Method and device for transmission of avatar data over IMS data channel
The method and device for secure IMS-based avatar communication address unauthorized access and data manipulation issues by verifying the authenticity of avatar objects, ensuring only authorized entities can use them, thus enhancing security in avatar communication systems.
Patent Information
- Application Number
- PCT/KR2025/011995
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-13
- Filing Date
- 2025-08-08
- Publication Date
- 2026-02-12
AI Technical Summary
In avatar communication scenarios, unauthorized users can impersonate or manipulate avatar objects, posing security threats by initiating IMS avatar communication with forged IDs or tampering with data transmission, necessitating a system to ensure only authorized entities can access and verify the integrity of avatar objects.
A method and device for secure IMS-based avatar communication that involves establishing avatar communication, receiving rendering results, and determining the likelihood of attacks, ensuring only authorized UEs and network entities can use and verify the authenticity of avatar objects through a network-centric or UE-centric approach.
Ensures the security of avatar communication by allowing only authorized entities to use and verify the authenticity of avatar objects, preventing impersonation and data manipulation threats.
Smart Images

Figure KR2025011995_12022026_PF_FP_ABST
Abstract
Description
Method and device for transmitting avatar data via IMS data channel
[0001] The present disclosure relates to the field of communications, specifically, the operation of terminals, base stations, and core networks. In particular, the present disclosure relates to a method and device for ensuring that avatar data is used only by authorized entities in IMS (IP Multimedia Subsystem)-based avatar communication, and for verifying this fact.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz frequency band such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band called millimeter wave (mmWave) such as 28GHz and 39GHz ('Above 6GHz'). In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz band (for example, the 3 terahertz (3THz) band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and an ultra-low latency time that is reduced to one-tenth.
[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for enhanced Mobile Broadband (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC). These include beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple subcarrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and Polar Code for reliable transmission of control information, and L2 pre-processing (L2). Standardization has been made for network slicing, which provides dedicated networks specialized for specific services, and pre-processing.
[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.
[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (Industrial Internet of Things, IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) that simplifies random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture, Service-based Interface) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.
[0006] Once these 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, necessitating enhanced functionality and performance of 5G mobile communication systems and integrated operation of these connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), Array Antenna, and Large Scale Antenna, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, AI (Artificial Intelligence) from the design stage and AI-based communication technology that realizes system optimization by internalizing end-to-end AI support functions, and ultra-high-performance communication and computing resources to provide services with complexity that exceeds the limits of terminal computing capabilities. It can serve as a basis for the development of next-generation distributed computing technologies that can be realized by utilizing them.
[0008] This disclosure seeks to address the following issues:
[0009] In an avatar communication scenario where a user's avatar object (e.g., an avatar model) is used, if the avatar object is used by an unauthorized user, a security threat may arise where a user who is not the actual owner of the avatar object pretends to be the owner of the avatar object. Therefore, the avatar object should only be used by authorized users, and a means to ensure this is required. A system for verifying the validity of the means is also required.
[0010] More precisely, the potential security threats of avatar communication using avatar objects are as follows:
[0011] - A malicious UE can impersonate another UE by initiating IMS avatar communication in the IMS network using an Avatar-ID belonging to another UE or a forged Avatar-ID.
[0012] - Avatar-ID transmission between IMS networks can be tampered with by malicious intermediate network entities.
[0013] - The transmission of avatar data between IMS networks can be manipulated by malicious intermediate network entities.
[0014] Therefore, avatar communication using avatar objects must satisfy the following requirements:
[0015] - Avatar communication systems that use avatar objects must ensure that stored avatar objects and avatar IDs can only be accessed by authorized entities (UEs and / or network nodes).
[0016] - Avatar communication systems that use avatar objects must support integrity protection of Avatar IDs on both the sending and receiving sides.
[0017] - Avatar communication systems that use avatar objects must support integrity protection of avatar data in both the sending and receiving networks.
[0018] The present disclosure provides a description of a method and device for the above means.
[0019] According to one embodiment of the present disclosure, a method for a first terminal to perform communication in a wireless communication system may include a step of establishing a transmitting terminal-centered avatar communication with a second terminal. The method may include a step of receiving a first rendering result for the transmitting terminal-centered avatar communication from the second terminal. The method may include a step of receiving a second rendering result performed based on information about an avatar object of the second terminal from a network. The method may include a step of determining whether the second terminal is most likely to attack based on the first rendering result and the second rendering result.
[0020] According to one embodiment of the present disclosure, a first terminal performing communication in a wireless communication system may include a transceiver; and at least one processor connected to the transceiver. The at least one processor may establish transmitting terminal-centered avatar communication with a second terminal. The at least one processor may receive a first rendering result for transmitting terminal-centered avatar communication from the second terminal. The at least one processor may receive a second rendering result performed based on information about an avatar object of the second terminal from a network. The at least one processor may determine whether the second terminal is most vulnerable to attack based on the first rendering result and the second rendering result.
[0021] According to one embodiment of the present disclosure, a method for a network to perform communication in a wireless communication system may include a step of obtaining information about an avatar object of a first terminal for transmitting terminal-centered avatar communication. The method may include a step of obtaining a first rendering result based on the information about the avatar object of the first terminal. The method may include a step of transmitting the first rendering result to a second terminal to determine whether the first terminal is a most likely attacker. The method may determine whether the first terminal is a most likely attacker based on the first rendering result and a second rendering result received from the first terminal.
[0022] Various embodiments of the present disclosure can provide a method and device for secure IMS-based avatar communication. Through the embodiments of the present disclosure, only authorized UEs and / or network entities can use avatar objects. Furthermore, through the embodiments of the present disclosure, the UE and / or network entities can verify that only authorized entities are using the avatar objects. In other words, the present disclosure ensures the security of avatar communication by ensuring that only authorized entities can use avatar data and verify that fact.
[0023] The effects that can be obtained from the present disclosure are not limited to the effects mentioned in the various embodiments, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.
[0024] FIG. 1 is a conceptual diagram illustrating an architecture for IMS-based Avatar Communication according to one embodiment of the present disclosure.
[0025] FIG. 2 is a conceptual diagram illustrating a transmission process of an avatar object for network-centric avatar communication according to one embodiment of the present disclosure.
[0026] FIG. 3 is a conceptual diagram illustrating a transmission process of an avatar object for UE-A centric avatar communication according to one embodiment of the present disclosure.
[0027] FIG. 4 is a conceptual diagram illustrating a transmission process of an avatar object for UE-B centric avatar communication according to one embodiment of the present disclosure.
[0028] FIG. 5 is a conceptual diagram illustrating an impersonation attack method that may occur in avatar communication according to one embodiment of the present disclosure.
[0029] FIG. 6 is a conceptual diagram illustrating a method for preventing the most likely attacks that may occur in avatar communication according to one embodiment of the present disclosure.
[0030] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0031] In describing the embodiments, descriptions of technical details that are well known in the technical field to which the present disclosure pertains and are not directly related to the present disclosure will be omitted. This is to ensure that the gist of the present disclosure is conveyed more clearly without obscuring it by omitting unnecessary explanations.
[0032] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. In each drawing, identical or corresponding components are assigned the same or different reference numbers.
[0033] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided only to ensure that the disclosure of the present disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification. In addition, when describing the present disclosure, if a specific description of a related function or configuration is determined to unnecessarily obscure the gist of the present disclosure, the detailed description thereof will be omitted. In addition, the terms described below are terms defined in consideration of the functions of the present disclosure, and these may vary depending on the intention or custom of the user or operator. Therefore, their definitions should be made based on the contents throughout the specification.
[0034] In the present disclosure, it will be appreciated that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed based on computer program instructions. These computer program instructions can be selectively installed in at least one processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by any one or any combination of at least one processor of the computer or other programmable data processing equipment create means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce an article of manufacture that includes instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0035] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions mentioned in the blocks may occur out of order. For example, two blocks (or functions) depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on the corresponding function.
[0036] The term '~ unit' used in the embodiments of the present disclosure means a software or hardware component such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC), and the '~ unit' performs certain roles. However, terms including '~ unit' are not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Thus, as an example, the '~ unit' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functionality provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. In addition, the components and '~parts' may be implemented to play one or more central processing units (CPUs) within the device or secure multimedia card. Also, in an embodiment, the '~parts' may include one or more processors.
[0037] As described above, it should be noted that the blocks and combinations of flowcharts described in the present disclosure may be implemented by one or more computer programs containing instructions. One or more computer programs may be stored entirely in a single memory device, or one or more computer programs may be divided and stored in different portions across multiple memory devices.
[0038] Additionally, any / any function or operation described in the present disclosure may be processed by a single processor or a combination of processors. The single processor or the combination of processors may include circuitry that performs processing, such as an application processor (AP, e.g., a central processing unit (CPU)), a communication processor (CP, e.g., a modem), a graphics processing unit (GPU), a neural processing unit (NPU) (e.g., an artificial intelligence (AI) chip), a Wi-Fi chip, a Bluetooth® chip, a global positioning system (GPS) chip, a near-field communication (NFC) chip, a connectivity chip, a sensor controller, a touch controller, a fingerprint sensor controller, a display driver integrated circuit (IC), an audio codec (CODEC) chip, a universal serial bus (USB) controller, a camera controller, an image processing IC, a microprocessor unit (MPU), a system on a chip (SoC), an IC, or similar circuitry.
[0039] It should also be noted that the various embodiments in the claims and description of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.
[0040] Such software may be stored on a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores one or more computer programs (software modules), wherein the one or more computer programs include computer-executable instructions that, when executed alone or collectively by one or more processors of an electronic device, cause the electronic device to perform a method according to the present disclosure.
[0041] The software may be stored in a temporary or non-transitory storage device, for example, in the form of a read-only memory (ROM) (whether erasable or rewritable), a random access memory (RAM), a memory chip, a device, or an integrated circuit (IC). The software may also be stored in an optically or magnetically readable medium, for example, a compact disc (CD), a digital versatile disc (DVD), a magnetic disk, or a magnetic tape. It should be understood that the storage device and the storage medium are examples of non-transitory machine-readable storage media suitable for storing a program for implementing various embodiments of the present disclosure. Accordingly, various embodiments of the present disclosure may provide a program comprising code for implementing a device or method according to any one of the claims of the present specification, and a non-transitory machine-readable storage medium storing such a program.
[0042] In the present disclosure, determining the priority between A and B may be referred to in various ways, such as selecting a higher priority according to a predetermined priority rule and performing an action corresponding to it, or omitting or dropping an action for a lower priority.
[0043] Hereinafter, 'A or B' described in the present disclosure may be understood as 'A and / or B', which may be understood to include 'A', or 'B', or 'A and B'.
[0044] Additionally, 'at least one of A, B, and C' described in the present disclosure may be understood to include 'A', or 'B', or 'C', or 'any combination of A, B, and C'.
[0045] Additionally, 'at least one of A, B, or C' described in the present disclosure may be understood to include 'A', or 'B', or 'C', or 'any combination of A, B, and C'.
[0046] Additionally, 'A / B' described in the present disclosure may be understood as 'A and / or B', which may be understood to include 'A', or 'B', or 'A and B'.
[0047] Additionally, 'A, B' described in the present disclosure may be understood as 'A and / or B', which may be understood to include 'A', or 'B', or 'A and B'.
[0048] Additionally, 'A and B' described in the present disclosure may be understood as 'A and / or B', which may be understood to include 'A', or 'B', or 'A and B'.
[0049] In addition, it can be understood that the 'case where conditions A and B are satisfied' described in the present disclosure is not necessarily limited to the case where both conditions A and B are satisfied, but may include the case where each of conditions A or B is satisfied, the case where both conditions A and B are satisfied, or the case where one or more additional conditions are satisfied together.
[0050] Additionally, throughout this specification, ordinal terms such as "first," "second," "third," and the like (and modifiers thereof) are used solely to distinguish between various instances, occurrences, configurations, messages, stages, or aspects of elements, operations, or information, as described below. Unless the context clearly requires otherwise, the use of such ordinal terms does not require that the elements, operations, or information distinguished by them be structurally, numerically, or inherently different. For example, "a first signal" and "a second signal" may represent instances of the same signal transmitted at different times, may represent signals containing the same core information albeit with some modifications, or may represent signals having different content or characteristics depending on the specific context. Similarly, "a first value" and "a second value" may represent measurements or applications of the same magnitude in different circumstances, or may represent different magnitudes. Such interpretation should be determined by the specific technical context, functions and relationships described in the relevant portions of the specification and claims.
[0051] Furthermore, although terms such as "first" and "second" described in this disclosure are used to refer to various elements such as information, objects, actions, and sequences, they are not intended to limit such elements to a specific order. These terms may be understood to be used merely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element.
[0052] Additionally, it may be understood that the terms "first~" and "second~" described in this disclosure may refer to the same or different elements. For example, if the elements are information, the first information and the second information may both be information, and in some cases, they may be the same information or different information.
[0053] In addition, the expressions "if" and "in case that" described in the present disclosure or claims may be interpreted to mean "when or upon," "in response to," or "based on," or "according to," depending on the context, and these expressions may be used interchangeably. In addition, in addition to these expressions, other expressions having substantially the same meaning may be used interchangeably, within the scope that does not impair the technical features of the present disclosure.
[0054] Additionally, the term "not perform" as used in this disclosure or claims may be understood to mean omitting or skipping a step, depending on the context. Such terms may be replaced with other terms having the same or substantially similar meaning.
[0055] Additionally, "transmitting a message including A and B" as described herein may be interpreted to include both (i) cases where A and B are transmitted in a single message, as well as (ii) cases where A and B are transmitted individually via multiple messages (e.g., transmitting a first message including A and a second message including B). This interpretation may also apply when a message including two or more items, such as A, B, and C, is transmitted together or individually.
[0056] Additionally, 'sending a message containing A and sending a message containing B' can also be interpreted as sending a single message containing A and B.
[0057] In the specific embodiments of the present disclosure described below, terms or components included in the disclosure will be expressed in the singular or plural, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural may be composed of singular elements, or components expressed in the singular may be composed of plural elements.
[0058] The drawings or flowcharts described below illustrate exemplary methods that may be implemented according to the principles of the present disclosure, and various modifications may be made to the methods depicted in the flowcharts of the present disclosure. For example, although depicted as a series of steps, various steps in each drawing or flowchart may overlap, occur in parallel, occur in different orders, or occur multiple times. In other instances, any step may be omitted or replaced with another step.
[0059] The methods and devices proposed in the embodiments of the present disclosure are not limited to each embodiment, and may be utilized as a combination of one or more embodiments, all or part of the embodiments proposed in the disclosure. Accordingly, the embodiments of the present disclosure may be applied with some modifications within a scope that does not significantly deviate from the scope of the present disclosure, as determined by a person skilled in the art.
[0060] In this case, even if any wording is mentioned in different embodiments, if the concepts correspond, they may be used interchangeably, combined, or substituted. For example, for identical or corresponding concepts, even if one embodiment uses the expression "A" and another embodiment uses the expression "B," these may be understood interchangeably, substituted, or combined.
[0061] In the following description, terms used to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, terms referring to various identification information, etc. are examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects having equivalent technical meanings may be used. In addition, the terms may be replaced with terms defined in the 3rd generation partnership project (3GPP) Technical Specifications (TS), if appropriate.
[0062] Hereinafter, the base station is an entity that performs resource allocation of a terminal, and may be at least one of a gNode B, an eNode B, a Node B, a BS (base station), a radio access unit, a base station controller, or a node on a network. In addition, the base station of the present disclosure may include a structure that is split into a central unit (CU) and a distributed unit (DU). In this structure, the CU is responsible for the upper layers of the control and user planes, and the DU is responsible for radio resource processing of the lower layers. The embodiments of the present disclosure can be equally applied to a 5G base station structure in which functions are separated into the CU and DU.
[0063] The terminal may include a UE (user equipment), MS (mobile station), cellular phone, smartphone, computer, or multimedia system capable of performing communication functions.
[0064] In the present disclosure, downlink (DL) refers to a wireless transmission path of a signal transmitted from a base station to a terminal, and uplink (UL) refers to a wireless transmission path of a signal transmitted from a terminal to a base station.
[0065] In addition, although the fifth generation mobile communication system (5G, new radio, NR) and the sixth generation mobile communication system (6G) may be described below as examples, the embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, this may include new evolved mobile communication systems developed after 5G and 6G. In addition, the present disclosure may be applied to other communication systems (e.g., Wi-Fi systems) with some modifications within a range that does not significantly deviate from the scope of the present disclosure, as determined by a person having skilled technical knowledge.
[0066] In the following description, the terms "physical channel" and "signal" may be used interchangeably with data or control signals. For example, while PDSCH (physical downlink shared channel) refers to a physical channel through which data is transmitted, PDSCH may also be used to refer to data. That is, in the present disclosure, the expression "transmitting a physical channel" may be interpreted equivalently to the expression "transmitting data or a signal through a physical channel."
[0067] In the following description of the present disclosure, upper layer signaling may be signaling corresponding to at least one or a combination of one or more of MIB (master information block), SIB (system information block), SIB M (M=1, 2, …), RRC (radio resource control), MAC (medium access control) CE (control element), NAS (non-access stratum) signaling, or application layer messages. The RRC signaling may also be referred to as L3 signaling (layer 3 signaling).
[0068] In addition, L1 signaling may be signaling corresponding to at least one or a combination of one or more signaling methods using a physical layer channel or signaling of PDCCH (physical downlink control channel), DCI (downlink control information), UE-specific DCI, group common DCI, common DCI, scheduling DCI (e.g., DCI used for the purpose of scheduling downlink or uplink data), non-scheduling DCI (e.g., DCI not for the purpose of scheduling downlink or uplink data), physical uplink control channel (PUCCH), or uplink control information (UCI). The L1 signaling may also be referred to as physical layer signaling.
[0069] Hereinafter, the expression that information can be configured from a base station in the present disclosure or claims may mean that a terminal receives the information from the base station through physical layer signaling or upper layer signaling, depending on the context, and such expression may be replaced with other terms having the same or substantially similar meaning.
[0070] The operating principle of the present disclosure is described in detail with reference to the attached drawings below.
[0071] The terms used in this disclosure are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include plural expressions unless the context clearly indicates otherwise. Terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art described in this disclosure. Terms defined in general dictionaries among the terms used in this disclosure may be interpreted as having the same or similar meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even if a term is defined in this disclosure, it cannot be interpreted to exclude embodiments of the present disclosure.
[0072] The various embodiments of the present disclosure described below illustrate a hardware-based approach as an example. However, since the various embodiments of the present disclosure include techniques utilizing both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.
[0073] Hereinafter, various embodiments will be described in detail with reference to the accompanying drawings. Furthermore, when describing embodiments of the present disclosure, detailed descriptions of related known functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the embodiments. Furthermore, the terms described below are defined in consideration of their functions in the embodiments, and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the contents throughout this specification.
[0074] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size.
[0075] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure the completeness of the present disclosure and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined solely by the scope of the claims.
[0076] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0077] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
[0078] Here, the term '~ unit' used in various embodiments of the present disclosure means a software or hardware component such as an FPGA or ASIC, and the '~ unit' can perform certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Accordingly, as an example, the '~ unit' may include components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. Additionally, components and '~parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.
[0079] For convenience of explanation, this disclosure uses terms and names defined in the 3GPP NR (New Radio, a 5th generation mobile communications standard) standards. However, this disclosure is not limited to these terms and names and can be equally applied to systems conforming to other standards. Furthermore, the term "terminal" can refer to not only mobile phones, smartphones, IoT devices, and sensors, but also other wireless communication devices.
[0080] Hereinafter, a base station is an entity that performs resource allocation of a terminal, and may be at least one of a gNode B, a gNB, an eNode B, an eNB, a Node B, a BS (Base Station), a wireless access unit, a base station controller, or a node on a network. The terminal may include a UE (user equipment), an MS (mobile station), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. Of course, the present invention is not limited to the above examples.
[0081] FIG. 1 is a conceptual diagram illustrating an architecture for IMS-based avatar communication (IP Multimedia Subsystem based Avatar Communication) to be used in the present disclosure.
[0082] Network Exposure Function (NEF) is an entity that securely exposes network services and functions to Application Functions (AF) through an Application Programming Interface (API).
[0083] The Data Channel Signaling Function (DCSF) is an entity that controls signals that provide data channel control logic. In the present disclosure, the DCSF may perform one or more of the following various tasks (for a more detailed description of each task, refer to the disclosures of FIGS. 2 to 4): The DCSF may verify whether an avatar object to be used for avatar communication is used by an authorized UE; the DCSF may request an electronic signature to establish trust between PLMNs; the DCSF may request and receive an avatar object from the BAR; and the DCSF may transmit the received avatar object to an entity that performs rendering. In the present disclosure, since the DCSF plays a leading role in IMS-based avatar communication, unnecessary processes inside and outside the IMS system (e.g., token generation for communication inside and outside, signing procedures, etc.) can be omitted. For example, since the DCSF located within the IMS system plays a leading role in IMS-based avatar communication, additional verification operations for communication with entities located outside the IMS system can be omitted. In this disclosure, DCSF plays a leading role in IMS-based avatar communication, enabling efficient implementation of network-centric avatar communication, as well as transmitting terminal-centric and receiving terminal-centric avatar communication. For specific details, see FIGS. 2 through 4.
[0084] The IMS Home Subscriber Server (HSS) is a master database that maintains all user profile information used to authenticate and authorize IMS service subscribers. The HSS may also be referred to as Unified Data Management (UDM). Therefore, in this disclosure, the terms "HSS / UDM" will be used to collectively refer to the IMS HSS and UDM.
[0085] An IMS AS (Application Server) is an entity that communicates with the DCSF to notify events, communicates with the HSS / UDM to extract stored data channel improvement service data, or communicates with the MF / MRF according to instructions received from the DCSF. In the present disclosure, the IMS AS may be an entity capable of electronic signatures. The electronic signature may be a value whose validity can be verified by an entity of a PLMN other than the PLMN to which the IMS AS belongs. In this case, the entity that verifies the validity of the signature in the other PLMN may be called an IMS VS. The IMS VS may be the same entity as the IMS AS. That is, an electronic signature created by an IMS AS of one PLMN can be verified by an IMS VS of another PLMN, and the IMS VS may or may not be the same entity as the IMS AS.
[0086] The Media Function (MF) / Multimedia Resource Function (MRF) is an entity that provides media resource management and forwarding functions for data channel media traffic. In the present disclosure, the MF / MRF can perform rendering for avatar communication according to specific embodiments. The definition and execution method of this operation will be presented in embodiments to be disclosed later.
[0087] P-CSCF (Proxy Call Session Control Function) is an entity that is the first server that a UE connects to when connecting to IMS and that performs the role of routing packets to other CSCFs.
[0088] I-CSCF (Interrogating Call Session Control Function) is an entity that routes messages received from P-CSCF to S-CSCF.
[0089] S-CSCF (Serving Call Session Control Function) is an entity that processes messages received from P-CSCF.
[0090] IMS-AGW (IMS Access Gateway) is an access gateway that supports the P-CSCF function to expand the range of devices that can access IMS.
[0091] IBCF / TrGW (Interconnection Border Control Functions / Transition Gateway) is an entity that converts and transmits signals and media between the IMS network and its own network to enable services at the border of the IMS network.
[0092] A UE (User Equipment) is a terminal that utilizes IMS services. In this disclosure, a UE may be an entity that constitutes two ends of avatar communication.
[0093] Remote IMS means another IMS system that communicates with the above-described IMS.
[0094] An XR AS (XR application server) is a server that manages XR services related to XR communications. XR services include avatar communications, which will be described in this disclosure. That is, in this disclosure, the XR AS is a server that manages avatar communication services.
[0095] The Base Avatar Repository (BAR) is an entity that stores avatar objects and extracts and transmits them upon request from the UE and / or the network. Avatar objects will be described in more detail below. The BAR can be located within the IMS system or outside the IMS system. Examples of cases where the BAR is located within the IMS system and outside the system are provided below.
[0096] Before disclosing the embodiments of FIGS. 2 to 4, we will first provide some common basic knowledge required for the technology disclosed in FIGS. 2 to 4.
[0097] (1) Avatar object, data for rendering, avatar animation, rendering
[0098] An avatar object corresponds to the avatar frame used in avatar communication. For the avatar object to express changes in facial expressions or movements, it must undergo a process called rendering. In other words, data for rendering, which indicates changes in facial expressions or movements, is added to the avatar object, creating avatar animation or rendered data that vividly expresses facial expressions or movements.
[0099] To summarize, the 'avatar object' and 'data for rendering' are added to create 'avatar animation or rendered data', and the creation process is called rendering.
[0100] (2) Transmitting terminal, receiving terminal
[0101] In this specification, the two terminals performing avatar communication may be referred to as UE-A and UE-B. At this time, the avatars of UE-A and UE-B may be used simultaneously, or only one of them may be used. This specification discloses embodiments described only from the perspective of the avatar of UE-A. The perspective of the avatar of UE-B can be easily derived by reversing the roles of UE-A and UE-B in the embodiments described herein.
[0102] From the perspective of UE-A's avatar, UE-A can be viewed as a 'transmitting terminal' that provides an avatar, and UE-B can be viewed as a 'receiving terminal' that receives an avatar.
[0103] (3) Network-centric, transmitting terminal-centric, and receiving terminal-centric models
[0104] Depending on the entity performing the rendering described in (1), the following three models are possible.
[0105] Network-centric model: The network handles rendering. The data required for this process is transmitted from UE-A to the network. The network then forwards the rendered data to UE-B.
[0106] Transmitting Terminal-Centric Model: UE-A is responsible for rendering. The data required for this process is generated by UE-A. UE-A then transmits the rendered data to UE-B.
[0107] Receiving terminal-centric model: UE-B is responsible for rendering. The data required for this process is transmitted from UE-A to UE-B.
[0108] (4) Avatar ID, UE ID
[0109] UE-A's avatar object is stored in the BAR, and then transmitted to DCSF at UE-A's request, and then transmitted to the entity performing rendering. An Avatar ID (an ID indicating UE-A's avatar object) may be stored together with the avatar object in the BAR. The avatar object and avatar ID may be referred to as avatar data.
[0110] The UE ID may be a factor that designates a specific UE. The UE ID may be the UE's Subscription Permanent Identifier (SUPI), IMS public user identity (IMPU), IMS private user identity (IMPI), or an encrypted value of the above factors, or a value that can infer the factor related to the above factors. The UE ID may be stored in the HSS / UDM. In addition, the HSS / UDM may have authentication information that can authenticate the UE. In addition, the HSS / UDM may have the UE ID and a list of Avatar IDs that the UE can use.
[0111] (5) UE attestation
[0112] When additional authentication of BAR and UE-A is required, the UE and BAR may satisfy one or more of the following settings. In one embodiment of the present disclosure, the case where additional authentication of BAR and UE-A is required may include, but is not limited to, a case where BAR is located outside the IMS system.
[0113] [Setting 1]
[0114] The UE may possess a "private key UE.SK used to generate an electronic signature." The UE may possess a certificate containing a "public key UE.PK required to verify an electronic signature generated using the UE.SK." The BAR may possess information capable of verifying the UE's certificate (e.g., a public key capable of verifying the certificate's signature).
[0115] [Setting 2]
[0116] The UE may possess a 'private key used to generate an electronic signature' called UE.SK. The BAR may possess a 'public key required to verify an electronic signature generated using the UE.SK' called UE.PK.
[0117] In a situation where the above assumptions are satisfied, the UE can generate UE attestation including one or more of the following information:
[0118] - ID that can refer to UE
[0119] - Avatar ID of the avatar to be used by UE
[0120] - A designator for DCSF to be used in avatar communication
[0121] - Time information (e.g., creation time of UE attachment)
[0122] - Electronic signatures created using UE.SK for some and / or all of the above information;
[0123] FIG. 2 is a conceptual diagram illustrating a transmission process of an avatar object for network-centric avatar communication according to an embodiment of the present disclosure.
[0124] In step 1, one or more of the following processes may be performed:
[0125] - UE-A and / or the network and / or UE-B can establish a session for avatar communication and form a data channel for transmitting bootstrap data. Bootstrap data may refer to a data set generated to have a similar distribution using reconstructed sampling from sample data.
[0126] - UE-A can obtain a list of avatar IDs that it can use. This information can be obtained from the HSS / UDM. The network authentication required for the above process may have already been performed or may be performed for the above process. Through this authentication, the HSS / UDM can identify UE-A and transmit to UE-A a list of avatar IDs associated with UE-A.
[0127] In step 2, one or more of the following processes may be performed:
[0128] - UE-A can select network-centric avatar communication. This process can be achieved through negotiation between UE-A and / or the IMS entities of the IMS system to which UE-A belongs. This negotiation can involve negotiating the following process:
[0129] * UE-A can transmit data required for rendering to the network (e.g. MR / MRF).
[0130] * A network (e.g., MR / MRF) can perform rendering using the 'UE-A's avatar object' and 'data required for rendering'. For example, by rendering information about facial expressions or movements contained in the 'data required for rendering' to the 'UE-A's avatar object', rendering data or avatar animation can be obtained.
[0131] - UE-A can select the ID of the avatar object to be used from the list of avatar IDs received in step 1. UE-A can transmit the selected Avatar ID to DCSF.
[0132] - If additional authentication of BAR and UE-A is required, UE-A can generate UE attestation and send it to DCSF. If additional authentication of BAR and UE-A is required and [Setting 1], UE-A can send a certificate together to DCSF. In one embodiment of the present disclosure, if additional authentication of BAR and UE-A is required, it may mean, but is not limited to, a case where BAR is outside the IMS system to which UE-A belongs.
[0133] - DCSF can check whether the Avatar Object matching the Avatar ID received from UE-A belongs to UE-A. This process can be verified by checking whether the 'UE-A's ID' and the 'Avatar ID transmitted by UE-A' match each other. To perform the above process, DCSF may need to have 'UE-A's ID' and 'a list of Avatar IDs that UE-A can use'. The above information may have been provided to DCSF in step 1 (e.g., from HSS / UDM) or may be information that DCSF already has.
[0134] In step 3, DCSF may perform one or more of the following processes:
[0135] - DCSF can request UE-A's avatar object from BAR. At this time, DCSF can perform the request using the Avatar ID received from UE-A in step 2.
[0136] - In step 2, if UE attestation is received, DCSF can transmit UE attestation to BAR. If UE certificate is also received in step 2, DCSF can transmit UE certificate received to BAR.
[0137] In Step 4, BAR may perform one or more of the following processes:
[0138] - If additional authentication of BAR and UE-A is required and [Setting 1] is set, BAR can verify the validity of UE certificate and verify the validity of UE attestation using UE.PK included in the UE certificate.
[0139] - If additional authentication of BAR and UE-A is required and [Setting 2] is set, BAR can verify the validity of UE attestation using the UE.PK it has. After verifying the validity of the UE attestation, BAR can additionally verify one or more of the following by checking the contents of the UE attestation: whether the UE is entitled to use the avatar object it requested, whether the DCSF that requested the avatar object is the DCSF intended by the UE, and whether the validity period of UE attestation has not expired.
[0140] - BAR can transmit an avatar object to DCSF. The transmitted avatar object may be an avatar object matching the Avatar ID received from DCSF in step 3.
[0141] In Step 5, DCSF may perform one or more of the following processes:
[0142] DCSF may request an electronic signature from the IMS AS. The electronic signature may be a signature value that can be verified in an IMS network other than the one to which the DCSF belongs. The value to be subject to the electronic signature may be one or more of the following values:
[0143] * Avatar ID of the avatar object to be used for avatar communication.
[0144] In step 6, the IMS AS may perform one or more of the following steps:
[0145] - IMS AS can perform the electronic signature process requested in step 5 and then transmit the signature value to DCSF.
[0146] In step 7, one or more of the following processes may be performed:
[0147] - DCSF can transmit the avatar object of UE-A to MF / MRF.
[0148] - It can be confirmed between PLMNs that avatar communication will be performed using the above avatar object. The above process can be performed by transmitting the electronic signature obtained by DCSF in step 6 to the IMS system of the network to which UE-B belongs, and an entity (e.g., IMS VS disclosed in the drawing) among entities in the IMS system of the network to which UE-B belongs that can verify the electronic signature verifies the validity of the received electronic signature.
[0149] In step 8, UE-A may perform one or more of the following processes:
[0150] - UE-A can transmit data required for rendering to MF / MRF.
[0151] In step 9, the MR / MRF may perform one or more of the following processes:
[0152] - MR / MRF can perform avatar rendering using the avatar object of UE-A received from DCSF and the data for rendering received from UE-A. As a result, avatar animation can be generated.
[0153] In step 10, MR / MRF may perform one or more of the following processes:
[0154] - MR / MRF can transmit the generated rendering results (e.g., avatar animation) to UE-B.
[0155] In step 11, the MR / MRF may perform one or more of the following processes:
[0156] - MR / MRF can transmit the generated rendering results (e.g., avatar animation) to UE-A.
[0157] FIG. 3 is a conceptual diagram illustrating a transmission process of an avatar object for UE-A centric avatar communication according to an embodiment of the present disclosure.
[0158] In step 1, one or more of the following processes may be performed:
[0159] - UE-A and / or the network and / or UE-B can establish a session for avatar communication and form a data channel for transmitting bootstrap data. Bootstrap data may refer to a data set generated to have a similar distribution using reconstructed sampling from sample data.
[0160] - UE-A can obtain a list of avatar IDs that it can use. This information can be obtained from the HSS / UDM. The network authentication of UE-A required for the above process may have already been performed or may be performed for the above process. Through this authentication, the HSS / UDM can identify UE-A and send the list of avatar IDs associated with UE-A to UE-A.
[0161] In step 2, one or more of the following processes may be performed:
[0162] - UE-A can select avatar communication in a UE-centric manner. This process can be achieved through negotiation between UE-A and / or entities in the IMS system to which UE-A belongs. This negotiation can involve negotiating the following process:
[0163] * UE-A can perform rendering using the 'avatar object' and 'data required for rendering'. For example, UE-A can obtain rendering data or avatar animation by rendering information about facial expressions or movements contained in the 'data required for rendering' to the 'UE-A's avatar object'.
[0164] - UE-A can select the ID of the avatar object to be used from the list of avatar IDs received in step 1. UE-A can transmit the selected Avatar ID to DCSF.
[0165] - If additional authentication of BAR and UE-A is required, UE-A can generate UE attestation and send it to DCSF. If additional authentication of BAR and UE-A is required and [Setting 1], UE-A can send a certificate together to DCSF. In one embodiment of the present disclosure, if additional authentication of BAR and UE-A is required, it may mean, but is not limited to, a case where BAR is outside the IMS system to which UE-A belongs.
[0166] - DCSF can check whether the Avatar Object matching the Avatar ID received from UE-A belongs to UE-A. This process can be verified by checking whether the 'UE-A's ID' and the 'Avatar ID transmitted by UE-A' match each other. To perform the above process, DCSF may need to have 'UE-A's ID' and 'a list of Avatar IDs that UE-A can use'. The above information may have been provided to DCSF in step 1 (e.g., from HSS / UDM) or may be information that DCSF already has.
[0167] In step 3, DCSF may perform one or more of the following processes:
[0168] - DCSF can request UE-A's avatar object from BAR. At this time, DCSF can perform the request using the Avatar ID received from UE-A in step 2.
[0169] - If UE attestation is received in step 2, DCSF can transmit UE attestation to BAR. If UE certificate is received together in step 2, DCSF can transmit UE certificate received together to BAR.
[0170] In Step 4, BAR may perform one or more of the following processes:
[0171] - If additional authentication of BAR and UE-A is required and [Setting 1], BAR can verify the validity of UE certificate and verify the validity of UE attestation using UE.PK included in the UE certificate. If additional authentication of BAR and UE-A is required and [Setting 2], BAR can verify the validity of UE attestation using UE.PK that it has. After verifying the validity of UE attestation, BAR can check the contents of UE attestation and additionally verify one or more of the following: It can verify whether UE is qualified to use the avatar object it requested, whether DCSF that requested the avatar object is the DCSF intended by UE, and whether the validity period of UE attestation has not expired.
[0172] - BAR can transmit an avatar object to DCSF. The transmitted avatar object may be an avatar object matching the Avatar ID received from DCSF in step 3.
[0173] In Step 5, DCSF may perform one or more of the following processes:
[0174] DCSF may request an electronic signature from the IMS AS. The electronic signature may be a signature value that can be verified in an IMS network other than the one to which the DCSF belongs. The value to be subject to the electronic signature may be one or more of the following values:
[0175] * Avatar ID of the avatar object to be used for avatar communication.
[0176] In step 6, the IMS AS may perform one or more of the following steps:
[0177] - IMS AS can perform the electronic signature process requested in step 5 and then transmit the signature value to DCSF.
[0178] In step 7, one or more of the following processes may be performed:
[0179] - DCSF can transmit avatar objects to UE-A.
[0180] - It can be confirmed between PLMNs that avatar communication will be performed using the above avatar object. The above process can be performed by transmitting the electronic signature obtained by DCSF in step 6 to the IMS system of the network to which UE-B belongs, and an entity (e.g., IMS VS disclosed in the drawing) among entities in the IMS system of the network to which UE-B belongs that can verify the electronic signature verifies the validity of the received electronic signature.
[0181] In step 8, UE-A may perform one or more of the following processes:
[0182] - UE-A can perform rendering using the 'avatar object' and the 'data required for rendering' it created. As a result, avatar animation can be created.
[0183] In step 9, UE-A may perform one or more of the following processes:
[0184] - UE-A can transmit the generated rendering result (e.g., avatar animation) to UE-B.
[0185] FIG. 4 is a conceptual diagram illustrating a transmission process of an avatar object for UE-B centric avatar communication according to an embodiment of the present disclosure.
[0186] In step 1, one or more of the following processes may be performed:
[0187] - UE-A and / or the network and / or UE-B can establish a session for avatar communication and form a data channel for transmitting bootstrap data. Bootstrap data may refer to a data set generated to have a similar distribution using reconstructed sampling from sample data.
[0188] - UE-A can obtain a list of avatar IDs that it can use. This information can be obtained from the HSS / UDM. The network authentication of UE-A required for the above process may have already been performed or may be performed for the above process. Through this authentication, the HSS / UDM can identify UE-A and send the list of avatar IDs associated with UE-A to UE-A.
[0189] In step 2, one or more of the following processes may be performed:
[0190] - UE-A can select avatar communication in a UE-B centric manner. The above process can be achieved through negotiation between UE-A and / or 'entities of the IMS system to which UE-A belongs' and / or UE-B and / or 'entities of the IMS system to which UE-B belongs'. The above negotiation can be a negotiation that the following process will be performed.
[0191] * UE-B can perform rendering using 'UE-A's avatar object' and 'data required for rendering received from UE-A'. For example, UE-B can obtain rendering data or avatar animation by rendering information about facial expressions or movements included in 'data required for rendering' to 'UE-A's avatar object'.
[0192] - UE-A can select the ID of the avatar object to be used from the list of avatar IDs received in step 1. UE-A can transmit the selected Avatar ID to DCSF.
[0193] - If additional authentication of BAR and UE-A is required, UE-A can generate UE attestation and send it to DCSF. If additional authentication of BAR and UE-A is required and [Setting 1], UE-A can send a certificate together to DCSF. In one embodiment of the present disclosure, if additional authentication of BAR and UE-A is required, it may mean, but is not limited to, a case where BAR is outside the IMS system to which UE-A belongs.
[0194] - DCSF can check whether the Avatar Object matching the Avatar ID received from UE-A belongs to UE-A. This process can be verified by checking whether the 'UE-A's ID' and the 'Avatar ID transmitted by UE-A' match each other. To perform the above process, DCSF may need to have 'UE-A's ID' and 'a list of Avatar IDs that UE-A can use'. The above information may have been provided to DCSF in step 1 (e.g., from HSS / UDM) or may be information that DCSF already has.
[0195] In step 3, DCSF may perform one or more of the following processes:
[0196] - DCSF can request UE-A's avatar object from BAR. At this time, DCSF can perform the request using the Avatar ID received from UE-A in step 2.
[0197] - If UE attestation is received in step 2, DCSF can transmit UE attestation to BAR. If UE certificate is received together in step 2, DCSF can transmit UE certificate received together to BAR.
[0198] In Step 4, BAR may perform one or more of the following processes:
[0199] - If additional authentication of BAR and UE-A is required and [Setting 1], BAR can verify the validity of UE certificate and verify the validity of UE attestation using UE.PK included in the UE certificate. If additional authentication of BAR and UE-A is required and [Setting 2], BAR can verify the validity of UE attestation using UE.PK that it has. After verifying the validity of UE attestation, BAR can check the contents of UE attestation and additionally verify one or more of the following: It can verify whether UE is qualified to use the avatar object it requested, whether DCSF that requested the avatar object is the DCSF intended by UE, and whether the validity period of UE attestation has not expired.
[0200] - BAR can transmit an avatar object to DCSF. The transmitted avatar object may be an avatar object matching the Avatar ID received from DCSF in step 3.
[0201] In Step 5, DCSF may perform one or more of the following processes:
[0202] - DCSF may request an electronic signature from the IMS AS. The electronic signature may be a signature value that can be verified in a network other than the IMS network to which DCSF belongs. The value to be subject to the electronic signature may be one or more of the following values.
[0203] * Avatar ID of the avatar object to be used for avatar communication
[0204] * For part or all of the avatar object, the original and / or hash values of the above values.
[0205] In step 6, the IMS AS may perform one or more of the following steps:
[0206] - IMS AS can perform the electronic signature process requested in step 5 and then transmit the signature value to DCSF.
[0207] In step 7, one or more of the following processes may be performed:
[0208] - DCSF can transfer the avatar object of UE-A to UE-B.
[0209] - It can be confirmed between PLMNs that avatar communication will be performed using the above avatar object. The above process can be performed by transmitting the electronic signature obtained by DCSF in step 6 to the IMS system of the network to which UE-B belongs, and an entity (e.g., IMS VS disclosed in the drawing) among entities in the IMS system of the network to which UE-B belongs that can verify the electronic signature verifies the validity of the received electronic signature.
[0210] In one embodiment, the request for an electronic signature for the Avatar ID of an avatar object to be used for avatar communication and the validation of the electronic signature may be performed before the DCSF acquires the avatar object. The step of validating the Avatar ID of the avatar object using an electronic signature may be performed separately from the validation of the original and / or hash values for some or all of the avatar object. In one embodiment, since the request for an electronic signature for the Avatar ID of the avatar object to be used for avatar communication is performed by the DCSF in step 4 after acquiring the avatar object, the step of validating the Avatar ID of the avatar object using an electronic signature may be performed together with the validation of the original and / or hash values for some or all of the avatar object. In one embodiment, the number of validations (steps 5 to 7) may be reduced by performing validations using electronic signatures for two or more objects simultaneously.
[0211] In step 8, UE-A may perform one or more of the following processes:
[0212] - UE-A can transmit data required for rendering to UE-B.
[0213] In step 9, UE-B may perform one or more of the following processes:
[0214] - UE-B can perform avatar rendering using the 'obtained avatar object of UE-A' and 'data for rendering received from UE-A'. As a result, avatar animation can be generated.
[0215] FIG. 5 is a conceptual diagram illustrating an impersonation attack method that may occur in avatar communication according to one embodiment of the present disclosure.
[0216] This disclosure is divided into the following two steps.
[0217] i) Prerequisite: Prerequisites for the most attackable attack (steps A1 to A2)
[0218] ii) Attack: Actual most attack (stage B1 to B3)
[0219] The above two steps are described in detail below.
[0220] Prerequisite:
[0221] In Step A1, one or more of the following processes may be performed:
[0222] - UE-C can perform avatar communication centered on UE-A and receiving terminals.
[0223] - The definition of the above 'receiving terminal-centered avatar communication' is as follows: UE-C receives UE-A's avatar object and then performs rendering using it.
[0224] - An example of 'receiving terminal-centered avatar communication' performed in step A1 according to the above definition may be the embodiment disclosed in FIG. 4.
[0225] - However, the example of 'receiving terminal-centered avatar communication' performed in step A1 is not limited to Fig. 4 and may be any avatar communication method that satisfies the above definition.
[0226] In step A2, one or more of the following processes may be performed:
[0227] - UE-C can store the avatar object of UE-A received in step A1. In one embodiment, UE-C can store the avatar object of UE-A even after avatar communication is terminated.
[0228] Attack:
[0229] At step B1, one or more of the following processes may be performed:
[0230] - UE-C can perform settings for avatar communication centered on the transmitting terminal with UE-B.
[0231] - The definition of the above ‘transmitting terminal-centered avatar communication’ is as follows: UE-C performs rendering using the avatar object it possesses and then transmits the result to UE-B.
[0232] - The ‘setting’ for the above transmitting terminal-centered avatar communication refers to the entire process by which the UE-C possesses an avatar object to be used for rendering.
[0233] - According to the above definition, the 'setting for transmitting terminal-centered avatar communication' mentioned in step B1 may mean a part of the process disclosed in FIG. 3, that is, the entire process by which UE-C acquires an avatar object to be used for rendering by the procedure of FIG. 3.
[0234] - However, the 'setting for avatar communication centered on the transmitting terminal' performed in step B1 is not limited to a part of the process disclosed in Fig. 3 and may be any method that satisfies the above definition.
[0235] At step B2, one or more of the following processes may be performed:
[0236] - UE-C can perform rendering using UE-A's avatar object acquired in the prerequisite process, rather than its own avatar object.
[0237] At step B3, one or more of the following processes may be performed:
[0238] - UE-C can transmit the rendering results obtained in step B2 to UE-B.
[0239] - In this case, since the result received by UE-B is created using UE-A's avatar object, UE-B may be mistaken into thinking that it is communicating with UE-A, not UE-C. In other words, UE-C can successfully execute a masquerade attack by impersonating UE-A to deceive UE-B.
[0240] FIG. 6 is a conceptual diagram illustrating a method for preventing the most likely attacks that may occur in avatar communication according to one embodiment of the present disclosure.
[0241] FIG. 6 can be performed in parallel while UE-C is performing avatar communication centered on the transmitting terminal with UE-B. In particular, it can be performed in parallel while UE-C is performing the most attack disclosed in FIG. 5 while performing avatar communication centered on the transmitting terminal with UE-B. In step 0, one or more of the following processes can be performed.
[0242] - The network is UE-C
[0243] - The above network may be any network entity disclosed in FIG. 1 to FIG. 4.
[0244] - The network can acquire or select an avatar object of UE-C in step B1 of FIG. 5.
[0245] The purpose of this disclosure is to present a method for preventing the most common attack described in FIG. 5. FIG. 6 presents two different methods for this purpose.
[0246] i) Network-driven: The network first transmits data that can determine whether there is an attack to UE-B (steps A1 to A3).
[0247] ii) UE-driven: Transmits data that can determine whether there is an attack on the network at the request of UE-B (steps B1 to B4).
[0248] Below, the two methods are described in detail.
[0249] Network-driven:
[0250] At stage A1, one or more of the following processes may be performed:
[0251] - The network can perform rendering using the avatar of the UE-C selected in step 0 and the 'data for rendering'(s) selected by itself.
[0252] In step A2, one or more of the following processes may be performed:
[0253] - The network can transmit the rendering result performed in step A1 to UE-B.
[0254] At step A3, one or more of the following processes may be performed:
[0255] - UE-B can compare the rendering result received in step A2 with the rendering result currently being received from UE-C to determine whether UE-C is currently performing the most attack.
[0256] UE-driven:
[0257] At stage B1, one or more of the following processes may be performed:
[0258] - UE-B can request data from the network to determine the most attack.
[0259] - In the above process, UE-B may additionally transmit ‘data for rendering’ required to generate the above data.
[0260] At stage B2, one or more of the following processes may be performed:
[0261] - The network can perform rendering using the avatar object of UE-C selected in step 0 and the 'data for rendering'(s) (selected by itself) or the 'data for rendering' (received from UE-B in step B1).
[0262] At step B3, one or more of the following processes may be performed:
[0263] - The network can transmit the rendering results performed in step B2 to UE-B.
[0264] At step B4, one or more of the following processes may be performed:
[0265] - UE-B can compare the rendering result received in step B3 with the rendering result currently being received from UE-C to determine whether UE-C is currently performing the most attack.
[0266] It should be noted that the configuration diagrams, exemplary diagrams of control / data signal transmission / reception methods, and exemplary diagrams of operating procedures illustrated in FIGS. 1 to 6 are not intended to limit the scope of the embodiments of the present disclosure. That is, not all components, entities, or operational steps described in FIGS. 1 to 6 should be construed as essential components for the implementation of the disclosure, and implementation may be performed within a scope that does not detract from the essence of the disclosure even if only some components are included.
[0267] The operations of the embodiments described above can be realized by providing a memory device storing the corresponding program code in any component within the device. That is, the control unit within the device can execute the operations described above by reading and executing the program code stored in the memory device through a processor or a CPU (Central Processing Unit).
[0268] The various components and modules of the entity or terminal device described in the present disclosure may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software, and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates, and application-specific semiconductors.
[0269] The methods according to the embodiments described in the claims or specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.
[0270] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to embodiments described in the claims or specification of the present disclosure.
[0271] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage devices, compact disc-ROMs (CD-ROMs), digital versatile discs (DVDs) or other forms of optical storage devices, magnetic cassettes, or may be stored in memories formed by a combination of some or all of these. In addition, each configuration memory may include multiple copies.
[0272] Additionally, the program may be stored on an attachable storage device that is accessible via a communication network, such as the Internet, an intranet, a local area network (LAN), a wide area network (WAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device implementing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device implementing an embodiment of the present disclosure.
[0273] According to one embodiment of the present disclosure, a method for a first terminal to perform communication in a wireless communication system may include a step of establishing a transmitting terminal-centered avatar communication with a second terminal. The method may include a step of receiving a first rendering result for the transmitting terminal-centered avatar communication from the second terminal. The method may include a step of receiving a second rendering result performed based on information about an avatar object of the second terminal from a network. The method may include a step of determining whether the second terminal is most likely to attack based on the first rendering result and the second rendering result.
[0274] In one embodiment, the method may include transmitting a request to the network to determine whether the second terminal is most vulnerable to an attack.
[0275] In one embodiment, the request may include data for rendering.
[0276] In one embodiment, the second rendering result may be performed based on data for rendering selected by the network or data for rendering received from the first terminal.
[0277] In one embodiment, the first rendering result may be obtained based on information about the avatar object of the second terminal or information about the avatar object of the third terminal for the most attack.
[0278] According to one embodiment of the present disclosure, a first terminal performing communication in a wireless communication system may include a transceiver; and at least one processor connected to the transceiver. The at least one processor may establish transmitting terminal-centered avatar communication with a second terminal. The at least one processor may receive a first rendering result for transmitting terminal-centered avatar communication from the second terminal. The at least one processor may receive a second rendering result performed based on information about an avatar object of the second terminal from a network. The at least one processor may determine whether the second terminal is most vulnerable to attack based on the first rendering result and the second rendering result.
[0279] According to one embodiment of the present disclosure, a method for a network to perform communication in a wireless communication system may include a step of obtaining information about an avatar object of a first terminal for transmitting terminal-centered avatar communication. The method may include a step of obtaining a first rendering result based on the information about the avatar object of the first terminal. The method may include a step of transmitting the first rendering result to a second terminal to determine whether the first terminal is a most likely attacker. The method may determine whether the first terminal is a most likely attacker based on the first rendering result and a second rendering result received from the first terminal.
[0280] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed singularly or plurally, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in plural may be composed of singular elements, or components expressed in singular may be composed of plural elements.
[0281] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
[0282] A device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, the term "non-transitory storage medium" simply means a tangible device that does not contain signals (e.g., electromagnetic waves). This term does not distinguish between cases where data is permanently stored in the storage medium and cases where data is temporarily stored. For example, a "non-transitory storage medium" may include a buffer in which data is temporarily stored.
[0283] According to one embodiment, the method according to various embodiments disclosed in the present document may be provided as included in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) through an application store or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product (e.g., a downloadable app) may be temporarily stored or temporarily generated in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0284] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
Claims
1. In a method for a first terminal to perform communication in a wireless communication system, A step for establishing avatar communication centered on the second terminal and the transmitting terminal; A step of receiving a first rendering result for the transmitting terminal-centered avatar communication from the second terminal; A step of receiving a second rendering result performed based on information about the avatar object of the second terminal from the network; and A method comprising: a step of determining whether the second terminal is most vulnerable to attack based on the first rendering result and the second rendering result.
2. In paragraph 1, A method further comprising: a step of transmitting a request to the network to determine whether the second terminal is most vulnerable to attack; 3. In paragraph 2, A method wherein the above request includes data for rendering.
4. In paragraph 1, A method in which the second rendering result is performed based on data for rendering selected by the network or data for rendering received from the first terminal.
5. In paragraph 1, A method in which the first rendering result is obtained based on information about the avatar object of the second terminal or information about the avatar object of the third terminal for the most attack.
6. In a first terminal performing communication in a wireless communication system, Transmitter and receiver; and At least one processor connected to the transceiver, wherein the at least one processor comprises: Establish avatar communication centered on the second terminal and the transmitting terminal, Receive a first rendering result for the transmitting terminal-centered avatar communication from the second terminal, Receive a second rendering result performed based on information about the avatar object of the second terminal from the network, A first terminal that determines whether the second terminal is most likely to be attacked based on the first rendering result and the second rendering result.
7. In the sixth paragraph, the at least one processor, A first terminal that transmits a request to the above network to determine whether the second terminal is most likely to be attacked.
8. In paragraph 7, The above request is a first terminal containing data for rendering.
9. In paragraph 1, The first terminal, wherein the second rendering result is performed based on data for rendering selected by the network or data for rendering received from the first terminal.
10. In paragraph 1, A first terminal, wherein the first rendering result is obtained based on information about the avatar object of the second terminal or information about the avatar object of the third terminal for the most attack.
11. In a method for a network to perform communication in a wireless communication system, A step of acquiring information about an avatar object of a first terminal for transmitting terminal-centered avatar communication; A step of obtaining a first rendering result based on information about the avatar object of the first terminal; and A step of transmitting the first rendering result to a second terminal to determine whether the first terminal is most attacked; including; A method in which whether the first terminal is most vulnerable is determined based on the first rendering result and the second rendering result received from the first terminal.
12. In paragraph 11, A method further comprising: receiving a request for determining whether the first terminal is most vulnerable to attack; 13. In paragraph 12, A method wherein the above request includes data for rendering.
14. In paragraph 11, A method in which the first rendering result is performed based on data for rendering selected by the network or data for rendering received from the second terminal.
15. In paragraph 11, A method in which the second rendering result is obtained based on information about the avatar object of the first terminal or information about the avatar object of the third terminal for the most attack.
Citation Information
Patent Citations
System and Method for Asynchronous User-Centric Context-Based Shared Viewing of Multimedia
US20220368743A1
Method for managing transmission of a content protected against copying to a rendering device
US20220382835A1
Systems and methods to control publication of user content in a virtual world
US20230068761A1
Systems and methods for the interactive rendering of a virtual environment on a user device with limited computational capacity
US20240013495A1
User-centered open protocol cube metaverse construction system using three-dimensional metaverse environment and internet network, and operating method thereof
WO2024005599A1