fig. 8. As shown in Fig. 9, the apparatus 900 may comprise a means 910 for performing the operation 810 in the method 800, a means 920 for performing the operation 820 in the method 800, a means 930 for performing the operation 830 in the method 800, a means 940 for performing the operation 840 in the method 800, and a means 950 for performing the operation 850 in the method 800. The means 910-950 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 810-850 in the method 800. Since the operations 810-850 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0118] Fig. 10 illustrates a method 1000 according to example embodiments of the present disclosure. The method 1000 may be carried out at an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above. In an example, the second spatial anchor management node 304 may be implemented with a CAPIF core function (CCF) or a SEAL identity management server (SIM-S) to carry out the method 1000.
[0119] As shown in Fig. 10, at 1010, the authentication and authorization node 306 may receive an access token request along with an authorization token from a spatial anchor management client, e.g., the second spatial anchor management node 304 discussed above. The access token request may indicate that the second spatial anchor management node 304 requests to perform a management operation (e.g., one or more of CRUD operations) on a spatial anchor created by another spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above. The access token request may also indicate service information offered by the second spatial anchor management node 304, which is requested to be managed in the spatial anchor. The authorization token may be issued by the first spatial anchor management node 302 and signed with a private key of the first spatial anchor management node 302. The private key may be established when the first spatial anchor management node 302 is onboarded / registered with the authentication and authorization node 306. The authorization token may contain information of the spatial anchor management operation (e.g., one or more of CRUD operations) or an API for performing the spatial anchor management operation that is authorized to the second spatial anchor management node 304, and information of the service offered by the second spatial anchor management node 304 that is authorized for the second spatial anchor management node 304 to manage in the spatial anchor.
[0120] The authentication and authorization node 306 may validate the authorization token and the access token request at 1020. The authentication and authorization node 306 may verify the signature of the authorization token using a public key of the first spatial anchor management node 302 stored at the authentication and authorization node 306. The public key may be established when the first spatial anchor management node 302 was onboarded / registered with the authentication and authorization node 306. If the verification is successful, the authentication and authorization node 306 may verify the access token request by comparing it with content of the authorization token. If the requested management operation and related service information indicated in the access token request is identical to or consistent with those indicated in the authorization token, the access token request is successfully verified.
[0121] In case the authorization token and the access token request are successfully validated, the authentication and authorization node 306 may send an enhanced access token to the second spatial anchor management node 304 at 1030. The enhanced access token may contain information of the spatial anchor management operation (e.g., one or more of CRUD operations) that the second spatial anchor management node 304 is permitted to perform on the spatial anchor owned by the first spatial anchor management node 302, and the service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor.
[0122] Fig. 11 illustrates an apparatus 1100 according to example embodiments of the present disclosure. The apparatus 1100 may be implemented at an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above, to carry out the method 1000 discussed above with reference to Fig. 10. As shown in Fig. 11, the apparatus 1100 may comprise a means 1110 for performing the operation 1010 in the method 1000, a means 1120 for performing the operation 1020 in the method 1000, and a means 1130 for performing the operation 1030 in the method 1000. The means 1010-1030 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 1010-1030 in the method 1000. Since the operations 1010-1030 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0123] Fig. 12 illustrates a method 1200 according to example embodiments of the present disclosure. The method 1200 may be carried out at a spatial anchor management server, e.g., the spatial anchor management server 308 discussed above. In an example, the spatial anchor management server 308 may be implemented with a SEAL server or a spatial anchor management network function (SAMNF) to carry out the method 1200.
[0124] As shown in Fig. 12, at 1210, the spatial anchor management server 308 may receive a spatial anchor creation request from a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above. The spatial anchor creation request may comprise an authorization policy preconfigured for the spatial anchor requested to create. In an example, the preconfigured authorization policy may indicate one or more nodes, entities or functions that are authorized to manage the spatial anchor. Optionally, the authorization policy may also define a scope of spatial anchor management operations that the one or more nodes, entities or functions are permitted to perform on the spatial anchor, and / or information of services that the one or more nodes, entities or functions are permitted to manage in the spatial anchor. In another example, the authorization policy may simply indicate that an explicit authorization from the spatial anchor owner (the first spatial anchor management node 302 in the example) is needed before other service providers perform a management operation on the spatial anchor.
[0125] In response to the spatial anchor creation request, the spatial anchor management server 308 may create the spatial anchor and assign an ID to the spatial anchor at 1220. Then the spatial anchor management server 308 may send information of the spatial anchor including the spatial anchor ID to the first spatial anchor management node 302 at 1230. The spatial anchor management server 308 may send the spatial anchor information in a spatial anchor creation response message to the first spatial anchor management node 302.
[0126] At 1240, the spatial anchor management server 308 may provide the spatial anchor information and the authorization policy preconfigured for the spatial anchor to an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above.
[0127] Fig. 13 illustrates an apparatus 1300 according to example embodiments of the present disclosure. The apparatus 1300 may be implemented at a spatial anchor management server, e.g., the spatial anchor management server 308 discussed above, to carry out the method 1200 discussed above with reference to Fig. 12. As shown in Fig. 13, the apparatus 1300 may comprise a means 1310 for performing the operation 1210 in the method 1200, a means 1320 for performing the operation 1220 in the method 1200, a means 1330 for performing the operation 1230 in the method 1200, and a means 1340 for performing the operation 1240 in the method 1200. The means 1310-1340 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 1210-1240 in the method 1200. Since the operations 1210-1240 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0128] Fig. 14 illustrates a method 1400 according to example embodiments of the present disclosure. The method 1400 may be carried out at a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above. In an example, the first spatial anchor management node 302 may be implemented with a VAL server or a SEAL client to carry out the method 1400.
[0129] As shown in Fig. 14, at 1410, the first spatial anchor management node 302 may send a spatial anchor creation request to a spatial anchor management server, e.g., the spatial anchor management server 308 discussed above. The spatial anchor creation request may comprise an authorization policy preconfigured for the spatial anchor requested to create. In an example, the preconfigured authorization policy may indicate one or more nodes, entities or functions that are authorized to manage the spatial anchor. Optionally, the authorization policy may also define a scope of spatial anchor management operations that the one or more nodes, entities or functions are permitted to perform on the spatial anchor, and / or information of services that the one or more nodes, entities or functions are permitted to manage in the spatial anchor. In another example, the authorization policy may simply indicate that an explicit authorization from the spatial anchor owner (the first spatial anchor management node 302 in the example) is needed before other service providers perform a management operation on the spatial anchor.
[0130] At 1420, the first spatial anchor management node 302 may receive a spatial anchor creation response from the spatial anchor management server 308. The spatial anchor creation response may indicate whether the spatial anchor is successfully created. If the spatial anchor is successfully created, the spatial anchor creation response may also contain information of the spatial anchor, including a spatial anchor ID.
[0131] If the authorization policy preconfigured for the spatial anchor indicates that an explicit authorization from the spatial anchor owner is needed before other service providers perform a management operation on the spatial anchor, the first spatial anchor management node 302 may receive a notification about an authorization request from an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above at 1430. In an example, the notification about the authorization request may be received via a callback URI that the first spatial anchor management node 302 registered with the authentication and authorization node 306. For example, the first spatial anchor management node 302 may register the callback URI during onboarding with the authentication and authorization node 306. In another example, the notification may be received via an authorization request message transmitted by the authentication and authorization node 306. The authorization request may indicate that a second spatial anchor management node, e.g., the second spatial anchor management node 304 discussed above, requests an authorization to perform a spatial anchor management operation on the spatial anchor with regard to a service offered by the second spatial anchor management node 304.
[0132] The first spatial anchor management node 302 may validate the authorization request in the notification at 1440. If the validation is successful, the first spatial anchor management node 302 may send an authorization response to the authentication and authorization node 306 at 1450 indicating that the second spatial anchor management node 304 is authorized to perform the requested spatial anchor management operation on the spatial anchor with regard to the service offered by it. If the validation is failed, the first spatial anchor management node 302 may indicate a failure cause in the authorization response.
[0133] Fig. 15 illustrates an apparatus 1500 according to example embodiments of the present disclosure. The apparatus 1500 may be implemented at a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above, to carry out the method 1400 discussed above with reference to Fig. 14. As shown in Fig. 15, the apparatus 1500 may comprise a means 1510 for performing the operation 1410 in the method 1400, and a means 1520 for performing the operation 1420 in the method 1400. In an example, the apparatus 1500 may optionally comprise a means 1530 for performing the operation 1430 in the method 1400, a means 1540 for performing the operation 1440 in the method 1400, and a means 1550 for performing the operation 1450 in the method 1400. The means 1510-1550 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 1410-1450 in the method 1400. Since the operations 1410-1450 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0134] Fig. 16 illustrates a method 1600 according to example embodiments of the present disclosure. The method 1600 may be carried out at a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above. In an example, the first spatial anchor management node 302 may be implemented with a VAL server or a SEAL client to carry out the method 1600.
[0135] As shown in Fig. 16, at 1610, the first spatial anchor management node 302 may send a spatial anchor creation request to a spatial anchor management server, e.g., the spatial anchor management server 308 discussed above. The spatial anchor creation request may contain information for creating a spatial anchor. For example, the spatial anchor creation request may contain spatial anchor position information and service information associated with the spatial anchor.
[0136] At 1620, the first spatial anchor management node 302 may receive a spatial anchor creation response from the spatial anchor management server 308. The spatial anchor creation response may indicate whether the spatial anchor is successfully created. If the spatial anchor is successfully created, the spatial anchor creation response may also contain information of the spatial anchor, including a spatial anchor ID.
[0137] In response to the spatial anchor creation response indicating successful creation of the spatial anchor, the first spatial anchor management node 302 may send at 1630 the spatial anchor information including the spatial anchor ID to an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above. The spatial anchor information may include an authorization policy preconfigured for the spatial anchor. In an example, the preconfigured authorization policy may indicate one or more nodes, entities or functions that are authorized to manage the spatial anchor. Optionally, the authorization policy may also define a scope of spatial anchor management operations that the one or more nodes, entities or functions are permitted to perform on the spatial anchor, and / or information of services that the one or more nodes, entities or functions are permitted to manage in the spatial anchor. In another example, the authorization policy may simply indicate that an explicit authorization from the spatial anchor owner (the first spatial anchor management node 302 in the example) is needed before other service providers perform a management operation on the spatial anchor.
[0138] In case the authorization policy preconfigured for the spatial anchor indicates that an explicit authorization from the spatial anchor owner is needed before other service providers perform a management operation on the spatial anchor, the first spatial anchor management node 302 may receive a notification about an authorization request from the authentication and authorization node 306 at 1640. In an example, the notification about the authorization request may be received via a callback URI that the first spatial anchor management node 302 registered with the authentication and authorization node 306. For example, the first spatial anchor management node 302 may register the callback URI during onboarding with the authentication and authorization node 306. In another example, the notification may be received via an authorization request message transmitted by the authentication and authorization node 306. The authorization request may indicate that a second spatial anchor management node, e.g., the second spatial anchor management node 304 discussed above, requests an authorization to perform a spatial anchor management operation on the spatial anchor with regard to a service offered by the second spatial anchor management node 304.
[0139] The first spatial anchor management node 302 may validate the authorization request in the notification at 1650. If the validation is successful, the first spatial anchor management node 302 may send an authorization response to the authentication and authorization node 306 at 1660 indicating that the second spatial anchor management node 304 is authorized to perform the requested spatial anchor management operation on the spatial anchor with regard to the service offered by it. If the validation is failed, the first spatial anchor management node 302 may indicate a failure cause in the authorization response.
[0140] Fig. 17 illustrates an apparatus 1700 according to example embodiments of the present disclosure. The apparatus 1700 may be implemented at a spatial anchor management client, e.g., the first spatial anchor management node 302 discussed above, to carry out the method 1600 discussed above with reference to Fig. 16. As shown in Fig. 17, the apparatus 1700 may comprise a means 1710 for performing the operation 1610 in the method 1600, a means 1720 for performing the operation 1620 in the method 1600, and a means 1730 for performing the operation 1630 in the method 1600. In an example, the apparatus 1700 may optionally comprise a means 1740 for performing the operation 1640 in the method 1600, a means 1750 for performing the operation 1650 in the method 1600, and a means 1760 for performing the operation 1660 in the method 1600. The means 1710-1760 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 1610-1660 in the method 1600. Since the operations 1610-1660 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0141] Fig. 18 illustrates a method 1800 according to example embodiments of the present disclosure. The method 1800 may be carried out at an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above. In an example, the authentication and authorization node 306 may be implemented with a CAPIF core function (CCF) or a SEAL identity management server (SIM-S) to carry out the method 1800.
[0142] As shown in Fig. 18, at 1810, the authentication and authorization node 306 may receive spatial anchor information from a first spatial anchor management node e.g., the first spatial anchor management node 302 discussed above, or from a spatial anchor management server e.g., the spatial anchor management server 308 discussed above. The spatial anchor information is related to a spatial anchor owned / created by the first spatial anchor management node 302, and it may contain an authorization policy preconfigured for the spatial anchor. In an example, the preconfigured authorization policy may indicate one or more nodes, entities or functions that are authorized to manage the spatial anchor. Optionally, the authorization policy may also define a scope of spatial anchor management operations that the one or more nodes, entities or functions are permitted to perform on the spatial anchor, and / or information of services that the one or more nodes, entities or functions are permitted to manage in the spatial anchor. In another example, the authorization policy may simply indicate that an explicit authorization from the spatial anchor owner (the first spatial anchor management node 302 in the example) is needed before other service providers perform a management operation on the spatial anchor.
[0143] The authentication and authorization node 306 may update a profile of the first spatial anchor management node 302 with the received spatial anchor information including the authorization policy at 1820. The profile of the first spatial anchor management node 302 may be locally stored at the authentication and authorization node 306 or at an external repository e.g., a unified data management (UDM) or unified data repository (UDR) network function.
[0144] At 1830, the authentication and authorization node 306 may receive an access token request from a spatial anchor management client, e.g., the second spatial anchor management node 304 discussed above. The access token request may indicate that the second spatial anchor management node 304 requests to perform a management operation (e.g., one or more of CRUD operations) on the spatial anchor owned / created by the first spatial anchor management node 302. The access token request may also indicate service information offered by the second spatial anchor management node 304, which is requested to be managed in the spatial anchor.
[0145] In response to the access token request, the authentication and authorization node 306 may retrieve the authorization policy preconfigured for the spatial anchor present in the profile of the first spatial anchor management node 302 (the spatial anchor owner) . If the authorization policy indicates the nodes authorized to management the spatial anchor and optionally management scope and service information permitted for the authorized nodes, the authentication and authorization node 306 may validate the access token request based on the authorization policy at 1840. If the authorization policy indicates that the second spatial anchor management node 304 is authorized to carry out the spatial anchor management operation on the spatial anchor with regard to the service information indicated in the access token request, the access token request is successfully validated, and the authentication and authorization node 306 may generate an enhanced access token for the second spatial anchor management node 304 and send the enhanced access token to the second spatial anchor management node 304 at 1880. The enhanced access token may include information of the entity issuing the token (the authentication and authorization node 306 in the example) , the authorization scope associated with the token (e.g., the spatial anchor management operation or the API authorized to perform / invoke) , the entity to which the token is issued (the second spatial anchor management node 304 in the example) , the expiry time of the token, and the like. The enhanced access token may also contain service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor.
[0146] If the authorization policy indicates that an explicit authorization from the spatial anchor owner is needed, the authentication and authorization node 306 may determine at 1850 to request an authorization from the spatial anchor owner, i.e., the first spatial anchor management node 302 in the example. Then the authentication and authorization node 306 may send a notification about an authorization request to the first spatial anchor management node 302 at 1860. In an example, the notification about the authorization request may be transmitted via a callback URI that the first spatial anchor management node 302 registered with the authentication and authorization node 306. The authentication and authorization node 306 may write the authorization request in the callback URI, and the first spatial anchor management node 302 will get the authorization request. In another example, the notification may be conveyed via an authorization request message transmitted from the authentication and authorization node 306. The authorization request may indicate that the second spatial anchor management node 304 requests an authorization to perform a spatial anchor management operation on the spatial anchor with regard to a service offered by the second spatial anchor management node 304.
[0147] At 1870, the authentication and authorization node 306 may receive an authorization response from the first spatial anchor management node. The authorization response may indicate whether the second spatial anchor management node 304 is authorized to perform the requested spatial anchor management operation on the spatial anchor with regard to the service information provided by the second spatial anchor management node 304. If the second spatial anchor management node 304 is authorized, the authentication and authorization node 306 may generate an enhanced access token for the second spatial anchor management node 304 and send the enhanced access token to the second spatial anchor management node 304 at 1880.
[0148] Fig. 19 illustrates an apparatus 1900 according to example embodiments of the present disclosure. The apparatus 1900 may be implemented at an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above, to carry out the method 1800 discussed above with reference to Fig. 18. As shown in Fig. 19, the apparatus 1900 may comprise a means 1910 for performing the operation 1810 in the method 1800, and a means 1920 for performing the operation 1820 in the method 1800. In an example, the apparatus 1900 may optionally comprise a means 1930 for performing the operation 1830 in the method 1800, a means 1940 for performing the operation 1840 in the method 1800, a means 1950 for performing the operation 1850 in the method 1800, a means 1960 for performing the operation 1860 in the method 1800, a means 1970 for performing the operation 1870 in the method 1800, and a means 1980 for performing the operation 1880 in the method 1800. The means 1910-1980 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 1810-1880 in the method 1800. Since the operations 1810-1880 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0149] Fig. 20 illustrates a method 2000 according to example embodiments of the present disclosure. The method 2000 may be carried out at a spatial anchor management client, e.g., the second spatial anchor management node 304 discussed above. In an example, the second spatial anchor management node 304 may be implemented with a VAL server or a SEAL client to carry out the method 2000.
[0150] At the beginning of the method 2000, it is assumed that the second spatial anchor management node 304 discovers the spatial anchor created by another service provider, e.g., the first spatial anchor management node 302 discussed above, and decides to add its service information in the spatial anchor. Referring to Fig. 20, at 2010, the second spatial anchor management node 304 may send an access token request to an authentication and authorization node, e.g., the authentication and authorization node 306 discussed above. The access token request may indicate that the second spatial anchor management node 304 requests to perform a management operation (e.g., one or more of CRUD operations) on the spatial anchor owned by the first spatial anchor management node 302. The access token request may also indicate service information that the second spatial anchor management node 304 requests to manage in the spatial anchor.
[0151] At 2020, the second spatial anchor management node 304 may receive an enhanced access token from the authentication and authorization node 306. The enhanced access token may include information of the entity issuing the token (the authentication and authorization node 306 in the example) , the authorization scope associated with the token (e.g., the spatial anchor management operation or the API authorized to perform / invoke) , the entity to which the token is issued (the second spatial anchor management node 304 in the example) , the expiry time of the token, and the like. The enhanced access token may also contain service information that the second spatial anchor management node 304 is permitted to manage in the spatial anchor.
[0152] At 2030, the second spatial anchor management node 304 may send a request for performing the spatial anchor management operation on the spatial anchor, along with the enhanced access token, to a spatial anchor management server, e.g., the spatial anchor management server 308 discussed above. Though not shown in Fig. 20, the second spatial anchor management node 304 may receive a response from the spatial anchor management server 308 indicating whether the requested spatial anchor management operation is successfully performed or not.
[0153] Fig. 21 illustrates an apparatus 2100 according to example embodiments of the present disclosure. The apparatus 2100 may be implemented at a spatial anchor management client, e.g., the second spatial anchor management node 304 discussed above, to carry out the method 2000 discussed above with reference to Fig. 20. As shown in Fig. 21, the apparatus 2100 may comprise a means 2110 for performing the operation 2010 in the method 2000, and a means 2120 for performing the operation 2020 in the method 2000, and a means 2130 for performing the operation 2030 in the method 2000. The means 2110-2130 each may be implemented with software, hardware, firmware or any combination thereof to perform the respective operations 2010-2030 in the method 2000. Since the operations 2010-2030 have been described above in detail, a repetitive description thereof is omitted here for convenience.
[0154] Fig. 22 illustrates an example of a spatial anchor management client device 2200, which may correspond to one or both of the first spatial anchor management node 302 and the second spatial anchor management node 304 discussed above. Referring to Fig. 22, the spatial anchor management client device 2200 may comprise one or more processors 2210, one or more memories 2220 and one or more transceivers 2230 interconnected through one or more buses 2240. The one or more transceivers 2230 each may comprise a receiver and a transmitter, which are collectively referred to as transceiver, and may receive / transmit signals from / to other network nodes, entities or functions in a wireless or wired manner. The one or more memories 2220 may include instructions 2222 which, when executed by the one or more processors 2210, may cause the spatial anchor management client device 2200 to perform operations relating to one or both of the first spatial anchor management node 302 and the second spatial anchor management node 304 as discussed above.
[0155] Fig. 23 illustrates an example of an authentication and authorization device 2300, which may correspond to the authentication and authorization node 306 discussed above. Referring to Fig. 23, the authentication and authorization device 2300 may comprise one or more processors 2310, one or more memories 2320 and one or more transceivers 2330 interconnected through one or more buses 2340. The one or more transceivers 2330 each may comprise a receiver and a transmitter, which may receive / transmit signals from / to other network nodes, entities or functions in a wireless or wired manner. The one or more memories 2320 may include instructions 2322 which, when executed by the one or more processors 2310, may cause the authentication and authorization device 2300 to perform operations relating to the authentication and authorization node 306 as discussed above.
[0156] Fig. 24 illustrates an example of a spatial anchor management server device 2400, which may correspond to the spatial anchor management server 308 discussed above. Referring to Fig. 24, the spatial anchor management server device 2400 may comprise one or more processors 2410, one or more memories 2420 and one or more transceivers 2430 interconnected through one or more buses 2440. The one or more transceivers 2430 each may comprise a receiver and a transmitter, which may receive / transmit signals from / to other network nodes, entities or functions in a wireless or wired manner. The one or more memories 2420 may include instructions 2422 which, when executed by the one or more processors 2410, may cause the spatial anchor management server device 2400 to perform operations relating to the spatial anchor management server 308 as discussed above.
[0157] The one or more processors 2210, 2310, 2410 discussed above may be of any appropriate type that is suitable for the local technical network, and may include one or more of general purpose processors, special purpose processor, microprocessors, a digital signal processor (DSP) , one or more processors in a processor based multi-core processor architecture, as well as dedicated processors such as those developed based on Field Programmable Gate Array (FPGA) and Application Specific Integrated Circuit (ASIC) . The one or more processors 2210, 2310, 2410 may be configured to control other elements of the devices 2200, 2300, 2400 and operate in cooperation with them to implement the procedures discussed above.
[0158] The one or more memories 2220, 2320, 2420 may include at least one storage medium in various forms, such as a transitory memory and / or a non-transitory memory. The transitory memory may include, but not limited to, for example, a random access memory (RAM) or a cache. The non-transitory memory may include, but not limited to, for example, a read only memory (ROM) , a hard disk, a flash memory, and the like. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) . Further, the one or more memories 2220, 2320, 2420 may include but not limited to an electric, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, apparatus, or device or any combination of the above.
[0159] It would be understood that blocks in the drawings may be implemented in various manners, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more blocks may be implemented using software and / or firmware, for example, machine-executable instructions stored in the storage medium. In addition to or instead of machine-executable instructions, parts or all of the blocks in the drawings may be implemented, at least in part, by one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include Field-Programmable Gate Arrays (FPGAs) , Application-Specific Integrated Circuits (ASICs) , Application-Specific Standard Products (ASSPs) , System-on-Chip systems (SOCs) , Complex Programmable Logic Devices (CPLDs) , etc.
[0160] Some example embodiments further provide program instruction or instructions which, when executed by one or more processors, may cause a device or apparatus to perform the procedures described above. The program instruction for carrying out procedures of the example embodiments may be written in any combination of one or more programming languages. The program instruction may be provided to one or more processors or controllers of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program instruction, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program instruction may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0161] Some example embodiments further provide a computer program product or a computer readable medium having the program instruction or instructions stored therein. The computer readable medium may be any tangible medium that may contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine readable medium may be a machine readable signal medium or a machine readable storage medium. A machine readable medium may include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0162] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0163] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0164] Throughout the present disclosure, reference to “one embodiment, ” “an embodiment, ” “some embodiments, ” “other embodiments, ” etc. indicates that one or more particular features, structures, steps, concepts, and / or characteristics in accordance with principles of the present disclosure may be included in connection with the embodiment. However, such references do not necessarily mean that all embodiments include the particular features, structures, steps, concepts, and / or characteristics, or that an embodiment includes all features, structures, steps, concepts, and / or characteristics. Some embodiments may include one or more such features, structures, steps, concepts, and / or characteristics, in various combinations thereof. It should be understood that one or more of the features, structures, steps, concepts, and / or characteristics described with reference to one embodiment can be combined with one or more of the features, structures, steps, concepts, and / or characteristics of any of the other embodiments provided herein. That is, any of the features, structures, steps, concepts, and / or characteristics described herein can be mixed and matched to create hybrid embodiments, and such hybrid embodiments are within the scope of the present disclosure. Moreover, references to “one embodiment, ” “an embodiment, ” “some embodiments, ” “other embodiments, ” etc. in various places in the specification are not necessarily all referring to the same embodiment, nor are separate or alternative embodiments necessarily mutually exclusive of other embodiments. It should further be understood that various features, structures, steps, concepts, and / or characteristics of disclosed embodiments are independent of and separate from one another, and may be used or present individually or in various combinations with one another to create alternative embodiments which are considered part of the present disclosure. Therefore, the present disclosure is not limited to only the embodiments specifically described herein, as it would be too cumbersome to describe all of the numerous possible combinations and subcombinations of features, structures, steps, concepts, and / or characteristics, and the examples of embodiments disclosed herein are not intended as limiting the broader aspects of the present disclosure.
[0165] Although the subject matter has been described in a language that is specific to structural features and / or method actions, it is to be understood the subject matter defined in the appended claims is not limited to the specific features or actions described above. On the contrary, the above-described specific features and actions are disclosed as an example of implementing the claims.
Claims
1.A first spatial anchor management node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first spatial anchor management node at least to:receive, from a second spatial anchor management node, an authorization request for a spatial anchor management operation on a spatial anchor owned by the first spatial anchor management node;validate the authorization request received from the second spatial anchor management node; andsend, to the second spatial anchor management node, an authorization token for the spatial anchor management operation on the spatial anchor.2.The first spatial anchor management node of claim 1, wherein the authorization request comprises at least one of:information of an application programming interface, API, that is requested to be invoked by the second spatial anchor management node for performing the spatial anchor management operation; orinformation of a service to be managed in the spatial anchor by the spatial anchor management operation.3.The first spatial anchor management node of claim 1 or 2, wherein the authorization token is signed with a private key of the first spatial anchor management node used during registering with an authentication and authorization node.4.The first spatial anchor management node of any of claims 1 to 3, wherein the spatial anchor management operation comprises at least one of:creating a service in the spatial anchor;retrieving a service in the spatial anchor;updating a service in the spatial anchor; ordeleting a service in the spatial anchor.5.The first spatial anchor management node of any of claims 1 to 4, wherein the first spatial anchor management node comprises at least one of:a vertical application layer server; ora service enabler architecture layer for verticals client.6.A second spatial anchor management node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second spatial anchor management node at least to:send, to a first spatial anchor management node, an authorization request for a spatial anchor management operation on a spatial anchor owned by the first spatial anchor management node;receive, from the first spatial anchor management node, an authorization token for the spatial anchor management operation;send, to an authentication and authorization node, an access token request for the spatial anchor along with the authorization token;receive, from the authentication and authorization node, an enhanced access token for the spatial anchor; andsend, to a spatial anchor management server, a request for performing the spatial anchor management operation along with the enhanced access token for the spatial anchor.7.The second spatial anchor management node of claim 6, wherein the authorization token comprises at least one of:information of an application programming interface, API, that is authorized for the second spatial anchor management node to invoke for performing the spatial anchor management operation on the spatial anchor; orinformation of a service that is authorized for the second spatial anchor management node to manage in the spatial anchor by the spatial anchor management operation.8.The second spatial anchor management node of claim 6 or 7, wherein the second spatial anchor management node comprises at least one of:a vertical application layer server; ora service enabler architecture layer for verticals client.9.An authentication and authorization node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the authentication and authorization node at least to:receive, from a second spatial anchor management node, an access token request for a spatial anchor owned by a first spatial anchor management node, along with an authorization token issued by the first spatial anchor management node;validate the access token request and the authorization token; andsend, to the second spatial anchor management node, an enhanced access token for the second spatial anchor management node to access the spatial anchor.10.The authentication and authorization node of claim 9, wherein the access token request comprises at least one of:information of a spatial anchor management operation that is requested to be performed on the spatial anchor; orinformation of a service to be managed in the spatial anchor by the spatial anchor management operation.11.The authentication and authorization node of claim 9 or 10, wherein the enhanced access token comprises at least one of:information of a spatial anchor management operation that is permitted to be performed on the spatial anchor; orinformation of a service that is permitted to be managed in the spatial anchor by the spatial anchor management operation.12.The authentication and authorization node of any of claims 9 to 11, wherein the authorization token is signed with a private key of the first spatial anchor management node, and the authentication and authorization node validates the authorization token by verifying signature of the authorization token using a public key of the first spatial anchor management node stored at the authentication and authorization node, the public-private key pair being established during registration of the first spatial anchor management node with the authentication and authorization node.13.The authentication and authorization node of any of claims 9 to 12, wherein the access token request is validated based on content of the authorization token.14.The authentication and authorization node of any of claims 9 to 13, wherein the authentication and authorization node comprises at least one of:a common API framework for northbound APIs, CAPIF, core function, ora service enabler architecture layer for verticals, SEAL, identity management server.15.A spatial anchor management server, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the spatial anchor management server at least to:receive, from a first spatial anchor management node, a spatial anchor creation request comprising an authorization policy preconfigured for a spatial anchor;create the spatial anchor in response to the spatial anchor creation request;send, to the first spatial anchor management node, a spatial anchor creation response indicating successful creation of the spatial anchor; andprovide, to an authentication and authorization node, information of the spatial anchor comprising the preconfigured authorization policy.16.The spatial anchor management server of claim 15, wherein the authorization policy preconfigured for the spatial anchor indicates one or more nodes, entities or functions that are authorized to manage the spatial anchor, and optionally one or more of:scope of spatial anchor management permitted to the one or more nodes, entities or functions, orinformation of services permitted to be managed in the spatial anchor.17.The spatial anchor management server of claim 15, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed.18.A first spatial anchor management node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first spatial anchor management node at least to:send, to a spatial anchor management server, a spatial anchor creation request comprising an authorization policy preconfigured for a spatial anchor; andreceive, from the spatial anchor management server, a spatial anchor creation response indicating success creation of the spatial anchor.19.The first spatial anchor management node of claim 18, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed,the instructions, when executed by the at least one processor, further cause the first spatial anchor management node at least to:receive, from an authentication and authorization node, a notification about an authorization request to authorize a second spatial anchor management node to perform a spatial anchor management operation on the spatial anchor;validate the authorization request in the notification; andsend, to the authentication and authorization node, an authorization response indicating that the second spatial anchor management node is authorized to perform the spatial anchor management operation on the spatial anchor.20.The first spatial anchor management node of claim 19, wherein the notification about the authorization request is received via:a callback uniform resource identifier registered by the first spatial anchor management node with the authentication and authorization node, oran authorization request message received from the authentication and authorization node.21.A first spatial anchor management node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first spatial anchor management node at least to:send, to a spatial anchor management server, a spatial anchor creation request;receive, from the spatial anchor management server, a spatial anchor creation response indicating success creation of a spatial anchor; andprovide, to an authentication and authorization node, information of the spatial anchor comprising an authorization policy preconfigured for the spatial anchor.22.The first spatial anchor management node of claim 21, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed,the instructions, when executed by the at least one processor, further cause the first spatial anchor management node at least to:receive, from the authentication and authorization node, a notification about an authorization request to authorize a second spatial anchor management node to perform a spatial anchor management operation on the spatial anchor;validate the authorization request in the notification; andsend, to the authentication and authorization node, an authorization response indicating that the second spatial anchor management node is authorized to perform the spatial anchor management operation on the spatial anchor.23.The first spatial anchor management node of claim 22, wherein the notification about the authorization request is received from the authentication and authorization node via:a callback uniform resource identifier registered by the first spatial anchor management node towards the authentication and authorization node, oran authorization request message.24.An authentication and authorization node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the authentication and authorization node at least to:receive, from a first spatial anchor management node or a spatial anchor management server, information of a spatial anchor owned by the first spatial anchor management node, the spatial anchor information comprising an authorization policy preconfigured for the spatial anchor; andupdate profile of the first spatial anchor management node with the received spatial anchor information.25.The authentication and authorization node of claim 24, wherein the authorization policy preconfigured for the spatial anchor indicates one or more nodes, entities or functions that are authorized to manage the spatial anchor, and optionally one or more of:scope of spatial anchor management permitted to the one or more nodes, entities or functions, orinformation of services permitted to be managed in the spatial anchor.26.The authentication and authorization node of claim 25, wherein the instructions, when executed by the at least one processor, further cause the authentication and authorization node at least to:receive, from a second spatial anchor management node, an access token request for the spatial anchor owned by the first spatial anchor management node;validate the access token request based on the authorization policy preconfigured for the spatial anchor; andsend, to the second spatial anchor management node, an enhanced access token for the second spatial anchor management node to access the spatial anchor.27.The authentication and authorization node of claim 24, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed.28.The authentication and authorization node of claim 27, wherein the instructions, when executed by the at least one processor, further cause the authentication and authorization node at least to:receive, from a second spatial anchor management node, an access token request for a spatial anchor management operation on the spatial anchor owned by the first spatial anchor management node;determine to request from the first spatial anchor management node an authorization for the second spatial anchor management node, based on the authorization policy preconfigured for the spatial anchor;send, to the first spatial anchor management node, a notification about an authorization request to authorize the second spatial anchor management node to perform the spatial anchor management operation on the spatial anchor;receive, from the first spatial anchor management node, an authorization response indicating that the second spatial anchor management node is authorized to perform the spatial anchor management operation on the spatial anchor; andsend, to the second spatial anchor management node, an enhanced access token for the spatial anchor management operation on the spatial anchor.29.The authentication and authorization node of claim 28, wherein the notification about the authorization request is sent to the first spatial anchor management node via:a callback uniform resource identifier registered by the first spatial anchor management node towards the authentication and authorization node, oran authorization request message.30.A second spatial anchor management node, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the second spatial anchor management node at least to:send, to an authentication and authorization node, an access token request for a spatial anchor management operation on a spatial anchor owned by a first spatial anchor management node;receive, from the authentication and authorization node, an enhanced access token for the spatial anchor management operation on the spatial anchor; andsend, to a spatial anchor management server, a request for performing the spatial anchor management operation on the spatial anchor, along with the access token.31.A method, comprising:receiving, from a second spatial anchor management node, an authorization request for a spatial anchor management operation on a spatial anchor owned by a first spatial anchor management node;validating the authorization request received from the second spatial anchor management node; andsending, to the second spatial anchor management node, an authorization token for the spatial anchor management operation on the spatial anchor.32.The method of claim 31, wherein the authorization request comprises at least one of:information of an application programming interface, API, that is requested to be invoked by the second spatial anchor management node for performing the spatial anchor management operation; orinformation of a service to be managed in the spatial anchor by the spatial anchor management operation.33.The method of claim 31 or 32, wherein the authorization token is signed with a private key of the first spatial anchor management node used during registering with an authentication and authorization node.34.The method of any of claims 31 to 33, wherein the spatial anchor management operation comprises at least one of:creating a service in the spatial anchor;retrieving a service in the spatial anchor;updating a service in the spatial anchor; ordeleting a service in the spatial anchor.35.The method of any of claims 31 to 34, wherein the first spatial anchor management node comprises at least one of:a vertical application layer server; ora service enabler architecture layer for verticals client.36.A method, comprising:sending, to a first spatial anchor management node, an authorization request for a spatial anchor management operation on a spatial anchor owned by the first spatial anchor management node;receiving, from the first spatial anchor management node, an authorization token for the spatial anchor management operation;sending, to an authentication and authorization node, an access token request for the spatial anchor along with the authorization token;receiving, from the authentication and authorization node, an enhanced access token for the spatial anchor; andsending, to a spatial anchor management server, a request for performing the spatial anchor management operation along with the enhanced access token for the spatial anchor.37.The method of claim 36, wherein the authorization token comprises at least one of:information of an application programming interface, API, that is authorized for a second spatial anchor management node to invoke for performing the spatial anchor management operation on the spatial anchor; orinformation of a service that is authorized for the second spatial anchor management node to manage in the spatial anchor by the spatial anchor management operation.38.The method of claim 37, wherein the second spatial anchor management node comprises at least one of:a vertical application layer server; ora service enabler architecture layer for verticals client.39.A method, comprising:receiving, from a second spatial anchor management node, an access token request for a spatial anchor owned by a first spatial anchor management node, along with an authorization token issued by the first spatial anchor management node;validating the access token request and the authorization token; andsending, to the second spatial anchor management node, an enhanced access token for the second spatial anchor management node to access the spatial anchor.40.The method of claim 39, wherein the access token request comprises at least one of:information of a spatial anchor management operation that is requested to be performed on the spatial anchor; orinformation of a service to be managed in the spatial anchor by the spatial anchor management operation.41.The method of claim 39 or 40, wherein the enhanced access token comprises at least one of:information of a spatial anchor management operation that is permitted to be performed on the spatial anchor; orinformation of a service that is permitted to be managed in the spatial anchor by the spatial anchor management operation.42.The method of any of claims 39 to 41, wherein the authorization token is signed with a private key of the first spatial anchor management node, and the authorization token is validated by verifying signature of the authorization token using a public key of the first spatial anchor management node stored at an authentication and authorization node, the public-private key pair being established during registration of the first spatial anchor management node with the authentication and authorization node.43.The method of any of claims 39 to 42, wherein the access token request is validated based on content of the authorization token.44.The method of claim 42, wherein the authentication and authorization node comprises at least one of:a common API framework for northbound APIs, CAPIF, core function, ora service enabler architecture layer for verticals, SEAL, identity management server.45.A method, comprising:receiving, from a first spatial anchor management node, a spatial anchor creation request comprising an authorization policy preconfigured for a spatial anchor;creating the spatial anchor in response to the spatial anchor creation request;sending, to the first spatial anchor management node, a spatial anchor creation response indicating successful creation of the spatial anchor; andproviding, to an authentication and authorization node, information of the spatial anchor comprising the preconfigured authorization policy.46.The method of claim 45, wherein the authorization policy preconfigured for the spatial anchor indicates one or more nodes, entities or functions that are authorized to manage the spatial anchor, and optionally one or more of:scope of spatial anchor management permitted to the one or more nodes, entities or functions, orinformation of services permitted to be managed in the spatial anchor.47.The method of claim 45, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed.48.A method, comprising:sending, to a spatial anchor management server, a spatial anchor creation request comprising an authorization policy preconfigured for a spatial anchor; andreceiving, from the spatial anchor management server, a spatial anchor creation response indicating success creation of the spatial anchor.49.The method of claim 48, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed,the method further comprises:receiving, from an authentication and authorization node, a notification about an authorization request to authorize a second spatial anchor management node to perform a spatial anchor management operation on the spatial anchor;validating the authorization request in the notification; andsending, to the authentication and authorization node, an authorization response indicating that the second spatial anchor management node is authorized to perform the spatial anchor management operation on the spatial anchor.50.The method of claim 49, wherein the notification about the authorization request is received via:a callback uniform resource identifier registered by a first spatial anchor management node with the authentication and authorization node, oran authorization request message received from the authentication and authorization node.51.A method, comprising:sending, to a spatial anchor management server, a spatial anchor creation request;receiving, from the spatial anchor management server, a spatial anchor creation response indicating success creation of a spatial anchor; andproviding, to an authentication and authorization node, information of the spatial anchor comprising an authorization policy preconfigured for the spatial anchor.52.The method of claim 51, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed,the method further comprises:receiving, from the authentication and authorization node, a notification about an authorization request to authorize a second spatial anchor management node to perform a spatial anchor management operation on the spatial anchor;validating the authorization request in the notification; andsending, to the authentication and authorization node, an authorization response indicating that the second spatial anchor management node is authorized to perform the spatial anchor management operation on the spatial anchor.53.The method of claim 52, wherein the notification about the authorization request is received from the authentication and authorization node via:a callback uniform resource identifier registered by a first spatial anchor management node towards the authentication and authorization node, oran authorization request message.54.A method, comprising:receiving, from a first spatial anchor management node or a spatial anchor management server, information of a spatial anchor owned by the first spatial anchor management node, the spatial anchor information comprising an authorization policy preconfigured for the spatial anchor; andupdating profile of the first spatial anchor management node with the received spatial anchor information.55.The method of claim 54, wherein the authorization policy preconfigured for the spatial anchor indicates one or more nodes, entities or functions that are authorized to manage the spatial anchor, and optionally one or more of:scope of spatial anchor management permitted to the one or more nodes, entities or functions, orinformation of services permitted to be managed in the spatial anchor.56.The method of claim 55, further comprising:receiving, from a second spatial anchor management node, an access token request for the spatial anchor owned by the first spatial anchor management node;validating the access token request based on the authorization policy preconfigured for the spatial anchor; andsending, to the second spatial anchor management node, an enhanced access token for the second spatial anchor management node to access the spatial anchor.57.The method of claim 54, wherein the authorization policy preconfigured for the spatial anchor indicates that an authorization from an owner of the spatial anchor is needed.58.The method of claim 57, further comprising:receiving, from a second spatial anchor management node, an access token request for a spatial anchor management operation on the spatial anchor owned by the first spatial anchor management node;determining to request from the first spatial anchor management node an authorization for the second spatial anchor management node, based on the authorization policy preconfigured for the spatial anchor;sending, to the first spatial anchor management node, a notification about an authorization request to authorize the second spatial anchor management node to perform the spatial anchor management operation on the spatial anchor;receiving, from the first spatial anchor management node, an authorization response indicating that the second spatial anchor management node is authorized to perform the spatial anchor management operation on the spatial anchor; andsending, to the second spatial anchor management node, an enhanced access token for the spatial anchor management operation on the spatial anchor.59.The method of claim 58, wherein the notification about the authorization request is sent to the first spatial anchor management node via:a callback uniform resource identifier registered by the first spatial anchor management node towards an authentication and authorization node, oran authorization request message.60.A method, comprising:sending, to an authentication and authorization node, an access token request for a spatial anchor management operation on a spatial anchor owned by a first spatial anchor management node;receiving, from the authentication and authorization node, an enhanced access token for the spatial anchor management operation on the spatial anchor; andsending, to a spatial anchor management server, a request for performing the spatial anchor management operation on the spatial anchor, along with the access token.61.An apparatus, comprising means for performing the method of any of claims 31 to 60.62.A computer readable medium, comprising instructions that, when executed by an apparatus, cause the apparatus to perform the method of any of claims 31 to 60.
Citation Information
Patent Citations
Systems and methods for locking virtual environments in mixed reality
US20240119680A1
Enabling sensing and sensing fusion for a metaverse service in a wireless communication system
WO2024088584A1
An application layer architecture and method for managing spatial anchor in a wireless communication system
WO2024150987A1