Apparatus, method and computer program
The CAPIF framework addresses the challenge of secure API communication across trust domains by enabling secure method negotiation and authentication, ensuring efficient and interoperable service sharing.
Patent Information
- Application Number
- PCT/EP2025/072214
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-04
- Filing Date
- 2025-08-01
- Publication Date
- 2026-02-12
AI Technical Summary
Existing communication networks face challenges in establishing secure connections between application programming interfaces (APIs) across different trust domains, particularly in scenarios where security information for API invokers and exposure functions is not readily available or synchronized across domains.
Implementing a common application programming interface (CAPIF) framework that facilitates the exchange of security information and methods between API invokers and exposure functions across trust domains, using mechanisms like TLS-PSK and TLS-PKI to establish secure connections and authenticate entities, and utilizing CAPIF core functions to manage and share security information.
Enables secure and efficient communication between APIs across different trust domains by ensuring mutual authentication and secure method negotiation, thereby facilitating seamless service sharing and interoperability among service providers.
Smart Images

Figure EP2025072214_12022026_PF_FP_ABST
Abstract
Description
[0001] APPARATUS, METHOD AND COMPUTER PROGRAM
[0002] TECHNICAL FIELD
[0003] Various example embodiments relate generally to methods, apparatus, system and computer programs and in particular, but not exclusively, to methods, apparatus, system and computer programs relating to Common Application Interface (API) Framework (CAPIF) interconnection between different domains.
[0004] BACKGROUND
[0005] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 5G (5th Generation) standards provided by 3GPP and future standards such as 6G and beyond
[0006] SUMMARY
[0007] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.
[0008] According a first aspect, there is provided an apparatus providing a first common application programming interface core function in a first trust domain comprising means for: receiving a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0009] Other optional features of the first aspect may be seen from the claims dependent on claim 1.
[0010] According to a second aspect, there is provided a method comprising: receiving a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0011] The method may comprise one or more of: receiving the request for security information from the application programming interface invoker; or providing the security information for the connection between the application programming interface invoker and the application programming interface exposure function to the application programming interface invoker.
[0012] The request for security information may comprise a request for a security method to be used in the connection between the application programming interface invoker and the application programming interface exposure function.
[0013] The request for security information may comprise one or more of: information indicating one or more security methods supported by the application programming interface invoker; or information about the application programming interface exposure function.
[0014] The method may comprise sending a request for security information to a second common application programming interface core function in the second trust domain.
[0015] The request for security information for sending to the second common application programming interface core function may comprise information relating to a first common application programming interface core function.
[0016] The method may comprise determining the second common application programming interface core function in the second trust domain associated with the application programming interface exposure function.
[0017] The method may comprise receiving a response from the second common application programming interface core function to the request for security information, the response comprising one or more of: information about the second common application programming interface core function; information about a security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
[0018] The security information for the connection between the application programming interface invoker and the application programming interface exposure function provided to the application programming interface invoker may comprise one or more of: information about the security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
[0019] The method may comprise one or more of: receiving the request for security information from a second common application programming interface core function in the second trust domain; or providing the security information, for the connection between the application programming interface invoker and the application programming interface exposure function, to the second common application programming interface core function.
[0020] The request for security information may comprise information relating to the second common application programming interface core function.
[0021] The security information, for the connection between the application programming interface invoker and the application programming interface exposure function, provided to the second common application programming interface core function may comprise: a pre-shared key of the application programming interface exposure function.
[0022] The method may comprise receiving a query from the second common application programming interface core function, said query relating to ownership of the application programming interface invoker, and providing a response to the second common application programming interface core function indicating that the first common application programming interface core function is an owner of the application programming interface invoker.
[0023] The method may be performed by an apparatus.
[0024] The apparatus may be an apparatus providing a first common application programming interface core function. The apparatus may be in a / the first trust domain.
[0025] The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to provide one or more of the methods of the second aspect.
[0026] According to a third aspect, there is provided an apparatus providing a second common application programming interface core function in a second trust domain comprising means for: receiving, from a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, to the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0027] The request for security information for sending to the second common application programming interface core function may comprise information relating to the first common application programming interface core function.
[0028] The means may be for selecting a security method
[0029] The response may comprise one or more of: information about the second common application programming interface core function; information about a security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
[0030] According to a fourth aspect, there is provided a method comprising: receiving, from a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, to the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0031] The request for security information for sending to the second common application programming interface core function may comprise information relating to the first common application programming interface core function.
[0032] The means may be for selecting a security method
[0033] The response may comprise one or more of: information about the second common application programming interface core function; information about a security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
[0034] The method may be performed by an apparatus.
[0035] The apparatus may be an apparatus providing a second common applica- tion programming interface core function. The apparatus may be in a / the second trust domain. The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to provide one or more of the methods of the fourth aspect.
[0036] According to a fifth aspect, there is provided an apparatus providing a second common application programming interface core function in a second trust domain comprising means for: providing, to a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and an application programming interface exposure function in the second trust domain; and receiving, from the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0037] The received security information may comprise: a pre-shared key of the application programming interface exposure function.
[0038] The means may be for sending a query to the first common application programming interface core function, said query relating to ownership of the application programming interface invoker, and receiving a response indicating that the first common application programming interface core function is an owner of the application programming interface invoker.
[0039] The means may be for sending the query relating to ownership of the application programming interface invoker to a plurality of common application programming interface core functions, said plurality of common application programming interface core functions being interconnected to the second application programming interface core function.
[0040] The means may be for receiving a request for security information from the application exposure function, prior the providing the request for security information to the first common application programming interface core function.
[0041] The request for security information received from the application exposure function may comprise one or more of: information about the first common application programming interface core function; and identity information for the application programming interface invoker.
[0042] According to a sixth aspect, there is provided a method comprising: providing, to a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and an application programming interface exposure function in a second trust domain; and receiving, from the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0043] The received security information may comprise: a pre-shared key of the application programming interface exposure function.
[0044] The method may comprise sending a query to the first common application programming interface core function, said query relating to ownership of the application programming interface invoker, and receiving a response indicating that the first common application programming interface core function is an owner of the application programming interface invoker.
[0045] The method may comprise sending the query relating to ownership of the application programming interface invoker to a plurality of common application programming interface core functions, said plurality of common application programming interface core functions being interconnected to the second application programming interface core function.
[0046] The method may comprise receiving a request for security information from the application exposure function, prior the providing the request for security information to the first common application programming interface core function.
[0047] The request for security information received from the application exposure function may comprise one or more of: information about the first common application programming interface core function; and identity information for the application programming interface invoker.
[0048] The method may be performed by an apparatus.
[0049] The apparatus may be an apparatus providing a second common application programming interface core function. The apparatus may be in a / the second trust domain.
[0050] The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to provide one or more of the methods of the sixth aspect.
[0051] According to a seventh aspect, there is provided an apparatus providing an application programming interface invoker in a first trust domain comprising means for: sending a request for security information for a connection between the application programming interface invoker and an application programming interface exposure function in a second trust domain; and receiving, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0052] The means may be for one or more of: sending the request to a first common application programming interface core function in the first trust domain; or the receiving the response from the first common application programming interface core function.
[0053] The means may be for one or more of: sending the request to the application exposure function; or the receiving the response from the application exposure function.
[0054] The request for security information may comprise a request for a security method to be used in the connection between the application programming interface invoker and the application programming interface exposure function.
[0055] The request for security information may comprise one or more of: information indicating one or more security methods supported by the application programming interface invoker; information about the application programming interface exposure function; or information about a first common application programming interface core function in the first trust domain .
[0056] The security information for the connection between the application programming interface invoker and the application programming interface exposure function provided to the application programming interface invoker may comprise one or more of: information about the security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
[0057] According to an eighth aspect, there is provided a method comprising: sending a request for security information for a connection between the application programming interface invoker and an application programming interface exposure function in a second trust domain; and receiving, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0058] The method may comprise one or more of: sending the request to a first common application programming interface core function in the first trust domain; or the receiving the response from the first common application programming interface core function. The method may comprise one or more of: sending the request to the application exposure function; or the receiving the response from the application exposure function.
[0059] The request for security information may comprise a request for a security method to be used in the connection between the application programming interface invoker and the application programming interface exposure function.
[0060] The request for security information may comprise one or more of: information indicating one or more security methods supported by the application programming interface invoker; information about the application programming interface exposure function; or information about a first common application programming interface core function in the first trust domain .
[0061] The security information for the connection between the application programming interface invoker and the application programming interface exposure function provided to the application programming interface invoker may comprise one or more of: information about the security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
[0062] The method may be performed by an apparatus.
[0063] The apparatus may be an apparatus providing an application programming interface invoker. The apparatus may be in a / the first trust domain.
[0064] The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to provide one or more of the methods of the eighth aspect.
[0065] According to a ninth aspect, there is provided an apparatus providing an application exposure function in a second trust domain comprising means for: providing, to a second common application programming interface core function in the second trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and the application programming interface exposure function; and receiving, from the second common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0066] The request provided to the second common application programming interface core function may comprise one or more of: information about the identity of the application programming interface invoker; and information about a first common application programming interface core function in the first trust domain.
[0067] The security information may comprise: a pre-shared key of the application programming interface exposure function.
[0068] According to a ninth aspect, there is provided a method comprising: providing, to a second common application programming interface core function in the second trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and the application programming interface exposure function; and receiving, from the second common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0069] The request provided to the second common application programming interface core function may comprise one or more of: information about the identity of the application programming interface invoker; and information about a first common application programming interface core function in the first trust domain.
[0070] The security information may comprise: a pre-shared key of the application programming interface exposure function.
[0071] The method may be performed by an apparatus.
[0072] The apparatus may be an apparatus providing an application exposure function. The apparatus may be in a / the second trust domain.
[0073] The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to provide one or more of the methods of the sixth aspect.
[0074] According to another aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0075] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0076] According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods. In the above, many different aspects have been described. It should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above.
[0077] Various other aspects are also described in the following detailed description and in the attached claims.
[0078] List Of The Drawings
[0079] In the following, the invention will be described in greater detail with reference to the embodiments and the accompanying drawings, in which:
[0080] Fig. 1 shows an example of a negotiation of a security method between and API invoker and a CAPIF core function (CCF);
[0081] Fig. 2 shows establishment of a TLS (transport layer security) session between the API invoker and an API exposure function;
[0082] Fig. 3 shows an example architecture with a first trust domain and a second trust domain;
[0083] Fig. 4 shows a first procedure of some embodiments;
[0084] Fig. 5 shows a second procedure of some embodiments;
[0085] Fig. 6 shows a third procedure of some embodiments;
[0086] Fig. 7 to 11 show first to fifth methods of some embodiments; and
[0087] Fig. 12 shows an example of an apparatus;
[0088] DETAILED DESCRIPTION
[0089] The following embodiments are provided by way of non-limiting and illustrative example. Although the specification may refer to “an”, “one”, or “some” embodiments) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s), or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it intended such feature, structure, or characteristic may be applied in connection with other embodiments (whether or not explicitly described).
[0090] It shall be understood that although the terms “first,” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.
[0091] For the purposes of this disclosure, the phrases “at least one of A or B”, “at least one of A and B”, and “A and / or B” means (A), (B), or (A and B). For the purposes of this disclosure, the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).
[0092] As used herein, the term “or” refers to a non-exclusive “or” unless otherwise indicated (e.g., use of “or else” or “or in the alternative”).
[0093] As used herein, unless stated explicitly, performing a respective feature, step, or functionality “in response to A” does not indicate that the respective feature, step, or functionality is performed immediately after “A” occurs as one or more intervening features, steps, or functionalities may be performed (at least in part) between an occurrence of the respective feature, step, or function and “A”. Analogously, performing a respective feature, step, or functionality “based on A” does not indicate that the respective feature, step, or functionality is performed solely based on “A” as the respective feature, step, or functionality may be further based on one or more other features, steps, or functionalities in addition to “A”.
[0094] Some embodiments relate to a common API framework (CAPIF). This defines common aspects applicable to any northbound service API. A northbound service API is exposed to higher-layer API invokers.
[0095] Reference is made to Figure 1 which shows an example of a negotiation of a security method between and API invoker and a CAPIF core function (CCF). The API invoker is an entity which invokes the CAPIF or service APIs. The CAPIF core function may be configured as a serving CAPIF core function for interconnection.
[0096] In this example, the security method is negotiated between the API invoker and the CCF. A connection between the API invoker and an API exposing function (AEF) is then established. The connection may be established using the TLS (transport layer security )-PSK (pre-shared key) and TLS-PKI (public key infrastructure) methodology after security method negotiation.
[0097] After successful mutual authentication between the API invoker and the CCF, the CCF core function may choose the security method(s) and sends the chosen security method(s) along with the information required for authentication of the API invoker at the AEF to the API invoker.
[0098] In the example of Figure 1 , the API invoker is onboarded with the CCF.
[0099] As referenced 1 , mutual authentication of API invoker and the CAPIF core function may be established. This may be based on client and server certificates and use a TLS protocol between the API invoker and the CAPIF core function.
[0100] As referenced 2, the API invoker may send security capability information to the CAPIF core function in a security method request message. This message may indicate the list of security methods that the API invoker supports for each AEF.
[0101] As referenced 3, the CAPIF core function selects a security method to be used over CAPIF-2 / 2e reference point (that is between the API invoker and the AEF) for each requested AEF. This may take into account the information received from the API invoker in the security method request message, one or more access scenarios, and AEF capabilities.
[0102] As referenced 4, the CAPIF core function sends a security method response message to the API invoker. This security method response message indicates the selected security method for each AEF and any security information related to the security method. The API invoker may use the selected security method in the subsequent communication establishment with the API exposing function.
[0103] To negotiate and obtain service API security method information from the CAPIF core function, the API invoker may send an HTTP (hypertext transfer protocol) PUT message to the CAPIF core function. The body of the HTTP PUT message may comprise the security method request and a notification destination URI (uniform resource identifier) for security related notifications. The security method request from the API invoker may comprise interface details of the service APIs and may contain a preferred method for a respective service API interface.
[0104] When the HTTP PUT message is received by the CCF, the CCF may determine the security method for each service API interface. The CCF may store the notification destination URI for security related notifications. The CCF may create a new resource. The CCF may return the security method information and the CAPIF resource URI in the response message. If an error occurs when processing the request, the CAPI F core function may respond to the API invoker with an appropriate error message.
[0105] Reference is made to Figure 2 which shows the establishment of a TLS session between the API invoker and the AEF. This may use a TLS-PSK method.
[0106] CAPIF-1e (between the API invoker and the CCF) authentication may be used to bootstrap a pre-shared key for authenticating a TLS connection for CAPIF-2e (between the API invoker and the AEF). The API invoker and the CAPIF core function may be pre-provisioned with certificates.
[0107] As referenced 1 , a CAPIF-1e authentication and secure session is established between the API invoker and the CCF. The CCF may provide a validity timer value for the key AEF PSK.
[0108] As referenced 2, the API invoker and the CCF each derive the secret key AEF PSK. The key AEF PSK may be bound to an AEF. The API invoker and the CAPIF core function each start the validity timer for the key AEF PSK.
[0109] In some cases, the parts of the procedure referenced 1 and 2 may be skipped if the API invoker is already in possession of a valid key AEF PSK.
[0110] As referenced 3, the API invoker sends an authentication initiation request to the AEF. This request may comprise the CAPIF core function assigned API invoker ID.
[0111] As referenced 4A, the AEF may request security information from the CCF to perform authentication and secure interface establishment with the API invoker, if the AEF does not have a valid key.
[0112] As referenced 4B, the CCF provides the security information related to the chosen security method (TLS-PSK: AEF PSK) to the AEF. The CCF may provide the remaining validity timer value for the key AEF PSK.
[0113] As referenced 5, after fetching the relevant security information (AEF PSK) for the authentication, the AEF may send an authentication initiation response message to the API invoker to initiate the TLS session establishment. The AEF may starts the validity timer based on the value received from the CCF.
[0114] As referenced 6, the API invoker and the AEF perform mutual authentication using the key AEF PSK and establish TLS session over the CAPIF-2e. After successful establishment of TLS on CAPIF-2e reference point, the AEF may authorize the service API invocation request of the API invoker based on authorization information obtained from the CCF.
[0115] Service federation between different service providers supports service sharing. For example, two organizations with a business relationship that have each deployed CAPIF may need to interoperate to allow API invokers in each trust domain to utilize service APIs from both CAPIFs.
[0116] Some embodiments may relate to the issue of ensuring security where for example an API invoker wants to invoke an API from a different service provider.
[0117] Reference is made to Figure 3 which shows an example architecture with a first trust domain and a second trust domain. The first and second trust domain may be associated with different trust providers.
[0118] Each trust domain has a CCF and an API invoker. It should be appreciated than one or more API invokers may be provided outside the first and second trusted domains. An API invoke may for example be on a UE or outside the UE.
[0119] Each trust domain has an API provider domain. The API provider domain may comprise an API management function, an API publishing function and an API exposing functions.
[0120] The interfaces are as follows:
[0121] CAPIF-1 - between the API invoker and the CAPIF APIs of the CCF.
[0122] CAPIF-1e - between an API invoker outside the trust domain and the CAPIF APIs of the CCF.
[0123] CAPIF-2 - between the API invoker and the service APIs of the AEF.
[0124] CAPIF-2e - between an API invoker outside the trust domain and the service APIs of the AEF.
[0125] CAPIF-3 - between the AEF and the CCF.
[0126] CAPIF-4 - between the API publishing function and the CCF.
[0127] CAPIF-5 - between the API management function and the CCF.
[0128] CAPIF6e - between the CCF of one domain and the CCF of a different trust domain.
[0129] Some embodiments address the issue of how an API invoker of one domain finds out the security method supported by the AEF of another domain. For example the API invoker of one trust domain needs to know the security method supported by the AEF in a different trust domain. This is to establish a secure connection with AEF before fetching of any service from the AEF.
[0130] Some embodiments may address the issue of how an AEF of one domain finds out the session security information of API invoker of another domain to allow authentication between API invoker and AEF of the different security domains.
[0131] For example an API invoker and a first CCF are in a first domain and the AEF and the second CCF are in a second domain. When the API invoker in the first domain sends an authentication initiation request to AEF in the second domain, the AEF needs to request security information. However, the second CCF will not have the security information of the API invoker in the first domain. Some embodiments may address this issue.
[0132] Consider the following example where an API invoker on a user equipment (UE) seeks to access a location service provided by AEF of a different domain. The API invoker needs to authenticate with the AEF. The AEF requires the certificate (TLS-PKI) or AEF-PSK (TLS-PSK) of the API invoker to establish a secure TLS connection. However, currently the CCF in the same domain as the AEF is not able to the fetch security information details specific to the API invoker which is in a different domain. Some embodiments may address this issue.
[0133] Some embodiments will now be described. In the following examples, the API invoker and CCF-B are situated within one domain (domain B in this example). The AEF and CCF-A reside within another domain (domain A in this example). The API invoker of domain B wants to access the AEF of domain A.
[0134] A first example procedure of some embodiments will now be described with reference to Figure 3. In this procedure, the API invoker of one domain (domain B in this example) gets to know the security method supported by the AEF of another domain (domain A in this example).
[0135] As referenced 1 , mutual authentication is established between the API invoker and the CCF-B. The API invoker and the CCF-B are in the same domain (domain B). The mutual authentication may be established based on client and server certificates using TLS methodology between the API invoker and the CCF-B.
[0136] As referenced 2, the API invoker sends its security capability information along with the AEF details to CCF-B. The security capability information along with the AEF details may be sent in a security method request message. The security capability information may be CAPIF-2 / 2e security capability information. The AEF details are to indicate the AEF with which the secure connection is to be established.
[0137] CCF-B is where the API invoker is registered. CCF-B knows the APIs offered by other domain AEFs via an API publish request done by other domain CCFs.
[0138] The API invoker security capability information may indicate one or more or a list of security methods supported by the API invoker.
[0139] The API invoker sends its CAPIF-2 / 2e security capability information along with AEF details to the CCF-B in the Security Method Request message.
[0140] As referenced 3, CCF-B may identifies the CCF (CCF-A) associated with AEF from its locally stored data. For example, the CCF-A may publish the API details supported by its domain (domain A) to CCF-B. This may be by an API publish request. The CCF-B may identify that the request should go to CCF-A based on the information in the published details.
[0141] As referenced 4, CCF-B sends the request to CCF-A. CCF-B may optionally append CCF-B information.
[0142] As referenced 5, CCF-A may select a security method to be used between the AEF and the API invoker. This may be over the CAPIF-2 / 2e reference point for requested AEF. The selection of the security method is based on the information received from CCF-B. The selection of the security method may alternatively or additionally be based on one or more of access scenarios and / or AEF capabilities.
[0143] As referenced 6, the CCF-A may send a response to the CCF-B. The response may be a security method response message. The CCF-A may optionally provide CCF-A. The response may comprise the selected security method for the AEF. The response may also comprise security information related to the security method.
[0144] As referenced 7, the CCF-B sends the response to the API invoker. The response may be the security method response. The CCF-B may provide an indication to the API invoker that AEF belongs to a different domain to the API invoker.
[0145] A second example procedure of some embodiments will now be described with reference to Figure 4. In this procedure, the AEF of one domain (domain A) gets to know the session security information of an API invoker of another domain (domain B) to allow authentication between the API invoker and AEF.
[0146] The parts of the procedure referenced 1 to 3 may be regarded as preconditions.
[0147] As referenced 1 , the API invoker has the detail relating to the AEF. These details may comprise the security method(s) supported by the AEF and the TLS-PSK from CCF-B. This may be as discussed in relation to the procedure shown in Figure 3.
[0148] As referenced 2, an authentication and secure session is established between the API invoker and CCF-B. Mutual authentication based on client and server certificates is thus established using TLS between the API invoker and the CCF-B. The CCF may provide a validity timer value for the key AEF PSK.
[0149] As referenced 3, the API invoker and CCF-B each derive the secret key AEF PSK. This may be based on the TLS master key used in the part of the procedure referenced 2. The key AEF PSK may be bound to an AEF. The API invoker and the CAPIF core function each start the validity timer for the key AEF PSK.
[0150] As referenced 4, the API invoker sends an authentication initiation request to the AEF based on the AEF details received in the part of the procedure referenced 1.
[0151] As referenced 5, the AEF requests security information from CCF-A. The AEF is registered with CCF-A. The security information may be for the API invoker. The request may comprise the identity of the API invoker.
[0152] CCF-A checks if the API invoker is registered. If not, then as referenced 6 and 7 (which may take place at the same time or in any order), CCF-A sends a query to one or more or all of its interconnected CCFs, which in this example are CCF-B and CCF-C. It should be appreciated that there may be one or more interconnected CCFs. The query may be determine which CCF owns or is associated with the API invoker. The query may comprise the identity of the API invoker. The query may be an API invoker ID ownership query.
[0153] The CCF with which the API invoker is registered will, as referenced 8, provide a response. In this example CCF-B responds to CCF-A. The response from CCF-B will indicate that the API invoker is associated with it. This response may comprise the identity of the API invoker.
[0154] As referenced 9, the CCF-A sends a request to CCF-B for security information for the API invoker. Optionally, CCF-A provides information relation to CCF-A.
[0155] As referenced 10, CCF-B sends a response to CCF-A. This response comprises the AEF-PSK.
[0156] As referenced 11 , CCF-A sends a response to AEF.
[0157] As referenced 12, the AEF may send an authentication initiation response message to the API invoker to initiate the TLS session establishment. The AEF may starts the validity timer based on the value received from CCF-B via CCF-A.
[0158] As referenced 13, the API invoker and the AEF perform mutual authentication using the key AEF PSK and establish TLS session over the CAPIF-2e. After successful establishment of TLS on CAPIF-2e reference point, the AEF may authorize the service API invocation request of the API invoker based on authorization information obtained from CCF-B via CCF-A.
[0159] This example procedure ensures that CCF-A obtains the necessary information from the appropriate source (CCF-B) within its interconnected network of CCFs. Mutual authentication is provided by establishing the TLS between the API invoker of CCF-B and the AEF of CCF-A utilizing AEF PSK.
[0160] A third example procedure of some embodiments will now be described with reference to Figure 5. In this procedure, the AEF of one domain (domain A) gets to know the session security information of an API invoker of another domain (domain B) to allow authentication between the API invoker and AEF.
[0161] The parts of the procedure referenced 1 to 3 may be as described in the corresponding parts of the procedure of Figure 4.
[0162] As referenced 4, the API invoker sends an authentication initiation request to the AEF based on the AEF details received in the part of the procedure referenced 1. The API invoker also provides information about CCF-B.
[0163] As referenced 5, the AEF requests security information from CCF-A. The AEF is registered with CCF-A. The security information may be for the API invoker. The request may comprise the identity of the API invoker. The request comprises the information about CCF-B. As referenced 6, CCF-A determines that CCF is to be contacted.
[0164] As referenced 7, the CCF-A sends a request to CCF-B for security information for the API invoker. Optionally, CCF-A provides information relation to CCF-A. The request may comprise the identity of the API invoker.
[0165] As referenced 8, CCF-B sends a response to CCF-A. This response comprises the AEF-PSK.
[0166] As referenced 9, CCF-A sends a response to AEF.
[0167] As referenced 10, the AEF may send an authentication initiation response message to the API invoker to initiate the TLS session establishment. The AEF may starts the validity timer based on the value received from CCF-B via CCF-A.
[0168] As referenced 11 , the API invoker and the AEF perform mutual authentication using the key AEF PSK and establish TLS session over the CAPIF-2e. After successful establishment of TLS on CAPIF-2e reference point, the AEF may authorize the service API invocation request of the API invoker based on authorization information obtained from CCF-B via CCF-A.
[0169] In the example procedure of Figure 5, the API invoker thus sends the CCF-B details to the AEF. This allows the AEF / CCF-A to identify the CCF from which it can get the security information of the API invoker (i.e. from CCF-B).
[0170] Reference is made to FIGs. 7 to 11 which shows some methods of some example embodiments.
[0171] The respective methods may be performed by an apparatus.
[0172] The apparatus may comprise suitable means, such as circuitry for providing the method.
[0173] Alternatively or additionally, the apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor cause the apparatus at least to provide the method below.
[0174] Alternatively or additionally, the apparatus may be such as discussed in relation to FIG. 12.
[0175] The respective methods may be provided by computer program code or computer executable instructions.
[0176] Reference is made to Figure 7. The apparatus may be or provide a common application programming interface core function.
[0177] The method comprises as referenced A1 , receiving a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain.
[0178] The method comprises as referenced A2, providing, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0179] Reference is made to Figure 8. The apparatus may be or provide a common application programming interface core function.
[0180] The method comprises as referenced B1 , receiving, from a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain.
[0181] The method comprises as referenced B2, providing, to the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0182] Reference is made to Figure 9. The apparatus may be or provide a common application programming interface core function.
[0183] The method comprises as referenced C1 , providing, to a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and an application programming interface exposure function in a second trust domain.
[0184] The method comprises as referenced C2, receiving, from the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0185] Reference is made to Figure 10. The apparatus may be or provide a an application programming interface invoker.
[0186] The method comprises as referenced D1 , sending a request for security information for a connection between the application programming interface invoker and an application programming interface exposure function in a second trust domain.
[0187] The method comprises as referenced D2, receiving, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0188] Reference is made to Figure 11. The apparatus may be or provide an application programming interface exposure function.
[0189] The method comprises as referenced E1 , providing, to a second common application programming interface core function in the second trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and the application programming interface exposure function.
[0190] The method comprises as referenced E2, receiving, from the second common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
[0191] Fig. 12 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). In an example, the at least one memory and the instructions (e.g. a computer program code, software), are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof).
[0192] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with embodiments described herein.
[0193] As used herein, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit(s) with software / f ironware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessors), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0194] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may, for example, be at least in part external to apparatus 10 but accessible to apparatus 10.
[0195] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM).
[0196] For example, the apparatus 10 may provide a common application programming interface core function. The apparatus may comprise a chipset, The apparatus 10 may be caused or configured to perform at least the method of Figs. 6, 7 or 8, and / or any one or more of the embodiments described herein.
[0197] For example, the apparatus 10 may provide a an application exposure function. The apparatus may comprise a chipset, The apparatus 10 may be caused or configured to perform at least the method of Fig. 11 , and / or any one or more of the embodiments described herein.
[0198] For example, the apparatus 10 may provide an application programming interface invoker. The apparatus may comprise a chipset, The apparatus 10 may be caused or configured to perform at least the method of Fig. 10, and / or any one or more of the embodiments described herein.
[0199] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity.
[0200] The apparatus 10 optionally comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.
[0201] The apparatus 10 may optionally comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.
[0202] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C]”, is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.
[0203] The following provide some example 3GPP contributions according to some embodiments of this disclosure.
[0204] Security aspects in CAPIF interconnect
[0205] Two organizations with a business relationship that have each deployed CAPIF may need to interoperate to allow API invokers in each trust domain to utilize service APIs from both CAPIFs. For example, see figure 4.12.1-1 of 3GPP TS 23.222
[0206] The existing CAPIF procedures supporting interconnection are described in 3GPP TS 23.222 clause 8.25 which include service API publish / retrieval / update / un- publish and discovery over CAPIF-6 / 6e reference point. Only the scenario in which the API provider domain functions are registered in a CCF within the same trusted domain are considered.
[0207] The CCFs are connected via CAPIF-6e, in order to share service APIs. The API provider domain function (e.g. AEF) of one domain only sees its CCF, where it is registered. It does not see the interconnected CCF in another domain, but needs to be able to provide AEF service APIs to an API invoker onboarded in a CCF in another domain via CAPIF-2e. CCFs that are interconnected know from each other.
[0208] This issue is about how to secure the provisioning of AEF service APIs to API invokers onboarded in the CCF of one domain when the API provider domain functions are registered in a CCF of another domain.
[0209] I.e. how does the AEF of one domain authenticate and authorize the API access from an API invoker of another domain as the API invoker needs to obtain authorization information from CCF in the other domain.
[0210] It may need to be checked, if security needs to be enhanced for any new event exposure service in support of CAPIF interconnection over CAPIF-6 / 6e.
[0211] Security threats
[0212] An unauthenticated API Invoker of one domain could access API services of an AEF hosted in another domain.
[0213] API invoker may get unauthorized access to API services exposed by an AEF.
[0214] Security requirements
[0215] The API invoker of one security domain and the AEF of a different security domain may be able to mutually authenticate.
[0216] The API invoker may be able to get authorization for accessing the API services of an AEF different from where the API invoker is registered.
[0217] The API invoker may be able to retrieve securely the security method needed for accessing an API service registered at a CCF different from its own registration.
[0218] Security method retrieval in CAPIF interconnect
[0219] This example may address security aspects for CAPIF interconnect, specifically the security method retrieval to allow for authentication and authorization of the API invoker to the AEF.
[0220] An API invoker may fetch from CCF (via CAPIF-2) information about the security method to access the API service (via CAPIF-1).
[0221] An API invoker may request an API Service and the AEF is fetching the information about the API invoker from CCF (via CAPIF-3).
[0222] While this is specified for one security domain, in case of interconnect additional steps may be needed because the API invoker is registered with one service provider's CCF while the AEF offering the API services is registered in another service provider’s CCF.
[0223] The solution describes how the API invoker is retrieving the supported security method of the exposing API in the CAPIF interconnect case, i.e. the API invoker wants to invoke the API from a different service provider than a AEF known at its local CCF.
[0224] The API invoker wants to consume APIs offered at an AEF outside of its trust domain. In its Security Method Request message to its local CCF (CCF-B) (via CAPIF-2 / 2e) the API invoker may include AEF details along with the security capability information to allow the local CCF to find the CCF where the AEF is registered. [With the current CAPIF framework the API invoker cannot get details from its own CCF (CCF-B) about the APIs offered at the requested AEF in the other security domain.]
[0225] Based on the AEF details received from the API invoker, CCF-B identifies the CCF responsible (i.e. CCF-A) where the AEF is registered and forwards the request to this CCF-A.
[0226] CCF-A selects a security method for the API service requested from its AEF, considering the information received from CCF-B, access scenarios and AEF capabilities. CCF-A sends a Security Method Response message back to CCF-B, providing the selected security method that allows to get authorization to access the AEF, and any security information related to the security method.
[0227] CCF-B sends the response to the API Invoker.
[0228] Reference is made to Figure 4: Information flow to retrieve security method in interconnect.
[0229] Step 1 : Mutual authentication based on client and server certificates may be established using TLS between the API invoker and the CCF-B.
[0230] Step 2: The API invoker sends its CAPI F-2 / 2e security capability information along with AEF details to the CCF-B in the Security Method Request message. API Invoker security capability information is to indicate the list of security methods it supports and the AEF details from which the security method information retrieval is requested.
[0231] Step 3: CCF-B identifies the CCF (CCF-A) associated with AEF from its locally stored data.
[0232] Step 4: CCF-B sends the request to CCF-A, optionally appending CCF-B information.
[0233] Step 5: CCF-A may select a security method to be used over CAPIF-2 / 2e reference point for requested AEF, considering the information received from CCF-B, access scenarios and AEF capabilities.
[0234] Step 6: The CCF-A may send a Security Method Response message to the CCF-B (optionally adding CCF-A information), indicating the selected security method for the AEF, any security information related to the security method.
[0235] Step 7: The CCF-B sends the Security Method Response to API Invoker. Additionally, CCF-B also provides an indication to API Invoker that AEF belongs to a different domain.
[0236] Authentication using TLS-PSK in CAPIF interconnect
[0237] This may address security aspects for CAPIF interconnect, specifically the authentication aspect between API invoker and AEF if in different security domains.
[0238] An API invoker registered at CCF-B wants to authenticate to an AEF (registered at CCF-A) to consume its API services. CCF-B knows the security method of AEF to enable an API invoker to access the API service (via CAPIF-1). This example describes how the AEF in one security domain and the API invoker in the other security domain are enabled to establish a security session using TLS-PSK in the interconnect case.
[0239] CCF-B and API invoker have obtained the security method that allows to authenticate to the AEF, and any security information related to the security method TLS-PSK. Hence, CCF-B and API invoker can derive AEFPSK based on the AEF’s API service details.
[0240] AEF receives an Authentication Initiation Request from API Invoker and requests security information of API invoker from the CCF-A it is registered with, mentioning the API Invoker ID. Since CCF-A does not know the API invoker, CCF-A needs to find the correct CCF. It therefore forwards the API Invoker ID to all interconnected CCFs. One of these CCFs responds (i.e. CCF-B) by confirming that it possesses information about the API Invoke rID. CCF-A gets the API Invoker information including the AEF PSKfrom CCF-B that confirmed about the knowledge of API Invoker ID information and authenticates the API invoker to AEF.
[0241] Reference is made to Figure 5: Information flow to allow establishment of TLS-PSK in interconnect
[0242] Step 1 : API Invoker gets the AEF details using Obtains_Security method from CCF-B
[0243] Step 2: Mutual authentication based on client and server certificates may be established using TLS between the API invoker and the CCF-B. Step 3: API invoker and CCF-B derive AEF-PSK based on TLS master key used in step 2.
[0244] Step 4: API Invoker sends Authentication Initiation Request to AEF based on AEF details received in step 1.
[0245] Step 5: AEF requests security information from CCF-A.
[0246] Step 6,7: CCF-A sends API Invoker ID Ownership Query to all its interconnected CCFs (in the figure CCF-B and CCF-C).
[0247] Step 8: CCF-B responds to API Invoker ID Ownership Query request confirming that the API Invoker ID belongs to it.
[0248] Step 9: CCF-A requests the security information from CCF-B and optionally provides CCF-A ‘s information.
[0249] Step 10: CCF-B sends the response by providing AEF-PSK to CCF-A.
[0250] Step 11 : CCF-A sends the response to AEF.
[0251] Step 12: AEF sends the Authentication Initiation Response to API Invoker.
[0252] Step 13: TLS connection is established between API Invoker and AEF using AEFPSK.
[0253] This process may ensure that CCF-A obtains the necessary information from the appropriate source within its interconnected network of CCFs and allows AEF to establish the TLS between API invoker and CCF-A utilizing AEF PSK in order to authenticate the API invoker of a different security domain.
[0254] Requesting security information from another CCF in order to authenticate using TLS-PSK in CAPIF interconnect
[0255] This may address security aspects for CAPIF interconnect, specifically the authentication aspect between API invoker and AEF if in different security domains.
[0256] CCF-B and API invoker have obtained the security method that allows to authenticate to the AEF, and any security information related to the security method TLS-PSK. Hence, CCF-B and API invoker can derive AEF PSK based on the AEF’s API service details.
[0257] AEF receives an Authentication Initiation Request from API Invoker, which includes the CCF-B information where the API invoker is registered. AEF requests security information of API invoker from the CCF-A it is registered with, mentioning the API Invoker ID and the CCF-B Information. CCF-A forwards the API Invoker ID to CCF- B which responds to CCF-A with the AEFPSK, which is forwarded to AEF.
[0258] API invoker and AEF authenticate using AEF PSK with the knowledge that
[0259] CCF-B confirmed the API Invoker ID information. Reference is made to Figure 6 - Information flow to allow authenticating API invoker to AEF in a different security domain
[0260] Step 1 : API Invoker gets the AEF details using Obtains_Security method from CCF-B (as described previously, for example)
[0261] Step 2: Mutual authentication based on client and server certificates shall be established using TLS between the API invoker and the CCF-B.
[0262] Step 3: API invoker and CCF-B derives AEF-PSK based on TLS master key used in step 2.
[0263] Step 4: API Invoker sends Authentication Initiation Request to AEF based on AEF details received in step 1 and CCF-B information.
[0264] Step 5: AEF requests security information from CCF-A by passing the CCB’s information received in step 4 along with API Invoker ID.
[0265] Step 6,7: CCF-A based on CCF-B’s information received requests security information from CCF-B.
[0266] Step 8: CCF-B sends the response by providing AEF-PSK to CCF-A.
[0267] Step 9: CCF-A sends the response to AEF.
[0268] Step 10: AEF sends the Authentication Initiation Response to API Invoker.
[0269] Step 11 : TLS connection is established between API Invoker and AEF using AEF-PSK.
[0270] Even though this disclosure has been described above with reference to non-limiting and illustrative examples according to the accompanying figures, it is clear that the scope of this disclosure is not restricted thereto - but can be modified in many different ways. As technology advances, it will become apparent to a person skilled in art as to how the disclosure can be further implemented and / or modified in various ways. Further, it is clear to a person skilled in the art that the embodiments described herein may, but are not required to, be combined in various ways with other embodiments described herein.
Claims
28CLAIMS1. An apparatus providing a first common application programming interface core function in a first trust domain comprising means for: receiving a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
2. The apparatus as claimed in claim 1 , wherein the means is for one or more of: receiving the request for security information from the application programming interface invoker; or providing the security information for the connection between the application programming interface invoker and the application programming interface exposure function to the application programming interface invoker.
3. The apparatus as claimed in claim 1 or 2, wherein the request for security information comprises a request for a security method to be used in the connection between the application programming interface invoker and the application programming interface exposure function.
4. The apparatus as claimed in any preceding claim, wherein the request for security information comprises one or more of: information indicating one or more security methods supported by the application programming interface invoker; or information about the application programming interface exposure function.
5. The apparatus as claimed in any preceding claim wherein the means is further for sending a request for security information to a second common application programming interface core function in the second trust domain.
6. The apparatus as claimed in claim 5, wherein the request for security information for sending to the second common application programming interface core function further comprises information relating to the first common application programming interface core function.
7. The apparatus as claimed in claim 5 or 6, wherein the means is for determining the second common application programming interface core function in the second trust domain associated with the application programming interface exposure function.
8. The apparatus as claimed in any of claims 5 to 7, wherein the means is for receiving a response from the second common application programming interface core function to the request for security information, the response comprising one or more of: information about the second common application programming interface core function; information about a security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
9. The apparatus as claimed in claim 2 or any claim appended thereto, wherein the security information for the connection between the application programming interface invoker and the application programming interface exposure function provided to the application programming interface invoker comprises one or more of: information about the security method to be used for the connection between the application programming interface invoker and the application programming interface exposure function; information about the application programming interface exposure function; or security information.
10. The apparatus as claimed in claim 1 , wherein the means is for one or more of: receiving the request for security information from a second common application programming interface core function in the second trust domain; or providing the security information, for the connection between the application programming interface invoker and the application programming interface exposure function, to the second common application programming interface core function..
11. The apparatus as claimed in claim 10, wherein the request for security information comprises information relating to the second common application programming interface core function.
12. The apparatus as claimed in claim 10 or 11 , wherein the security information, for the connection between the application programming interface invoker and the application programming interface exposure function, provided to the second common application programming interface core function comprises: a preshared key of the application programming interface exposure function.
13. The apparatus as claimed in any of claims 10 to 12, wherein the means is for receiving a query from the second common application programming interface core function, said query relating to ownership of the application programming interface invoker, and providing a response to the second common application programming interface core function indicating that the first common application programming interface core function is an owner of the application programming interface invoker.
14. An apparatus providing a second common application programming interface core function in a second trust domain comprising means for: receiving, from a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, to the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
15. An apparatus providing a second common application programming interface core function in a second trust domain comprising means for: providing, to a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and an application programming interface exposure function in the second trust domain; and receiving, from the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
16. The apparatus as claimed in claim 15, wherein the received security information comprises: a pre-shared key of the application programming interface exposure function.
17. The apparatus as claimed in claims 15 or 16, wherein the means is for sending a query to the first common application programming interface core function, said query relating to ownership of the application programming interface invoker, and receiving a response indicating that the first common application programming interface core function is an owner of the application programming interface invoker.
18. The apparatus as claimed in claim 17, wherein the means is for sending the query relating to ownership of the application programming interface invoker to a plurality of common application programming interface core functions, said plurality of common application programming interface core functions being interconnected to the second application programming interface core function.
19. An apparatus providing an application programming interface invoker in a first trust domain comprising means for: sending a request for security information for a connection between the application programming interface invoker and an application programming interface exposure function in a second trust domain; and receiving, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
20. An apparatus providing an application exposure function in a second trust domain comprising means for: providing, to a second common application programming interface core function in the second trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and the application programming interface exposure function; and receiving, from the second common application programming interface core function, in response to the request, security information for the connection between32 the application programming interface invoker and the application programming interface exposure function.
21. A method comprising: receiving a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
22. A method comprising: receiving, from a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in the first trust domain and an application programming interface exposure function in a second trust domain; and providing, to the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
23. A method comprising: providing, to a first common application programming interface core function in a first trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and an application programming interface exposure function in a second trust domain; and receiving, from the first common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
24. A method comprising: sending a request for security information for a connection between the application programming interface invoker and an application programming interface exposure function in a second trust domain; andreceiving, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
25. A method comprising: providing, to a second common application programming interface core function in the second trust domain, a request for security information for a connection between an application programming interface invoker in a first trust domain and the application programming interface exposure function; and receiving, from the second common application programming interface core function, in response to the request, security information for the connection between the application programming interface invoker and the application programming interface exposure function.
Citation Information
Patent Citations
Application programming interface (API) access management in wireless systems
WO2023144649A1