Information processing method, and device, system and storage medium

By acquiring and verifying authorization-related information, the problem of insufficient security in the existing API call authorization process is solved, and a more secure communication process is achieved.

WO2026031222A1PCT designated stage Publication Date: 2026-02-12BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/111263
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-09
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

The existing API call authorization process lacks an effective security verification mechanism, which leads to potential security risks during communication.

Method used

The security of the authorization process is ensured by acquiring and verifying authorization-related information, including the identification information of the resource owner, the identification information of the API caller, and service information.

Benefits of technology

It improves security during communication, ensures the accuracy and validity of authorization information, and prevents unauthorized API calls.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024111263_12022026_PF_FP_ABST
    Figure CN2024111263_12022026_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure relate to the technical field of communications. Disclosed are an information processing method, and an apparatus and a computer-readable storage medium. The information processing method comprises: acquiring first information, wherein the first information comprises authorization-related information related to a second node. In the embodiments of the present disclosure, by acquiring authorization-related information related to a second node, a basis can be provided for further verifying the authorization-related information.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, device, system and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and in particular, the present disclosure relates to an information processing method, device, system and storage medium. BACKGROUND

[0002] A resource owner can use a Common API Framework (CAPIF) to authorize an API invoker to access its own resources (e.g., location information). The resource owner can use two existing authorization flows (i.e., authorization code flow, client credentials flow) to authorize.

[0003] SUMMARY

[0004] Embodiments of the present disclosure provide an information processing method, device, system and storage medium.

[0005] In a first aspect, an information processing method is provided, the method being performed by a first node, and the method comprising:

[0006] obtaining first information, the first information comprising authorization-related information related to a second node.

[0007] In a second aspect, an information processing method is provided, the method being performed by a second node, and the method comprising:

[0008] sending, to a first node, first information, the first information comprising authorization-related information related to the second node.

[0009] In a third aspect, an information processing method is provided, the method being performed by a third node, and the method comprising:

[0010] sending, to a first node, third information, the third information comprising authorization request-related information of a second resource owner related to the third node;

[0011] wherein the third information is used to request authorization for a first API invoker, and the second resource owner is an expected resource owner of the first API invoker.

[0012] In a fourth aspect, an information processing method is provided, the method being performed by a first API invoker, and the method comprising:

[0013] sending third information to the first node, the third information comprising authorization request related information of a second resource owner related to the third node;

[0014] The third information is used to request authorization for a first API invoker, and the second resource owner is an expected resource owner for the first API invoker.

[0015] In a fifth aspect, the present disclosure provides an information processing method, which is performed by a second API invoker, and the method comprises:

[0016] receiving fourth information sent by the first node, the fourth information being used to inform the second API invoker that authorization is revoked, and the fourth information indicating revoked authorization information;

[0017] sending fifth information to the first node, the fifth information being used to feed back that authorization is revoked.

[0018] In a sixth aspect, the present disclosure provides an information processing method, which is performed by a fourth node, and the method comprises:

[0019] receiving sixth information sent by the first node, the sixth information being used to request the fourth node to provide address information of a second node;

[0020] sending seventh information to the first node, the seventh information comprising the address information of the second node;

[0021] The sixth information comprises identification information of a first resource owner related to the second node and / or identification information of the second API invoker, the first resource owner is related to the second node, and the second API invoker runs on the second node.

[0022] In a seventh aspect, the present disclosure provides an information processing method, which is performed by a fifth node, and the method comprises:

[0023] receiving eighth information sent by the first node or the fourth node, the eighth information being used to request the fifth node to provide identification information of a second node;

[0024] sending ninth information to the first node or the fourth node, the ninth information comprising the identification information of the second node;

[0025] The eighth information comprises identification information of the first resource owner and / or identification information of the second API invoker.

[0026] In an eighth aspect, a method for processing information is provided. The method is performed by a sixth node and includes:

[0027] receiving tenth information sent by the first node or the fourth node, the tenth information being used to request the sixth node to provide address information of the second node, the tenth information comprising identification information of the second node;

[0028] sending eleventh information to the first node or the fourth node, the eleventh information comprising the address information of the second node.

[0029] In a ninth aspect, a first node is provided. The first node comprises:

[0030] a first transceiver configured to obtain first information, the first information comprising authorization-related information related to a second node.

[0031] In a tenth aspect, a second node is provided. The second node comprises:

[0032] a second transceiver configured to send first information to a first node, the first information comprising authorization-related information related to the second node.

[0033] In an eleventh aspect, a third node is provided. The third node comprises:

[0034] a third transceiver configured to send third information to a first node, the third information comprising authorization request-related information of a second resource owner related to the third node;

[0035] wherein the third information is used to request authorization for a first API invoker, and the second resource owner is a desired resource owner of the first API invoker.

[0036] In a twelfth aspect, a first API invoker is provided. The first API invoker comprises:

[0037] a fourth transceiver configured to send third information to a first node, the third information comprising authorization request-related information of a second resource owner related to the third node;

[0038] wherein the third information is used to request authorization for a first API invoker, and the second resource owner is a desired resource owner of the first API invoker.

[0039] In a thirteenth aspect, a second API invoker is provided. The second API invoker comprises:

[0040] The fifth transceiving module is configured to receive fourth information sent by the first node, the fourth information being used to inform that the authorization of the second API invoker is revoked, and the fourth information indicating the revoked authorization information;

[0041] The fifth information is sent to the first node, and the fifth information is used to feed back that the authorization is revoked.

[0042] A fourteenth aspect of the embodiments of the present disclosure provides a communication device, comprising:

[0043] One or more processors;

[0044] The terminal is configured to perform the optional implementation of the first aspect or the second aspect or the third aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0045] A fifteenth aspect of the embodiments of the present disclosure provides a communication device, comprising:

[0046] One or more processors;

[0047] The network device is configured to perform the optional implementation of the fourth aspect or the fifth aspect.

[0048] According to a sixteenth aspect of the embodiments of the present disclosure, a computer readable storage medium is provided, the computer readable storage medium stores executable instructions, the executable instructions are loaded and executed by the processor to implement the method described in the optional implementation of the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0049] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0050] The drawings herein are incorporated into the specification and form a part of the specification, show embodiments consistent with the present disclosure, and together with the specification serve to explain the principles of the present disclosure.

[0051] FIG. 1 is a schematic diagram of a structure of a wireless communication system according to an exemplary embodiment;

[0052] FIG. 2a is a flow chart of an information processing method according to an exemplary embodiment;

[0053] FIG. 2b is a flow chart of an information processing method according to an exemplary embodiment;

[0054] FIG. 2c is a flow chart of an information processing method according to an exemplary embodiment;

[0055] FIG. 2d is a flowchart illustrating a method of processing information according to an example embodiment;

[0056] FIG. 2e is a flowchart illustrating a method of processing information according to an example embodiment;

[0057] FIG. 2f is a flowchart illustrating a method of processing information according to an example embodiment;

[0058] FIG. 2g is a flowchart illustrating a method of processing information according to an example embodiment;

[0059] FIG. 3a is a flowchart illustrating a method of processing information according to an example embodiment;

[0060] FIG. 3b is a flowchart illustrating a method of processing information according to an example embodiment;

[0061] FIG. 3c is a flowchart illustrating a method of processing information according to an example embodiment;

[0062] FIG. 3d is a flowchart illustrating a method of processing information according to an example embodiment;

[0063] FIG. 4 is a flowchart illustrating a method of processing information according to an example embodiment;

[0064] FIG. 5 is a flowchart illustrating a method of processing information according to an example embodiment;

[0065] FIG. 6 is a flowchart illustrating a method of processing information according to an example embodiment;

[0066] FIG. 7a is a flowchart illustrating a method of processing information according to an example embodiment;

[0067] FIG. 7b is a flowchart illustrating a method of processing information according to an example embodiment;

[0068] FIG. 7c is a flowchart illustrating a method of processing information according to an example embodiment;

[0069] FIG. 7d is a flowchart illustrating a method of processing information according to an example embodiment;

[0070] FIG. 8a is a structural diagram of a first node according to an example embodiment;

[0071] FIG. 8b is a structural diagram of a second node according to an example embodiment;

[0072] FIG. 8c is a structural diagram of a third node according to an example embodiment;

[0073] FIG. 8d is a structural diagram of a first API invoker according to an example embodiment;

[0074] FIG. 8e is a structural schematic diagram of a second API invoker according to an embodiment of the present disclosure;

[0075] FIG. 9a is a structural schematic diagram of a communication device according to an embodiment of the present disclosure;

[0076] FIG. 9b is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0077] Embodiments of the present disclosure provide an information processing method, device, communication system, and storage medium.

[0078] In a first aspect, embodiments of the present disclosure provide an information processing method, the method being performed by a first node, and the method comprising:

[0079] obtaining first information, the first information comprising authorization-related information related to a second node.

[0080] In the above embodiments, by obtaining the authorization-related information related to the second node, a basis for verifying the authorization-related information can be provided, thereby enhancing the security of communication.

[0081] In some embodiments, combined with the first aspect, in some embodiments, the obtaining the first information comprises:

[0082] receiving the first information sent by the second node, the first information comprising authorization-related information of a first resource owner related to the second node.

[0083] In the above embodiments, the second node can configure the first node with the authorization-related information of the first resource owner related to the second node, so that in subsequent authorization of an API invoker, verification can be performed based on the obtained authorization-related information, thereby improving security.

[0084] In some embodiments, combined with the first aspect, in some embodiments, the obtaining the first information comprises:

[0085] sending second information to the second node, the second information being used to request the second node to provide authorization-related information of a first resource owner related to the second node;

[0086] receiving the first information sent by the second node, the first information comprising authorization-related information of a first resource owner related to the second node.

[0087] In the above embodiments, the first node can request the second node to provide the authorization-related information of the first resource owner related to the second node, so that in subsequent authorization of an API invoker, verification can be performed based on the obtained authorization-related information, thereby improving security.

[0088] In some embodiments of the first aspect, in some embodiments, the authorization-related information comprises at least one of the following information:

[0089] identification information of the first resource owner;

[0090] identification information of an application programming interface (API) invoker (e.g., API invoker ID, API invoker identification);

[0091] resource information;

[0092] data type;

[0093] data processing purpose.

[0094] In the above embodiments, by obtaining a plurality of authorization-related information, a plurality of options can be provided for subsequent verification of authorization information, thereby further improving the security of communication.

[0095] In some embodiments of the first aspect, in some embodiments, the method further comprises:

[0096] obtaining third information, the third information comprising authorization request-related information of a second resource owner related to a third node, the second resource owner being an expected resource owner of the first API invoker.

[0097] In some embodiments of the first aspect, in some embodiments, the obtaining the third information comprises:

[0098] receiving the third information sent by the third node; or,

[0099] receiving the third information sent by the first API invoker;

[0100] wherein the third information is used to request authorization for the first API invoker.

[0101] In the above embodiments, the first node can also determine whether to authorize the requested specific API invoker based on the obtained authorization-related information.

[0102] In some embodiments of the first aspect, in some embodiments, the authorization request-related information comprises at least one of the following information:

[0103] identification information of the second resource owner;

[0104] identification information of the first API invoker;

[0105] service information, wherein the service information comprises at least one of the following: service, service operation, and service API;

[0106] resource information;

[0107] data type;

[0108] data processing purpose.

[0109] In the above embodiment, the authorization information included in the authorization request can further determine whether to authorize the specific API invoker of the request, thereby ensuring the security of the communication.

[0110] In some embodiments of the first aspect, the method further comprises:

[0111] sending fourth information to the second API invoker, the fourth information being used to inform the second API invoker that the authorization is revoked, the fourth information indicating the revoked authorization information;

[0112] receiving fifth information sent by the second API invoker, the fifth information being used to feed back that the authorization is revoked.

[0113] In the above embodiment, the first node can further inform the specific API invoker that the authorization is revoked, and indicate the revoked authorization information, thereby ensuring the security of the communication.

[0114] In some embodiments of the first aspect, the authorization information comprises at least one of the following information:

[0115] identification information of a first resource owner related to the second node;

[0116] identification information of the second API invoker;

[0117] service information expected by the second API invoker, wherein the service information comprises at least one of a service, a service operation, and a service API;

[0118] identification information of the fourth node;

[0119] resource information;

[0120] data type;

[0121] data processing purpose.

[0122] In some embodiments of the first aspect, the method further comprises:

[0123] sending sixth information to the fourth node, the sixth information being used to request the fourth node to provide address information of the second node;

[0124] receiving seventh information sent by the fourth node, the seventh information comprising the address information of the second node;

[0125] The sixth information includes identification information of the first resource owner and / or identification information of the second API invoker, the first resource owner is related to the second node, and the second API invoker runs on the second node.

[0126] In the above embodiment, before actively requesting the second node to provide the authorization-related information of the first resource owner related to the second node, the first node can first obtain address information of the second node by interacting with other nodes, so that the authorization-related information can be more accurately obtained.

[0127] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:

[0128] sending eighth information to a fifth node, the eighth information being used to request the fifth node to provide identification information of the second node;

[0129] receiving ninth information sent by the fifth node, the ninth information including the identification information of the second node;

[0130] sending tenth information to a sixth node, the tenth information being used to request the sixth node to provide address information of the second node, the tenth information including the identification information of the second node;

[0131] receiving eleventh information sent by the sixth node, the eleventh information including the address information of the second node;

[0132] The eighth information includes identification information of the first resource owner and / or identification information of the second API invoker, the first resource owner is related to the second node, and the second API invoker runs on the second node.

[0133] In the above embodiment, before actively requesting the second node to provide the authorization-related information of the first resource owner related to the second node, the first node can first obtain address information of the second node by interacting with other nodes, so that the authorization-related information can be more accurately obtained.

[0134] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:

[0135] verifying the authorization-related information.

[0136] In combination with some embodiments of the first aspect, in some embodiments, if the authorization-related information includes identification information of the first resource owner related to the second node, the verifying the authorization-related information includes:

[0137] verify the identity information of the first resource owner in the authorization-related information based on the identity information of the authenticated resource owner related to the second node.

[0138] In the above embodiments, the first node can verify the identity information of the first resource owner in the authorization-related information based on the identity information of the authenticated resource owner, thereby ensuring the security of the subsequent authorization process.

[0139] In combination with some embodiments of the first aspect, in some embodiments, the method further includes at least one of the following operations:

[0140] if the identity information of the authenticated resource owner is inconsistent with the identity information of the first resource owner, sending twelfth information indicating that the authorization information configuration fails to the second node;

[0141] if the identity information of the authenticated resource owner is inconsistent with the identity information of the first resource owner, rejecting to accept the authorization-related information;

[0142] if the identity information of the authenticated resource owner is inconsistent with the identity information of the first resource owner, rejecting to store the authorization-related information;

[0143] if the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, storing the authorization-related information;

[0144] if the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, accepting the authorization-related information;

[0145] if the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, sending thirteenth information indicating that the authorization configuration succeeds to the second node;

[0146] wherein the twelfth information further indicates that the second node configures authorization information related to the identity information of the authenticated resource owner.

[0147] In combination with some embodiments of the first aspect, in some embodiments, if the identity information of the first resource owner related to the second node is not included in the authorization-related information, the method further includes:

[0148] associating the identity information of the authenticated resource owner with the authorization-related information; or,

[0149] map data types and data processing purposes included in the authorization-related information to service information, and associate the identification information of the authenticated resource owner and the service information, wherein the service information includes at least one of a service, a service operation, and a service API.

[0150] In some embodiments of the first aspect, the method further includes:

[0151] verifying the authorization request-related information.

[0152] In the above embodiments, the first node can verify the obtained authorization request-related information of a second resource owner related to a third node, to determine whether to accept the authorization information related to the first resource owner based on a verification result.

[0153] In some embodiments of the first aspect, the verifying the authorization request-related information includes:

[0154] verifying the identification information of the second resource owner based on the identification information of the authenticated resource owner related to the third node.

[0155] In some embodiments of the first aspect, the method further includes at least one of the following operations:

[0156] if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, sending, to the third node, fourteenth information indicating that authorization information configuration fails;

[0157] if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, rejecting to accept the authorization request-related information;

[0158] if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, rejecting to store the authorization request-related information;

[0159] if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, terminating the authorization process related to the first API invoker;

[0160] if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner, storing the authorization request-related information;

[0161] if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner, accepting the authorization request-related information;

[0162] the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, and it is determined whether service information included in the third information matches the data type and the data processing purpose;

[0163] the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, and it is determined whether service information included in the third information matches the data processing purpose;

[0164] The fourteenth information further includes authorization information related to the identity information of the authenticated resource owner.

[0165] In some embodiments of the first aspect, the method further includes at least one of the following operations:

[0166] If the service information included in the third information matches the data type and the data processing purpose, performing an authorization process on the first API invoker;

[0167] If the service information included in the third information matches the data processing purpose, performing an authorization process on the first API invoker;

[0168] If the service information included in the third information does not match the data type and the data processing purpose, sending fifteenth information indicating that the authorization request fails to the third node;

[0169] If the service information included in the third information does not match the data processing purpose, sending fifteenth information indicating that the authorization request fails to the third node;

[0170] The fifteenth information is used to indicate that the data type and the data processing purpose included in the authorization request related information do not match the service information included in the third information; or

[0171] The fifteenth information is used to indicate that the data processing purpose included in the authorization request related information does not match the service information included in the third information.

[0172] In some embodiments of the first aspect, the verification of the authorization request related information includes:

[0173] If a corresponding authorization policy is determined according to the identity information of the second resource owner included in the authorization request related information, it is further determined whether the first API invoker is authorized.

[0174] In some embodiments of the first aspect, the determining whether the first API invoker is authorized comprises:

[0175] mapping the service information included in the third information to a first data processing purpose;

[0176] if the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner matches the first data processing purpose, performing an authorization process on the first API invoker; or

[0177] if the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner does not match the first data processing purpose, refusing to authorize the first API invoker.

[0178] In the above embodiments, whether the first API invoker is authorized is determined by verifying whether the service information expected by the first API invoker matches the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner, so as to ensure the security of authorization.

[0179] In some embodiments of the first aspect, the determining whether the first API invoker is authorized comprises:

[0180] mapping the service information included in the third information to a first data type and a first data processing purpose;

[0181] if the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner match the first data type and the first data processing purpose, performing an authorization process on the first API invoker; or

[0182] if the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner do not match the first data type and the first data processing purpose, refusing to authorize the first API invoker.

[0183] In the above embodiments, whether the first API invoker is authorized is determined by verifying whether the service information expected by the first API invoker matches the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner, so as to ensure the security of authorization.

[0184] In a second aspect, the embodiments of the present disclosure provide an information processing method, which is performed by a second node, and the method comprises:

[0185] sending first information to a first node, the first information including authorization-related information related to the second node.

[0186] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises:

[0187] receiving second information sent by the first node, the second information being used for requesting the second node to provide authorization-related information of a first resource owner related to the second node.

[0188] With reference to some embodiments of the second aspect, in some embodiments, the first resource owner is related to the second node, and the address information of the second node is obtained by the first node from a fourth node or from a sixth node.

[0189] With reference to some embodiments of the second aspect, in some embodiments, the authorization-related information comprises at least one of the following information:

[0190] identification information of the first resource owner;

[0191] identification information of an application programming interface (API) invoker;

[0192] resource information;

[0193] data type;

[0194] number processing purpose.

[0195] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises:

[0196] receiving twelfth information sent by the first node, the twelfth information being used for indicating that authorization information configuration fails; or

[0197] receiving thirteenth information sent by the first node, the thirteenth information being used for indicating that authorization information configuration succeeds.

[0198] The twelfth information further indicates that the second node configures authorization information related to identification information of an authenticated resource owner related to the second node.

[0199] In a third aspect, embodiments of the present disclosure provide an information processing method, the method being performed by a third node, and the method comprising:

[0200] sending third information to a first node, the third information comprising authorization request-related information of a second resource owner related to the third node;

[0201] The third information is used for requesting authorization of a first API invoker, and the second resource owner is an expected resource owner of the first API invoker.

[0202] In some embodiments of the third aspect, in some embodiments, the authorization request related information comprises at least one of the following information:

[0203] identification information of the second resource owner;

[0204] identification information of the first API invoker;

[0205] service information, wherein the service information comprises at least one of the following: a service, a service operation, and a service API;

[0206] a data type;

[0207] a data processing purpose.

[0208] In some embodiments of the third aspect, in some embodiments, the method further comprises:

[0209] receiving fourteenth information sent by the first node, the fourteenth information being used to indicate that the authorization information configuration fails; or

[0210] receiving fifteenth information sent by the first node, the fifteenth information being used to indicate that the authorization request fails;

[0211] wherein the fourteenth information further comprises identification information of an authenticated resource owner related to the third node, which is configured by the third node and related to the identification information of the authenticated resource owner related to the third node;

[0212] wherein the fifteenth information is used to indicate that a data type and a data processing purpose comprised in the authorization request related information do not match the service information comprised in the third information; or

[0213] the fifteenth information is used to indicate that the data processing purpose comprised in the authorization request related information does not match the service information comprised in the third information.

[0214] In some embodiments of the third aspect, in some embodiments, the method further comprises:

[0215] receiving sixteenth information sent by the first API invoker, the sixteenth information comprising address information of the first node and the authorization request related information.

[0216] In some embodiments of the third aspect, in some embodiments, the method further comprises performing any one of the following judgment operations:

[0217] determining whether the identification information of the second resource owner comprised in the authorization request related information is consistent with identification information of a resource owner related to the third node;

[0218] determining whether the address information of the first node stored locally by the third node is same as the address information of the first node provided by the first API invoker; or

[0219] determining whether the address information of the first node provided by the resource owner related to the third node is same as the address information of the first node provided by the first API invoker; or

[0220] determining whether the data type and the data processing purpose included in the authorization request related information are authorized by the third node;

[0221] determining whether the data type and the data processing purpose included in the authorization request related information are authorized by the resource owner related to the third node.

[0222] In some embodiments of the third aspect, in some embodiments, the method further includes:

[0223] if the determination result of any of the determination operations is negative, refusing to authorize the first API invoker.

[0224] In a fourth aspect, the embodiments of the present disclosure provide an information processing method, which is performed by a first API invoker, and includes:

[0225] sending third information to a first node, the third information including authorization request related information of a second resource owner related to a third node;

[0226] The third information is used to request authorization of the first API invoker, and the second resource owner is a resource owner expected by the first API invoker.

[0227] In some embodiments of the fourth aspect, in some embodiments, the authorization request related information includes at least one of the following information:

[0228] identification information of the second resource owner;

[0229] identification information of the first API invoker;

[0230] service information, wherein the service information includes at least one of a service, a service operation, and a service API;

[0231] a data type;

[0232] a data processing purpose.

[0233] In a fifth aspect, the embodiments of the present disclosure provide an information processing method, which is performed by a second API invoker, and includes:

[0234] receive fourth information sent by the first node, the fourth information being used for notifying that authorization of the second API invoker is revoked, the fourth information indicating revoked authorization information;

[0235] send fifth information to the first node, the fifth information being used for feeding back that authorization is revoked.

[0236] With reference to some embodiments of the fifth aspect, in some embodiments, the authorization information comprises at least one of the following information:

[0237] identification information of a first resource owner related to the second node;

[0238] identification information of the second API invoker;

[0239] service information, wherein the service information comprises at least one of the following: a service, a service operation, and a service API;

[0240] identification information of the fourth node;

[0241] resource information;

[0242] a data type;

[0243] a data processing purpose.

[0244] With reference to some embodiments of the fifth aspect, in some embodiments, the second API invoker runs on the second node, and address information of the second node is obtained by the first node from the fourth node or from a sixth node.

[0245] In a sixth aspect, the embodiments of the present disclosure provide an information processing method, the method being performed by a fourth node, and the method comprising:

[0246] receiving sixth information sent by a first node, the sixth information being used for requesting the fourth node to provide address information of a second node;

[0247] sending seventh information to the first node, the seventh information comprising the address information of the second node;

[0248] wherein the sixth information comprises identification information of a first resource owner related to the second node, and / or identification information of the second API invoker; the first resource owner is related to the second node, and the second API invoker runs on the second node.

[0249] With reference to some embodiments of the sixth aspect, in some embodiments, the method further comprises:

[0250] sending eighth information to a fifth node, the eighth information being used for requesting the fifth node to provide identification information of the second node;

[0251] receiving ninth information sent by the fifth node, the ninth information comprising identification information of the second node;

[0252] sending tenth information to a sixth node, the tenth information being used for requesting the sixth node to provide address information of the second node, the tenth information comprising identification information of the second node;

[0253] receiving eleventh information sent by the sixth node, the eleventh information comprising the address information of the second node;

[0254] The eighth information comprises identification information of the first resource owner and / or identification information of the second API invoker.

[0255] In a seventh aspect, embodiments of the present disclosure provide an information processing method, the method being performed by a fifth node, and the method comprising:

[0256] receiving eighth information sent by a first node or a fourth node, the eighth information being used for requesting the fifth node to provide identification information of a second node;

[0257] sending ninth information to the first node or the fourth node, the ninth information comprising the identification information of the second node;

[0258] The eighth information comprises identification information of the first resource owner and / or identification information of the second API invoker.

[0259] In an eighth aspect, embodiments of the present disclosure provide an information processing method, the method being performed by a sixth node, and the method comprising:

[0260] receiving tenth information sent by a first node or a fourth node, the tenth information being used for requesting the sixth node to provide address information of a second node, the tenth information comprising identification information of the second node;

[0261] sending eleventh information to the first node or the fourth node, the eleventh information comprising the address information of the second node.

[0262] In a ninth aspect, embodiments of the present disclosure provide a first node, comprising:

[0263] a first transceiver module, configured to obtain first information, the first information comprising authorization-related information related to a second node.

[0264] In a tenth aspect, embodiments of the present disclosure provide a second node, comprising:

[0265] The second transceiver module is configured to send first information to the first node, the first information comprising authorization-related information related to the second node.

[0266] In a eleventh aspect, the embodiments of the present disclosure provide a third node, comprising:

[0267] The third transceiver module is configured to send third information to the first node, the third information comprising authorization request-related information of a second resource owner related to the third node.

[0268] The third information is used to request authorization for the first API invoker, and the second resource owner is an expected resource owner of the first API invoker.

[0269] In a twelfth aspect, the embodiments of the present disclosure provide a first API invoker, comprising:

[0270] The fourth transceiver module is configured to send third information to the first node, the third information comprising authorization request-related information of a second resource owner related to the third node.

[0271] The third information is used to request authorization for the first API invoker, and the second resource owner is an expected resource owner of the first API invoker.

[0272] In a thirteenth aspect, the embodiments of the present disclosure provide a second API invoker, comprising:

[0273] The fifth transceiver module is configured to receive fourth information sent by the first node, the fourth information being used to notify that authorization of the second API invoker is revoked, and the fourth information indicating revoked authorization information.

[0274] The first node sends fifth information, and the fifth information is used to feed back that the authorization has been revoked.

[0275] In a fourteenth aspect, the embodiments of the present disclosure provide a communication device, comprising:

[0276] One or more processors;

[0277] The terminal is configured to perform the optional implementation of the first aspect or the second aspect or the third aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0278] In a fifteenth aspect, the embodiments of the present disclosure provide a communication device, comprising:

[0279] One or more processors;

[0280] The network device is configured to perform the optional implementation of the fourth aspect or the fifth aspect.

[0281] In a sixteenth aspect, a computer-readable storage medium is provided, which stores executable instructions. The executable instructions are loaded and executed by a processor to implement the method described in the optional implementation of the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0282] In a seventeenth aspect, a communication system is provided, which comprises a first node and a second node. The first node is configured to implement the method described in the optional implementation of the first aspect, and the second node is configured to implement the method described in the optional implementation of the second aspect.

[0283] In an eighteenth aspect, a program product is provided. When the program product is executed by a communication device, the communication device is caused to perform the method described in the optional implementation of the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0284] In a nineteenth aspect, a computer program is provided. When the computer program is executed on a computer, the computer is caused to perform the method described in the optional implementation of the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0285] In a twentieth aspect, a chip or chip system is provided, which comprises processing circuitry configured to perform the method described in the optional implementation of the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect or the sixth aspect or the seventh aspect or the eighth aspect.

[0286] It can be understood that the apparatus for random access, the communication device, the communication system, the storage medium, the program product, and the computer program are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here again. The communication device can be a terminal or a network device.

[0287] The embodiments of the present disclosure propose an information processing method, an apparatus, a communication device, a communication system, and a storage medium.

[0288] In some embodiments, the information processing method and the information processing method, the apparatus for random access, and the like can be replaced with each other, the apparatus for random access and the information processing apparatus, the communication apparatus, and the like can be replaced with each other, and the information processing system and the communication system can be replaced with each other.

[0289] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the embodiments of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing part of the steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, part or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with optional implementation of other embodiments.

[0290] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0291] The terms used in the embodiments of the present disclosure are only for the purpose of describing the specific embodiments, and not as a limitation on the embodiments of the present disclosure.

[0292] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.

[0293] In the embodiments of the present disclosure, "a plurality of" means two or more.

[0294] In some embodiments, the terms "at least one of", "at least one of", "at least one of", "one or more", "a plurality of", "multiple" and the like can be replaced with each other.

[0295] The description manner such as "at least one of A, B, C, …", "A and / or B and / or C, …" and the like in the embodiments of the present disclosure includes any one of A, B, C, … existing alone, and also includes any combination of any multiple of A, B, C, …, each of which can exist alone; for example, "at least one of A, B, C" includes a case of A alone, a case of B alone, a case of C alone, a case of combination of A and B, a case of combination of A and C, a case of combination of B and C, and a case of combination of A and B and C; for example, A and / or B includes a case of A alone, a case of B alone, and a case of combination of A and B.

[0296] In some embodiments, the description manner such as "A in a case, B in another case", "in response to a case A, in response to another case B" and the like can include the following technical solutions according to the case: A is executed regardless of B, that is, A in some embodiments; B is executed regardless of A, that is, B in some embodiments; A and B are selectively executed, that is, from A and B, execution is selected in some embodiments; A and B are both executed, that is, A and B in some embodiments. When there are more branches of A, B, C and the like, it is similar to the above.

[0297] The prefix words "first", "second" and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description object is "information", and "first configuration" and "second configuration" can be the same information or different information, and the contents thereof can be the same or different.

[0298] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0299] In some embodiments, the terms "in response to", "in response to determining", "in the event that", "when", "if", and the like can be replaced with each other.

[0300] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.

[0301] In some embodiments, an apparatus and the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments, and the terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like can be replaced with each other.

[0302] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.

[0303] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", "client", and the like can be replaced with each other.

[0304] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, for a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (for example, also referred to as device-to-device (D2D), vehicle-to-everything (V2X), and the like), the embodiments of the present disclosure can also be applied. In this case, it can also be configured as a structure in which the terminal has all or part of the functions of the access network device. In addition, the language of "uplink", "downlink", and the like can also be replaced with language corresponding to the inter-terminal communication (for example, "side").

[0305] For example, the uplink channel, the downlink channel, and the like can be replaced with a sidelink channel, and the uplink, the downlink, and the like can be replaced with a sidelink.

[0306] In some embodiments, the terms "uplink", "uplink", "physical uplink", and the like can be replaced with each other, the terms "downlink", "downlink", "physical downlink", and the like can be replaced with each other, and the terms "side", "sidelink", "sidelink communication", "sidelink communication", "direct connection", "direct connection link", "direct connection communication", "direct connection link communication", and the like can be replaced with each other.

[0307] In some embodiments, the terms "downlink control information (DCI)", "downlink (DL) assignment", "DL DCI", "uplink (UL) grant", "UL DCI", and the like can be replaced with each other.

[0308] In some embodiments, the terms "physical downlink shared channel (PDSCH)", "DL data", and the like can be replaced with each other, and the terms "physical uplink shared channel (PUSCH)", "UL data", and the like can be replaced with each other.

[0309] In some embodiments, determination or judgment can be made by a value (0 or 1) represented by 1 bit, or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.

[0310] In some embodiments, "network" can be interpreted as devices (for example, access network devices, core network devices, and the like) contained in the network.

[0311] In some embodiments, obtaining data, information, and the like can comply with the laws and regulations of the country where the location is located.

[0312] In some embodiments, data, information, and the like can be obtained after obtaining the consent of the user.

[0313] FIG. 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0314] As shown in FIG. 1, the communication system 100 includes a terminal 101 and a network device 102.

[0315] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet (Pad), a wireless transceiver-equipped computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, and the like, but is not limited thereto.

[0316] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.

[0317] In some embodiments, the access network device is at least one of a node or a device that accesses a terminal to a wireless network, for example, an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, and the like, but is not limited thereto.

[0318] In some embodiments, the technical solutions of the embodiments of the present disclosure can be applied to an Open RAN architecture, at this time, the interfaces between or within the network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the flow and information interaction between the internal interfaces can be realized through software or programs.

[0319] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the network device, and the functions of part of the protocol layers are controlled by the CU, and the functions of the remaining part or all of the protocol layers are distributed in the DU and controlled by the CU. However, the present disclosure is not limited to this.

[0320] In some embodiments, the access network device can be one device, or a plurality of devices or device groups, and respectively includes all or part of the first network element, the second network element and the like. The network element can be virtual or physical. The network device includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next generation core (NGC), and the like.

[0321] In some embodiments, the core network device can be one device including one or more network elements, or a plurality of devices or device groups, and respectively includes all or part of the one or more network elements described above. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next generation core (NGC), and the like.

[0322] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed in the embodiments of the present disclosure are also applicable to similar technical problems.

[0323] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1, or part of the main bodies, but are not limited thereto. The main bodies shown in FIG. 1 are illustrative, and the communication system can include all or part of the main bodies in FIG. 1, or other main bodies other than those in FIG. 1. The number and form of each main body is arbitrary, and the connection relationship between the main bodies is illustrative. The main bodies can be connected or not connected, and the connection can be in any manner, can be direct or indirect, and can be wired or wireless.

[0324] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), systems using other random access, next-generation systems expanded based thereon, and the like. In addition, a plurality of systems can be combined (for example, a combination of LTE or LTE-A and 5G, and the like).

[0325] A resource owner can use CAPIF to authorize API invokers to access its own resources (e.g., location information). The resource owner can use the existing two authorization flows (i.e., authorization code flow, client credentials flow) for authorization.

[0326] In the above two authorization flows, the CAPIF system needs to use the authorization information provided by the resource owner to authorize the API invoker. However, at present, the communication system does not verify the authorization information provided by the resource owner. This will lead to malicious resource owners providing authorization information related to other resource owners (for example, resource owner A can provide authorization data related to resource owner B).

[0327] Based on the above wireless communication system, various embodiments of the communication method proposed by the present disclosure are described in detail below.

[0328] FIG. 2a is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2a, the information processing method is used in the communication system 100, and the method comprises:

[0329] S201, the second node sends first information to the first node.

[0330] In some embodiments, the first information comprises authorization-related information related to the second node.

[0331] In some embodiments, the first node can be a CAPIF authentication and authorization function, for example, it can include but is not limited to CCF (CAPIF core function) or an authorization function, wherein CAPIF is a common API framework, and API is an application programming interface.

[0332] In some embodiments, the authorization-related information related to the second node can be authorization-related information of a first resource owner related to the second node.

[0333] In some embodiments, the second node can be a node related to the first resource owner, for example, a terminal.

[0334] In some embodiments, the authorization-related information can include at least one of the following:

[0335] identification information of the first resource owner;

[0336] identification information of an application programming interface API invoker;

[0337] resource information;

[0338] data type;

[0339] data processing purpose.

[0340] In some embodiments, the authorization-related information includes resource information, data type, and data processing purpose, which can be used to indicate resource information, data type, and data processing purpose that the first API invoker is allowed to access.

[0341] In some embodiments, the authorization-related information includes resource information, data type, and data processing purpose, which can be used to indicate resource information, data type, and data processing purpose that the first API invoker is allowed to access.

[0342] In some embodiments, the first resource owner can be one of the following: an end user, a subscriber, or a terminal (UE).

[0343] In some embodiments, the API invoker (API invoker) can be one of the following: an application function, a terminal, an application residing on a UE, or a client in the UE, an application server, an application function.

[0344] It should be noted that the difference between the client and the application is that the client is a program deeply integrated with the underlying system of the terminal, for example, an edge enabler client (Edge Enabler Client) can enable the terminal to support edge computing functions.

[0345] In some embodiments, the identification information of the first resource owner can be at least one of the following:

[0346] Application layer identification of the first resource owner;

[0347] Subscription Permanent Identifier (SUPI, Subscription Permanent Identifier);

[0348] Generic Public Subscription Identifier (GPSI, Generic Public Subscription Identifier).

[0349] In some embodiments, the identification of the API invoker includes at least one of the following:

[0350] Application ID (Application ID);

[0351] Application function id (AF ID)

[0352] In some embodiments, the resource information can be a location, a quality of service (QoS), or the like.

[0353] In embodiments of the present disclosure, the API invoker can also be described as an API invoker, which is not limited.

[0354] In some embodiments, the first information can be an authorization policy configuration request, or the first information can be carried by the request, and the name of the first information is not limited.

[0355] In some embodiments, the above method can further include:

[0356] S202, the first node verifies the authorization related information of the first resource owner related to the second node.

[0357] In some embodiments, if the authorization related information includes the identification information of the first resource owner related to the second node, the first node can verify the identification information of the first resource owner based on the identification information of the authenticated resource owner related to the second node.

[0358] In some embodiments, the identification information of the authenticated resource owner related to the second node can be obtained by the first node based on the source IP address information or the identification information (TLS session ID) of the secure transmission layer protocol (TLS) session associated with the second node.

[0359] In some embodiments, if the identification information of the authenticated resource owner is inconsistent with the identification information of the first resource owner, the first node can refuse to accept the authorization related information.

[0360] In some embodiments, if the identification information of the authenticated resource owner is inconsistent with the identification information of the first resource owner, the first node can refuse to store the authorization related information.

[0361] In some embodiments, if the identification information of the authenticated resource owner is consistent with the identification information of the first resource owner, the first node can accept the authorization related information.

[0362] In some embodiments, the above method can further include:

[0363] S203, the first node sends the twelfth information or the thirteenth information to the second node to feed back the verification result.

[0364] In some embodiments, if the identity information of the authenticated resource owner is inconsistent with the identity information of the first resource owner, the first node can send twelfth information indicating that the authorization information configuration fails to the second node.

[0365] In some embodiments, the twelfth information further indicates that the authorization information related to the identity information of the authenticated resource owner is configured.

[0366] In some embodiments, if the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, the first node can send thirteenth information indicating that the authorization configuration succeeds to the second node.

[0367] In some embodiments, the twelfth information or the thirteenth information can be an authorization policy configuration response, or the twelfth information or the thirteenth information can be carried by the response, and the name of the twelfth information or the thirteenth information is not limited thereto.

[0368] In some embodiments, the above method can further include:

[0369] S204, the first node stores the authorization related information of the first resource owner related to the second node.

[0370] In some embodiments, if the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, the first node can store the authorization related information.

[0371] In some embodiments, if the identity information of the authenticated resource owner is inconsistent with the identity information of the first resource owner, the above method can further include:

[0372] The first node associates the identity information of the authenticated resource owner with the authorization related information; or,

[0373] The first node maps the data type and the data processing purpose included in the authorization related information to service information, and associates the identity information of the authenticated resource owner with the service information, wherein the service information includes at least one of a service, a service operation, and a service API.

[0374] In some embodiments, the first node can generate the authorization policy related to the resource owner by associating the identity information of the authenticated resource owner with the authorization related information.

[0375] In some embodiments, the first node can generate the authorization policy related to the resource owner by mapping the data type and data processing purpose included in the authorization related information into service information, and associating the identification information of the authenticated resource owner and the service information.

[0376] In some embodiments, before step S201, the above method can further include:

[0377] S200, the first node and the second node can perform a mutual authentication process.

[0378] In some embodiments, the first node can perform mutual authentication with the second node based on a certificate, or a generic bootstrapping authentication (GBA) mechanism, or an AKMA mechanism.

[0379] In some embodiments, the first node is a CAPIF core function, and the second node is a terminal. The terminal can authenticate the identity of the CAPIF core function based on a certificate, and the CAPIF core function can authenticate the identity of the terminal based on the GBA, AKMA mechanism, or certificate. Optionally, the CAPIF core function can generate a certificate for the resource owner after the resource owner is onboarded through the terminal.

[0380] In some embodiments, the first node is an authorization function in a CAPIF core function, and the second node is a terminal. The terminal can authenticate the identity of the authorization function based on a certificate, and the authorization function can authenticate the identity of the terminal based on the GBA, AKMA mechanism, or certificate. Meanwhile, the authorization function can authenticate the resource owner based on the certificate of the resource owner and a resource owner function running on the terminal.

[0381] In some embodiments, the certificate can be assigned by the CAPIF core function.

[0382] In some embodiments, the resource owner authenticates the identity of the first node through the second node.

[0383] In some embodiments, the first node authenticates the identity of the resource owner through the second node.

[0384] In some embodiments, the first node can authenticate the identity of the resource owner through a password.

[0385] In some embodiments, the second node verifies the identity of the first node by checking a certificate of the first node.

[0386] In some embodiments, the resource owner verifies the identity of the first node by verifying a certificate of the first node through the second node.

[0387] In some embodiments, the first node can be a CCF (CAPIF core function).

[0388] In some embodiments, the first node can be an Authorization function in a CCF (CAPIF core function).

[0389] In some embodiments, the second node can be an ROF (resource owner function).

[0390] In some embodiments, the second node can be a terminal running an ROF (resource owner function).

[0391] In the above embodiments, if the second node related to the first resource owner is a first terminal, the API invoker is another terminal or an AF (API Function), which is not limited by the present disclosure.

[0392] In this embodiment, the first resource owner can configure the authorization-related information of the first resource owner to the first node through the second node. In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and the terms of "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "data", etc. can be replaced with each other.

[0393] In some embodiments, the terms of "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive", etc. can be replaced with each other.

[0394] In some embodiments, the terms "certain", "preset", "pre-set", "set", "indicated", "a certain", "any", "first", and the like can be replaced with each other, and "certain A", "preset A", "pre-set A", "set A", "indicated A", "a certain A", "any A", "first A" can be interpreted as A predetermined in a protocol or the like, or A obtained by setting, configuring, or indicating, or a certain A, a certain A, any A, or first A, but are not limited thereto.

[0395] In some embodiments, the terms "in the case of", "when", "if", and the like can be replaced with each other.

[0396] The method related to the embodiments of the present disclosure can include at least one of steps S200 to S204. For example, step S201 can be implemented as an independent embodiment, steps S201 and S202 can be implemented as an independent embodiment, steps S201, S202, and S203 can be implemented as an independent embodiment, steps S201 and S204 can be implemented as an independent embodiment, steps S200 and S201 can be implemented as an independent embodiment, steps S200, S201, and S202 can be implemented as an independent embodiment, steps S200, S201, S202, and S203 can be implemented as an independent embodiment, steps S200, S201, and S204 can be implemented as an independent embodiment, but are not limited thereto.

[0397] In some embodiments, step S200 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0398] In some embodiments, step S202 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0399] In some embodiments, step S203 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0400] In some embodiments, step S204 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0401] It should be understood that the method related to the embodiments of the present disclosure includes various steps which can be exchanged in order, combined, and implemented without conflict.

[0402] It should also be understood that the steps included in the method according to the embodiments of the present disclosure can be implemented independently, or combined and implemented in any order without contradiction, for example, the combination of steps in the embodiments of the present disclosure, or the combination of steps in the embodiments of the present disclosure and one or more steps included in one or more other embodiments.

[0403] It should be noted that the "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0404] FIG. 2b is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2b, the information processing method is used in the communication system 100, and the method comprises:

[0405] S210, the first node sends sixth information to the fourth node.

[0406] In some embodiments, the sixth information is used to request the fourth node to provide address information of the second node.

[0407] In some embodiments, the sixth information comprises identification information of the first resource owner. In some embodiments, the second node is a node used by the first resource owner.

[0408] In some embodiments, the second node is a terminal used by the first resource owner.

[0409] Optionally, the identification information of the first resource owner can be a GPSI (Generic Public Subscription Identifier), but is not limited thereto.

[0410] In some embodiments, the fourth node can be an AEF (API Exposing Function).

[0411] S211, the fourth node sends eighth information to the fifth node.

[0412] In some embodiments, the eighth information is used to request the fifth node to provide identification information of the second node.

[0413] In some embodiments, the eighth information comprises identification information of the first resource owner.

[0414] In some embodiments, the identification of the first resource owner is a GPSI.

[0415] In some embodiments, after obtaining the identification information of the first resource owner provided by the first node, the fourth node can request the fifth node for identification information of the second node corresponding to the identification information of the first resource owner.

[0416] In some embodiments, the fifth node can be a core network function node, for example, it can be a UDM (Unified Data Management) node or a UDR (Unified Data Repository) node.

[0417] S212, the fourth node receives the ninth information sent by the fifth node.

[0418] In some embodiments, the ninth information includes the identification information of the second node.

[0419] Optionally, the second node can be a terminal related to the first resource owner, and the identification information of the second node is the identification information of the terminal, for example, it can be SUPI (Subscription Permanent Identifier), but is not limited thereto.

[0420] In some embodiments, the fifth node can determine the identification information of the second node corresponding to the identification information of the first resource owner based on the identification information of the first resource owner provided by the fourth node, and feed back to the fourth node.

[0421] S213, the fourth node sends the tenth information to the sixth node.

[0422] In some embodiments, the tenth information is used to request the sixth node to provide address information of the second node.

[0423] In some embodiments, the address information of the second node can be an IP address of the second node.

[0424] In some embodiments, the tenth information includes the identification information of the second node.

[0425] In some embodiments, after obtaining the identification information of the second node from the fifth node, the fourth node can request the sixth node for address information of the second node corresponding to the identification information of the second node.

[0426] In some embodiments, the sixth node can be a core network function node, for example, it can be a UPF (User Plane Function), or it can be a BSF (Binding Support Function).

[0427] S214, the fourth node receives the eleventh information sent by the sixth node.

[0428] In some embodiments, the eleventh information comprises address information of the second node.

[0429] In some embodiments, the sixth node can determine the address information of the corresponding second node based on the identification information of the second node provided by the fourth node, and feed back to the fourth node.

[0430] S215, the fourth node sends seventh information to the first node.

[0431] In some embodiments, the seventh information comprises address information of the second node.

[0432] In some embodiments, the fourth node can provide the address information of the corresponding second node to the first node after obtaining the address information of the corresponding second node through the fifth node and the sixth node based on the identification information of the first resource owner provided by the first node. The first node learns the address information of the second node, and can request the second node for authorization related information of the first resource owner related to the second node.

[0433] S216, the first node sends second information to the second node.

[0434] In some embodiments, the second information is used to request the second node to provide authorization related information of the first resource owner related to the second node.

[0435] In some embodiments, the second information can be an authorization policy related request (Authorization Policies Related Request), or the second information can be carried by the request, and the name of the second information is not limited.

[0436] S217, the second node sends first information to the first node.

[0437] In some embodiments, the first information comprises authorization related information of the first resource owner related to the second node.

[0438] In some embodiments, the authorization related information can comprise at least one of the following:

[0439] identification information of the first resource owner;

[0440] identification information of an application programming interface (API) caller;

[0441] resource information;

[0442] data type;

[0443] data processing purpose.

[0444] In some embodiments, the resource information, data type, and data processing purpose included in the authorization related information can be used to indicate the resource information, data type, and data processing purpose that the first API invoker is allowed to use.

[0445] In some embodiments, the resource information, data type, and data processing purpose included in the authorization related information can be used to indicate the resource information, data type, and data processing purpose that the first API invoker is allowed to use.

[0446] In some embodiments, the first information can be an authorization policies related response, or the first information can be carried by the response, and the name of the first information is not limited thereto.

[0447] In some embodiments, the above method can further include:

[0448] S218, the first node verifies the authorization related information of the first resource owner related to the second node.

[0449] The optional implementation of step S218 can refer to the optional implementation of step S202 in FIG. 2a, which will not be repeated here.

[0450] In some embodiments, the above method can further include:

[0451] S219, the first node sends the twelfth information or the thirteenth information to the second node to feed back the verification result.

[0452] The optional implementation of step S219 can refer to the optional implementation of step S203 in FIG. 2a, which will not be repeated here.

[0453] In some embodiments, the above method can further include:

[0454] S2110, the first node stores the authorization related information of the first resource owner related to the second node.

[0455] The optional implementation of step S2110 can refer to the optional implementation of step S204 in FIG. 2a, which will not be repeated here.

[0456] In some embodiments, if the authorization related information does not include the identification information of the first resource owner related to the second node, the above method can further include:

[0457] The first node associates the identification information of the authenticated resource owner with the authorization related information; or

[0458] The first node maps the data type and data processing purpose included in the authorization-related information into service information, and associates the identification information of the authenticated resource owner with the service information.

[0459] Optionally, the service information includes at least one of a service, a service operation, and a service API.

[0460] In some embodiments, before step S216, the above method can further include:

[0461] S2100, the first node and the second node can perform a mutual authentication process.

[0462] Optionally, the implementation of step S2100 can refer to the optional implementation of step S200 in FIG. 2a, which will not be repeated here.

[0463] In this embodiment, the first node can obtain the address information of the second node related to the first resource owner based on the identification information of the first resource owner, by interacting with the fourth node, the fourth node interacting with the fifth node and the sixth node, and requesting the second node to provide the authorization-related information of the first resource owner.

[0464] The method related to the embodiments of the present disclosure can include at least one of steps S2100-S2110. For example, step S217 can be implemented as an independent embodiment, steps S216, S217 can be implemented as independent embodiments, steps S210-S217 can be implemented as independent embodiments, steps S216, S217, S218 can be implemented as independent embodiments, steps S216-S219 can be implemented as independent embodiments, steps S216, S217, S2110 can be implemented as independent embodiments, steps S2100, S216, S217 can be implemented as independent embodiments, steps S2100, S210-S217 can be implemented as independent embodiments, steps S2100, S216, S217, S218 can be implemented as independent embodiments, steps S2100, S216-S219 can be implemented as independent embodiments, steps S2100, S216, S217, S2110 can be implemented as independent embodiments, but are not limited thereto.

[0465] In some embodiments, step S2100 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0466] In some embodiments, steps S210-S215 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0467] In some embodiments, step S218 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0468] In some embodiments, step S219 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0469] In some embodiments, step S2110 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0470] It should be understood that the steps included in the method according to the embodiments of the present disclosure can be exchanged in any order, combined and implemented without conflict.

[0471] It should also be understood that the steps included in the method according to the embodiments of the present disclosure can be implemented individually, or combined and implemented in any order without conflict, for example, the steps in the embodiments of the present disclosure are combined, or the steps in the embodiments of the present disclosure are combined with one or more steps included in one or more other embodiments.

[0472] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0473] FIG. 2c is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2c, the information processing method is used in the communication system 100, and the method includes:

[0474] S221, the first node sends eighth information to the fifth node.

[0475] In some embodiments, the eighth information is used to request the fifth node to provide the identification information of the second node.

[0476] In some embodiments, the eighth information includes the identification information of the first resource owner.

[0477] In some embodiments, the identification of the first resource owner is GPSI.

[0478] In some embodiments, the first node can directly request the fifth node for the identification information of the second node corresponding to the identification information of the first resource owner.

[0479] In some embodiments, the fifth node can be a core network function node, for example, it can be a UDM (Unified Data Management) node or a UDR (Unified Data Repository) node.

[0480] S222, the first node receives ninth information sent by the fifth node.

[0481] In some embodiments, the ninth information comprises identification information of the second node.

[0482] Optionally, the second node can be a terminal associated with the first resource owner, and the identification information of the second node is identification information of the terminal, for example, can be SUPI (Subscription Permanent Identifier, Subscription Permanent Identifier), but is not limited thereto.

[0483] In some embodiments, the fifth node can determine the identification information of the corresponding second node based on the identification information of the first resource owner provided by the first node, and feed back to the first node.

[0484] In some embodiments, the second node is a node associated with the resource owner.

[0485] In some embodiments, the second node is a terminal used by the resource owner.

[0486] S223, the first node sends tenth information to the sixth node.

[0487] In some embodiments, the tenth information is used to request the sixth node to provide address information of the second node.

[0488] In some embodiments, the address information of the second node can be an IP address of the second node.

[0489] In some embodiments, the tenth information comprises identification information of the second node.

[0490] In some embodiments, after the first node obtains the identification information of the second node from the fifth node, the first node can request the sixth node for address information of the second node corresponding to the identification information of the second node.

[0491] In some embodiments, the sixth node can be a core network function node, for example, it can be a UPF (User Plane Function, User Plane Function), or it can be a BSF (Binding Support Function, Binding Support Function).

[0492] S224, the first node receives eleventh information sent by the sixth node.

[0493] In some embodiments, the eleventh information comprises address information of the second node.

[0494] In some embodiments, the sixth node can determine the address information of the corresponding second node based on the identification information of the second node provided by the first node, and feed back to the first node.

[0495] S225, the first node sends the second information to the second node.

[0496] The optional implementation of step S225 can refer to the optional implementation of step S216 in FIG. 2b, which will not be repeated here.

[0497] S226, the second node sends the first information to the first node.

[0498] The optional implementation of step S226 can refer to the optional implementation of step S217 in FIG. 2b, which will not be repeated here.

[0499] In some embodiments, the above method can further include:

[0500] S227, the first node verifies the authorization related information of the first resource owner related to the second node.

[0501] The optional implementation of step S227 can refer to the optional implementation of step S202 in FIG. 2a, which will not be repeated here.

[0502] S228, the first node sends the twelfth information or the thirteenth information to the second node to feed back the verification result.

[0503] The optional implementation of step S228 can refer to the optional implementation of step S203 in FIG. 2a, which will not be repeated here.

[0504] In some embodiments, the above method can further include:

[0505] S229, the first node stores the authorization related information of the first resource owner related to the second node.

[0506] The optional implementation of step S228 can refer to the optional implementation of step S204 in FIG. 2a, which will not be repeated here.

[0507] In some embodiments, before step S225, the above method can further include:

[0508] S220, the first node and the second node can perform a mutual authentication process.

[0509] The optional implementation of step S220 can refer to the optional implementation of step S200 in FIG. 2a, which will not be repeated here.

[0510] The method related to the embodiments of the present disclosure can comprise at least one of steps S220-S229. For example, step S226 can be implemented as an independent embodiment, steps S225, S226 can be implemented as an independent embodiment, steps S221-S224 can be implemented as an independent embodiment, steps S225, S226, S227 can be implemented as an independent embodiment, steps S225-S228 can be implemented as an independent embodiment, steps S225, S226, S229 can be implemented as an independent embodiment, steps S220, S225, S226 can be implemented as an independent embodiment, steps S220, S221-S226 can be implemented as an independent embodiment, steps S220, S225, S226, S227 can be implemented as an independent embodiment, steps S220, S225-S228 can be implemented as an independent embodiment, steps S220, S225, S226, S229 can be implemented as an independent embodiment, but are not limited thereto.

[0511] In some embodiments, step S220 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0512] In some embodiments, steps S221-S224 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0513] In some embodiments, step S228 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0514] In some embodiments, step S229 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0515] It should be understood that the steps included in the method related to the embodiments of the present disclosure can be arbitrarily exchanged in order and combined for implementation without conflict.

[0516] It should also be understood that the steps included in the method related to the embodiments of the present disclosure can be implemented individually, or can be arbitrarily adjusted in order and combined for implementation without conflict, for example: combination of steps in the embodiments of the present disclosure, or combination of steps in the embodiments of the present disclosure and one or more steps included in one or more other embodiments.

[0517] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0518] FIG. 2d is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2d, the information processing method is used for the communication system 100, and the method comprises the following steps.

[0519] S230. The first node sends sixth information to the fourth node.

[0520] In some embodiments, the sixth information is used to request the fourth node to provide address information of the first terminal.

[0521] In some embodiments, the sixth information comprises identification information of the second API invoker.

[0522] Optionally, the identification information of the second API invoker can be a GPSI (Generic Public Subscription Identifier), but is not limited thereto.

[0523] In some embodiments, the fourth node can be an AEF (API Exposing Function).

[0524] S231. The fourth node sends eighth information to the fifth node.

[0525] In some embodiments, the eighth information is used to request the fifth node to provide identification information of the second node.

[0526] In some embodiments, the eighth information comprises identification information of the second API invoker.

[0527] In some embodiments, after the fourth node obtains the identification information of the second API invoker provided by the first node, the fourth node can request the fifth node for identification information of the second node corresponding to the identification information of the second API invoker.

[0528] In some embodiments, the fifth node can be a core network function node, for example, it can be a UDM (Unified Data Management) node or a UDR node.

[0529] S232. The fourth node receives ninth information sent by the fifth node.

[0530] In some embodiments, the ninth information comprises identification information of the second node.

[0531] Optionally, the second node running the second API invoker can be a terminal, i.e., the second API invoker runs on the terminal, and the identification information of the second node is identification information of the terminal, for example, can be a SUPI (Subscription Permanent Identifier, Subscription Permanent Identifier), but is not limited thereto.

[0532] In some embodiments, the fifth node can determine the identification information of the corresponding second node based on the identification information of the second API invoker provided by the fourth node, and feed back to the fourth node.

[0533] S233, the fourth node sends tenth information to the sixth node.

[0534] The optional implementation of step S233 can refer to the optional implementation related to step S213 in FIG. 2b, which will not be repeated here.

[0535] S234, the fourth node receives eleventh information sent by the sixth node.

[0536] The optional implementation of step S234 can refer to the optional implementation related to step S214 in FIG. 2b, which will not be repeated here.

[0537] S235, the fourth node sends seventh information to the first node.

[0538] In some embodiments, the seventh information includes address information of the second node.

[0539] In some embodiments, the fourth node can provide the first node with the address information of the corresponding second node after obtaining the address information of the corresponding second node through the fifth node and the sixth node based on the identification information of the second API invoker provided by the first node. The first node learns the address information of the second node, and can notify the second API invoker running on the second node that the authorization is revoked.

[0540] In some embodiments, the address information of the second node is IP address information of the second node.

[0541] S236, the first node sends fourth information to the second API invoker.

[0542] In some embodiments, the fourth information is used to notify the second API invoker that the authorization is revoked.

[0543] In some embodiments, since the second API invoker runs on the second node, the first node can also send the fourth information to the second node to notify the second API invoker running on the second node that the authorization is revoked.

[0544] In some embodiments, the fourth information can indicate revoked authorization information.

[0545] In some embodiments, the authorization information comprises at least one of the following information:

[0546] identification information of a first resource owner related to the second node;

[0547] identification information of the second API invoker;

[0548] service information, wherein the service information comprises at least one of the following: a service, a service operation, a service API;

[0549] identification information of the fourth node;

[0550] resource information;

[0551] a data type;

[0552] a data processing purpose.

[0553] In some embodiments, the resource information, the data type, and the data processing purpose comprised in the authorization information can be used to indicate resource information, a data type, and a data processing purpose of a resource owner related to the second API invoker that is authorized.

[0554] In some embodiments, the information comprised in the authorization information, such as the resource information, the data type, and the data processing purpose, can be understood as resource information, a data type, and a data processing purpose of a resource owner that has been authorized to the second API invoker.

[0555] In some embodiments, the resource information, the data type, and the data processing purpose comprised in the authorization information can be used to indicate service information, resource information, a data type, and a data processing purpose of the second API invoker that is authorized.

[0556] In some embodiments, if the token comprises the authorization information, the fourth information can indicate identification of the token that needs to be revoked, thereby indicating revoked authorization information.

[0557] It should be noted that the information in the authorization information, such as the data type and the data processing purpose, is information agreed by the resource owner.

[0558] S237, the second API invoker sends fifth information to the first node.

[0559] In some embodiments, the fifth information is used to feed back that the authorization has been revoked.

[0560] In some embodiments, the second API invoker can feed back to the first node that the authorization is revoked; or the second node run by the second API invoker can feed back to the first node that the authorization of the second API invoker is revoked.

[0561] In some embodiments, before step S236, the above method can further include:

[0562] S2300, the first node and the second API invoker can perform a mutual authentication process.

[0563] In some embodiments, the first node can perform mutual identity authentication with the second API invoker based on a certificate, or a generic bootstrapping architecture (GBA), or an AKMA mechanism.

[0564] In some embodiments, the first node is a CAPIF core function, the second API invoker can perform identity authentication on the CAPIF core function based on a certificate, and the CAPIF core function can perform identity authentication on the second API invoker based on the GBA, AKMA mechanism or certificate. Optionally, the CAPIF core function can generate a certificate for the second API invoker after onboarding of the second API invoker.

[0565] In some embodiments, the first node is an authorization function, the second API invoker can perform identity authentication on the authorization function based on a certificate, and the authorization function can perform identity authentication on the second API invoker based on the GBA, AKMA mechanism or certificate. The certificate can be assigned by the CAPIF core function.

[0566] The method related to the embodiments of the present disclosure can include at least one of steps S2300, S230-S237. For example, step S236 can be implemented as an independent embodiment, steps S236, S237 can be implemented as an independent embodiment, steps S230-S235 can be implemented as an independent embodiment, steps S230, S235, S236, S237 can be implemented as an independent embodiment, steps S230, S235, S236 can be implemented as an independent embodiment, steps S2300, S230-S236 can be implemented as an independent embodiment, steps S2300, S230, S235, S236, S237 can be implemented as an independent embodiment, but not limited thereto.

[0567] In some embodiments, step S2300 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0568] In some embodiments, steps S230-S235 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0569] In some embodiments, step S237 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0570] It should be understood that the steps included in the method according to the embodiments of the present disclosure can be exchanged in any order, combined and implemented without conflict.

[0571] It should also be understood that the steps included in the method according to the embodiments of the present disclosure can be implemented individually, or combined and implemented in any order without conflict, for example, the steps in the embodiments of the present disclosure are combined, or the steps in the embodiments of the present disclosure are combined with one or more steps included in one or more other embodiments.

[0572] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0573] FIG. 2e is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2e, the information processing method is used in the communication system 100, and the method includes:

[0574] S241, the first node sends eighth information to the fifth node.

[0575] In some embodiments, the eighth information is used to request the fifth node to provide the identification information of the second node.

[0576] In some embodiments, the eighth information includes the identification information of the second API invoker.

[0577] In some embodiments, the first node can directly request the fifth node for the identification information of the second node corresponding to the identification information of the second API invoker.

[0578] In some embodiments, the fifth node can be a core network function node, for example, it can be a UDM (Unified Data Management) node or a UDR node.

[0579] S242, the first node receives ninth information sent by the fifth node.

[0580] In some embodiments, the ninth information includes the identification information of the second node.

[0581] Optionally, the second node run by the second API invoker can be a terminal, i.e., the second API invoker runs on the terminal, and the identification information of the second node is identification information of the terminal, for example, can be a SUPI (Subscription Permanent Identifier, Subscription Permanent Identifier), but is not limited thereto.

[0582] In some embodiments, the fifth node can determine the identification information of the corresponding second node based on the identification information of the second API invoker provided by the first node, and feed back to the first node.

[0583] S243, the first node sends the tenth information to the sixth node.

[0584] The optional implementation of step S243 can refer to the optional implementation related to step S223 in FIG. 2c, which will not be repeated here.

[0585] S244, the first node receives the eleventh information sent by the sixth node.

[0586] The optional implementation of step S244 can refer to the optional implementation related to step S224 in FIG. 2c, which will not be repeated here.

[0587] S245, the first node sends the fourth information to the second API invoker.

[0588] The optional implementation of step S245 can refer to the optional implementation related to step S236 in FIG. 2d, which will not be repeated here.

[0589] S246, the second API invoker sends the fifth information to the first node.

[0590] The optional implementation of step S246 can refer to the optional implementation related to step S237 in FIG. 2d, which will not be repeated here.

[0591] In some embodiments, before step S245, the above method can further include:

[0592] S240, the first node and the second API invoker can perform a mutual authentication process.

[0593] The optional implementation of step S240 can refer to the optional implementation related to step S2300 in FIG. 2d, which will not be repeated here.

[0594] The method according to the embodiments of the present disclosure can comprise at least one of steps S240-S246. For example, step S245 can be implemented as an independent embodiment, steps S245 and S246 can be implemented as independent embodiments, steps S241-S244 can be implemented as independent embodiments, steps S240, S245 and S246 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0595] In some embodiments, step S240 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0596] In some embodiments, steps S241-S244 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0597] In some embodiments, step S246 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0598] It should be understood that the steps included in the method according to the embodiments of the present disclosure can be exchanged in any order or combined for implementation without conflict.

[0599] It should also be understood that the steps included in the method according to the embodiments of the present disclosure can be implemented individually or combined in any order without conflict, for example, the steps in the embodiments of the present disclosure are combined, or the steps in the embodiments of the present disclosure are combined with one or more steps included in one or more other embodiments.

[0600] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0601] FIG. 2f is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2f, the information processing method is used in the communication system 100, and the method comprises:

[0602] S250, the first API caller sends sixteenth information to the third node.

[0603] In some embodiments, the sixteenth information comprises address information of the first node and authorization request related information of a second resource owner related to the third node.

[0604] In some embodiments, the address information of the first node is an IP address of the first node or a FQDN (Fully Qualified Domain Name) of the first node.

[0605] In some embodiments, the second resource owner is a resource owner expected by the first API invoker.

[0606] In some embodiments, the authorization request related information comprises at least one of the following information:

[0607] identification information of the second resource owner;

[0608] identification information of the first API invoker;

[0609] service information;

[0610] data type;

[0611] data processing purpose.

[0612] Optionally, the service information comprises at least one of the following: service, service operation, and service API.

[0613] In some embodiments, the third node can be the same node as the second node or a different node.

[0614] It should be noted that the information in the authorization request related information, such as data type and data processing purpose, is the authorization information expected or desired by the first API invoker.

[0615] In some embodiments, the service information, data type, and data processing purpose can be described in the authorization request related information in a display manner as "expected" service information, data type, and data processing purpose for the first API invoker; or the "expected" can not be explicitly described, and the embodiments of the present disclosure do not limit this.

[0616] S251, the third node verifies the authorization request related information.

[0617] In some embodiments, the process of verifying the authorization request related information by the third node can comprise at least one of the following judgment operations:

[0618] determining whether the identification information of the second resource owner included in the authorization request related information is consistent with the identification information of the resource owner related to the third node;

[0619] determining whether the address information of the first node stored locally by the third node is the same as the address information of the first node provided by the first API invoker; or

[0620] determining whether the address information of the first node provided by the resource owner related to the third node is the same as the address information of the first node provided by the first API invoker; or

[0621] determine whether the data type and the data processing purpose included in the authorization request related information are authorized by the third node; or

[0622] determine whether the data type and the data processing purpose included in the authorization request related information are authorized by the resource owner related to the third node.

[0623] In some embodiments, if the determination result of any of the above determination operations is negative, the authorization to the first API invoker is denied; otherwise, the authorization process to the first API invoker is performed. In some embodiments, if the determination result of any of the above determination operations is negative, the following steps are not continued to be performed.

[0624] In some embodiments, if the determination result of all of the above determination operations is positive, the authorization process to the first API invoker can be performed.

[0625] In some embodiments, if the determination operation is any of the above operations, and the determination result is negative, the authorization to the first API invoker is denied; otherwise (i.e., the determination result is positive), the authorization process to the first API invoker is performed.

[0626] In some embodiments, if the determination operation is any two or more of the above operations, and the determination result of one of the operations is negative, the authorization to the first API invoker is denied; otherwise (i.e., the determination result of all of the operations is positive), the authorization process to the first API invoker is performed. In some embodiments, if the determination result of all of the above determination operations is positive, the following steps can be performed:

[0627] S252, the third node sends third information to the first node.

[0628] In some embodiments, the third information includes authorization request related information, and the authorization request is an authorization request related to a second resource owner related to the third node.

[0629] In some embodiments, the third information is used to request authorization to the first API invoker.

[0630] In some embodiments, the second resource owner is a resource owner expected by the first API invoker.

[0631] The authorization request related information can refer to the description in the above step S250, which is not repeated here.

[0632] S253, the first node verifies the authorization request related information.

[0633] In some embodiments, the first node needs further verification for the received authorization request related information.

[0634] In some embodiments, the first node verifying the authorization request related information can include verifying the identification information of the second resource owner based on the identification information of the authenticated resource owner related to the third node.

[0635] In some embodiments, the process of the first node verifying the authorization request related information can include at least one of the following:

[0636] In some embodiments, if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, the first node can reject accepting the authorization request related information.

[0637] In some embodiments, if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, the first node can reject storing the authorization request related information.

[0638] In some embodiments, if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner, the first node can terminate the authorization process related to the first API caller.

[0639] In some embodiments, if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner, the first node can store the authorization request related information.

[0640] In some embodiments, if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner, the first node can accept the authorization request related information.

[0641] In some embodiments, if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner, the first node can further determine whether the service information included in the third information matches the data type and the data processing purpose.

[0642] In some embodiments, if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner, the first node can further determine whether the service information included in the third information matches the data processing purpose.

[0643] In some embodiments, if the service information included in the third information matches the data type and the data processing purpose, the first node can perform the authorization process for the first API caller.

[0644] In some embodiments, the first node can perform an authorization process on the first API invoker if the service information included in the third information matches the data processing purpose.

[0645] In some embodiments, the first node can further determine whether the service information included in the authorization request related information matches the data type and the data processing purpose if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner.

[0646] In some embodiments, the first node can further determine whether the service information included in the authorization request related information matches the data processing purpose if the identification information of the authenticated resource owner is consistent with the identification information of the second resource owner.

[0647] In some embodiments, the first node can perform an authorization process on the first API invoker if the service information included in the authorization request related information matches the data type and the data processing purpose.

[0648] In some embodiments, the first node can perform an authorization process on the first API invoker if the service information included in the authorization request related information matches the data processing purpose.

[0649] S254, the first node sends the fourteenth information or the fifteenth information to the third node to feed back the verification result.

[0650] In some embodiments, the first node can send the fourteenth information to the third node to indicate that the authorization information configuration fails if the identification information of the authenticated resource owner is inconsistent with the identification information of the second resource owner.

[0651] In some embodiments, the fourteenth information further includes: the third node configures the authorization information related to the identification information of the authenticated resource owner.

[0652] In some embodiments, the first node can send the fifteenth information to the third node to indicate that the authorization request fails if the service information included in the third information does not match the data type and the data processing purpose.

[0653] In some embodiments, the first node can send the fifteenth information to the third node to indicate that the authorization request fails if the service information included in the third information does not match the data type and the data processing purpose.

[0654] In some embodiments, the first node can send the fifteenth information to the third node to indicate that the authorization request fails if the service information included in the third information does not match the data processing purpose.

[0655] In some embodiments, the fifteenth information is used to indicate the data type and data processing purpose included in the authorization request-related information, which does not match the service information included in the third information.

[0656] In some embodiments, the fifteenth information is used to indicate the data processing purpose included in the authorization request-related information, which does not match the service information included in the third information.

[0657] In some embodiments, if the service information included in the authorization request does not match the data type and data processing purpose, the first node may send a fifteenth message to the third node to indicate that the authorization request has failed.

[0658] In some embodiments, if the service information included in the authorization request does not match the data type and data processing purpose, the first node may send a fifteenth message to the third node to indicate that the authorization request has failed.

[0659] In some embodiments, if the service information included in the authorization request does not match the data processing purpose, the first node may send a fifteenth message to the third node to indicate that the authorization request has failed.

[0660] In some embodiments, the fifteenth information is used to indicate the data type and data processing purpose included in the authorization request-related information, which does not match the service information included in the authorization request-related information.

[0661] In some embodiments, the fifteenth information is used to indicate that the data processing purpose included in the authorization request-related information does not match the service information included in the authorization request-related information.

[0662] For example, the second resource owner can be a user, whose identifiable data type is, for example, location data, and whose data processing purpose is, for example, openness. The first API invoker can be a server or a user entity (UE). If the authorization request information sent by the first API invoker includes data type of location data, and the data processing purpose is openness, and the service included in the authorization request information has a corresponding data type of the user's phone number, and the data processing purpose is to open the phone number, then in this case, the service included in the authorization request information does not match the data type and data processing purpose.

[0663] S255, the third node sends the fourteenth or fifteenth message to the first API caller to provide feedback on the verification result.

[0664] In some embodiments, if it is verified that the first API caller is authorized, the first node sends an authorization code to the first API caller through the third node.

[0665] In some embodiments, before step S252, the above method can further include:

[0666] S2500, the first node and the third node can perform a mutual authentication process.

[0667] Optional implementation of step S2500 can refer to the optional implementation related to step S200 in FIG. 2a, which will not be repeated here.

[0668] In this embodiment, the first API caller sends an authorization-related request to the third node (resource owner function), and the third node itself or the second resource owner checks the address information of the first node (CCF) through the third node, and checks the data type and data processing purpose at the same time. If the address information of the CCF is consistent with the address information of the CCF stored locally by the third node, or the address information of the CCF is consistent with the address information of the CCF provided by the resource owner, and the data type and data processing purpose are agreed by the resource owner, the third node sends the related authorization request of the first API caller to the CCF. At the same time, it is defaulted that the second resource owner (resource owner) agrees with the data processing purpose. The CCF authenticates the identification information of the second resource owner, and judges whether the third node or the second resource owner has the qualification to agree with a certain data processing purpose. If it has the qualification to agree (i.e., the CCF finds that the ID authentication of the second resource owner is passed), the CCF further checks whether the data processing purpose and the requested service information (service) are consistent.

[0669] If the CCF finds that the ID of the second resource owner has a problem, it refuses to authorize the authorization-related request of the first API caller sent based on the third node to perform an authorization action.

[0670] If the verification result shows that the data processing purpose requested by the first API caller and the requested service information are consistent, an authorization code is sent to the third node, and the third node sends the authorization code to the first API caller, which is used by the first API caller to exchange a token from the CCF in the subsequent process using the code.

[0671] The method related to the embodiments of the present disclosure can include at least one of steps S2500, S250-S255. For example, steps S250 and S251 can be implemented as independent embodiments, steps S2500, S250-S253 can be implemented as independent embodiments, and steps S250-S255 can be implemented as independent embodiments, but are not limited thereto.

[0672] In some embodiments, step S2500 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0673] In some embodiments, steps S252-S255 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0674] In some embodiments, steps S254, S255 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0675] It should be understood that the steps included in the method according to the embodiments of the present disclosure can be exchanged in any order, combined and implemented without conflict.

[0676] It should also be understood that the steps included in the method according to the embodiments of the present disclosure can be implemented individually, or combined and implemented in any order without conflict, for example, the steps in the embodiments of the present disclosure are combined, or the steps in the embodiments of the present disclosure are combined with one or more steps included in one or more other embodiments.

[0677] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0678] FIG. 2g is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 2g, the information processing method is used in the communication system 100, and the method includes:

[0679] S261, the first API caller sends third information to the first node.

[0680] In some embodiments, the third information is used to request authorization for the first API caller.

[0681] In some embodiments, the third information includes authorization request related information of a second resource owner related to the third node.

[0682] In some embodiments, the second resource owner is an expected resource owner of the first API caller.

[0683] In some embodiments, the authorization request related information includes at least one of the following information:

[0684] identification information of the second resource owner;

[0685] identification information of the first API caller;

[0686] service information;

[0687] data type;

[0688] Data processing purpose.

[0689] Optionally, the service information includes at least one of a service, a service operation, and a service API.

[0690] In some embodiments, the third node can be the same node as the second node or a different node.

[0691] In some embodiments, the third information can be an authorization related request, or the third information can be carried by the request, and the name of the third information is not limited thereto.

[0692] S262, the first node verifies the authorization request related information.

[0693] In some embodiments, if the first node determines the corresponding authorization policy according to the identification information of the second resource owner included in the authorization request related information, it further determines whether the first API caller is authorized.

[0694] In some embodiments, determining whether the first API caller is authorized includes:

[0695] mapping the service information included in the third information to a first data processing purpose;

[0696] if the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner matches the first data processing purpose, performing an authorization process on the first API caller; or

[0697] if the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner does not match the first data processing purpose, refusing to authorize the first API caller.

[0698] In some embodiments, determining whether the first API caller is authorized includes:

[0699] mapping the service information included in the third information to a first data type and a first data processing purpose;

[0700] if the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner match the first data type and the first data processing purpose, performing an authorization process on the first API caller; or

[0701] if the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner do not match the first data type and the first data processing purpose, refusing to authorize the first API caller.

[0702] S263, the first node feeds back the verification result to the first API invoker.

[0703] In some embodiments, if it is determined in step S262 to perform the authorization process for the first API invoker, the first node can send a token to the first API invoker.

[0704] In some embodiments, the first node can send the token to the first API invoker through an authorization related response.

[0705] In some embodiments, before step S261, the following steps can also be included:

[0706] The first node and the first API invoker can perform a mutual authentication process.

[0707] Optional implementation manners of the above embodiments can refer to the optional implementation manners related to step S2300 in FIG. 2d, which will not be repeated here.

[0708] In some embodiments, before step S261, the following steps can also be included:

[0709] The first node obtains authorization related information of part or all resource owners related to one or more nodes.

[0710] In some embodiments, the manner in which the first node obtains the authorization related information can refer to step S201 in FIG. 2a, or refer to steps S210-S217 in FIG. 2b, or refer to the optional implementation manners related to steps S221-S226 in FIG. 2c, which will not be repeated here.

[0711] In this embodiment, the first node can verify authorization request related information of a resource owner expected by the first API invoker based on the obtained authorization related information of the resource owner related to the node, so as to determine whether to authorize the first API invoker.

[0712] The method related to the embodiments of the present disclosure can include at least one of steps S261-S2636. For example, steps S261 and S262 can be implemented as independent embodiments, but are not limited thereto.

[0713] In some embodiments, step S263 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0714] It should be understood that the method related to the embodiments of the present disclosure includes various steps which can be arbitrarily exchanged in order and combined for implementation without conflict.

[0715] It should also be understood that the steps included in the method according to the embodiments of the present disclosure can be implemented independently, or combined and implemented in any order without contradiction, for example, the steps in the embodiments of the present disclosure are combined, or the steps in the embodiments of the present disclosure are combined with one or more steps included in other embodiments (one or more).

[0716] It should be noted that the "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0717] FIG. 3a is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3a, the information processing method can be performed by a first node, and the method comprises:

[0718] S301, obtaining address information of a second node.

[0719] The optional implementation of step S301 can refer to the optional implementation of steps S210-S215 in FIG. 2b and other associated parts in the embodiments related to FIG. 2b, which will not be repeated here.

[0720] Alternatively, the optional implementation of step S301 can refer to the optional implementation of steps S221-S224 in FIG. 2c and other associated parts in the embodiments related to FIG. 2c, which will not be repeated here.

[0721] In some embodiments, the first resource owner is related to the second node.

[0722] In some embodiments, the first node can obtain the address information of the second node related to the first resource owner based on the identification information of the first resource owner.

[0723] In some embodiments, the identification information of the first resource owner can be GPSI.

[0724] In some embodiments, the second node can be a terminal, and the address information can be an IP address of the terminal.

[0725] S302, sending second information to the second node.

[0726] The optional implementation of step S302 can refer to the optional implementation of step S216 in FIG. 2b and other associated parts in the embodiments related to FIG. 2b, which will not be repeated here.

[0727] Alternatively, the optional implementation of step S302 can refer to the optional implementation of step S225 in FIG. 2c and other associated parts in the embodiments related to FIG. 2c, which will not be repeated here.

[0728] In some embodiments, the second information is used to request the second node to send authorization-related information of the first resource owner.

[0729] In some embodiments, the authorization-related information can include at least one of the following:

[0730] identification information of the first resource owner;

[0731] identification information of the API invoker;

[0732] resource information;

[0733] data type;

[0734] data processing purpose.

[0735] S303, receiving the first information sent by the second node.

[0736] The optional implementation of step S303 can refer to the optional implementation of step S217 in FIG. 2b and other associated parts in the embodiments involved in FIG. 2b, which will not be repeated here.

[0737] Alternatively, the optional implementation of step S303 can refer to the optional implementation of step S226 in FIG. 2c and other associated parts in the embodiments involved in FIG. 2c, which will not be repeated here.

[0738] In some embodiments, the first node receives the authorization-related information of the first resource owner related to the second node sent by the second node.

[0739] In some embodiments, on the basis of the above scheme, at least one of the following operations can be further included:

[0740] verifying the authorization-related information;

[0741] feeding back the verification result to the second node;

[0742] storing the authorization-related information.

[0743] The optional implementation of verifying the authorization-related information in the above optional embodiments can refer to the optional implementation of step S202 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.

[0744] The optional implementation of feeding back the verification result to the second node in the above optional embodiments can refer to the optional implementation of step S203 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.

[0745] The optional implementation of storing the authorization-related information in the optional embodiment can refer to the optional implementation of step S204 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.

[0746] The method involved in the embodiments of the present disclosure can include at least one of steps S301-S303. For example, step S303 can be implemented as an independent embodiment, but is not limited thereto.

[0747] In some embodiments, step S301 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0748] In some embodiments, step S302 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0749] It should be understood that the method involved in the embodiments of the present disclosure can include various steps that can be arbitrarily exchanged in order and combined for implementation without conflict.

[0750] It should also be understood that the steps included in the method involved in the embodiments of the present disclosure can be implemented individually or combined in any order without conflict, for example: the combination of steps in the embodiments of the present disclosure, or the combination of steps in the embodiments of the present disclosure and one or more steps included in one or more other embodiments.

[0751] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0752] FIG. 3b is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3b, the information processing method can be performed by a first node, and the method includes:

[0753] S311, obtaining address information of a second node.

[0754] The optional implementation of step S311 can refer to the optional implementation of steps S210-S215 in FIG. 2b and other associated parts in the embodiments involved in FIG. 2b, which will not be repeated here.

[0755] Alternatively, the optional implementation of step S311 can refer to the optional implementation of steps S221-S224 in FIG. 2c and other associated parts in the embodiments involved in FIG. 2c, which will not be repeated here.

[0756] Alternatively, the optional implementation of step S311 can refer to the optional implementation of steps S230-S235 in FIG. 2d and other associated parts in the embodiments involved in FIG. 2d, which will not be repeated here.

[0757] Alternatively, optional implementations of step S311 can be found in optional implementations of steps S241-S244 in Figure 2e, and other related parts in the embodiments involved in Figure 2e, which will not be repeated here.

[0758] In some embodiments, the second API caller runs on the second node.

[0759] In some embodiments, the first node may obtain the address information of the second node associated with the second API caller based on the identification information of the second API caller.

[0760] In some embodiments, the identification information of the second API caller may be GPSI.

[0761] In some embodiments, the second node can be a terminal, and the address information can be the IP address of the terminal.

[0762] S312, Send the fourth message to the second API caller.

[0763] The optional implementation of step S312 can be found in the optional implementation of step S236 in Figure 2d and other related parts in the embodiment involved in Figure 2d, which will not be repeated here.

[0764] Alternatively, optional implementations of step S312 can be found in optional implementations of step S245 in Figure 2e and other related parts in the embodiments involved in Figure 2e, which will not be repeated here.

[0765] In some embodiments, the fourth information is used to notify the second API caller that the authorization has been revoked.

[0766] In some embodiments, the fourth information indicates the revoked authorization information.

[0767] In some embodiments, the authorization information may include at least one of the following:

[0768] Identification information of the first resource owner associated with the second node;

[0769] The identifier information of the second API caller;

[0770] Service information, which includes at least one of the following: service, service operation, and service API;

[0771] The identification information of the fourth node;

[0772] Resource information;

[0773] Data type;

[0774] Data processing purpose.

[0775] S313, receiving fifth information sent by the second API invoker.

[0776] The optional implementation of step S313 can refer to the optional implementation of step S237 in FIG. 2d and other associated parts in the embodiment involved in FIG. 2d, which will not be repeated here.

[0777] Alternatively, the optional implementation of step S313 can refer to the optional implementation of step S246 in FIG. 2e and other associated parts in the embodiment involved in FIG. 2e, which will not be repeated here.

[0778] In some embodiments, the fifth information is used to feed back that the authorization has been revoked.

[0779] The method involved in the embodiments of the present disclosure can include at least one of steps S311-S313. For example, step S312 can be implemented as an independent embodiment, but is not limited thereto.

[0780] In some embodiments, step S311 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0781] In some embodiments, step S313 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0782] It should be understood that the method involved in the embodiments of the present disclosure includes various steps which can be arbitrarily exchanged in order, combined and implemented.

[0783] It should also be understood that the steps included in the method involved in the embodiments of the present disclosure can be implemented individually, or can be combined and implemented in any order without contradiction, for example: the combination of steps in the embodiments of the present disclosure, or the combination of steps in the embodiments of the present disclosure and one or more steps included in other embodiments (one or more).

[0784] It should be noted that “multiple” in the embodiments of the present disclosure can be understood as two or more.

[0785] FIG. 3c is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3c, the information processing method can be performed by a first node, and the method includes:

[0786] S321, obtaining third information.

[0787] In some embodiments, the third information includes authorization request related information of a second resource owner related to the third node.

[0788] Optionally, the second resource owner is a resource owner desired by the first API invoker.

[0789] In some embodiments, the third information is used to request authorization for the first API invoker.

[0790] In some embodiments, the first node receives the third information sent by the third node. At this time, the optional implementation of step S321 can refer to the optional implementation of step S252 in FIG. 2f and other associated parts in the embodiments involved in FIG. 2f, which will not be repeated here.

[0791] In some embodiments, the first node receives the third information sent by the first API invoker. At this time, the optional implementation of step S321 can refer to the optional implementation of step S261 in FIG. 2g and other associated parts in the embodiments involved in FIG. 2g, which will not be repeated here.

[0792] In some embodiments, the second node can be a terminal, and the address information can be an IP address of the terminal.

[0793] S322, verifying the authorization request related information included in the third information.

[0794] In some embodiments, if the third information comes from the third node, the optional implementation of step S322 can refer to the optional implementation of step S253 in FIG. 2f and other associated parts in the embodiments involved in FIG. 2f, which will not be repeated here.

[0795] In some embodiments, if the third information comes from the first API invoker, the optional implementation of step S322 can refer to the optional implementation of step S262 in FIG. 2g and other associated parts in the embodiments involved in FIG. 2g, which will not be repeated here.

[0796] In some embodiments, on the basis of the above scheme, it can further include: feeding back the verification result.

[0797] If the third information comes from the third node, the optional implementation of the optional implementation scheme can refer to the optional implementation of steps S254-S255 in FIG. 2f and other associated parts in the embodiments involved in FIG. 2f, which will not be repeated here.

[0798] If the third information comes from the first API invoker, the optional implementation of the optional implementation scheme can refer to the optional implementation of step S263 in FIG. 2g and other associated parts in the embodiments involved in FIG. 2g, which will not be repeated here.

[0799] It should be understood that the methods involved in the embodiments of the present disclosure include various steps which can be arbitrarily exchanged in order and combined for implementation without conflict.

[0800] It should also be understood that the methods involved in the embodiments of the present disclosure include steps that can be implemented individually, or combined in any order without contradiction, such as: combination of steps in the embodiments of the present disclosure, or combination of steps in the embodiments of the present disclosure and one or more steps included in other embodiments (one or more).

[0801] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[0802] FIG. 3d is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3d, the information processing method can be performed by a first node, and the method includes:

[0803] S331, obtaining first information.

[0804] In some embodiments, the first information includes authorization-related information related to the second node.

[0805] In some embodiments, the first node receives the first information sent by the second node. Optionally, the first information includes authorization-related information of a first resource owner related to the second node.

[0806] The optional implementation of step S331 can refer to the optional implementation of step S201 of FIG. 2a, step S303 of FIG. 3a, and other associated parts of the embodiments involved in FIGS. 2a and 3a, which will not be repeated here.

[0807] In some embodiments, the authorization-related information includes at least one of the following information:

[0808] identification information of the first resource owner;

[0809] identification information of an application programming interface (API) caller;

[0810] resource information;

[0811] data type;

[0812] data processing purpose.

[0813] In some embodiments, the method further includes:

[0814] obtaining third information, the third information including authorization request-related information of a second resource owner related to a third node, the second resource owner being an expected resource owner of the first API caller.

[0815] In some embodiments, obtaining the third information includes:

[0816] receiving the third information sent by the third node; or

[0817] receiving third information sent by the first API invoker;

[0818] The third information is used for requesting authorization of the first API invoker.

[0819] In some embodiments, the authorization request related information comprises at least one of the following information:

[0820] identification information of the second resource owner;

[0821] identification information of the first API invoker;

[0822] service information, wherein the service information comprises at least one of a service, a service operation, and a service API;

[0823] resource information;

[0824] data type;

[0825] data processing purpose.

[0826] In some embodiments, the method further comprises:

[0827] sending fourth information to the second API invoker, the fourth information being used for notifying the second API invoker that the authorization is revoked, and the fourth information indicating the revoked authorization information;

[0828] receiving fifth information sent by the second API invoker, the fifth information being used for feeding back that the authorization is revoked.

[0829] In some embodiments, the authorization information comprises at least one of the following information:

[0830] identification information of the first resource owner related to the second node;

[0831] identification information of the second API invoker;

[0832] service information expected by the second API invoker, wherein the service information comprises at least one of a service, a service operation, and a service API;

[0833] identification information of the fourth node;

[0834] resource information;

[0835] data type;

[0836] data processing purpose.

[0837] In some embodiments, the method further comprises:

[0838] sending sixth information to the fourth node, the sixth information being used for requesting the fourth node to provide address information of the second node;

[0839] receiving seventh information sent by the fourth node, the seventh information comprising address information of the second node;

[0840] The sixth information comprises identification information of a first resource owner and / or identification information of a second API invoker, the first resource owner being related to the second node, and the second API invoker running on the second node.

[0841] In some embodiments, the method further comprises:

[0842] sending, to the fifth node, eighth information for requesting the fifth node to provide identification information of the second node;

[0843] receiving ninth information sent by the fifth node, the ninth information comprising the identification information of the second node;

[0844] sending, to the sixth node, tenth information for requesting the sixth node to provide address information of the second node, the tenth information comprising the identification information of the second node;

[0845] receiving eleventh information sent by the sixth node, the eleventh information comprising the address information of the second node;

[0846] The eighth information comprises identification information of a first resource owner and / or identification information of a second API invoker, the first resource owner being related to the second node, and the second API invoker running on the second node.

[0847] In some embodiments, the method further comprises verifying the authorization-related information.

[0848] In some embodiments, if the authorization-related information comprises identification information of a first resource owner related to the second node, verifying the authorization-related information comprises:

[0849] verifying the identification information of the first resource owner based on identification information of an identity-authenticated resource owner related to the second node.

[0850] In some embodiments, the method further comprises at least one of the following operations:

[0851] if the identification information of the identity-authenticated resource owner is inconsistent with the identification information of the first resource owner, sending, to the second node, twelfth information for indicating that the authorization information configuration fails;

[0852] if the identification information of the identity-authenticated resource owner is inconsistent with the identification information of the first resource owner, rejecting the authorization-related information;

[0853] If the identity information of the authenticated resource owner is inconsistent with the identity information of the first resource owner, the authorization-related information is rejected to be stored;

[0854] If the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, the authorization-related information is stored;

[0855] If the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, the authorization-related information is accepted;

[0856] If the identity information of the authenticated resource owner is consistent with the identity information of the first resource owner, the thirteenth information indicating that the authorization configuration is successful is sent to the second node;

[0857] The twelfth information further indicates that the second node configures authorization information related to the identity information of the authenticated resource owner.

[0858] In some embodiments, if the identity information of the first resource owner related to the second node is not included in the authorization-related information, the method further includes:

[0859] associating the identity information of the authenticated resource owner with the authorization-related information; or

[0860] mapping a data type and a data processing purpose included in the authorization-related information to service information, and associating the identity information of the authenticated resource owner with the service information, wherein the service information includes at least one of a service, a service operation, and a service API.

[0861] In some embodiments, the method further includes verifying the authorization request-related information.

[0862] In some embodiments, verifying the authorization request-related information includes:

[0863] verifying the identity information of the second resource owner based on the identity information of the authenticated resource owner related to the third node.

[0864] In some embodiments, the method further includes at least one of the following operations:

[0865] If the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, the fourteenth information indicating that the authorization information configuration fails is sent to the third node;

[0866] If the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, the authorization request-related information is rejected to be accepted;

[0867] If the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, the authorization request related information is rejected to be stored;

[0868] If the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, the authorization process related to the first API invoker is terminated;

[0869] If the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, the authorization request related information is stored;

[0870] If the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, the authorization request related information is accepted;

[0871] If the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, it is determined whether the service information included in the third information matches the data type and the data processing purpose;

[0872] If the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, it is determined whether the service information included in the third information matches the data processing purpose;

[0873] The fourteenth information further includes: the third node configures the authorization information related to the identity information of the authenticated resource owner.

[0874] In some embodiments, the method further includes at least one of the following operations:

[0875] If the service information included in the third information matches the data type and the data processing purpose, the authorization process for the first API invoker is performed;

[0876] If the service information included in the third information matches the data processing purpose, the authorization process for the first API invoker is performed;

[0877] If the service information included in the third information does not match the data type and the data processing purpose, the fifteenth information indicating that the authorization request fails is sent to the third node;

[0878] If the service information included in the third information does not match the data processing purpose, the fifteenth information indicating that the authorization request fails is sent to the third node;

[0879] The fifteenth information is used to indicate that the data type and the data processing purpose included in the authorization request related information do not match the service information included in the third information; or

[0880] The fifteenth information is used to indicate that the data processing purpose included in the authorization request related information does not match the service information included in the third information.

[0881] In some embodiments, the authorization request related information is verified, including:

[0882] If the corresponding authorization policy is determined according to the identification information of the second resource owner included in the authorization request related information, it is further determined whether the first API caller is authorized.

[0883] In some embodiments, it is determined whether the first API caller is authorized, including:

[0884] The service information included in the third information is mapped to the first data processing purpose.

[0885] If the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner matches the first data processing purpose, the authorization process of the first API caller is performed; or

[0886] If the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner does not match the first data processing purpose, the authorization of the first API caller is refused.

[0887] In some embodiments, it is determined whether the first API caller is authorized, including:

[0888] The service information included in the third information is mapped to the first data type and the first data processing purpose.

[0889] If the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner match the first data type and the first data processing purpose, the authorization process of the first API caller is performed; or

[0890] If the data type and the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner do not match the first data type and the first data processing purpose, the authorization of the first API caller is refused.

[0891] FIG. 4 is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 4, the method involved in the embodiment of the present disclosure is executed by a second node, and the above method includes:

[0892] S401, sending first information.

[0893] In some embodiments, the second node sends the first information to the first node.

[0894] In some embodiments, the first information includes authorization related information related to the second node.

[0895] In some embodiments, the first node receives first information sent by the second node. Optionally, the first information comprises authorization-related information of a first resource owner related to the second node.

[0896] Optional implementation of step S331 can refer to step S201 of FIG. 2a, step S217 of FIG. 2b, step S226 of FIG. 2c, optional implementation of step S303 of FIG. 3a, and other associated parts in the embodiments involved in FIGS. 2a-2c and 3a, which will not be repeated here.

[0897] In some embodiments, the method further comprises:

[0898] receiving second information sent by the first node, the second information being used to request the second node to provide authorization-related information of a first resource owner related to the second node.

[0899] Optional implementation of the optional embodiments above can refer to step S216 of FIG. 2b, step S225 of FIG. 2c, optional implementation of step S303 of FIG. 3a, and other associated parts in the embodiments involved in FIGS. 2b-2c and 3a, which will not be repeated here.

[0900] In some embodiments, the first resource owner is related to the second node, and the address information of the second node is obtained by the first node from a fourth node or from a sixth node.

[0901] In some embodiments, the authorization-related information comprises at least one of the following information:

[0902] identification information of the first resource owner;

[0903] identification information of an application programming interface (API) invoker;

[0904] resource information;

[0905] data type;

[0906] quantity processing purpose.

[0907] In some embodiments, the method further comprises:

[0908] receiving twelfth information sent by the first node, the twelfth information being used to indicate that the configuration of the authorization information fails; or

[0909] receiving thirteenth information sent by the first node, the thirteenth information being used to indicate that the configuration of the authorization information succeeds.

[0910] In some embodiments, the twelfth information further indicates that the second node configures identification information of an identity-authenticated resource owner related to the second node.

[0911] Optional implementation of the optional embodiment can refer to optional implementation of step S203 in FIG. 2a, step S219 in FIG. 2b, step S228 in FIG. 2c, and other associated parts in the embodiments involved in FIGS. 2a-2c, which will not be repeated here.

[0912] FIG. 5 is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5, the method involved in the embodiment of the present disclosure is performed by the third node or the first API dispatcher, and the method comprises:

[0913] S501, sending third information.

[0914] In some embodiments, the third node or the first API dispatcher sends the third information to the first node.

[0915] If the third node sends the third information to the first node, optional implementation of step S501 can refer to step S252 in FIG. 2f, optional implementation of step S321 in FIG. 3c, and other associated parts in the embodiments involved in FIGS. 2f and 3c, which will not be repeated here.

[0916] If the first API dispatcher sends the third information to the first node, optional implementation of step S501 can refer to step S261 in FIG. 2g, optional implementation of step S321 in FIG. 3c, and other associated parts in the embodiments involved in FIGS. 2g and 3c, which will not be repeated here.

[0917] In some embodiments, the third information comprises authorization request related information of a second resource owner related to the third node.

[0918] In some embodiments, the third information is used to request authorization for the first API invoker.

[0919] In some embodiments, the second resource owner is a resource owner expected by the first API invoker.

[0920] In some embodiments, the authorization request related information comprises at least one of the following information:

[0921] identification information of the second resource owner;

[0922] identification information of the first API invoker;

[0923] service information, wherein the service information comprises at least one of the following: a service, a service operation, and a service API;

[0924] a data type;

[0925] a data processing purpose.

[0926] In some embodiments, if the third node sends the third information to the first node, at least one of the following solutions can also be included:

[0927] Solution 1:

[0928] receiving sixteenth information sent by the first API invoker, the sixteenth information including address information of the first node and authorization request related information.

[0929] The optional implementation of the above optional implementation 1 can refer to the optional implementation of step S250 in FIG. 2f and other associated parts in the embodiments involved in FIG. 2f, which will not be repeated here.

[0930] Solution 2:

[0931] receiving fourteenth information sent by the first node for indicating that the configuration of the authorization information fails; or,

[0932] receiving fifteenth information sent by the first node for indicating that the authorization request fails;

[0933] The fourteenth information further includes: the third node configures the authorization information related to the identification information of the authenticated resource owner related to the third node.

[0934] The fifteenth information is used to indicate that the data type and the data processing purpose included in the authorization request related information do not match the service information included in the third information; or,

[0935] The fifteenth information is used to indicate that the data processing purpose included in the authorization request related information does not match the service information included in the third information.

[0936] Solution 3: performing any one of the following judgment operations:

[0937] determining whether the identification information of the second resource owner included in the authorization request related information is consistent with the identification information of the resource owner related to the third node;

[0938] determining whether the address information of the first node stored locally by the third node is the same as the address information of the first node provided by the first API invoker; or,

[0939] determining whether the address information of the first node provided by the resource owner related to the third node is the same as the address information of the first node provided by the first API invoker; or,

[0940] determining whether the data type and the data processing purpose included in the authorization request related information are authorized by the third node; or,

[0941] Determine whether the data type and data processing purpose included in the authorization request related information are authorized by the resource owner related to the third node.

[0942] Scheme 4:

[0943] If the determination result of any one of the determination operations is a negative result, the authorization to the first API invoker is rejected.

[0944] The optional implementation of the above-mentioned optional embodiments 2-4 can refer to the optional implementation of step S251 in FIG. 2f and other associated parts in the embodiments involved in FIG. 2f, which will not be repeated here.

[0945] FIG. 6 is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 6, the method involved in the embodiment of the present disclosure is performed by a second API dispatcher, and the above-mentioned method comprises:

[0946] S601, receiving fourth information sent by a first node.

[0947] The optional implementation of step S601 can refer to the optional implementation of step S236 in FIG. 2d, step S312 in FIG. 3b, and other associated parts in the embodiments involved in FIG. 2d and FIG. 3b, which will not be repeated here.

[0948] Alternatively, the optional implementation of step S601 can refer to the optional implementation of step S245 in FIG. 2e, step S312 in FIG. 3b, and other associated parts in the embodiments involved in FIG. 2e and FIG. 3b, which will not be repeated here.

[0949] In some embodiments, the fourth information is used to inform the second API invoker that the authorization is revoked.

[0950] In some embodiments, the second API invoker runs on a second node, and the address information of the second node is obtained by the first node from a fourth node or from a sixth node.

[0951] In some embodiments, the fourth information indicates the revoked authorization information.

[0952] In some embodiments, the authorization information comprises at least one of the following information:

[0953] identification information of a first resource owner related to the second node;

[0954] identification information of the second API invoker;

[0955] service information, wherein the service information comprises at least one of a service, a service operation, and a service API;

[0956] identification information of the fourth node;

[0957] resource information;

[0958] data type;

[0959] data processing purpose.

[0960] S602, sending fifth information to the first node.

[0961] In some embodiments, the fifth information is used for feeding back that the authorization has been revoked.

[0962] Optional implementation of step S602 can be seen in step S237 of FIG. 2d, optional implementation of step S313 of FIG. 3b, and other associated parts in the embodiments related to FIG. 2d and FIG. 3b, which will not be repeated here.

[0963] Alternatively, optional implementation of step S602 can be seen in step S246 of FIG. 2e, optional implementation of step S313 of FIG. 3b, and other associated parts in the embodiments related to FIG. 2e and FIG. 3b, which will not be repeated here.

[0964] The embodiments of the present disclosure further provide an information processing method, executed by a fourth node, comprising:

[0965] receiving sixth information sent by the first node, the sixth information being used for requesting the fourth node to provide address information of the second node;

[0966] sending seventh information to the first node, the seventh information comprising the address information of the second node;

[0967] In some embodiments, the sixth information comprises identification information of a first resource owner related to the second node, and / or identification information of a second API invoker running on the second node.

[0968] In some embodiments, the method further comprises:

[0969] sending eighth information to a fifth node, the eighth information being used for requesting the fifth node to provide identification information of the second node;

[0970] receiving ninth information sent by the fifth node, the ninth information comprising the identification information of the second node;

[0971] sending tenth information to a sixth node, the tenth information being used for requesting the sixth node to provide address information of the second node, the tenth information comprising the identification information of the second node;

[0972] receiving eleventh information sent by the sixth node, the eleventh information comprising the address information of the second node;

[0973] The eighth information includes identification information of the first resource owner and / or identification information of the second API invoker.

[0974] The embodiments of the present disclosure further provide an information processing method, executed by a fifth node, including:

[0975] receiving eighth information sent by the first node or the fourth node, the eighth information being used to request the fifth node to provide identification information of the second node;

[0976] sending ninth information to the first node or the fourth node, the ninth information including the identification information of the second node;

[0977] In some embodiments, the eighth information includes identification information of the first resource owner and / or identification information of the second API invoker.

[0978] The embodiments of the present disclosure further provide an information processing method, executed by a sixth node, including:

[0979] receiving tenth information sent by the first node or the fourth node, the tenth information being used to request the sixth node to provide address information of the second node, the tenth information including identification information of the second node;

[0980] sending eleventh information to the first node or the fourth node, the eleventh information including the address information of the second node.

[0981] The present disclosure further provides the following optional embodiments:

[0982] Embodiment one, a scheme based on an authorization configuration mechanism of a resource owner function

[0983] Preconditions:

[0984] The resource owner function can be part of a UE, a personal computer, etc.

[0985] The resource owner can be a user of the UE or a subscription user.

[0986] The specific implementation of the resource owner identity authentication is handled by the application layer, which is not defined in the scheme of the embodiments of the present disclosure.

[0987] The method shown in FIG. 7a includes:

[0988] S700, the resource owner function obtains address information of a CCF (CAPIF core function) from a network or an API invoker (API invoker). The CCF performs identity authentication on the resource owner by interacting with the resource owner function, and obtains an authenticated resource owner ID.

[0989] S701, To configure the authorization information, the resource owner function (may correspond to the second node in the foregoing) sends authorization-related information to the CCF (may correspond to the first node in the foregoing).

[0990] In some embodiments, the authorization-related information can include at least one of the following: resource owner ID, API caller ID, resource information (for example, QoS, location), data type, and allowed data processing purpose.

[0991] In some embodiments, the authorization-related information is used to represent the authorization information of the resource owner indicated by the resource owner ID to the API caller indicated by the API caller ID, and the authorization information includes at least one of the following: resource information (for example, QoS, location) allowed to be accessed by the API caller, data type allowed to be accessed by the API caller, and data processing purpose allowed to be triggered by the API caller to perform.

[0992] In some embodiments, the authorization-related information can be included in the first information in the foregoing.

[0993] S702, Step 2 is optional.

[0994] If the authorization-related information includes the resource owner ID, the CCF checks the authorization-related information with the authenticated resource owner ID.

[0995] S704, If the CCF finds that the authenticated resource owner ID is inconsistent with the resource owner identification in the authorization-related information, the CCF sends failure information (may correspond to the twelfth information in the foregoing) to the resource owner function.

[0996] In some embodiments, the failure information indicates that the authorization information configuration fails.

[0997] In some embodiments, the failure information indicates that the resource owner configures the authorization information related to the authenticated resource owner ID, or indicates that the authorization information configuration request fails.

[0998] S703, If the authorization-related information contains the resource owner ID and the ID is the same as the authenticated ID, the CCF stores the authorization information related to the resource owner ID.

[0999] In some embodiments, if the authorization-related information does not contain the resource owner ID, the CCF stores the authenticated resource owner ID and the authorization information (for example, API caller ID, resource, data type, data processing purpose) included in the authorization-related information.

[1000] In some embodiments, the CCF can map the data type and data processing purpose to service information, and then the CCF stores at least one of the following: an authenticated resource owner ID, authorization information included in authorization-related information (e.g., an API caller ID, a resource, mapped service information including a service, a service operation, a service API).

[1001] In some embodiments, the resource owner ID and the authorization-related information together constitute authorization information related to the resource owner ID.

[1002] It should be noted that since the CCF knows the source IP address or the TLS session ID related to the resource owner function, the CCF can bind the authenticated resource owner ID to the source IP address or the TLS session identification of the resource owner function.

[1003] In some embodiments, if the resource owner function does not send the resource owner ID in the authorization-related request, the CCF can obtain the authenticated resource owner ID through the source IP address or the TLS session ID of the resource owner function. Using the source IP address to track the resource owner ID cannot handle the case where multiple resource owners use the same UE / PC to implement resource owner authentication.

[1004] It should be understood that the steps included in the method related to the embodiments of the present disclosure can be arbitrarily exchanged in order and combined for implementation without conflict.

[1005] It should also be understood that the steps included in the method related to the embodiments of the present disclosure can be implemented individually, or can be arbitrarily adjusted in order and combined for implementation without contradiction, for example: combination of steps in the embodiments of the present disclosure, or combination of steps in the embodiments of the present disclosure and one or more steps included in one or more other embodiments.

[1006] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[1007] Embodiment two, CCF (CAPIF core function) actively requests resource owner to provide authorization information

[1008] The method as shown in FIG. 7b includes:

[1009] S711, the CCF sends a resource owner ID (e.g., GPSI) to the AEF (which can correspond to the fourth node in the foregoing) to obtain the SUPI of the resource owner UE. The AEF sends the resource owner ID to the UDM (which can correspond to the fifth node in the foregoing). The UDM sends the SUPI of the resource owner-related UE to the AEF.

[1010] S712a, the AEF sends the SUPI to the UPF (may correspond to the sixth node in the foregoing) to obtain the IP address of the UE.

[1011] Alternatively,

[1012] S712b, the AEF sends the SUPI to the BSF (may correspond to the sixth node in the foregoing) to obtain the IP address of the UE.

[1013] S713, the AEF sends the IP address of the UE to the CCF.

[1014] S714, the CCF authenticates the resource owner ID by the user UE. In some embodiments, the CCF establishes a connection with the UE through the IP address.

[1015] S715, the CCF actively sends a request related to the authorization policy to the resource owner function running on the user UE (may correspond to the second information in the foregoing).

[1016] S716, the resource owner function sends authorization-related information to the CCF, which includes the same information as described in step S701 of Embodiment One.

[1017] S717-S718, the same as steps S702-S703 of Embodiment One.

[1018] It should be understood that the steps included in the method related to the embodiments of the present disclosure can be arbitrarily exchanged in order and combined for implementation without conflict.

[1019] It should also be understood that the steps included in the method related to the embodiments of the present disclosure can be implemented individually, or can be arbitrarily adjusted in order and combined for implementation without conflict, for example: the combination of steps in the embodiments of the present disclosure, or the combination of steps in the embodiments of the present disclosure and one or more steps included in one or more other embodiments.

[1020] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[1021] Embodiment Three, Scheme for Verifying Authorization Request in Authorization Code Flow

[1022] The method shown in FIG. 7c includes:

[1023] S721, the API caller (may correspond to the first API caller in the foregoing) sends an authorization-related request (may correspond to the sixteenth information in the foregoing) to the resource owner function (may correspond to the third node in the foregoing).

[1024] In some embodiments, the request includes address information (e.g., IP address, FQDN) of the CCF.

[1025] In some embodiments, the request further includes a resource owner ID, a service / service operation / service API, a data type, and a corresponding data processing purpose that the API invoker desires.

[1026] S722, the resource owner function checks the request as follows.

[1027] If the address information available in the resource owner is the same as the address information provided by the API invoker, the resource owner function continues the authorization process. Otherwise, the resource owner will reject the request.

[1028] If the data type and the corresponding data processing purpose are authorized by the resource owner, the resource owner function will continue the authorization process. Otherwise, the resource owner will reject the request.

[1029] S723, the resource owner function and the CCF perform mutual authentication. In some embodiments, the CCF authenticates the resource owner ID through the resource owner function.

[1030] S724, the resource owner function sends the CCF: a resource owner ID, a service / service operation / service API, a data type, and a corresponding data processing purpose that the API invoker desires.

[1031] S725, the CCF checks the resource owner ID that the API invoker desires with the authenticated resource owner ID.

[1032] In some embodiments, if the CCF finds that the authenticated resource owner ID is inconsistent with the resource owner ID that the API invoker desires, the CCF sends failure information to the resource owner function.

[1033] In some embodiments, if the CCF finds that the authenticated resource owner ID is inconsistent with the resource owner ID that the API invoker desires, the CCF terminates the authorization process.

[1034] In some embodiments, the failure information indicates that the authorization information configuration fails.

[1035] In some embodiments, the failure information indicates that the resource owner configures the authorization information related to the authenticated resource owner ID, or indicates that the authorization information configuration request fails.

[1036] In some embodiments, if the resource owner ID expected by the API invoker is the same as the authenticated resource owner ID, the CCF continues the authorization process.

[1037] S726, the CCF checks the expected service / service operation / service API according to the data type and the corresponding data processing purpose.

[1038] If the expected service / service operation matches the data type and the corresponding data processing purpose, the CCF will continue the authorization process. Otherwise, the CCF will terminate the authorization process.

[1039] In some embodiments, if the expected service / service operation does not match the data type and the corresponding data processing purpose, the CCF can send a failure message to the resource owner function to indicate that the data type and the corresponding data processing purpose do not match the expected service / service operation.

[1040] S727-S728, if the API invoker is authorized, the CCF sends an authorization code to the API invoker through the resource owner function.

[1041] It should be noted that the information in the authorization request related information, such as: data type and data processing purpose, is the authorization information expected or desired by the API invoker.

[1042] In some embodiments, the service information, data type, and data processing purpose can be explicitly described as the "expected" service information, data type, and data processing purpose for the first API invoker in the authorization request related information. It can also not be explicitly described as "expected". The present embodiment is not limited in this regard.

[1043] It should be understood that the steps involved in the method of the present embodiment can be arbitrarily exchanged in order and combined for implementation without conflict.

[1044] It should also be understood that the steps involved in the method of the present embodiment can be implemented individually, or can be arbitrarily adjusted in order and combined for implementation without conflict, for example: combination of steps in the present embodiment, or combination of steps in the present embodiment and one or more steps included in one or more other embodiments.

[1045] It should be noted that "multiple" in the present embodiment can be understood as two or more.

[1046] Embodiment four, scheme for verifying authorization request in client credential flow

[1047] The method shown in FIG. 7d includes:

[1048] S731, the API caller (which can correspond to the first API caller in the foregoing) sends an authorization-related request (which can correspond to the third information in the foregoing) to the CCF.

[1049] In some embodiments, the request includes a resource owner ID expected by the API caller, a service / service operation, a data type, and a corresponding data processing purpose.

[1050] S732, the CCF verifies the expected service / service operation / service API. In some embodiments, the CCF can obtain some resource owner IDs and corresponding authorization policies and store them locally before step S731 in the manner of Embodiment One or Embodiment Two described above. The authorization policies can include the number type and corresponding data processing purpose, service, and other information.

[1051] In some embodiments, the CCF finds the authorization information related to the resource owner corresponding to the resource owner ID provided by the API caller locally based on the resource owner ID, and performs an authorization operation on the request of the API caller according to the authorization information.

[1052] In some embodiments, the CCF checks the service / service operation / service API (service API) expected by the API caller according to the data type and corresponding data processing purpose in the authorization policy. If the expected service / service operation / service API (service API) matches the data type and corresponding data processing purpose in the authorization policy, the CCF will continue the authorization process. Otherwise, the CCF will terminate the authorization process.

[1053] In some embodiments, the CCF checks the service / service operation / service API (service API) expected by the API caller according to the data processing purpose in the authorization policy. If the expected service / service operation / service API (service API) matches the data processing purpose in the authorization policy, the CCF will continue the authorization process. Otherwise, the CCF will terminate the authorization process.

[1054] S733, if the API caller is authorized, the CCF sends a token to the API caller.

[1055] It should be noted that the information in the authorization request-related information, such as the data type and the data processing purpose, is the authorization information expected or desired by the API invoker.

[1056] In some embodiments, the service information, data type, data processing purpose "expected" by the first API invoker can be explicitly described in the authorization request related information, or can not be explicitly described, which is not limited in the embodiments of the present disclosure.

[1057] It should be understood that the steps involved in the methods of the embodiments of the present disclosure can be exchanged in any order or combined for implementation without conflict.

[1058] It should also be understood that the steps involved in the methods of the embodiments of the present disclosure can be implemented individually or combined in any order without conflict, for example, the steps in the embodiments of the present disclosure are combined, or the steps in the embodiments of the present disclosure are combined with one or more steps included in one or more other embodiments.

[1059] It should be noted that "multiple" in the embodiments of the present disclosure can be understood as two or more.

[1060] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device including units or modules for implementing each step performed by the terminal in any of the above methods. For another example, another device is proposed, including units or modules for implementing each step performed by the network equipment (such as access network equipment, core network function node, core network equipment, etc.) in any of the above methods.

[1061] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the units or modules of the apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of the elements in the circuit; for another example, in another implementation, the above hardware circuit is realized by a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules.

[1062] All units or modules of the above apparatus can be implemented in the form of processor invoking software, or in the form of hardware circuit, or partially in the form of processor invoking software and partially in the form of hardware circuit. In the embodiments of the present disclosure, the processor is a circuit with signal processing capability, and in one implementation, the processor can be a circuit with instruction reading and running capability, for example, a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), etc.; in another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the above hardware circuit is fixed or reconfigurable, for example, the hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD) such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit, and the process can be understood as the process in which the processor loads instructions to implement the functions of part or all of the units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[1063] FIG. 8a is a structural schematic diagram of a first node according to an embodiment of the present disclosure. As shown in FIG. 8a, the first node can include at least one of a first transceiver module 811, a first processing module 812, etc.

[1064] In some embodiments, the first transceiver module 811 is configured to obtain first information, wherein the first information includes authorization-related information related to the second node.

[1065] Optionally, the first receiving module 811 is further configured to perform the steps related to communication performed by the first node in any of the above methods, for example, at least one of the steps S203 shown in FIG. 2a, the steps S210, S215-S217, S219 shown in FIG. 2b, the steps S228, S221-S226 shown in FIG. 2c, the steps S230-S237 shown in FIG. 2d, the steps S241-S246 shown in FIG. 2e, the steps S252, S254 shown in FIG. 2f, the steps S261, S263 shown in FIG. 2g, which will not be described here again.

[1066] Optionally, the first processing module 812 is configured to perform the steps related to information processing performed by the first node in any of the above methods, for example, at least one of the steps S202, S204 shown in FIG. 2a, the steps S218, S2110 shown in FIG. 2b, the steps S227, S229 shown in FIG. 2c, the step S253 shown in FIG. 2f, the step S262 shown in FIG. 2g, which will not be described here again.

[1067] Optionally, the first processing module 812 is further configured to perform the steps related to identity authentication performed by the first node in any of the above methods, for example, at least one of the steps S200 shown in FIG. 2a, the steps S2100 shown in FIG. 2b, the steps S220 shown in FIG. 2c, the steps S2300 shown in FIG. 2d, the steps S240 shown in FIG. 2e, the steps S2500 shown in FIG. 2f, which will not be described here again.

[1068] FIG. 8b is a structural schematic diagram of a second node according to an embodiment of the present disclosure. As shown in FIG. 8b, the second node includes at least one of a second receiving module 821, a second processing module 822, etc.

[1069] In some embodiments, the second receiving module 821 is configured to send first information to the first node, the first information including authorization-related information related to the second node.

[1070] Optionally, the second receiving module 821 is further configured to perform the steps related to communication performed by the second node in any of the above methods, for example, at least one of the steps S203 shown in FIG. 2a, the steps S216, S217, S219 shown in FIG. 2b, the steps S228, S225, S226 shown in FIG. 2c, which will not be described here again.

[1071] Optionally, the first processing module 822 is configured to perform the steps related to identity authentication performed by the first node in any of the above methods, for example, at least one of the steps S200 shown in FIG. 2a, the steps S2100 shown in FIG. 2b, and the steps S220 shown in FIG. 2c. Details are not described herein again.

[1072] FIG. 8c is a schematic diagram of a structure of the third node according to an embodiment of the present disclosure. As shown in FIG. 8c, the third node can include at least one of a third transceiver module 831, a third processing module 832, and the like.

[1073] In some embodiments, the third transceiver module 831 is configured to send third information to the third node, the third information including authorization request related information of a second resource owner related to the third node.

[1074] The third information is used to request authorization for a third API invoker, and the second resource owner is an expected resource owner of the third API invoker.

[1075] Optionally, the third transceiver module 831 is further configured to perform the steps related to communication performed by the third node in any of the above methods, for example, at least one of the steps S250, S252, S254, and S255 shown in FIG. 2f. Details are not described herein again.

[1076] Optionally, the third processing module 832 is configured to perform the steps related to information processing performed by the third node in any of the above methods, for example, the step S251 shown in FIG. 2f. Details are not described herein again.

[1077] Optionally, the third processing module 832 is further configured to perform the steps related to identity authentication performed by the third node in any of the above methods, for example, at least one of the steps S2500 shown in FIG. 2f. Details are not described herein again.

[1078] FIG. 8d is a schematic diagram of a structure of the first API dispatcher according to an embodiment of the present disclosure. As shown in FIG. 8d, the first API dispatcher can include at least one of a fourth transceiver module 841, a fourth processing module 842, and the like.

[1079] In some embodiments, the fourth transceiver module 841 is configured to send third information to the first node, the third information including authorization request related information of a second resource owner related to the third node.

[1080] The third information is used to request authorization for a first API invoker, and the second resource owner is an expected resource owner of the first API invoker.

[1081] Optionally, the fourth transceiver 841 is further configured to perform the steps related to communication performed by the first API dispatcher in any of the above methods, for example, step S263 in FIG. 2g, which will not be repeated here.

[1082] Optionally, the fourth processing module 842 is configured to perform the steps related to information processing performed by the first API dispatcher in any of the above methods, for example, step S262 in FIG. 2g, which will not be repeated here.

[1083] FIG. 8e is a structural diagram of a second API dispatcher according to an embodiment of the present disclosure. As shown in FIG. 8e, the second API dispatcher can include at least one of a fifth transceiver 841, a fifth processing module 842, etc.

[1084] In some embodiments, the fifth transceiver 841 is configured to receive fourth information sent by a first node, the fourth information being used to inform that authorization of the second API invoker is revoked, and the fourth information indicating revoked authorization information; and send fifth information to the first node, the fifth information being used to feed back that authorization is revoked.

[1085] Optionally, the fifth processing module 842 is configured to perform the steps related to identity authentication performed by the second API dispatcher in any of the above methods, for example, at least one of step S2300 in FIG. 2d and step S240 in FIG. 2e, which will not be repeated here.

[1086] FIG. 9a is a structural diagram of a communication device 9100 according to an embodiment of the present disclosure. The communication device 9100 can be a network device (for example, an access network device, a core network device, etc.), a terminal (for example, a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 9100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[1087] As shown in FIG. 9a, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (for example, a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. The processor 9101 is configured to invoke instructions to enable the communication device 9100 to perform any of the above methods.

[1088] In some embodiments, the communication device 9100 further includes one or more transceivers 9103. When the communication device 9100 includes one or more transceivers 9103, the transceiver 9103 performs at least one of the communication steps (e.g., at least one of steps S201, S203 in FIG. 2a, steps S210, S215-S217, S219 in FIG. 2b, steps S228, S221-S226 in FIG. 2c, steps S230-S237 in FIG. 2d, steps S241-S246 in FIG. 2e, steps S252, S254 in FIG. 2f, steps S261, S263 in FIG. 2g, but not limited to) in the above-described methods, and the processor 9101 performs at least one of the other steps (e.g., at least one of steps S200, S202, S204 in FIG. 2a, steps S2100, S218, S2110 in FIG. 2b, steps S220, S227, S229 in FIG. 2c, steps S2300 in FIG. 2d, steps S240 in FIG. 2e, steps S2500 in FIG. 2f, steps S262 in FIG. 2g, but not limited to) in the above-described methods. In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[1089] In some embodiments, the communication device 9100 further includes one or more memories 9102 for storing instructions. Optionally, all or part of the memory 9102 can also be outside the communication device 9100.

[1090] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[1091] Optionally, the communication device 9100 further includes one or more interface circuits 9104, which are connected with the memory 9102, and which can be used to receive signals from the memory 9102 or other devices, and can be used to send signals to the memory 9102 or other devices. For example, the interface circuit 9104 can read the instructions stored in the memory 9102 and send the instructions to the processor 9101.

[1092] The communication device 9100 in the above embodiments can be a network device or a terminal, but the scope of the communication device 9100 described in the embodiments of the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited to that of FIG. 9a. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally include a storage component for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[1093] FIG. 9b is a structural schematic diagram of a chip 9200 according to an embodiment of the present disclosure. For the case where the communication device 9100 is a chip or a chip system, the structural schematic diagram of the chip 9200 shown in FIG. 9b can be referred to, but is not limited thereto.

[1094] The chip 9200 includes one or more processors 9201. The chip 9200 is configured to execute any of the above methods.

[1095] In some embodiments, the chip 9200 further includes one or more interface circuits 9202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 9200 further includes one or more memories 9203 for storing data. Optionally, all or part of the memory 9203 can be outside the chip 9200. Optionally, the interface circuit 9202 is connected to the memory 9203, and the interface circuit 9202 can be configured to receive data from the memory 9203 or other devices, and the interface circuit 9202 can be configured to send data to the memory 9203 or other devices. For example, the interface circuit 9202 can read data stored in the memory 9203 and send the data to the processor 9201.

[1096] In some embodiments, the interface circuit 9202 performs at least one of the communication steps (for example, at least one of steps S201, S203 in FIG. 2a, steps S210, S215-S217, S219 in FIG. 2b, steps S228, S221-S226 in FIG. 2c, steps S230-S237 in FIG. 2d, steps S241-S246 in FIG. 2e, steps S252, S254 in FIG. 2f, steps S261, S263 in FIG. 2g, but not limited thereto) of transmitting and / or receiving in the above-described methods. The interface circuit 9202 performing the communication steps of transmitting and / or receiving in the above-described methods, for example, means that the interface circuit 9202 performs data interaction between the processor 9201, the chip 9200, the memory 9203, or the transceiver device. In some embodiments, the processor 9201 performs at least one of other steps (for example, at least one of steps S200, S202, S204 in FIG. 2a, steps S2100, S218, S2110 in FIG. 2b, steps S220, S227, S229 in FIG. 2c, steps S2300 in FIG. 2d, steps S240 in FIG. 2e, steps S2500 in FIG. 2f, steps S253 in FIG. 2g, but not limited thereto).

[1097] The disclosure also proposes a program product which, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.

[1098] The disclosure also proposes a computer program which, when running on a computer, causes the computer to perform any of the above methods.

[1099] The technical solutions described in the disclosure can be combined arbitrarily without conflict, as long as there is no conflict.

[1100] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The disclosure is intended to cover any variations, uses, or adaptations of the application following, in general, the principles of the application and including such departures from the present disclosure as come within known or customary practice in the art to which the application pertains. The specification and examples are to be regarded as exemplary only, and the true scope and spirit of the application are indicated by the following claims.

[1101] It should be understood that the application is not limited to the precise construction that has been described above and shown in the accompanying drawings, and that changes and modifications can be effected therein by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the claims that follow.

Claims

1. An information processing method characterized by comprising: The method is performed by a first node, and the method comprises: obtaining first information, the first information comprising authorization-related information related to a second node.

2. The method of claim 1, wherein, The obtaining of the first information comprises: receiving the first information sent by the second node, the first information comprising authorization-related information of a first resource owner related to the second node.

3. The method of claim 1, wherein, The obtaining of the first information comprises: sending second information to the second node, the second information being used to request the second node to provide authorization-related information of a first resource owner related to the second node; receiving the first information sent by the second node, the first information comprising authorization-related information of a first resource owner related to the second node.

4. The method according to claim 2 or 3, characterized in that, The authorization-related information comprises at least one of the following information: identification information of the first resource owner; identification information of an application programming interface (API) invoker; resource information; data type; data processing purpose.

5. The method of claim 1, wherein, The method further comprises: obtaining third information, the third information comprising authorization request-related information of a second resource owner related to a third node, the second resource owner being an expected resource owner of the first API invoker.

6. The method of claim 5, wherein, The obtaining of the third information comprises: receiving the third information sent by the third node; or receiving the third information sent by the first API invoker; wherein the third information is used to request authorization for the first API invoker.

7. The method according to claim 5 or 6, characterized in that, The authorization request-related information comprises at least one of the following information: identification information of the second resource owner; identification information of the first API invoker; service information, wherein the service information comprises at least one of a service, a service operation, and a service API; resource information; data type; data processing purpose.

8. The method of claim 1, wherein, The method further comprises: sending fourth information to a second API invoker, the fourth information being used to inform the second API invoker that authorization is revoked, the fourth information indicating revoked authorization information; receiving fifth information sent by the second API invoker, the fifth information being used to feed back that authorization has been revoked.

9. The method of claim 8, wherein, The authorization information comprises at least one of the following information: identification information of a first resource owner related to the second node; identification information of the second API invoker; service information, wherein the service information comprises at least one of a service, a service operation, and a service API; identification information of a fourth node; resource information; data type; data processing purpose.

10. The method of claim 3 or 8, wherein, The method further comprises: sending sixth information to a fourth node, the sixth information being used to request the fourth node to provide address information of the second node; receiving seventh information sent by the fourth node, the seventh information comprising the address information of the second node; wherein the sixth information comprises identification information of the first resource owner and / or identification information of the second API invoker, the first resource owner being related to the second node, and the second API invoker running on the second node.

11. The method according to claim 3 or 8, characterized in that, The method further comprises: sending eighth information to the fifth node, the eighth information being used for requesting the fifth node to provide identification information of the second node; receiving ninth information sent by the fifth node, the ninth information comprising the identification information of the second node; sending tenth information to the sixth node, the tenth information being used for requesting the sixth node to provide address information of the second node, the tenth information comprising the identification information of the second node; receiving eleventh information sent by the sixth node, the eleventh information comprising the address information of the second node; wherein the eighth information comprises identification information of the first resource owner and / or identification information of the second API invoker, the first resource owner being related to the second node, and the second API invoker running on the second node.

12. The method of any one of claims 1-4, wherein, The method further comprises: verifying the authorization-related information.

13. The method of claim 12, wherein, If the authorization-related information comprises the identification information of the first resource owner related to the second node, the verifying the authorization-related information comprises: verifying the identification information of the first resource owner based on the identification information of the authenticated resource owner related to the second node.

14. The method of claim 13, wherein, The method further comprises at least one of the following operations: if the identification information of the authenticated resource owner is inconsistent with the identification information of the first resource owner, sending twelfth information to the second node, the twelfth information being used for indicating that authorization information configuration fails; if the identification information of the authenticated resource owner is inconsistent with the identification information of the first resource owner, rejecting to accept the authorization-related information; if the identification information of the authenticated resource owner is inconsistent with the identification information of the first resource owner, rejecting to store the authorization-related information; if the identification information of the authenticated resource owner is consistent with the identification information of the first resource owner, storing the authorization-related information; if the identification information of the authenticated resource owner is consistent with the identification information of the first resource owner, accepting the authorization-related information; if the identification information of the authenticated resource owner is consistent with the identification information of the first resource owner, sending thirteenth information to the second node, the thirteenth information being used for indicating that authorization configuration succeeds; wherein the twelfth information further indicates that the second node configures authorization information related to the identification information of the authenticated resource owner.

15. The method of claim 13, wherein, If the authorization-related information does not comprise the identification information of the first resource owner related to the second node, the method further comprises: associating the identification information of the authenticated resource owner with the authorization-related information; or mapping a data type and a data processing purpose comprised in the authorization-related information into service information, and associating the identification information of the authenticated resource owner with the service information, wherein the service information comprises at least one of a service, a service operation, and a service API.

16. The method of claim 5 or 6, wherein, The method further comprises: verifying the authorization request-related information.

17. The method of claim 16, wherein, The verifying the authorization request-related information comprises: verify the identity information of the second resource owner based on the identity information of the authenticated resource owner related to the third node.

18. The method of claim 17, wherein, The method further includes at least one of the following operations: if the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, sending, to the third node, fourteenth information indicating that authorization information configuration fails; if the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, rejecting the authorization request related information; if the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, rejecting the authorization request related information; if the identity information of the authenticated resource owner is inconsistent with the identity information of the second resource owner, terminating the authorization process related to the first API invoker; if the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, storing the authorization request related information; if the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, accepting the authorization request related information; if the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, determining whether service information included in the third information matches the data type and the data processing purpose; if the identity information of the authenticated resource owner is consistent with the identity information of the second resource owner, determining whether service information included in the third information matches the data processing purpose; The fourteenth information further includes authorization information configured by the third node and related to the identity information of the authenticated resource owner.

19. The method of claim 17 or 18, wherein, The method further includes at least one of the following operations: if the service information included in the third information matches the data type and the data processing purpose, performing an authorization process on the first API invoker; if the service information included in the third information matches the data processing purpose, performing an authorization process on the first API invoker; if the service information included in the third information does not match the data type and the data processing purpose, sending, to the third node, fifteenth information indicating that an authorization request fails; if the service information included in the third information does not match the data processing purpose, sending, to the third node, fifteenth information indicating that an authorization request fails; The fifteenth information indicates that the data type and the data processing purpose included in the authorization request related information do not match the service information included in the third information; or The fifteenth information indicates that the data processing purpose included in the authorization request related information does not match the service information included in the third information.

20. The method of claim 16, wherein, The verification of the authorization request related information includes: If a corresponding authorization policy is determined according to the identification information of the second resource owner included in the authorization request related information, it is further determined whether the first API invoker is authorized.

21. The method of claim 20, wherein, The determination of whether the first API invoker is authorized comprises: mapping service information included in the third information into a first data processing purpose; if the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner matches the first data processing purpose, performing an authorization process on the first API invoker; or if the data processing purpose included in the authorization information corresponding to the identification information of the second resource owner does not match the first data processing purpose, refusing to authorize the first API invoker.

22. The method of claim 20, wherein, The determination of whether the first API invoker is authorized comprises: mapping service information included in the third information into a first data type and a first data processing purpose; if the data type and data processing purpose included in the authorization information corresponding to the identification information of the second resource owner match the first data type and first data processing purpose, performing an authorization process on the first API invoker; or if the data type and data processing purpose included in the authorization information corresponding to the identification information of the second resource owner do not match the first data type and first data processing purpose, refusing to authorize the first API invoker. The method is performed by a second node, and the method comprises:

23. An information processing method characterized by comprising: sending first information to a first node, the first information including authorization related information related to the second node. Further comprising:

24. The method of claim 23, wherein, receiving second information sent by the first node, the second information being used to request the second node to provide authorization related information of a first resource owner related to the second node. The first resource owner is related to the second node, and address information of the second node is obtained by the first node from a fourth node or from a sixth node.

25. The method of claim 24, wherein, The authorization related information includes at least one of the following information:

26. The method of any one of claims 23 or 25, wherein, identification information of the first resource owner; identification information of an application programming interface (API) invoker; resource information; data type; number processing purpose. The method further comprises:

27. The method of any one of claims 23-26, wherein, receiving twelfth information sent by the first node for indicating that authorization information configuration fails; or receiving thirteenth information sent by the first node for indicating that authorization information configuration succeeds; The twelfth information further indicates that the second node configures authorization information related to identification information of an authenticated resource owner related to the second node. The method is performed by a third node, and the method comprises:

28. An information processing method characterized by comprising: sending third information to a first node, the third information including authorization request related information of a second resource owner related to the third node; The third information is used to request authorization of a first API invoker, and the second resource owner is a resource owner expected by the first API invoker. The authorization request related information includes at least one of the following information:

29. The method of claim 28, wherein, identification information of the second resource owner; ​ identification information of the first API invoker; service information, wherein the service information comprises at least one of a service, a service operation, and a service API; a data type; a data processing purpose.

30. The method of any one of claims 28 or 29, wherein, The method further comprises: receiving fourteenth information sent by the first node and used for indicating that the authorization information configuration fails; or receiving fifteenth information sent by the first node and used for indicating that the authorization request fails; The fourteenth information further comprises: the third node configures authorization information related to identification information of an authenticated resource owner related to the third node. The fifteenth information is used for indicating that a data type and a data processing purpose included in the authorization request related information do not match service information included in the third information; or The fifteenth information is used for indicating that a data processing purpose included in the authorization request related information does not match service information expected by the first API invoker.

31. The method of any one of claims 28-30, wherein, The method further comprises: receiving sixteenth information sent by the first API invoker, the sixteenth information comprising address information of the first node and the authorization request related information.

32. The method of claim 31, wherein, The method further comprises performing any one of the following judgment operations: determining whether identification information of the second resource owner included in the authorization request related information is consistent with identification information of a resource owner related to the third node; determining whether address information of the first node stored locally by the third node is the same as address information of the first node provided by the first API invoker; or determining whether address information of the first node provided by a resource owner related to the third node is the same as address information of the first node provided by the first API invoker; or determining whether a data type and a data processing purpose included in the authorization request related information are authorized by the third node; determining whether a data type and a data processing purpose included in the authorization request related information are authorized by a resource owner related to the third node.

33. The method of claim 32, wherein, The method further comprises: if a result of any one of the judgment operations is a negative result, refusing to authorize the first API invoker.

34. An information processing method characterized by comprising: The method is performed by a first API invoker, and the method comprises: sending, to a first node, third information comprising authorization request related information of a second resource owner related to a third node; The third information is used for requesting authorization of the first API invoker, and the second resource owner is a resource owner expected by the first API invoker.

35. The method of claim 34, wherein, The authorization request related information comprises at least one of the following information: identification information of the second resource owner; identification information of the first API invoker; service information, wherein the service information comprises at least one of a service, a service operation, and a service API; a data type; a data processing purpose.

36. An information processing method characterized by comprising: The method is performed by a second API invoker, and the method comprises: receiving fourth information sent by the first node, the fourth information being used for notifying that authorization of the second API invoker is revoked, the fourth information indicating revoked authorization information; sending fifth information to the first node, the fifth information being used for feeding back that authorization is revoked.

37. The method of claim 36, wherein, The authorization information comprises at least one of the following information: identification information of a first resource owner related to the second node; identification information of the second API invoker; service information, wherein the service information comprises at least one of a service, a service operation, and a service API; identification information of the fourth node; resource information; data type; data processing purpose.

38. The method of claim 36 or 37, wherein, The second API invoker runs on the second node, and address information of the second node is obtained by the first node from the fourth node or from a sixth node.

39. An information processing method characterized by comprising: The method is executed by the fourth node, and the method comprises: receiving sixth information sent by the first node, the sixth information being used for requesting the fourth node to provide address information of the second node; sending seventh information to the first node, the seventh information comprising the address information of the second node; The sixth information comprises identification information of a first resource owner related to the second node, and / or identification information of the second API invoker; the first resource owner is related to the second node, and the second API invoker runs on the second node.

40. The method of claim 39, wherein, The method further comprises: sending eighth information to a fifth node, the eighth information being used for requesting the fifth node to provide identification information of the second node; receiving ninth information sent by the fifth node, the ninth information comprising the identification information of the second node; sending tenth information to a sixth node, the tenth information being used for requesting the sixth node to provide address information of the second node, the tenth information comprising the identification information of the second node; receiving eleventh information sent by the sixth node, the eleventh information comprising the address information of the second node; The eighth information comprises the identification information of the first resource owner, and / or the identification information of the second API invoker.

41. An information processing method characterized by comprising: The method is executed by the fifth node, and the method comprises: receiving eighth information sent by the first node or the fourth node, the eighth information being used for requesting the fifth node to provide identification information of the second node; sending ninth information to the first node or the fourth node, the ninth information comprising the identification information of the second node; The eighth information comprises the identification information of the first resource owner, and / or the identification information of the second API invoker.

42. An information processing method characterized by comprising: The method is executed by the sixth node, and the method comprises: receiving tenth information sent by the first node or the fourth node, the tenth information being used for requesting the sixth node to provide address information of the second node, the tenth information comprising the identification information of the second node; sending eleventh information to the first node or the fourth node, the eleventh information comprising the address information of the second node.

43. A first node, the first node comprising: The method comprises: The first transceiver module is configured to obtain first information, wherein the first information comprises authorization-related information associated with the second node.

44. A second node, comprising: The first transceiver module is configured to obtain first information, wherein the first information comprises authorization-related information associated with the second node. The second transceiver module is configured to send the first information to the first node, wherein the first information comprises authorization-related information associated with the second node.

45. A third node, characterized in that, The second transceiver module is configured to send the first information to the first node, wherein the first information comprises authorization-related information associated with the second node. The third transceiver module is configured to send third information to the first node, wherein the third information comprises authorization request-related information associated with a second resource owner of a third node. The third information is used to request authorization for a first API invoker, and the second resource owner is an expected resource owner of the first API invoker.

46. A first API caller, characterized by, The third transceiver module is configured to send third information to the first node, wherein the third information comprises authorization request-related information associated with a second resource owner of a third node. The third information is used to request authorization for a first API invoker, and the second resource owner is an expected resource owner of the first API invoker. The fifth transceiver module is configured to receive fourth information sent by the first node, wherein the fourth information is used to notify that authorization of the second API invoker is revoked, and the fourth information indicates revoked authorization information.

47. A second API invoker, characterized in that, The first transceiver module is configured to send fifth information to the first node, wherein the fifth information is used to feed back that the authorization is revoked. One or more processors are included. The processor is configured to perform the communication method in any one of claims 1-22, or 23-27, or 28-33, or 39-40, or 41, or 42.

48. A communications device, characterized by One or more processors are included. The processor is configured to perform the communication method in any one of claims 34-35, or 36-38. The computer-readable storage medium stores executable instructions, which are loaded and executed by the processor to implement the method in any one of claims 1-22, or 23-27, or 28-33, 34-35, or 36-38, or 39-40, or 41, or 42.

49. A communications device, characterized by ​ ​ ​ 50. A computer-readable storage medium, characterized in that, ​

Citation Information

Patent Citations

  • Service API calling method and related device

    CN110362412A

  • Authorization method, device and system and storage medium

    CN117546163A

  • Authorization revocation method and device, and storage medium

    CN117882052A

  • Method and apparatus for revoking authorization of API invoker

    US20210320923A1

  • Network node, resource owner device, system, and communication method

    WO2023084606A1