Method and apparatus for security enhancement of avatar communication

The method and apparatus for enhanced security in avatar communication address security issues by implementing TLS and EAP-TLS protocols and credential exchange, ensuring secure and authorized avatar data transmission.

WO2026051011A1PCT designated stage Publication Date: 2026-03-12ALCATEL LUCENT SHANGHAI BELL CO LTD +2
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing avatar communication systems face security issues due to the lack of robust authentication and authorization mechanisms, which can compromise the integrity and privacy of user interactions.

Method used

Implementing a method and apparatus for enhanced security in avatar communication involving terminal devices and network nodes, utilizing security procedures such as Transport Layer Security (TLS) and Extensible Authentication Protocol-TLS (EAP-TLS), credential exchange, and token-based authorization to authenticate and authorize user equipment (UE) for secure avatar data transmission.

Benefits of technology

Enhances the security of avatar communication by validating the legitimacy of user equipment, improving the overall security and privacy of user interactions through secure credential exchange and authorization processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024117497_12032026_PF_FP_ABST
    Figure CN2024117497_12032026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a method and an apparatus for security enhancement of avatar communication. An apparatus (260) for a first terminal device for an avatar communication between the first terminal device and a second terminal device comprises: at least one processor (2602); and at least one memory (2604) including computer program code; the at least one memory (2604) and the computer program code configured to, with the at least one processor (2602), cause the apparatus (260) for the first terminal device at least to perform: receiving (S902) a first credential from a first network node; performing (S904) a security procedure with a second network node, based at least on the first credential; and communicating (S906) with the second terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node. According to embodiments of the present disclosure, a mechanism provides specifical procedures to authenticate and / or authorize a UE to establish an avatar communication. The authenticity / legitimacy of UE in avatar communication may be validated. The security related to avatar communication may be improved.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND APPARATUS FOR SECURITY ENHANCEMENT OF AVATAR COMMUNICATIONTECHNICAL FIELD

[0001] Various example embodiments of the present disclosure relate generally to the technology of communication, and in particular to a method and apparatus for security enhancement of avatar communication.BACKGROUND

[0002] In communication networks, the avatar objects are used more and more widely. The avatar objects may be any kind of virtual representations that are controlled by a human user.

[0003] Such avatar objects have many usages, for example, the human user may protect his privacy by using an avatar object to replace himself, or just use them to create some special digital decoration. However, there are also some problems about the usage of such avatar objects, particularly security issues.SUMMARY

[0004] This summary is provided to introduce some aspects in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0005] Certain aspects of the present disclosure and their embodiments may provide solutions to these or other challenges. There are, proposed herein, various embodiments which address one or more of the issues disclosed herein. Specific method and apparatus for security enhancement of avatar communication may be provided.

[0006] A first aspect of the present disclosure provides an apparatus for a first terminal device for an avatar communication between the first terminal device and a second terminal device. The apparatus for the first terminal device comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the first terminal device at least to perform: receiving a first credential from a first network node; performing a security procedure with a second network node, based at least on the first credential; and communicating with the second terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.

[0007] In exemplary embodiments of the present disclosure, the first terminal device receives a root certificate and / or a fingerprint of the second network node. The first terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.

[0008] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform:  storing the first credential before the avatar communication.

[0009] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: receiving the avatar data of the second terminal device from the second network node after the successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the first terminal device.

[0010] In exemplary embodiments of the present disclosure, communicating with the second terminal device comprises: starting an avatar rendering process, based at least on the avatar data; and the avatar communication between the first terminal device and the second terminal device is with or without a data channel.

[0011] In exemplary embodiments of the present disclosure, the security procedure comprises a mutual authentication procedure, such as Transport Layer Security, mTLS, procedure; or the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.

[0012] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure. Performing the security procedure with the second network node comprises: transmitting the first credential to the second network node for authentication; receiving a second credential from the second network node; and authenticating the second network node, based at least on the second credential and a received root certificate and / or a received fingerprint of the second network node. The first credential comprises a client certificate. The second credential comprises a server certificate.

[0013] In exemplary embodiments of the present disclosure, performing the security procedure with the second network node further comprises: generating a session key based at least on the first credential and / or the second credential; and transmitting, to the second network node, a Message Authentication Code, MAC, generated based at least on the session key.

[0014] In exemplary embodiments of the present disclosure, the first credential is generated by a third network node; and the third network node comprises a Credential Management Function, CMF.

[0015] In exemplary embodiments of the present disclosure, the security procedure comprises an authorization procedure. Performing the security procedure with the second network node comprises: receiving a token for accessing the avatar data of the second terminal device; and transmitting the token to the second network node, for an authorization.

[0016] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or a fourth network node; the first terminal device receives the token from the second terminal device, or from the first network node; and the fourth network node comprises an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0017] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or a fifth network node; the first terminal device receives the token from the second terminal device, or from the first network node; and the first terminal device transmits the token to the second network node, via the fifth network node.

[0018] In exemplary embodiments of the present disclosure, the fifth network node comprises: an  Extended Reality, XR, application server.

[0019] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0020] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0021] A second aspect of the present disclosure provides an apparatus for a first network node for an avatar communication between a first terminal device and a second terminal device. The apparatus for the first network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the first network node at least to perform: exchanging a root certificate with a fourth network node; and transmitting the first credential to the first terminal device and / or a second network node, for a security procedure.

[0022] In exemplary embodiments of the present disclosure, the first network node generates the first credential for the first terminal device; or the first network node receives the first credential from a third network node.

[0023] In exemplary embodiments of the present disclosure, the third network node comprises a Credential Management Function, CMF.

[0024] In exemplary embodiments of the present disclosure, the first network node transmits the first credential to the first terminal device; the first terminal device performs the security procedure with the second network node, based at least on the first credential.

[0025] In exemplary embodiments of the present disclosure, the first terminal device receives a root certificate and / or a fingerprint of the second network node; and the first terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.

[0026] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: receiving the avatar data of the second terminal device from the second network node after a successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the first network node.

[0027] In exemplary embodiments of the present disclosure, the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0028] In exemplary embodiments of the present disclosure, performing the security procedure with  the second network node comprises: transmitting, to the first terminal device, a token for accessing the avatar data of the second terminal device; and the first terminal device transmits the token to the second network node, for an authorization.

[0029] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or the fourth network node.

[0030] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or a fifth network node.

[0031] In exemplary embodiments of the present disclosure, the fifth network node comprises: an Extended Reality, XR, application server.

[0032] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0033] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0034] A third aspect of the present disclosure provides an apparatus for a second network node for an avatar communication between a first terminal device and a second terminal device. The apparatus for the second network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the second network node at least to perform: receiving a second credential for the second network node, from a third network node or a fourth network node; receiving a first credential for the first terminal device, from the first terminal device or a first network node; and performing a security procedure for the first terminal device or the first network node, based at least on the first credential and the second credential.

[0035] In exemplary embodiments of the present disclosure, the second network node receives a root certificate and / or a fingerprint of the first terminal device; and the second network node performs the security procedure with the first terminal device, further based on the received root certificate and / or the received fingerprint.

[0036] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: storing the second credential before the avatar communication.

[0037] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: transmitting the avatar data of the second terminal device, to the first terminal device or the first network node, after the successful security procedure for the first terminal device or the first network node.

[0038] In exemplary embodiments of the present disclosure, the avatar communication between the first terminal device and the second terminal device is with or without a data channel.

[0039] In exemplary embodiments of the present disclosure, the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure; or the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.

[0040] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure; the first credential comprises a client certificate; and the second credential comprises a server certificate.

[0041] In exemplary embodiments of the present disclosure, performing the security procedure for the first terminal device further comprises: receiving, from the first terminal device, a Message Authentication Code, MAC, generated based at least on a session key derived by the first terminal device; deriving a session key based at least on the first credential and / or the second credential; and validating the MAC.

[0042] In exemplary embodiments of the present disclosure, the first credential is generated by the first network node; the second credential is generated by the fourth network node.

[0043] In exemplary embodiments of the present disclosure, the first credential and the second credential are generated by the third network node.

[0044] In exemplary embodiments of the present disclosure, the security procedure comprises an authorization procedure; performing the security procedure for the first terminal device comprises: receiving a token for accessing the avatar data of the second terminal device, from the first terminal device or a fifth network node; and verifying the token.

[0045] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or the fourth network node; and the first terminal device receives the token from the second terminal device, or from the first network node.

[0046] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or the fifth network node; the first terminal device receives the token from the second terminal device, or from the first network node, or from the fifth network node; and the first terminal device transmits the token to the second network node, via the fifth network node.

[0047] In exemplary embodiments of the present disclosure, the fifth network node comprises: an Extended Reality, XR, application server.

[0048] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository; the third network node comprises a Credential Management Function, CMF; and the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0049] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0050] A fourth aspect of the present disclosure provides an apparatus for a third network node for an avatar communication between a first terminal device and a second terminal device. The apparatus for the third network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the third network node at least to perform: generating a first credential for a first terminal device, and / or a second credential for a second network node. The first credential and the second credential are for a security procedure between the first terminal device and the second network node.

[0051] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure; the first credential comprises a client certificate; and the second credential comprises a server certificate.

[0052] In exemplary embodiments of the present disclosure, the third network node comprises a Credential Management Function, CMF.

[0053] In exemplary embodiments of the present disclosure, the third network node is in a terminating or receiving side of the avatar communication, and generates the first credential for the first terminal device. The apparatus is further caused to perform: transmitting the first credential to a CMF in an originating or transmitting side of the avatar communication; and receiving the second credential from the CMF in an originating or transmitting side of the avatar communication.

[0054] In exemplary embodiments of the present disclosure, the third network node is in an originating or transmitting side of the avatar communication, and generates the second credential for the second network node. The apparatus is further caused to perform: transmitting the second credential to a CMF in a terminating or receiving side of the avatar communication; and receiving the first credential from the CMF in a terminating or receiving side of the avatar communication.

[0055] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0056] A fifth aspect of the present disclosure provides an apparatus for a fourth network node for an avatar communication between a first terminal device and a second terminal device. The apparatus for the fourth network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the fourth network node at least to perform: generating a second credential for a second network node; transmitting the second credential to the second network node, for a security procedure between the first terminal device and the second  network node.

[0057] In exemplary embodiments of the present disclosure, the second credential is generated by the fourth network node; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; and the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0058] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0059] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: generating a token for accessing the avatar data of the second terminal device. The security procedure comprises an authorization procedure.

[0060] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: transmitting the token to the first terminal device, via a first network node; or transmitting the token to the second terminal device.

[0061] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: generating a third credential for a second terminal device; transmitting the third credential to the second terminal device, for a security procedure between the second terminal device and the second network node. The security procedure comprises an authentication procedure.

[0062] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0063] A six aspect of the present disclosure provides an apparatus for a fifth network node for an avatar communication between a first terminal device and a second terminal device. The apparatus for the fifth network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the fifth network node at least to perform: generating a token for accessing the avatar data of the second terminal device; transmitting the token to the first terminal device via a first network node, or to the second terminal device via a fourth network node.

[0064] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository; and the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a originating or  transmitting side of the avatar communication.

[0065] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0066] A seventh aspect of the present disclosure provides an apparatus for a second terminal device for an avatar communication between a first terminal device and the second terminal device. The apparatus for the second terminal device comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus for the second terminal device at least to perform: receiving a third credential from a fourth network node; performing a security procedure with a second network node, based at least on the third credential; and communicating with the first terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.

[0067] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: storing the third credential before the avatar communication.

[0068] In exemplary embodiments of the present disclosure, the apparatus is further caused to perform: receiving the avatar data of the second terminal device from the second network node after the successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the second terminal device.

[0069] In exemplary embodiments of the present disclosure, communicating with the second terminal device comprises: starting an avatar rendering process, based at least on the avatar data. The avatar communication between the first terminal device and the second terminal device is with or without a data channel.

[0070] In exemplary embodiments of the present disclosure, the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure; or the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.

[0071] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure; performing the security procedure with the second network node comprises: transmitting the third credential to the second network node for authentication; receiving a second credential from the second network node; and authenticating the second network node, based at least on the second credential. The third credential comprises a client certificate; and the second credential comprises a server certificate.

[0072] In exemplary embodiments of the present disclosure, the second terminal device receives a root certificate and / or a fingerprint of the second network node; and the second terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.

[0073] In exemplary embodiments of the present disclosure, the security procedure comprises an  authorization procedure; performing the security procedure with the second network node comprises: receiving a token for accessing the avatar data of the second terminal device; and transmitting the token to the second network node, for an authorization.

[0074] In exemplary embodiments of the present disclosure, the token is generated by the fourth network node.

[0075] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository; the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0076] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0077] An eighth aspect of the present disclosure provides a method performed by an apparatus for a first terminal device, according to any of embodiments of the first aspect.

[0078] A ninth aspect of the present disclosure provides a method performed by an apparatus for a first network node, according to any of embodiments of the second aspect.

[0079] A tenth aspect of the present disclosure provides a method performed by an apparatus for a second network node, according to any of embodiments of the third aspect.

[0080] An eleventh aspect of the present disclosure provides a method performed by an apparatus for a third network node, according to any of embodiments of the fourth aspect.

[0081] A twelfth aspect of the present disclosure provides a method performed by an apparatus for a fourth network node, according to any of embodiments of the fifth aspect.

[0082] A thirteenth aspect of the present disclosure provides a method performed by an apparatus for a fifth network node, according to any of embodiments of the sixth aspect.

[0083] A fourteenth aspect of the present disclosure provides a method performed by an apparatus for a second terminal device, according to any of embodiments of the seventh aspect.

[0084] A fifteenth aspect of the present disclosure provides a computer-readable storage medium storing instructions, which when executed by at least one processor of an apparatus, cause the at least one processor of the apparatus to perform at least the method according to any of the embodiments above mentioned.

[0085] According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism that provides specifical procedures to authenticate and / or authorize a UE to establish an avatar communication. The authenticity / legitimacy of UE in avatar communication may be validated. The security related to avatar communication may be improved.BRIEF DESCRIPTION OF DRAWINGS

[0086] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, by way of example, from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to designate like or equivalent elements. The drawings are illustrated for facilitating better understanding of the embodiments of the disclosure and not necessarily drawn to scale, in which:

[0087] FIG. 1 is a signalling flow for Establishment of UE-A centric IMS avatar call without using data channel.

[0088] FIG. 2 is a signalling flow for Establishment of UE-B centric IMS avatar call without using data channel.

[0089] FIG. 3 is a signalling flow for Establishment of network centric IMS avatar call using data channel.

[0090] FIG. 4 is a signalling flow for Establishment of UE-A centric IMS avatar call using data channel.

[0091] FIG. 5 is a signalling flow for Establishment of UE-B centric IMS avatar call using data channel.

[0092] FIG. 6 is a signalling flow for Establishment of Network or UE-B centric IMS avatar call using data channel.

[0093] FIG. 7 is a signalling flow for Establishment of UE-B centric IMS avatar call using data channel, indicating requirements about authentication and authorization for signalling flow as shown in FIG. 2.

[0094] FIG. 8 is a signalling flow for Establishment of UE-A centric IMS avatar call using data channel, indicating requirements about authentication and authorization for signalling flow as shown in FIG. 1.

[0095] FIG. 9A is a flow chart showing a method performed by a first terminal device.

[0096] FIG. 9B is a flow chart showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0097] FIG. 9C is a flow chart showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0098] FIG. 9D is a flow chart showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0099] FIG. 9E is a flow chart showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0100] FIG. 9F is a flow chart showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0101] FIG. 9G is a flow chart showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0102] FIG. 10A is a flow chart showing a method performed by a first network node.

[0103] FIG. 10B is a flow chart showing further steps of the method as shown in FIG. 10A,  according to exemplary embodiments of the present disclosure.

[0104] FIG. 10C is a flow chart showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.

[0105] FIG. 10D is a flow chart showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.

[0106] FIG. 11A is a flow chart showing a method performed by a second network node.

[0107] FIG. 11B is a flow chart showing further steps of the method as shown in FIG. 11A, according to exemplary embodiments of the present disclosure.

[0108] FIG. 11C is a flow chart showing further steps of the method as shown in FIG. 11A, according to exemplary embodiments of the present disclosure.

[0109] FIG. 11D is a flow chart showing further steps of the method as shown in FIG. 11A, according to exemplary embodiments of the present disclosure.

[0110] FIG. 11E is a flow chart showing further steps of the method as shown in FIG. 11A, according to exemplary embodiments of the present disclosure.

[0111] FIG. 12A is a flow chart showing a method performed by a third network node.

[0112] FIG. 12B is a flow chart showing further steps of the method as shown in FIG. 12A, according to exemplary embodiments of the present disclosure.

[0113] FIG. 12C is a flow chart showing further steps of the method as shown in FIG. 12A, according to exemplary embodiments of the present disclosure.

[0114] FIG. 13A is a flow chart showing a method performed by a fourth network node.

[0115] FIG. 13B is a flow chart showing further steps of the method as shown in FIG. 13A, according to exemplary embodiments of the present disclosure.

[0116] FIG. 13C is a flow chart showing further steps of the method as shown in FIG. 13A, according to exemplary embodiments of the present disclosure.

[0117] FIG. 13D is a flow chart showing further steps of the method as shown in FIG. 13A, according to exemplary embodiments of the present disclosure.

[0118] FIG. 14 is a flow chart showing a method performed by a fifth terminal device.

[0119] FIG. 15A is a flow chart showing a method performed by a second terminal device.

[0120] FIG. 15B is a flow chart showing further steps of the method as shown in FIG. 15A, according to exemplary embodiments of the present disclosure.

[0121] FIG. 15C is a flow chart showing further steps of the method as shown in FIG. 15A, according to exemplary embodiments of the present disclosure.

[0122] FIG. 15D is a flow chart showing further steps of the method as shown in FIG. 15A, according to exemplary embodiments of the present disclosure.

[0123] FIG. 15E is a flow chart showing further steps of the method as shown in FIG. 15A, according to exemplary embodiments of the present disclosure.

[0124] FIG. 15F is a flow chart showing further steps of the method as shown in FIG. 15A, according to exemplary embodiments of the present disclosure.

[0125] FIG. 16 is a first exemplary signalling flow for Establishment of UE-B centric IMS avatar  call with authentication, according to embodiments of the present disclosure.

[0126] FIG. 17 is a second exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0127] FIG. 18 is a third exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0128] FIG. 19 is a first exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0129] FIG. 20 is a second exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0130] FIG. 21 is a third exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0131] FIG. 22 is a fourth exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0132] FIG. 23 is a fifth exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0133] FIG. 24 is a first exemplary signalling flow for Establishment of UE-A centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0134] FIG. 25 is a first exemplary signalling flow for Establishment of UE-A centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0135] FIG. 26 is a block diagram showing an exemplary structure for a first terminal device, according to exemplary embodiments of the present disclosure.

[0136] FIG. 27 is a block diagram showing an exemplary structure for a first network node, according to exemplary embodiments of the present disclosure.

[0137] FIG. 28 is a block diagram showing an exemplary structure for a second network node, according to exemplary embodiments of the present disclosure.

[0138] FIG. 29 is a block diagram showing an exemplary structure for a third network node, according to exemplary embodiments of the present disclosure.

[0139] FIG. 30 is a block diagram showing an exemplary structure for a fourth network node, according to exemplary embodiments of the present disclosure.

[0140] FIG. 31 is a block diagram showing an exemplary structure for a fifth network node, according to exemplary embodiments of the present disclosure.

[0141] FIG. 32 is a block diagram showing an exemplary structure for a second terminal device, according to exemplary embodiments of the present disclosure.

[0142] FIG. 33 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.

[0143] FIG. 34 is a block diagram showing exemplary apparatus units for a first terminal device, which is suitable for performing the method according to embodiments of the disclosure.

[0144] FIG. 35 is a block diagram showing exemplary apparatus units for a first network node, which is suitable for performing the method according to embodiments of the disclosure.

[0145] FIG. 36 is a block diagram showing exemplary apparatus units for a second network node, which is suitable for performing the method according to embodiments of the disclosure.

[0146] FIG. 37 is a block diagram showing exemplary apparatus units for a third network node, which is suitable for performing the method according to embodiments of the disclosure.

[0147] FIG. 38 is a block diagram showing exemplary apparatus units for a fourth network node, which is suitable for performing the method according to embodiments of the disclosure.

[0148] FIG. 39 is a block diagram showing exemplary apparatus units for a fifth network node, which is suitable for performing the method according to embodiments of the disclosure.

[0149] FIG. 40 is a block diagram showing exemplary apparatus units for a second terminal device, which is suitable for performing the method according to embodiments of the disclosure.DETAILED DESCRIPTION

[0150] The embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for better understanding, rather than limitations on the scope of the present disclosure. The described features, advantages, and characteristics of the disclosure may be combined in any suitable manner in one or more embodiments.

[0151] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless clearly given and / or implied from the context. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate.

[0152] As used herein, the term “network” or “communication network” refers to a network following any suitable communication standards (such for an internet network, or any wireless network) . For example, wireless communication standards may comprise WLAN (Wireless Local Area Network) , new radio (NR) , long term evolution (LTE) , LTE-Advanced, 5G NR, 6G etc. In the following description, the terms “network” and “system” can be used interchangeably.

[0153] The term “node / network node” refers to a computing device or computing entity or computing function or any other devices (physical or virtual) in a communication network. For example, the node in the network may include a base station (BS) , an access point (AP) , or any other suitable device in a wireless communication network. The BS may be, for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a next generation NodeB (gNodeB or gNB) , a remote radio unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, a low power node such as a femto, a pico, and so forth. Further, the node may include other core network node, such as an Access and Mobility Management Function, AMF, a Session Management Function, SMF, a User Plane Function, UPF, a mobility management entity, MME, or a serving gateway, S-GW, etc.

[0154] The term “terminal device” refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal, user equipment (UE) , a non-AP device (such as a non-AP Station (STA) ) ,  or other suitable devices. The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, a wearable device, a vehicle-mounted wireless terminal device, a vehicle, and the like.

[0155] As one example, a terminal device may represent a device configured for communication in accordance with one or more communication standards promulgated by any standard organization, such as 3rd generation partnership project, 3GPP.

[0156] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another terminal device and / or network equipment. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or home or personal appliances, for example refrigerators, televisions, personal wearables such as watches etc. In other scenarios, a terminal device may represent a vehicle or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0157] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.

[0158] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0159] In the communication networks, there are already many kinds of solutions proposed for avatar communication, for example, Internet Protocol Multimedia Subsystem (IMS) avatar communication based on (or not based on) Data Channel (DC) solution.

[0160] FIG. 1 is a signalling flow for Establishment of UE-A centric IMS avatar call without using data channel.

[0161] FIG. 1 is from Figure 6.32.2.2-1 of 3GPP TR 23.700-77 V0.6.0.

[0162] As shown in FIG. 1, an exemplary solution for support of IMS avatar communication without using data channel is provided. Particularly, this is a UE-A centric IMS avatar call flow using Session Initiation Protocol (SIP)  / Session Description Protocol (SDP) .

[0163] The procedure in FIG. 1 mainly includes following steps.

[0164] The Avatar ID is exchanged with the IMS network for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0165] 1. UE A decides to request an avatar session with local avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0166] 2. UE A initiates an IMS Audio / Video session indicating in the SIP / SDP it would like to use avatar, using local rendering. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0167] NOTE 1: How to indicate an "avatar" session and how to transfer avatar-id in the SIP / SDP is up to SA WG4.

[0168] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0169] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0170] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication. Optionally, the avatar-id can be forwarded to UE-B as additional information. UE-B has the option to reject the avatar (but accept the regular A / V session) or terminate the session.

[0171] 6. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0172] 7. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC.

[0173] 8. UE A downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0174] NOTE 2: Security implications about how UE A requests and receives the Avatar representation from DAC is defined by SA WG3.

[0175] 9. UE A starts avatar media rendering process (e.g. replacing the face from the incoming media from the camera) .

[0176] 10. UE A sends rendered media to UE B, e.g. as regular A / V media or as avatar media depending on SDP negotiation.

[0177] FIG. 2 is a signalling flow for Establishment of UE-B centric IMS avatar call without using data channel.

[0178] FIG. 2 is from Figure 6.32.2.3-1 of 3GPP TR 23.700-77 V0.6.0.

[0179] As shown in FIG. 2, an exemplary solution for support of IMS avatar communication without using data channel is provided. Particularly, this is a UE-B centric IMS avatar call flow using  Session Initiation Protocol (SIP)  / Session Description Protocol (SDP) .

[0180] The procedure in FIG. 2 mainly includes following steps.

[0181] The Avatar ID is exchanged with UE-B for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0182] 1. UE A decides to request an avatar session with remote UE based avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0183] 2.-UE A initiates an IMS session indicating in the SIP / SDP it would like to use avatar, using remote UE rendering. For example, the SDP indicates audio and avatar media (instead of video media) as m-line. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0184] Editor's note: How to indicate an "avatar" session and how to transfer avatar-id in the SIP / SDP is up to SA WG4.

[0185] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0186] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0187] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication and the avatar-id to be rendered. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC. UE-B has the option to reject the avatar media (i.e. only establish an audio call) or terminate the session.

[0188] 6. UE B downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0189] NOTE: Security implications about how UE B requests and receives the Avatar representation from DAC is defined by SA WG3.

[0190] 7. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0191] 8. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used, and that avatar media can be received by UE B.

[0192] 9. UE A sends audio and avatar media to UE B.

[0193] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) .

[0194] FIG. 3 is a signalling flow for Establishment of network centric IMS avatar call using data channel.

[0195] FIG. 3 is from Figure 6.17.2.1-1 in s2-2404596.

[0196] ● The main steps in the call flow are as follows:

[0197] ● 1. The UE-A initiates an IMS session and establishes audio and video session connections with the UE-B. The bootstrap data channel (s) are established at the same time for both the UE-A and UE-B. UE-A also downloads the avatar application and Avatar-id (s) .

[0198] ● 2. The UE-A decides to request network media rendering based on its status such as power, signal, computing power, internal storage, etc. The UE-A selects the Avatar-id of the avatar, which is intended to use for the call.

[0199] ● 3. The UE-A performs the XR media rendering negotiation with the XR Application Server. The negotiation includes usage of the Avatar-id and the indication of network centric rendering preference received from the UE-A.

[0200] ● 4. If the negotiation result is successful in step 3, the UE-A initiates new P2A application data channels, which are used for XR data transmission between the UE-A and the network. During the P2A application data channel establishment procedure, the DCSF will instruct the MF via IMS AS how to establish the data channel and corresponding media processing specification.

[0201] ● 5 (Optional) . IMS AS initiates a media re-negotiation request with UE-A by exchanging the Avatar-id via the application DC, to connect UE-A's audio / video media stream to MF. UE-A provides to the XR Application Server via the application DC the Avatar-id of the avatar intended to use for the call.

[0202] ● 6. IMS AS initiates a media re-negotiation request with UE-B, to connect UE-B's audio / video media stream to MF. The Avatar-id is exchanged with UE-B to indicate about the avatar session during the signalling. UE-B has the option to reject the avatar alone or terminate the session based on Avatar-id.

[0203] ● NOTE: The SDP content is to be decided by SA4.

[0204] ● 7. If the negotiation result is successful in step 6, the IMS AS requests the XR Application Server via the DCSF to start network centric rendering procedure with Avatar-id.

[0205] ● 8. The XR Application Server retrieves the avatar metadata using the Avatar-id from DAC.

[0206] ● 9. The DAC responds to the XR Application Server with the avatar metadata.

[0207] ● 10. Based on the received network centric rendering indication in step 7, the XR Application Server decides to send the received avatar metadata to MF.

[0208] ● 11. The XR Application Server sends the avatar metadata to MF and requests rendering of the avatar by MF.

[0209] ● 12. After receiving the successful response from the MF, the XR Application Server starts controlling the XR media rendering. 13. The XR Application Server indicates to the UE-A about successful readiness of the network centric rendering.

[0210] ● 14. The UE-A sends audio / video data via RTP to MF.

[0211] ● 15. The MF receives the audio / video data from the UE-A and performs XR media data rendering with the selected avatar metadata, e.g. via face detection and / or recognition mechanisms, based on the instruction received from the XR Application Server.

[0212] ● 16. The rendered avatar media is sent as regular audio / video media to UE-B.

[0213] ● 17. The rendered avatar media is sent back to the UE-A as feedback (same content as the one sent to the UE-B in step 16) , e.g. to display a thumbnail view of the avatar to the UE-A in the IMS session.

[0214] FIG. 4 is a signalling flow for Establishment of UE-A centric IMS avatar call using data channel. FIG. 4 is from Figure 6.17.2.2-1 in s2-2404596.

[0215] ● The main steps in the call flow are as follows:

[0216] ● 1. The UE-A initiates an IMS session and establishes audio and video session connections with the UE-B. The bootstrap data channel (s) are established at the same time for both the UE-A and UE-B. The UE-A also downloads the avatar applications and Avatar-id (s) .

[0217] ● 2. The UE-A decides to request UE-A media rendering based on its status such as power, signal, computing power, internal storage, etc. The UE-A selects the Avatar-id of the avatar, which is intended to use for the call.

[0218] ● 3. The UE-A performs the XR media rendering negotiation with the XR Application Server. The negotiation includes usage of the Avatar-id and the indication of UE-A centric rendering preference received from the UE-A.

[0219] ● 4. If the negotiation result is successful in step 3, the UE-A initiates new P2A application data channel, which are used for XR data transmission between the UE-A and the network.

[0220] During the P2A application data channel establishment procedure, the DCSF will instruct the MF via IMS AS how to establish the data channel and corresponding media processing specification.

[0221] ● 5. IMS AS initiates a media re-negotiation request with UE-B, to connect UE-B's audio / video media stream to MF. The Avatar-id is exchanged with UE-B to indicate about the avatar session during the signalling. UE-B has the option to reject the avatar alone or terminate the session based on Avatar-id.

[0222] ● NOTE: The SDP content is to be decided by SA4.

[0223] ● 6. If the negotiation result is successful in step 5, the IMS AS requests the XR Application Server via the DCSF to start UE-A centric rendering procedure with Avatar-id.

[0224] ● 7. The XR Application Server retrieves the avatar metadata using the Avatar-id from DAC.

[0225] ● 8. The DAC responds to the XR Application Server with the avatar metadata.

[0226] ● 9. Based on the received UE-A centric rendering indication in step 6, the XR Application Server decides to send the avatar metadata to the UE-A.

[0227] ● 10. The XR Application Server sends the avatar metadata to the UE-A via the application data channel to start the UE-A centric rendering.

[0228] ● 11. The UE-A locally mixes the avatar metadata together with the audio / video media received from local sensors (e.g. camera) to animate the avatar (the rendered avatar audio / video media) .

[0229] ● 12. The UE-A sends the rendered avatar audio / video media as regular video media to the UE-B.

[0230] FIG. 5 is a signalling flow for Establishment of UE-B centric IMS avatar call using data channel. FIG. 5 is from Figure 6.17.2.3-1 in s2-2404596.

[0231] ● The main steps in the call flow are as follows:

[0232] ● 1. The UE-A initiates an IMS session and establishes audio and video session connections with the UE-B. The bootstrap data channel (s) are established at the same time for both the UE-A and UE-B. The UE-A also downloads the avatar applications and Avatar-id (s) .

[0233] ● 2. The UE-A decides to request UE-B media rendering based on its status such as power, signal, computing power, internal storage, etc. The UE-A selects the Avatar-id of the avatar, which is intended to use for the call.

[0234] ● 3. The UE-A performs the XR media rendering negotiation with the XR Application Server and the UE-B. The Avatar-id and the indication of UE-B centric rendering preference are exchanged with UE-B to indicate about the avatar session during the signalling and the UE-B accepts the UE-B preferred rendering option.

[0235] ● 4. If the negotiation result is successful in step 3, the UE-B initiates new P2A application data channels, which are used for XR data transmission between the UE-A and UE-B. During the P2A application data channel establishment procedure, the DCSF will instruct the MF via IMS AS how to establish the data channel and corresponding media processing specification.

[0236] ● 5. IMS AS initiates a media re-negotiation request with UE-B, to connect UE-B's audio / video media stream to MF. UE-B has the option to reject the avatar alone or terminate the session based on Avatar-id.

[0237] ● NOTE: The SDP content is to be decided by SA4.

[0238] ● 6. If the negotiation result is successful in step 5, the IMS AS requests the XR Application Server via the DCSF to start UE-B centric rendering procedure with Avatar-id.

[0239] ● 7. The XR Application Server retrieves the avatar metadata using the Avatar-id from DAC.

[0240] ● 8. The DAC responds to the XR Application Server with the avatar metadata.

[0241] ● 9. Based on the received UE-B centric rendering indication in step 6, the XR Application Server decides to send the avatar metadata to the UE-B.

[0242] ● 10. The XR Application Server sends the received avatar metadata with the Avatar-id to UE-B via the application data channel.

[0243] ● 11-13. After receiving the successful response from UE-B, the XR Application Server forwards the response to UE-A via IMS AS indicating about the readiness of UE-B centric rendering.

[0244] ● 14. The UE-A sends XR information about UE-A, which is sufficient for rendering, to UE-B.

[0245] ● 15. The UE-B locally mixes the avatar metadata together with the received information of UE-A to animate the avatar (the rendered avatar audio / video media) .

[0246] As shown in FIG. 3, FIG. 4, FIG. 5, different centrals for IMS avatar call are illustrated.

[0247] FIG. 6 is a signalling flow for Establishment of Network or UE-B centric IMS avatar call using data channel.

[0248] FIG. 6 is from Figure 6.26.2-1 of 3GPP TR 23.700-77 V0.6.0.

[0249] The procedures in this clause are based on the following assumptions:

[0250] - Animation of the Avatar is either done on the receiving UE (UE-B) or is delegated to the

[0251] MF / MRF.

[0252] - Network rendering is not performed but can easily be added as an independent step to the AR call.

[0253] The following figure (i.e., FIG. 6) depicts the call flow that is used to establish and operate an AR call with at least one participant offering an Avatar representation of themselves.

[0254] The main steps of the call flow are as follows:

[0255] 1. UE-A generates or updates a conformant Avatar representation of the user and uploads it to the Digital Asset Repository. The representation may include the Avatar base model as well as other accessories, such as garments. UE-A may upgrade each of the components independently.

[0256] 2. UE-A and UE-B establish an IMS session that includes audio, video, and a bootstrap data channel that is used to distribute the initial scene description to both participants.

[0257] 3. The AR Application Server generates the scene for the AR session and sends it over the data channel to the MF / MRF. The scene may include an Avatar representation of UE-A and UE-B. The AR Application Server may update the scene during the lifetime of the IMS session by sending scene updates to the receivers.

[0258] 4. Upon receiving request from UE-A and UE-B, the MF / MRF forwards the scene description to the UEs over the established data channel. Each participant may share their own proposed updates to the scene, e.g. by adding new nodes.

[0259] Editor's note: the terminology related to scene description needs to be harmonized by the end of the study phased.

[0260] 5. UE-B discovers the presence of UE-A's Avatar in the scene. If UE-B determines to apply Avatar communication, UE-B sends a request to the Digital Asset Repository to access UE-A's Avatar base model.

[0261] Editor's note: How UE-B access the Avatar base model and the security consideration is FFS.

[0262] 6. The Digital Asset Repository authorizes UE-B's access to UE-A's Avatar base model for the duration of the call. This step may involve the checking of the IMS session details and the authentication of UE-B. It may also include the checking of which assets and which level of details are to be shared.

[0263] 7. If successfully authorized, the Digital Asset Repository shares the selected subset of UE-A's Avatar base model and assets with UE-B.

[0264] NOTE: Steps 5-7 are optional and may be performed between MF / MRF and DAR, in case the animation is performed at the MF / MRF instead of at UE-B. The communication between DAR and UE-B or MF / MRF is via HTTPS.

[0265] There are two alternatives for the animation process:

[0266] Option A: Animation at the receiver:

[0267] 8. In case the animation streams are generated at the sender (UE-A) , UE-A uses its input data, e.g. the camera feeds and the user voice to generate the animation streams.

[0268] 9. UE-A then sends the animation streams to the MF / MRF.

[0269] 10. Alternatively, UE-A sends the media streams that are used to generate the animation streams to the MF / MRF. These streams may include video streams from user's cameras and / or user's captured audio streams.

[0270] 11. In that case, the MF / MRF generates the animation streams from the received media streams.

[0271] 12. The MF / MRF then sends the animation streams, which it received from UE-A or generated itself, to UE-B.

[0272] 13. UE-B animates UE-A's Avatar based on the downloaded Avatar base model and the received animation streams and then renders it as part of the scene.

[0273] Option B: Animation at the MF / MRF:

[0274] 14. In case the animation streams are generated at the sender (UE-A) , UE-A uses its input data, e.g. the camera feeds and the user voice to generate the animation streams.

[0275] 15. UE-A then sends the animation streams to the MF / MRF.

[0276] 16. Alternatively, UE-A sends the media streams that are used to generate the animation streams to the MF / MRF. These streams may include video streams from user's cameras and / or user's captured audio streams.

[0277] 17. In that case, the MF / MRF generates the animation streams from the received media streams.

[0278] 18. The MF / MRF animates and reconstructs UE-A's Avatar using the animation streams to match the current user's body pose and facial expressions. The output of this step may be a retargeted 3D mesh.

[0279] 19. The reconstructed 3D Avatar is then sent to UE-B for rendering.

[0280] NOTE: Which entity is selected for the generation of animation stream and proceeding of Avatar animation is determined based on UE capabilities and network policy. How to negotiate the Avatar related capabilities is out of SA WG2 scope.

[0281] With reference to the figures above, as in the Solution#17 of TR 23.700-77 V0.6.0, the avatar XR media rendering can be done in three options: by network (called network centric) , UE-A in the originating network (called UE-A centric) or UE-B in the terminating network (called UE-B centric) . The present disclosure will provide some exemplary embodiments which may be applied on the UE centric option, in which the avatar metadata will be downloaded from XR AS to UE-A (originating side) or UE-B (terminating side) to be rendered with the audio / video from the UE-A.

[0282] It should be noted that other solutions in TR 23.700-77 V0.6.0 may be also applied to support avatar solutions.

[0283] Those solutions are more or less based on IMS data channel, and it’s supposed that there's repository / container inside / outside 3GPP network to store avatar objects. Some solutions assumed the avatar representation is provided by UE, other assumed the avatar representation is provided by 3rd party and may associated to 3rd party applications, providing avatar by operator is also not excluded. For example,

[0284] Solution #23: Download avatar representation in bootstrap data channel from avatar repository;

[0285] Solution #24: Transition Between Avatar and Audio / Video Communication;

[0286] Solution #25: Supporting network-based avatar communication by media capability invocation;

[0287] Solution #27: Early capability negotiation for IMS Avatar Communication.

[0288] In SA3 TR 33.790 V0.3.0, some key issues are discussed as below.

[0289] 5.2.2 Threats

[0290] A malicious UE can use Avatar-IDs belonging to other UEs or forged Avatar-IDs to initiate IMS avatar communication in the IMS network and therefore impersonate other UEs.

[0291] The potential transfer of the Avatar-IDs between IMS networks can potentially be tampered by intermediary network entities.

[0292] The potential transfer of the Avatar metadata between IMS networks can potentially be manipulated by intermediary network entities.

[0293] The potential transfer of the Avatar media between IMS networks can potentially be manipulated by intermediary network entities.

[0294] Avatar objects could be used for impersonating a IMS caller.

[0295] 5.2.3 Potential security requirements

[0296] The 3GPP system shall support means to ensure that stored Avatar objects and Avatar-IDs are accessed only by authenticated and authorized entities, i.e. UEs and IMS network nodes.

[0297] The IMS network shall support the integrity protection of the Avatar-ID on the originating side and terminating side.

[0298] The IMS network shall support the integrity protection of the Avatar objects such as the Avatar representation on the originating network and terminating network.

[0299] Some exemplary proposals may be provided to try to solve some issues. For example, some solutions might be provided to protect IMS avatar communication (for network centric rendering) . Such method may be target network centric avatar rendering and propose solution to authenticate and authorize the usage of Avatar-id and avatar metadata / object by an user or application, so as to protect the integrity of the avatar metadata at rest and transmission. However, how to make sure the authenticity of the avatar pushed from XR AS to UE is still missing for UE centric rendering scenario.

[0300] In other proposals, the authenticity of the avatar pushed from XR AS to UE via data channel may be provided. However, for non-DC based scenario, the UE may access digital asset container (DAC) directly, authentication and authorization of UE by DAC was not considered, especially as the remote UE belongs to different PLMN of the DAC, how the authentication on the UE by the DAC is challenging. And this can be also applied to DC-based scenario in case UE needs to access Avatar Data from DAC directly.

[0301] Therefore, the embodiments of the present disclosure are intended at least to ensure that stored avatar data (such as Avatar objects and Avatar-IDs) are accessed only by authenticated and authorized entities, i.e. UEs and IMS network nodes. Then, the manipulated Avatar metadata, Avatar media manipulated may be avoided, and integrity protection of the Avatar-ID and / or objects may be provided.

[0302] FIG. 7 is a signalling flow for Establishment of UE-B centric IMS avatar call using data channel, indicating requirements about authentication and authorization for signalling flow as shown in FIG. 2.

[0303] The Avatar ID is exchanged with UE-B for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0304] 1. UE A decides to request an avatar session with remote UE based avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0305] 2.-UE A initiates an IMS session indicating in the SIP / SDP it would like to use avatar, using remote UE rendering. For example, the SDP indicates audio and avatar media (instead of video media) as m-line. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0306] Editor's note: How to indicate an "avatar" session and how to transfer avatar-id in the SIP / SDP is up to SA WG4.

[0307] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0308] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0309] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication and the avatar-id to be rendered. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC. UE-B has the option to reject the avatar media (i.e. only establish an audio call) or terminate the session.

[0310] 6a. It is not defined yet how will the UE-B from terminating IMS core be authenticated by DAC and how to authorize UE-B to fetch the UE-A Avatar from DAC.

[0311] 6b. UE B downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0312] 7. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0313] 8. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used, and that avatar media can be received by UE B.

[0314] 9. UE A sends audio and avatar media to UE B.

[0315] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) .

[0316] FIG. 8 is a signalling flow for Establishment of UE-A centric IMS avatar call using data channel, indicating requirements about authentication and authorization for signalling flow as shown in FIG. 1.

[0317] The Avatar ID is exchanged with the IMS network for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0318] 1. UE A decides to request an avatar session with local avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0319] 2. UE A initiates an IMS Audio / Video session indicating in the SIP / SDP it would like to use avatar, using local rendering. It can further provide to the IMS network the Avatar ID of the  avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0320] NOTE 1: How to indicate an "avatar" session and how to transfer avatar-id in the SIP / SDP is up to SA WG4.

[0321] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0322] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0323] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication. Optionally, the avatar-id can be forwarded to UE-B as additional information. UE-B has the option to reject the avatar (but accept the regular A / V session) or terminate the session.

[0324] 6. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0325] 7. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC.

[0326] 8a. It is not defined yet how will the UE-A from originating IMS core be authenticated by DAC and how to authorize UE-A to fetch the UE-A Avatar from DAC.

[0327] 8b. UE A downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0328] 9. UE A starts avatar media rendering process (e.g. replacing the face from the incoming media from the camera) .

[0329] 10. UE A sends rendered media to UE B, e.g. as regular A / V media or as avatar media depending on SDP negotiation.

[0330] For facilitating the solution of the above issues, the present disclosure provided some exemplary embodiments as follows.

[0331] FIG. 9A is a flow chart showing a method performed by a first terminal device. FIG. 9B-9G are flow charts showing further steps of the method as shown in FIG. 9A, according to exemplary embodiments of the present disclosure.

[0332] As shown in FIG. 9A-9G, a first aspect of the present disclosure provides a method 900 performed by a first terminal device. The method 900 comprises: a step S902, receiving a first credential from a first network node; a step S904, performing an security procedure with a second network node, based at least on the first credential; and a step S906, communicating with the second terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.

[0333] For example, the first credential may comprise certificate, fingerprint, token, etc. For example, the security procedure may comprise authentication and / or authorization procedure.

[0334] For example, the avatar data may be any data or information which can be used to create or generate a digital representation of a user, for example, avatar metadata, an avatar configuration, an avatar object, an avatar representation, or etc.

[0335] According to embodiments of the present disclosure, the terminal device will use avatar data after a successful security procedure. Thus, a mechanism for security enhancement of avatar communication may be provided.

[0336] In exemplary embodiments of the present disclosure, the first terminal device receives a root certificate and / or a fingerprint of the second network node. The first terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.

[0337] In exemplary embodiments of the present disclosure, the method 900 further comprises: a step S908, storing the first credential before the avatar communication.

[0338] For example, the credential may be provisioned to the first terminal device (UE-B) and it can be reused until expiration or enforced by the network. Further, in one option, removing each time after communication may be performed.

[0339] In exemplary embodiments of the present disclosure, the method 900 further comprises: a step S912, receiving the avatar data of the second terminal device from the second network node after the successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the first terminal device.

[0340] In exemplary embodiments of the present disclosure, the step S906, communicating with the second terminal device comprises: a substep S9062, starting an avatar rendering process, based at least on the avatar data; and the avatar communication between the first terminal device and the second terminal device is with or without a data channel.

[0341] According to embodiments of the present disclosure, the rendering may be performed by the first terminal device.

[0342] In exemplary embodiments of the present disclosure, the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure; or the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.

[0343] According to embodiments of the present disclosure, various kinds of security procedures may be applied.

[0344] In exemplary embodiments of the present disclosure, the security procedure comprises an  authentication procedure; the step S904, performing the security procedure with the second network node comprises: a step S9042, transmitting the first credential to the second network node for authentication; a step S9044, receiving a second credential from the second network node; and a step S9046, authenticating the second network node, based at least on the second credential and a received root certificate and / or a received fingerprint of the second network node. The first credential comprises a client certificate. The second credential comprises a server certificate.

[0345] According to embodiments, the authentication based on client certificate and server certificate may be applied.

[0346] In exemplary embodiments of the present disclosure, the step S904, performing the security procedure with the second network node further comprises: a step S9048, generating a session key based at least on the first credential and / or the second credential; and a step S90410, transmitting, to the second network node, a Message Authentication Code, MAC, generated based at least on the session key.

[0347]

[0348] For example, exchanging a root certificate means that an entity transmits a root certificate of itself to another entity and receives another certificate from said another entity.

[0349] In exemplary embodiments of the present disclosure, the first credential is generated by a third network node; and the third network node comprises a Credential Management Function, CMF.

[0350] In exemplary embodiments of the present disclosure, the security procedure comprises an authorization procedure; the step S904, performing the security procedure with the second network node comprises: a substep S90412, receiving a token for accessing the avatar data of the second terminal device; and a substep S90414, transmitting the token to the second network node, for an authorization.

[0351] According to embodiments of the present disclosure, authorization based on token may be applied.

[0352] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or a fourth network node; and the first terminal device receives the token from the second terminal device, or from the first network node; and the fourth network node comprises an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0353] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or a fifth network node; the first terminal device receives the token from the second terminal device, or from the first network node; and the first terminal device transmits the token to the second network node, via the fifth network node.

[0354] In exemplary embodiments of the present disclosure, the fifth network node comprises: an Extended Reality, XR, application server.

[0355] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node  comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0356] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0357] FIG. 10A is a flow chart showing a method performed by a first network node.

[0358] FIG. 10B-10D are a flow charts showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.

[0359] As shown in FIG. 10A-10D, a second aspect of the present disclosure provides a method 1000 performed by a first network node for an avatar communication between a first terminal device and a second terminal device. The method 1000 comprises: a step S1002, exchanging a root certificate with a fourth network node; and a step S1006, transmitting the first credential to the first terminal device and / or a second network node, for an security procedure.

[0360] In exemplary embodiments of the present disclosure, the first network node generates the first credential for the first terminal device; or the first network node receives the first credential from a third network node.

[0361] In exemplary embodiments of the present disclosure, the third network node comprises a Credential Management Function, CMF.

[0362] In exemplary embodiments of the present disclosure, the first network node transmits the first credential to the first terminal device; the first terminal device performs the security procedure with the second network node, based at least on the first credential.

[0363] In exemplary embodiments of the present disclosure, the first terminal device receives a root certificate and / or a fingerprint of the second network node; and the first terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.

[0364] In exemplary embodiments of the present disclosure, the method 1000 further comprises: a step S1012, receiving the avatar data of the second terminal device from the second network node after a successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the first network node.

[0365] In exemplary embodiments of the present disclosure, performing the security procedure with the second network node comprises: a step S10062, transmitting the first credential to the second network node for authentication; a step S10064, receiving a second credential from the second network node; and a step S10066, authenticating the second network node, based at least on the second credential; the first credential comprises a client certificate; and the second credential comprises a server certificate.

[0366] In exemplary embodiments of the present disclosure, the fourth network node comprises: an  Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0367] In exemplary embodiments of the present disclosure, performing the security procedure with the second network node comprises: a step S10068, transmitting, to the first terminal device, a token for accessing the avatar data of the second terminal device; and the first terminal device transmits the token to the second network node, for an authorization.

[0368] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or the fourth network node.

[0369] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or a fifth network node.

[0370] In exemplary embodiments of the present disclosure, the fifth network node comprises: an Extended Reality, XR, application server.

[0371] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0372] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0373] FIG. 11A is a flow chart showing a method performed by a second network node.

[0374] FIG. 11B-11E are flow charts showing further steps of the method as shown in FIG. 11A, according to exemplary embodiments of the present disclosure.

[0375] As shown in FIG. 11A-11E, a third aspect of the present disclosure provides a method 1100 performed by a second network node for an avatar communication between a first terminal device and a second terminal device. The method comprises: a step S1102, receiving a second credential for the second network node, from a third network node or a fourth network node; a step S1104, receiving a first credential for the first terminal device, from the first terminal device or a first network node; and a step S1106, performing an security procedure for the first terminal device or the first network node, based at least on the first credential and the second credential.

[0376] In exemplary embodiments of the present disclosure, the second network node receives a root certificate and / or a fingerprint of the first terminal device; and the second network node performs the security procedure with the first terminal device, further based on the received root certificate and / or the received fingerprint.

[0377] In exemplary embodiments of the present disclosure, the method 1100 further comprises: a step S1108, storing the second credential before the avatar communication.

[0378] In exemplary embodiments of the present disclosure, the method 1100 further comprises: a step S1112, transmitting the avatar data of the second terminal device, to the first terminal device or the first network node, after the successful security procedure for the first terminal device or the first network node.

[0379] In exemplary embodiments of the present disclosure, the avatar communication between the first terminal device and the second terminal device is with or without a data channel.

[0380] In exemplary embodiments of the present disclosure, the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure; or the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.

[0381] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure; the first credential comprises a client certificate; and the second credential comprises a server certificate.

[0382] In exemplary embodiments of the present disclosure, a step S1106, performing the security procedure for the first terminal device further comprises: a step S11062, receiving, from the first terminal device, a Message Authentication Code, MAC, generated based at least on a session key derived by the first terminal device; a step S11064, deriving a session key based at least on the first credential and / or the second credential; and a step S11066, validating the MAC.

[0383] In exemplary embodiments of the present disclosure, the first credential is generated by the first network node; the second credential is generated by the fourth network node.

[0384] In exemplary embodiments of the present disclosure, the first credential and the second credential are generated by the third network node.

[0385] In exemplary embodiments of the present disclosure, the security procedure comprises an authorization procedure; a step S1106, performing the security procedure for the first terminal device comprises: a step S11068, receiving a token for accessing the avatar data of the second terminal device, from the first terminal device or a fifth network node; and a step S110610, verifying the token.

[0386] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or the fourth network node; and the first terminal device receives the token from the second terminal device, or from the first network node.

[0387] In exemplary embodiments of the present disclosure, the token is generated by the second terminal device, or the fifth network node; the first terminal device receives the token from the second terminal device, or from the first network node, or from the fifth network node; and the first terminal device transmits the token to the second network node, via the fifth network node.

[0388] In exemplary embodiments of the present disclosure, the fifth network node comprises: an Extended Reality, XR, application server.

[0389] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; the second network node comprises: a Digital Asset  Container, DAC, or an Avatar Repository, or a Base Avatar Repository; the third network node comprises a Credential Management Function, CMF; and the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0390] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0391] FIG. 12A is a flow chart showing a method performed by a third network node.

[0392] FIG. 12B-12C are a flow charts showing further steps of the method as shown in FIG. 12A, according to exemplary embodiments of the present disclosure.

[0393] As shown in FIG. 12A-12C, a fourth aspect of the present disclosure provides a method 1200 performed by a third network node for an avatar communication between a first terminal device and a second terminal device. The method 1200 comprises: a step S1202, generating a first credential for a first terminal device, and / or a second credential for a second network node. The first credential and the second credential are for an security procedure between the first terminal device and the second network node.

[0394] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure; the first credential comprises a client certificate; and the second credential comprises a server certificate.

[0395] In exemplary embodiments of the present disclosure, the third network node comprises a Credential Management Function, CMF.

[0396] In exemplary embodiments of the present disclosure, the third network node is in a terminating or receiving side of the avatar communication, and generates the first credential for the first terminal device. The method 1200 further comprises: a step S1204, transmitting the first credential to a CMF in an originating or transmitting side of the avatar communication; and receiving a step S1206, the second credential from the CMF in an originating or transmitting side of the avatar communication.

[0397] In exemplary embodiments of the present disclosure, the third network node is in an originating or transmitting side of the avatar communication, and generates the second credential for the second network node. The method 1200 further comprises: a step S1208, transmitting the second credential to a CMF in a terminating or receiving side of the avatar communication; and a step S1210, receiving the first credential from the CMF in a terminating or receiving side of the avatar communication.

[0398] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0399] FIG. 13A is a flow chart showing a method performed by a fourth network node.

[0400] FIG. 13B-13D is a flow chart showing further steps of the method as shown in FIG. 13A, according to exemplary embodiments of the present disclosure.

[0401] As shown in FIG. 13A-13D, a fifth aspect of the present disclosure provides a method 1300 performed by a fourth network node for an avatar communication between a first terminal device and a second terminal device. The method 1300 comprises: a step S1302, generating a second credential for a second network node; a step S1304, transmitting the second credential to the second network node, for an security procedure between the first terminal device and the second network node.

[0402] In exemplary embodiments of the present disclosure, the second credential is generated by the fourth network node; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; and the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0403] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0404] In exemplary embodiments of the present disclosure, the method 1300 further comprises: generating a step S1306, a token for accessing the avatar data of the second terminal device. The security procedure comprises an authorization procedure.

[0405] In exemplary embodiments of the present disclosure, the method 1300 further comprises: a step S1308, transmitting the token to the first terminal device, via a first network node; or a step S1310, transmitting the token to the second terminal device.

[0406] In exemplary embodiments of the present disclosure, the method 1300 further comprises: a step S1312, generating a third credential for a second terminal device; a step S1314, transmitting the third credential to the second terminal device, for an security procedure between the second terminal device and the second network node. The security procedure comprises an authentication procedure.

[0407] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; and the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.

[0408] FIG. 14 is a flow chart showing a method performed by a fifth terminal device.

[0409] As shown in FIG. 14, a six aspect of the present disclosure provides a method 1400 performed by a fifth network node for an avatar communication between a first terminal device and a second terminal device. The method 1400 comprises: a step S1402, generating a token for accessing the avatar data of the second terminal device; a step S1404, transmitting the token to the first terminal device via a first network node, or to the second terminal device via a fourth network node.

[0410] In exemplary embodiments of the present disclosure, the first terminal device comprises a  terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository; and the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a originating or transmitting side of the avatar communication.

[0411] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0412] FIG. 15A is a flow chart showing a method performed by a second terminal device.

[0413] FIG. 15B-15F is a flow chart showing further steps of the method as shown in FIG. 15A, according to exemplary embodiments of the present disclosure.

[0414] As shown in FIG. 15A-15F, a seventh aspect of the present disclosure provides a method 1500 performed by a second terminal device for an avatar communication between a first terminal device and the second terminal device. The method 1500 comprises: a step S1502, receiving a third credential from a fourth network node; a step S1504, performing an security procedure with a second network node, based at least on the third credential; and a step S1506, communicating with the first terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.

[0415] In exemplary embodiments of the present disclosure, the method 1500 further comprises: a step S1508, storing the third credential before the avatar communication.

[0416] In exemplary embodiments of the present disclosure, the method 1500 further comprises: a step S1512, receiving the avatar data of the second terminal device from the second network node after the successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the second terminal device.

[0417] In exemplary embodiments of the present disclosure, a step S1506, communicating with the second terminal device comprises: a step S15062, starting an avatar rendering process, based at least on the avatar data. The avatar communication between the first terminal device and the second terminal device is with or without a data channel.

[0418] In exemplary embodiments of the present disclosure, the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure; or the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.

[0419] In exemplary embodiments of the present disclosure, the security procedure comprises an authentication procedure; a step S1504, performing the security procedure with the second network node comprises: a step S15042, transmitting the third credential to the second network node for authentication; a step S15044, receiving a second credential from the second network node; a step  S15046, and authenticating the second network node, based at least on the second credential. The third credential comprises a client certificate; and the second credential comprises a server certificate.

[0420] In exemplary embodiments of the present disclosure, the second terminal device receives a root certificate and / or a fingerprint of the second network node; and the second terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.

[0421] In exemplary embodiments of the present disclosure, the security procedure comprises an authorization procedure; a step S1504, performing the security procedure with the second network node comprises: a step S15048, receiving a token for accessing the avatar data of the second terminal device; and a step S15410, transmitting the token to the second network node, for an authorization.

[0422] In exemplary embodiments of the present disclosure, the token is generated by the fourth network node.

[0423] In exemplary embodiments of the present disclosure, the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication; the second terminal device comprises an originating or transmitting UE of the avatar communication; the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository; the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.

[0424] In exemplary embodiments of the present disclosure, the IMS core network node comprises at least one of: an Internet Protocol Multimedia Subsystem Application Server, IMS AS; a Proxy Call Session Control Function, P-CSCF; an Interrogating Call Session Control Function, I-CSCF; a Serving Call Session Control Function, S-CSCF; and / or an Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.

[0425] Therefore, according to exemplary embodiments of the present disclosure, at least a first terminal device (e.g., UE-B) centric solution and a second terminal device (e.g. UE-A) centric solution are provided.

[0426] For example, in a UE-B centric solution, an exemplary authentication procedure may include following main steps.

[0427] 1. UE-B interacts with Terminating IMS core (network node) to get credentials (e.g. certificate) from the Terminating IMS core;

[0428] 2. The Terminating IMS core share root certificate to sign the UE-B's certificate or fingerprint of the UE-B's certificate with Originating IMS core (network node) ;

[0429] 3. The Originating IMS core configure the root certificate / fingerprint to DAC;

[0430] 4. Then the UE-B can authenticate with DAC with its certificate and the root certificate / fingerprint .

[0431] Further, in a UE-B centric solution, there may be different options for authorization.

[0432] In a first option, there may be a delegate by UE-A. UE-B fetches the Avatar token from UE-A and provides it to DAC for Authorization.

[0433] In a second option, there may be a delegate by Originating IMS core. IMS AS will generate  Avatar Token and will send in INVITE message to UE-B. And during Authorization phase, the token is sent to DAC. DAC verifies it and sends an authorization response with SUCCESS or FAILURE to UE-B.

[0434] In a third option, there may be a delegate by a trusted AF. XR application server generates the access token and produce it via UE-B or directly towards DAC for the Avatar data download.

[0435] Further, for example, in a UE-A centric solution, an exemplary authentication procedure may include following main steps.

[0436] IMS core pushes client certificates to the UE-A and UE-A will store them. IMS core also pushes the server certificates to DAC. EAP TLS certificate exchange is executed between DAC and UE-A. After this EAP TLS procedure is successful, both DAC and UE-A will mutually authenticate each other.

[0437] Further, in a UE-A centric solution, an exemplary authorization procedure may provide following main steps.

[0438] IMS core will generate the Avatar Token and sends it to UE-A. The UE-A will send Authorization request and response with Avatar token towards the DAC. After the verification of the Avatar token, UE-A will download the avatar info from DAC.

[0439] Further detailed embodiments will be illustrated as examples below.

[0440] FIG. 16 is a first exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0441] As shown in FIG. 16, at least step 6 and 10 may be enhanced in comparation to FIG. 2.

[0442] The Avatar ID is exchanged with UE-B for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0443] 1. UE A decides to request an avatar session with remote UE based avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0444] 2.-UE A initiates an IMS session indicating in the SIP / SDP it would like to use avatar, using remote UE rendering. For example, the SDP indicates audio and avatar media (instead of video media) as m-line. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0445] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0446] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0447] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication and the avatar-id to be rendered. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC. UE-B has the option to reject the avatar media (i.e. only establish an audio call) or terminate the session.

[0448] 6. In a substep 6a1, the Root certificate (finger print) is exchanged between originating IMS core and terminating IMS core. In substep 6b1, the Terminating IMS core pushes the credentials (client certificate) to UE-B, and in substep 6b2 it is stored. In substeps 6c1 and 6c2, similarly the originating IMS core will push the server certificate to DAC and it is stored locally in DAC. In substeps 6d1, 6d2 and 6d3, UE-B and DAC will execute amutual authentication procedure (e.g., a mTLS, such as the EAP TLS procedure) which exchanges the certificates and mutually authenticate each other. In step 6e, the UE B downloads Avatar metadata (incl. avatar representation) from DAC after mutual authentication and / or authorization using the information provided by IMS AS, unless locally available.

[0449] For example, besides the certificate of UE-B, the root certificate to sign / fingerprint of the certificate of DAC (exchanged at step 6) may be also pushed to UE-B. Similarly, the originating IMS may push root cert to sign / fingerprint of the certificate of UE-B (which exchanged at the same step 6) to DAC. The root certificate or fingerprint is used by UE-B / DAC to validate the credential / certificate provided by DAC / UE-B during mutual authentication.

[0450] 7. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0451] 8. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used, and that avatar media can be received by UE B.

[0452] 9. UE A sends audio and avatar media to UE B.

[0453] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) . Client certificate and server certificates can be removed at DAC and UE-B.

[0454] FIG. 17 is a second exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0455] As shown in FIG. 17, at least step 6 and 10 may be enhanced in comparation to FIG. 2.

[0456] The difference to the FIG. 16 is that, in FIG. 17, terminating IMS network (instead of UE-B) download the avatar from the DAC and DAC authenticate the terminating IMS network via its certificate. Then terminating IMS network provides the avatar data to UE-B along with INVITE. In this way, UE-B authentication is not required.

[0457] 6. In a substep 6a1, the Root certificate (finger print) is exchanged between originating IMS core (network node) and terminating IMS core (network node) . In substeps 6c1 and 6c2, the originating IMS core will push the server certificate to DAC and it is stored locally in DAC. In substeps 6d1, 6d2, terminating IMS and DAC will execute mutual authentication procedure (e.g.,  a mTLS, such as the EAP TLS procedure) which exchanges the certificates and mutually authenticate each other. In step 6e, the terminating IMS core downloads Avatar metadata (incl. avatar representation) from DAC after mutual authentication and / or authorization using the information provided by IMS AS, unless locally available. In substep 6f, the terminating IMS core forward the INVITE message from step 5 to UE-B, and also provide UE-A avatar.

[0458] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) . Client certificate and server certificates can be removed at DAC and terminating core.

[0459] FIG. 18 is a third exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0460] As shown in FIG. 18, shared credentials may be used for authentication. The main procedure is same to FIG. 16 and FIG. 17, but with different authentication mechanisms, particularly as shown in steps 4-15.

[0461] 1. UE-A decides to start avatar session with remote rendering based on its status

[0462] 2. UE-A transmits INVITE (Audio, Avatar Media + Avatar ID) to source IMS Core (network node) .

[0463] 3. Source IMS Core forwards INVITE (Audio, Avatar Media + Avatar ID) to terminating IMS Core (network node) , and then to UE-B.

[0464] 4. If UE-B agrees the Avatar call with UE-A for UE-B rendering, UE-B sends credential request to Credential Management Function (CMF) , which includes IMS public Id of the UE-B (IMPU) , avatar download information such as DAC address, and optionally IMPU of UE-A, Avatar Id.

[0465] 5. Based on contract with source IMS and local policy, the CMF of terminating IMS creates credential for the UE-B for authentication with DAC based on DAC address, IMPU of UE-B, probably Avatar Id. The expiration time is set on the credential.

[0466] 6. The CMF of terminating IMS sends the credential to the CMF of the source IMS, together with DAC address, IMPU of UE-B, expiration time, and optional Avatar Id.

[0467] 7. The CMF of source IMS core configures the credential in corresponding DAC, and sends root certificate of DAC to CMF of terminating IMS as response of step 6.

[0468] 8. The CMF of terminating IMS responds the credential to the UE-B, together expiration time, and root certificate of DAC.

[0469] NOTE: GBA or AKMA can be used to protect interface between CMF and UE-B. inter-domain security mechanism defined in 3GPP TS 33.210 V18.1.0 (2024-06) can be used to protect interface between CMFs of source and terminating IMS.

[0470] 9. UE-B derives session key based on the credential sent from CMF, IMPU and random,

[0471] 10. UE-B forms download request, generates message authentication code (MAC) for the request using the session key.

[0472] 11. UE-B authenticates DAC based on root certificate of DAC received in step 8. The authentication can be implicitly performed when UE-B establish https session with DAC.

[0473] 12. UE-B sends download request to DAC, including IMPU of UE-B, download info, random number, and message authentication code, optional authorization info and Avatar Id. The request can be protected with public key of DAC's certificate.

[0474] 13. After received the request, DAC may decrypt the request with private key of DAC if the message is protected. Then DAC derives session key based on UE-B's credential received in step 6 if the credential is not expired, IMPU of UE-B and random.

[0475] 14. DAC generates MAC for the received download request with the session key, and compare the MAC with the one received in the request.

[0476] 15-16. If the MACs are matched DAC further authorizes the UE-B, and sends the avatar metadata together with Avatar Id to UE-B.

[0477] FIG. 19 is a first exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0478] As shown in FIG. 19, at least step 6 may be enhanced in comparation to FIG. 2.

[0479] The Avatar ID is exchanged with UE-B for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0480] 1. UE A decides to request an avatar session with remote UE based avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0481] 2.-UE A initiates an IMS session indicating in the SIP / SDP it would like to use avatar, using remote UE rendering. For example, the SDP indicates audio and avatar media (instead of video media) as m-line. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0482] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0483] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0484] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication and the avatar-id to be rendered. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC. UE-B has the option to reject the avatar media (i.e. only establish an audio call) or terminate the session.

[0485] 6. In substep 6a, UE-B will fetch the Avatar token from UE-A. In substep 6b, UE-B will send the authorization request with Avatar Token to DAC. In substep 6c, the DAC will verify the authorization avatar token, and in substep 6d, sends the authorization response back to the UE-B. In substep 6e, UE B downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available. The Avatar token is generated by UE-A to sign UE-A IMS id (IMPU) and avatar id with UE certificate.

[0486] 7. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0487] 8. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used, and that avatar media can be received by UE B.

[0488] 9. UE A sends audio and avatar media to UE B.

[0489] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) .

[0490] FIG. 20 is a second exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0491] As shown in FIG. 20, at least steps 1, 2, 3, 5, 6 may be enhanced in comparation to FIG. 2.

[0492] The Avatar ID is exchanged with UE-B for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0493] 1. UE A decides to request an avatar session with remote UE based avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session. UE-A will generate the Avatar Token to sign UE-A IMS id (IMPU) and avatar id with UE certificate.

[0494] 2. UE A initiates an IMS session indicating in the SIP / SDP it would like to use avatar, using remote UE rendering. For example, the SDP indicates audio, avatar token and avatar media (instead of video media) as m-line. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0495] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2. Avatar token is provided by the IMS AS to IMS HSS.

[0496] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0497] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication, Avatar token and the avatar-id to be rendered. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC. UE-B has the option to reject the avatar media (i.e. only establish an audio call) or terminate the session.

[0498] 6. In substep 6a, UE-B will send the authorization request with Avatar Token to DAC. In substep 6b, the DAC will verify the authorization avatar token, and in substep 6c, sends the authorization response back to the UE-B.

[0499] UE B downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0500] 7. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0501] 8. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used, and that avatar media can be received by UE B.

[0502] 9.UE A sends audio and avatar media to UE B.

[0503] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) .

[0504] FIG. 21 is a third exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0505] As shown in FIG. 21, at least steps 5, 6 may be enhanced in comparation to FIG. 2.

[0506] The Avatar ID is exchanged with UE-B for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0507] 1. UE A decides to request an avatar session with remote UE based avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0508] 2.-UE A initiates an IMS session indicating in the SIP / SDP it would like to use avatar, using remote UE rendering. For example, the SDP indicates audio and avatar media (instead of video media) as m-line. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0509] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0510] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the  avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0511] 5. In substep 5a, the IMS AS will generate the Authorization Avatar token to sign avatar id with IMS AS certificate. In substep 5b, the IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication, Avatar token and the avatar-id to be rendered. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC. UE-B has the option to reject the avatar media (i.e. only establish an audio call) or terminate the session.

[0512] 6. In substep 6a, UE-B will send the authorization request with Avatar Token to DAC. In substep 6b, the DAC will verify the authorization avatar token and in substep 6c, sends the authorization response back to the UE-B. In substep 6d, the UE B will send UE B downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0513] 7. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0514] 8. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used, and that avatar media can be received by UE B.

[0515] 9. UE A sends audio and avatar media to UE B.

[0516] 10. UE B starts the avatar rendering process (e.g. animating the avatar representation from UE A with the information provided in the incoming avatar media from UE A) .

[0517] FIG. 22 is a fourth exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0518] The main steps in the call flow are as follows:

[0519] 1. The UE-A initiates an IMS session and establishes audio and video session connections with the UE-B. The bootstrap data channel (s) are established at the same time for both the UE-A and UE-B.

[0520] 2. The UE-A decides to request UE-B media rendering of an avatar intended to use for the call based on its status such as power, signal, computing power, internal storage, etc. The UE-A selects the Avatar-id of the avatar.

[0521] 3. The UE-A performs the XR media rendering negotiation with the XR Application Server and the UE-B. The Avatar-id is exchanged with UE-B to indicate about the avatar session during the signalling.

[0522] 4. If the negotiation result is successful in step 3, the UE-B initiates new P2A application data channels, which are used for XR data transmission between the UE-A and UE-B. During the P2A application data channel establishment procedure, the DCSF will instruct the MF / MRF via IMS AS how to establish the data channel and corresponding media processing specification.

[0523] 5. IMS AS initiates a media re-negotiation request with UE-B, to connect UE-B's audio / video media stream to MF / MRF. UE-B has the option to reject the avatar alone or terminate the session based on Avatar-id.

[0524] NOTE: The SDP content is to be decided by SA4.

[0525] 6-9. In substep 6a, the XR Application Server requests DAC to retrieve avatar metadata by providing UE-identity and Avatar-id via DC, and send the avatar metadata to the UE-B. If the UE-B has the association avatar metadata available in cache, step 6-9 shall be skipped.

[0526] Otherwise, in substep 6b, the XR application server will generate the Avatar token to sign avatar id with XR AS certificate, and provide it to UE-B via substeps 6c-1, 6c-2, 6c-3, 6c-4.

[0527] The UE-B provide the token to DAC, via substeps 7a-1, 7a-2. In substep 7b, DAC will verify the token and metadata can be downloaded in substep 7c.

[0528] Alternatively, with token getting from XR AS in step 6, instead of getting Avatar metadata from XR AS, UE-B may access DAC via Access Control Enforcement Function (AEF) (if it's based on CAPIF)  / NEF in step 7, in that case, AEF / NEF authorizes UE-B and forwards the request and response between UE-B and DAC.

[0529] 10. The UE-A sends information about UE-A to UE-B.

[0530] 11. The UE-B locally mixes the avatar metadata together with the received information of UE-A to animate the avatar (the rendered avatar audio / video media) .

[0531] FIG. 23 is a fifth exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0532] In comparation to FIG. 22, the main difference is that, in FIG. 23, the UE-A (or a source IMS core) may generate the avatar token.

[0533] The main steps in the call flow are as follows:

[0534] 1. The UE-A initiates an IMS session and establishes audio and video session connections with the UE-B. The bootstrap data channel (s) are established at the same time for both the UE-A and UE-B.

[0535] 2. The UE-A decides to request UE-B media rendering of an avatar intended to use for the call based on its status such as power, signal, computing power, internal storage, etc. The UE-A selects the Avatar-id of the avatar. The UE-A will generate the Avatar token to sign UE-A IMS id (IMPU) and avatar id with UE-A certificate. Alternatively, the Avatar token can be generated by source IMS network as in the third exemplary embodiment.

[0536] 3. The UE-A performs the XR media rendering negotiation with the XR Application Server and the UE-B. The Avatar-id is exchanged with UE-B to indicate about the avatar session during the signalling. The Avatar token is sent to UE-B.

[0537] 4. If the negotiation result is successful in step 3, the UE-B initiates new P2A application data channels, which are used for XR data transmission between the UE-A and UE-B. During the P2A application data channel establishment procedure, the DCSF will instruct the MF / MRF  via IMS AS how to establish the data channel and corresponding media processing specification.

[0538] 5. IMS AS initiates a media re-negotiation request with UE-B, to connect UE-B's audio / video media stream to MF / MRF. UE-B has the option to reject the avatar alone or terminate the session based on Avatar-id.

[0539] NOTE: The SDP content is to be decided by SA4.

[0540] 6-9. The XR Application Server requests DAC to retrieve avatar metadata by providing UE-identity and Avatar-id via DC, and send the avatar metadata to the UE-B. If the UE-B has the association avatar metadata available in cache, step 6-9 shall be skipped. UE-B will send the Avatar token to DAC and DAC will verify the avatar token and avatar metadata can be downloaded.

[0541] 10. The UE-A sends information about UE-A to UE-B.

[0542] 11. The UE-B locally mixes the avatar metadata together with the received information of UE-A to animate the avatar (the rendered avatar audio / video media) .

[0543] FIG. 24 is a first exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authentication, according to embodiments of the present disclosure.

[0544] As shown in FIG. 24, at least step 8 may be enhanced in comparation to FIG. 1.

[0545] The Avatar ID is exchanged with the IMS network for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0546] 1. UE A decides to request an avatar session with local avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0547] 2. UE A initiates an IMS Audio / Video session indicating in the SIP / SDP it would like to use avatar, using local rendering. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0548] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0549] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0550] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication. Optionally, the avatar-id can be forwarded to UE-B as additional  information. UE-B has the option to reject the avatar (but accept the regular A / V session) or terminate the session.

[0551] 6. The UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0552] 7. The IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, from DAC.

[0553] 8. In substep 8a1, the IMS core will push the client certificates to UE-A and in substep 8a3 the IMS core also pushes the server certificates to DAC. In substep 8a2, the UE-A stores the client certificates. In substep 8a4, the DAC stores the client certificates. In substep 8a5, a mutual authentication procedure (e.g., a mTLS, such as the EAP TLS procedure) for certificate exchange is executed and in substep 8a6, 8a7, both UE-A and DAC will mutually authenticate each other. In substep 8b, UE A downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0554] 9. UE A starts avatar media rendering process (e.g. replacing the face from the incoming media from the camera) .

[0555] 10. UE A sends rendered media to UE B, e.g. as regular A / V media or as avatar media depending on SDP negotiation.

[0556] FIG. 25 is a first exemplary signalling flow for Establishment of UE-B centric IMS avatar call with authorization, according to embodiments of the present disclosure.

[0557] As shown in FIG. 25, at least steps 7, 8 may be enhanced in comparation to FIG. 1.

[0558] The Avatar ID is exchanged with the IMS network for getting the avatar representation. The Avatar ID is negotiated within SIP / SDP.

[0559] 1. UE A decides to request an avatar session with local avatar rendering, e.g. based on its internal capabilities, and can select an Avatar ID to be used for the session.

[0560] 2. UE A initiates an IMS Audio / Video session indicating in the SIP / SDP it would like to use avatar, using local rendering. It can further provide to the IMS network the Avatar ID of the avatar to be used in the call. For example, Avatar ID can be e.g. sent within a m-or a-line in the SDP.

[0561] 3. Based on the UE-A associated IMPU / IMPI, the IMS AS requests the IMS HSS to validate whether the Avatar ID can be used by UE-A, or to retrieve the "default" avatar-id associated to the subscription or the current registration if no Avatar ID was provided by UE-A at step 2.

[0562] 4. The IMS HSS responds to the IMS AS. If the avatar ID usage for this session was validated, then the IMS HSS can indicate additional information such as a download link to retrieve avatar metadata (incl. avatar representation) . If no Avatar ID was provided in step 3, the IMS HSS can respond with a "default" avatar-id associated to the subscription or the current registration, and related additional information to retrieve the avatar. If the usage of the  avatar ID requested by UE-A was not validated, an error response is generated towards UE-A and the session is terminated.

[0563] 5. The IMS AS forwards the INVITE to UE-B via the terminating IMS network including avatar session indication. Optionally, the avatar-id can be forwarded to UE-B as additional information. UE-B has the option to reject the avatar (but accept the regular A / V session) or terminate the session.

[0564] 6. UE B and terminating IMS network send 200 OK to IMS AS including avatar session indication acceptance.

[0565] 7. In substep 7a, the IMS AS generates the Avatar Token to sign UE-A IMS id (IMPU) and avatar id with IMS AS certificate. In substep 7b, the IMS AS forwards the 200 OK to UE-A including avatar session indication to confirm that this Avatar can be used. IMS AS further provides information to download Avatar metadata, e.g. Avatar representation, Avatar token from DAC.

[0566] 8. In substep 8a1, the UE A will send the Authorization request with Avatar Token to DAC and in substep 8a2, DAC will verify the Avatar token. Then in substep 8b, the UE A downloads Avatar metadata (incl. avatar representation) from DAC using the information provided by IMS AS, unless locally available.

[0567] 9. UE A starts avatar media rendering process (e.g. replacing the face from the incoming media from the camera) .

[0568] 10. UE A sends rendered media to UE B, e.g. as regular A / V media or as avatar media depending on SDP negotiation.

[0569] The embodiments of the present disclosure provide solutions for the Digital Asset Container (DAC) to authenticate and authorize a UE with security credentials for getting avatar object via Internet Protocol Multimedia Subsystem (IMS) core network.

[0570] Only authenticated and authorized UE can get avatar object from the DAC via DC channel or non-DC channel.

[0571] Therefore, some manners may be provided to address how will the UE-B from terminating IMS core be authenticated by DAC and how to authorize UE-B to fetch the UE-A Avatar from DAC, and how will the UE-A from originating IMS core be authenticated by DAC and how to authorize UE-A to fetch the UE-A Avatar from DAC.

[0572] FIG. 26 is a block diagram showing an exemplary structure for an IMS AS, according to exemplary embodiments of the present disclosure.

[0573] As shown in FIG. 26, the apparatus 260 for a first terminal device comprises at least one processor 2602, and at least one memory 2604 including computer program code. The at least one memory 2604 and the computer program code are configured to, with the at least one processor 2602, cause the apparatus 260 for the first terminal device at least to perform the method according to any of the above embodiments, such as shown in FIG. 9A-FIG. 9G, 16-25.

[0574] FIG. 27 is a block diagram showing an exemplary structure for a first network node  according to exemplary embodiments of the present disclosure.

[0575] As shown in FIG. 27, the apparatus 270 for a first network node comprises at least one processor 2702, and at least one memory 2704 including computer program code. The at least one memory 2704 and the computer program code are configured to, with the at least one processor 2702, cause the apparatus 270 for the first network node at least to perform the method according to any of the above embodiments, such as shown in FIG. 10A-FIG. 10D, 16-25.

[0576] FIG. 28 is a block diagram showing an exemplary structure for a second network node, according to exemplary embodiments of the present disclosure.

[0577] As shown in FIG. 28, the apparatus 280 for a second network node comprises at least one processor 2802, and at least one memory 2804 including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor 2802, cause the apparatus 280 for the second network node at least to perform the method according to any of the above embodiments, such as shown in FIG. 11A-FIG. 11E, 16-25.

[0578] FIG. 29 is a block diagram showing an exemplary structure for a third network node, according to exemplary embodiments of the present disclosure.

[0579] As shown in FIG. 29, the apparatus 290 for a third network node comprises at least one processor 2902, and at least one memory 2904 including computer program code. The at least one memory 2904 and the computer program code are configured to, with the at least one processor 2902, cause the apparatus 290 for the third network node at least to perform the method according to any of the above embodiments, such as shown in FIG. 12A-FIG. 12C, 16-25.

[0580] FIG. 30 is a block diagram showing an exemplary structure for a fourth network node, according to exemplary embodiments of the present disclosure.

[0581] As shown in FIG. 30, the apparatus 300 for a fourth network node comprises at least one processor 3002, and at least one memory 3004 including computer program code. The at least one memory 3004 and the computer program code are configured to, with the at least one processor 3002, cause the apparatus 300 for the fourth network node at least to perform the method according to any of the above embodiments, such as shown in FIG. 13A-FIG. 13C, 16-25.

[0582] FIG. 31 is a block diagram showing an exemplary structure for a fifth network node, according to exemplary embodiments of the present disclosure.

[0583] As shown in FIG. 31, the apparatus 310 for a fifth network node comprises at least one processor 3102, and at least one memory 3104 including computer program code. The at least one memory 3104 and the computer program code are configured to, with the at least one processor 3102, cause the apparatus 310 for the fifth network node at least to perform the method according to any of the above embodiments, such as shown in FIG. 14, 16-25.

[0584] FIG. 32 is a block diagram showing an exemplary structure for a second terminal device, according to exemplary embodiments of the present disclosure.

[0585] As shown in FIG. 32, the apparatus 320 for a second terminal device comprises at least one processor 3202, and at least one memory 3204 including computer program code. The at least one memory 3204 and the computer program code are configured to, with the at least one processor 3202,  cause the apparatus 320 for the second terminal device at least to perform the method according to any of the above embodiments, such as shown in FIG. 15A-FIG. 15F, 16-25.

[0586] The processor 2602, 2702, 2802, 2902, 3002, 3102, 3202 may be any kind of processing component, such as one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs) , special-purpose digital logic, and the like. The memory 2604, 2704, 2804, 2904, 3004, 3104, 3204 may be any kind of storage component, such as read-only memory (ROM) , random-access memory, cache memory, flash memory devices, optical storage devices, etc.

[0587] FIG. 33 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.

[0588] As shown in FIG. 33, a computer-readable storage medium 330 storing instructions 331, which when executed by at least one processor of a network node or a terminal device, cause the at least one processor of the network node or the terminal device to perform the method according to any of the embodiments above mentioned, such as shown in FIG. 9A-FIG. 15F, 16-25.

[0589] In addition, the present disclosure may also provide a carrier containing the computer program / instructions as mentioned above. The carrier is one of an electronic signal, optical signal, radio signal, or the above computer readable storage medium. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory) , a ROM (read only memory) , Flash memory, magnetic tape, CD-ROM, DVD, Blue-ray disc and the like.

[0590] FIG. 34 is a block diagram showing exemplary apparatus units for a first terminal device, which is suitable for performing the method according to embodiments of the disclosure.

[0591] As shown in FIG. 34, the first terminal device 340 may include: a receiving unit 3402, configured for receiving a first credential from a first network node; a performing unit 3404, configured for performing an security procedure with a second network node, based at least on the first credential; and a communicating unit 3406, configured for communicating with the second terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.

[0592] In exemplary embodiments of the present disclosure, the first terminal device 240 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 9A-FIG. 9G, 16-25.

[0593] FIG. 35 is a block diagram showing exemplary apparatus units for a first network node, which is suitable for performing the method according to embodiments of the disclosure.

[0594] As shown in FIG. 35, the first network node 350 may include: an exchanging unit 3502, configured for exchanging a root certificate with a fourth network node; and a transmitting unit 3506, configured for the first credential to the first terminal device and / or a second network node, for an security procedure.

[0595] In exemplary embodiments of the present disclosure, the first network node 350 is further configured for performing the method according to any of the embodiments above mentioned, such as  shown in FIG. 10A-FIG. 10D, 16-25.

[0596] FIG. 36 is a block diagram showing exemplary apparatus units for a second network node, which is suitable for performing the method according to embodiments of the disclosure.

[0597] As shown in FIG. 36, the second network node 360 may include: a receiving unit 3602, configured for receiving a second credential for the second network node, from a third network node or a fourth network node; a receiving unit 3604, configured for receiving a first credential for the first terminal device or the first network node, from the first terminal device or a first network node; and a performing unit 3606, configured for performing an security procedure for the first terminal device, based at least on the first credential and the second credential.

[0598] The receiving unit 3604 and the receiving unit 3606 may be the same or different.

[0599] In exemplary embodiments of the present disclosure, the second network node 360 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 11A-FIG. 11E, 16-25.

[0600] FIG. 37 is a block diagram showing exemplary apparatus units for a third network node, which is suitable for performing the method according to embodiments of the disclosure.

[0601] As shown in FIG. 37, the third network node 370 may include: a generating unit 3702, configured for generating a first credential for a first terminal device, and / or a second credential for a second network node. The first credential and the second credential are for an security procedure between the first terminal device and the second network node.

[0602] In exemplary embodiments of the present disclosure, the third network node 370 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 12A-FIG. 12C, 16-25.

[0603] FIG. 38 is a block diagram showing exemplary apparatus units for a fourth network node, which is suitable for performing the method according to embodiments of the disclosure.

[0604] As shown in FIG. 38, the fourth network node 380 may include: a generating unit 3802, configured for generating a second credential for a second network node; a transmitting unit 3804, configured for transmitting the second credential to the second network node, for an security procedure between the first terminal device and the second network node.

[0605] In exemplary embodiments of the present disclosure, the fourth network node 380 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 13A-FIG. 13C, 16-25.

[0606] FIG. 39 is a block diagram showing exemplary apparatus units for a fifth network node, which is suitable for performing the method according to embodiments of the disclosure.

[0607] As shown in FIG. 39, the fifth network node 390 may include: a generating unit 3902, configured for generating a token for accessing the avatar data of the second terminal device; a transmitting unit 3904, configured for transmitting the token to the first terminal device via a first network node, or to the second terminal device via a fourth network node.

[0608] In exemplary embodiments of the present disclosure, the fifth network node 390 is further configured for performing the method according to any of the embodiments above mentioned, such as  shown in FIG. 14, 16-25.

[0609] FIG. 40 is a block diagram showing exemplary apparatus units for a second terminal device, which is suitable for performing the method according to embodiments of the disclosure.

[0610] As shown in FIG. 40, the second terminal device 400 may include: a receiving unit 4002, configured for receiving a third credential from a fourth network node; a performing unit 4004, configured for performing an security procedure with a second network node, based at least on the third credential; and a communicating unit 4006, configured for communicating with the first terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.

[0611] In exemplary embodiments of the present disclosure, the second terminal device 400 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 15A-FIG. 15F, 16-25.

[0612] The term ‘unit’ may have conventional meaning in the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.

[0613] As used in the present disclosure, the term “circuitry” may refer to one or more or all of the following:

[0614] (a) hardware-only circuit implementations (such as implementations in only analogy and / or digital circuitry) and

[0615] (b) combinations of hardware circuits and software, such as (as applicable) :

[0616] (i) a combination of analogy and / or digital hardware circuit (s) with software / firmware and

[0617] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0618] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. ”

[0619] This definition of circuitry applies to all uses of this term in the present disclosure, including in any claims. As a further example, as used in the present disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0620] With these units, the apparatus may not need a fixed processor or memory, any kind of computing resource and storage resource may be arranged from at least one  node / device / entity / apparatus relating to the communication system. The virtualization technology and network computing technology (e.g., cloud computing) may be further introduced, so as to improve the usage efficiency of the network resources and the flexibility of the network.

[0621] The techniques described herein may be implemented by various means so that an apparatus implementing one or more functions of a corresponding apparatus described with an embodiment comprises not only prior art means, but also means for implementing the one or more functions of the corresponding apparatus described with the embodiment and it may comprise separate means for each separate function, or means that may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses) , firmware (one or more apparatuses) , software (one or more modules / units) , or combinations thereof. For a firmware or software, implementation may be made through modules (e.g., procedures, functions, and so on) that perform the functions described herein.

[0622] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0623] The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .

[0624] As described in above exemplary embodiments of this disclosure, embodiments herein afford many advantages. According to embodiments of the present disclosure, they propose a mechanism that provides specifical procedures for a UE to be authenticated and / or authorized before using an avatar related information (such as metadata) . The authenticity / legitimacy of avatar object / representation / metadata may be validated. The security related to avatar object may be improved.

[0625] It should be understood that the above embodiments are only for illustration but not limitation. The present disclosure may be carried out in other ways than those specifically set forth herein without departing from essential characteristics of the disclosure. All changes to these embodiments not departing from the meaning and equivalency of the appended claims are intended to be comprised herein.

[0626] The following documents may be incorporated in entirety by reference.

[0627] 3GPP TR 23.700-77 V0.6.0 (2024-06)

[0628] 3GPP, SA2; “s2-2404596” , Access:

[0629] https:  / / www. 3gpp. org / ftp / tsg_sa / WG2_Arch / TSGS2_162_Changsha_2024-04 / Docs 3GPP TR 33.790 V0.3.0 (2024-05)

[0630] 3GPP TS 33.210 V18.1.0 (2024-06)

[0631] ABBREVIATION            EXPLANATION

[0632] DAC             Digital Asset Container

[0633] DC               Data Channel

[0634] DCSF           Data Channel Signalling Function

[0635] IMS              Internet Protocol Multimedia Subsystem

[0636] IMSEF          IMS Exposure Function

[0637] MF               Media Function

[0638] MRF                    Multimedia Resource Function

[0639] NEF              Network Exposure Function

[0640] NF               Network Function

[0641] UE                       User Equipment

[0642] XR                       Extended Reality

[0643] XR AS                 Extended Reality Application Server

[0644] NR                New Radio

[0645] 3GPP             3rd Generation Partnership Project

[0646] TR                Technical Report

[0647] NW               Network

[0648] UE                User Equipment

[0649] CMF              Credential Management Function

[0650] IMS AS          IMS Application Server

[0651] AR               Augmented reality

[0652] 3GPP             3rd generation partnership project

[0653] SA6            3rd generation partnership project technical specification group service and system aspects working group 6 (3GPP TSG SA WG 6)

[0654] 5GC              5th Generation Core Network

[0655] KI                Key Issue

[0656] TLS              Transport Layer Security

[0657] VAL             Vertical application layer

[0658] 5G                fifth generation

[0659] NR               New Radio

[0660] 6G               sixth generation

[0661] RRC             Radio Resource Control

[0662] Rel               Release

[0663] DL               Downlink

[0664] UL               Uplink

[0665] EAP-TLS            Extensible Authentication Protocol-Transport Layer Security

[0666] mTLS           Mutual Transport Layer Security

[0667] SIP      Session Initiation Protocol

[0668] SDP              Session Description Protocol

[0669] IMS-AGW       IMS Access Gateway

[0670] IMPU            IP Multimedia Public Identity

[0671] IMPI             IP Multimedia Private Identity

[0672] RTP               Realtime Transport Protocol

[0673] P / I / S-CSCF    Proxy / Interrogating  / Serving -Call Session Control Function

[0674] IMS-AGW       IMS Access Gateway

[0675] HSS              Home Subscriber Server

[0676] SA WG               3GPP Service and System Aspects Working Group

[0677] A / V                Audio / Video

[0678] DCSF           Data Channel Signalling Function

[0679] DAR               Digital Asset Repository

[0680] PLMN            Public Land Mobile Network

[0681] GBA             Generic Bootstrapping Architecture

[0682] AKMA           Authentication and Key Management for Application

Claims

1.An apparatus (260) for a first terminal device for an avatar communication between the first terminal device and a second terminal device, comprising:at least one processor (2602) ; andat least one memory (2604) including computer program code;the at least one memory (2604) and the computer program code configured to, with the at least one processor (2602) , cause the apparatus (260) for the first terminal device at least to perform:receiving (S902) a first credential from a first network node;performing (S904) a security procedure with a second network node, based at least on the first credential; andcommunicating (S906) with the second terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.2.The apparatus (260) for the first terminal device according to claim 1,wherein the first terminal device receives a root certificate and / or a fingerprint of the second network node; andwherein the first terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.3.The apparatus (260) for the first terminal device according to claim 1 or 2, further caused to perform:storing (S908) the first credential before the avatar communication.4.The apparatus (260) for the first terminal device according to any of claims 1 to 3, further caused to perform:receiving (S912) the avatar data of the second terminal device from the second network node after the successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the first terminal device.5.The apparatus (260) for the first terminal device according to any of claims 1 to 4,wherein communicating (S906) with the second terminal device comprises:starting (S9062) an avatar rendering process, based at least on the avatar data; andwherein the avatar communication between the first terminal device and the second terminal device is with or without a data channel.6.The apparatus (260) for the first terminal device according to any of claims 1 to 5,wherein the security procedure comprises a mutual authentication procedure or authorization procedure;Wherein the authentication procedure comprises mutual-Transport Layer Security, mTLS, procedure; orwherein the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.7.The apparatus (260) for the first terminal device according to any of claims 1 to 6,wherein the security procedure comprises an authentication procedure;wherein performing (S904) the security procedure with the second network node comprises:transmitting (S9042) the first credential to the second network node for authentication;receiving (S9044) a second credential from the second network node; andauthenticating (S9046) the second network node, based at least on the second credential and a received root certificate and / or a received fingerprint of the second network node;wherein the first credential comprises a client certificate; andwherein the second credential comprises a server certificate.8.The apparatus (260) for the first terminal device according to claim 7,wherein performing (S904) the security procedure with the second network node further comprises:generating (S9048) a session key based at least on the first credential and / or the second credential; andtransmitting (S90410) , to the second network node, a Message Authentication Code, MAC, generated based at least on the session key.9.The apparatus (260) for the first terminal device according to any of claims 1 to 8,wherein the first credential is generated by a third network node; andwherein the third network node comprises a Credential Management Function, CMF.10.The apparatus (260) for the first terminal device according to any of claims 1 to 9,wherein the security procedure comprises an authorization procedure;wherein performing (S904) the security procedure with the second network node comprises:receiving (S90412) a token for accessing the avatar data of the second terminal device; andtransmitting (S90414) the token to the second network node, for an authorization.11.The apparatus (260) for the first terminal device according to claim 10,wherein the token is generated by the second terminal device, or a fourth network node;wherein the first terminal device receives the token from the second terminal device, or from the first network node; andwherein the fourth network node comprises an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.12.The apparatus (260) for the first terminal device according to claim 10,wherein the token is generated by the second terminal device, or a fifth network node;wherein the first terminal device receives the token from the second terminal device, or from the first network node; andwherein the first terminal device transmits the token to the second network node, via the fifth network node.13.The apparatus (260) for the first terminal device according to claim 12,wherein the fifth network node comprises: an Extended Reality, XR, application server.14.The apparatus (260) for the first terminal device according to any of claims 1 to 13,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication;wherein the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; andwherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.15.The apparatus (260) for the first terminal device according to claim 14,wherein the IMS core network node comprises at least one of:an Internet Protocol Multimedia Subsystem Application Server, IMS AS;a Proxy Call Session Control Function, P-CSCF;an Interrogating Call Session Control Function, I-CSCF;a Serving Call Session Control Function, S-CSCF; and / oran Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.16.An apparatus (270) for a first network node for an avatar communication between a first terminal device and a second terminal device, comprising:at least one processor (2702) ; andat least one memory (2704) including computer program code;the at least one memory (2704) and the computer program code configured to, with the at least one processor (2702) , cause the apparatus (270) for the first network node at least to perform:exchanging (S1002) a root certificate with a fourth network node; andtransmitting (S1006) a first credential to the first terminal device and / or a second network node, for a security procedure.17.The apparatus (270) for the first network node according to claim 16,wherein the first network node generates the first credential for the first terminal device; orwherein the first network node receives the first credential from a third network node.18.The apparatus (270) for the first network node according to claim 17,wherein the third network node comprises a Credential Management Function, CMF.19.The apparatus (270) for the first network node according to any of claims 16 to 18, wherein the first network node transmits the first credential to the first terminal device;wherein the first terminal device performs the security procedure with the second network node, based at least on the first credential.20.The apparatus (270) for the first network node according to claim 19,wherein the first terminal device receives a root certificate and / or a fingerprint of the second network node; andwherein the first terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.21.The apparatus (270) for the first network node according to any of claims 16 to 20, further caused to perform:receiving (S1012) the avatar data of the second terminal device from the second network node after a successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the first network node.22.The apparatus (270) for the first network node according to any of claims 16 to 21,wherein the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.23.The apparatus (270) for the first network node according to any of claims 16 to 22,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication;wherein the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; andwherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.24.The apparatus (270) for the first network node according to claim 23,wherein the IMS core network node comprises at least one of:an Internet Protocol Multimedia Subsystem Application Server, IMS AS;a Proxy Call Session Control Function, P-CSCF;an Interrogating Call Session Control Function, I-CSCF;a Serving Call Session Control Function, S-CSCF; and / oran Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.25.An apparatus (280) for a second network node for an avatar communication between a first terminal device and a second terminal device, comprising:at least one processor (2802) ; andat least one memory (2804) including computer program code;the at least one memory (2804) and the computer program code configured to, with the at least one processor (2802) , cause the apparatus (280) for the second network node at least to perform:receiving (S1102) a second credential for the second network node, from a third network node or a fourth network node;receiving (S1104) a first credential for the first terminal device, from the first terminal device or a first network node; andperforming (S1106) a security procedure for the first terminal device or the first network node, based at least on the first credential and the second credential.26.The apparatus (280) for the second network node according to claim 25,wherein the second network node receives a root certificate and / or a fingerprint of the first terminal device; andwherein the second network node performs the security procedure with the first terminal device, further based on the received root certificate and / or the received fingerprint.27.The apparatus (280) for the second network node according to claim 25 or 26, further caused to perform:storing (S1108) the second credential before the avatar communication.28.The apparatus (280) for the second network node according to claim 25 or 27, further caused to perform:transmitting (S1112) the avatar data of the second terminal device, to the first terminal device or the first network node, after the successful security procedure for the first terminal device or the first network node.29.The apparatus (280) for the second network node according to any of claims 25 to 28,wherein the avatar communication between the first terminal device and the second terminal device is with or without a data channel.30.The apparatus (280) for the second network node according to any of claims 25 to 29,wherein the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure orwherein the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.31.The apparatus (280) for the second network node according to any of claims 25 to 29, wherein the security procedure comprises an authentication procedure;wherein the first credential comprises a client certificate; andwherein the second credential comprises a server certificate.32.The apparatus (280) for the second network node according to claim 31,wherein performing (S1106) the security procedure for the first terminal device further comprises:receiving (S11062) , from the first terminal device, a Message Authentication Code, MAC, generated based at least on a session key derived by the first terminal device;deriving (S11064) a session key based at least on the first credential and / or the second credential; andvalidating (S11066) the MAC.33.The apparatus (280) for the second network node according to any of claims 25 to 32,wherein the first credential is generated by the first network node;wherein the second credential is generated by the fourth network node.34.The apparatus (280) for the second network node according to any of claims 25 to 32, wherein the first credential and the second credential are generated by the third network node.35.The apparatus (280) for the second network node according to any of claims 25 to 34,wherein the security procedure comprises an authorization procedure;wherein performing (S1106) the security procedure for the first terminal device comprises:receiving (S11068) a token for accessing the avatar data of the second terminal device, from the first terminal device or a fifth network node; andverifying (S110610) the token.36.The apparatus (280) for the second network node according to claim 35,wherein the token is generated by the second terminal device, or the fourth network node; andwherein the first terminal device receives the token from the second terminal device, or from the first network node.37.The apparatus (280) for the second network node according to claim 35,wherein the token is generated by the second terminal device, or the fifth network node;wherein the first terminal device receives the token from the second terminal device, or from the first network node, or from the fifth network node; andwherein the first terminal device transmits the token to the second network node, via the fifth network node.38.The apparatus (280) for the second network node according to claim 37,wherein the fifth network node comprises: an Extended Reality, XR, application server.39.The apparatus (280) for the second network node according to any of claims 25 to 38,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication;wherein the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication;wherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository;wherein the third network node comprises a Credential Management Function, CMF; andwherein the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.40.The apparatus (280) for the second network node according to claim 39,wherein the IMS core network node comprises at least one of:an Internet Protocol Multimedia Subsystem Application Server, IMS AS;a Proxy Call Session Control Function, P-CSCF;an Interrogating Call Session Control Function, I-CSCF;a Serving Call Session Control Function, S-CSCF; and / oran Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.41.An apparatus (290) for a third network node for an avatar communication between a first terminal device and a second terminal device, comprising:at least one processor (2902) ; andat least one memory (2904) including computer program code;the at least one memory (2904) and the computer program code configured to, with the at least one processor (2902) , cause the apparatus (290) for the third network node at least to perform:generating (S1202) a first credential for a first terminal device, and / or a second credential for a second network node;wherein the first credential and the second credential are for a security procedure between the first terminal device and the second network node.42.The apparatus (290) for the third network node according to claim 41,wherein the security procedure comprises an authentication procedure;wherein the first credential comprises a client certificate; andwherein the second credential comprises a server certificate.43.The apparatus (290) for the third network node according to any of claims 41 to42,wherein the third network node comprises a Credential Management Function, CMF.44.The apparatus (290) for the third network node according to any of claims 41 to 43,wherein the third network node is in a terminating or receiving side of the avatar communication, and generates the first credential for the first terminal device;wherein the apparatus (290) for the third network node is further caused to perform:transmitting (S1204) the first credential to a CMF in an originating or transmitting side of the avatar communication; andreceiving (S1206) the second credential from the CMF in an originating or transmitting side of the avatar communication.45.The apparatus (290) for the third network node according to any of claims 41 to 43,wherein the third network node is in an originating or transmitting side of the avatar communication, and generates the second credential for the second network node;wherein the apparatus (290) for the third network node is further caused to perform:transmitting (S1208) the second credential to a CMF in a terminating or receiving side of the avatar communication; andreceiving (S1210) the first credential from the CMF in a terminating or receiving side of the avatar communication.46.The apparatus (290) for the third network node according to any of claims 41 to 45,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication; andwherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.47.An apparatus (300) for a fourth network node for an avatar communication between a first terminal device and a second terminal device, comprising:at least one processor (3002) ; andat least one memory (3004) including computer program code;the at least one memory (3004) and the computer program code configured to, with the at least one processor (3002) , cause the apparatus (300) for the fourth network node at least to perform:generating (S1302) a second credential for a second network node;transmitting (S1304) the second credential to the second network node, for a security procedure between the first terminal device and the second network node.48.The apparatus (300) for the fourth network node according to claim 47,wherein the second credential is generated by the fourth network node;wherein the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication; andwherein the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.49.The apparatus (300) for the fourth network node according to claim 48,wherein the IMS core network node comprises at least one of:an Internet Protocol Multimedia Subsystem Application Server, IMS AS;a Proxy Call Session Control Function, P-CSCF;an Interrogating Call Session Control Function, I-CSCF;a Serving Call Session Control Function, S-CSCF; and / oran Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.50.The apparatus (300) for the fourth network node according to any of claims 47 to 49, further caused to perform:generating (S1306) a token for accessing the avatar data of the second terminal device;wherein the security procedure comprises an authorization procedure.51.The apparatus (300) for the fourth network node according to claim 50, further caused to perform:transmitting (S1308) the token to the first terminal device, via a first network node; ortransmitting (S1310) the token to the second terminal device.52.The apparatus (300) for the fourth network node according to any of claims 47 to 51, further caused to perform:generating (S1312) a third credential for a second terminal device;transmitting (S1314) the third credential to the second terminal device, for a security procedure between the second terminal device and the second network node;wherein the security procedure comprises an authentication procedure.53.The apparatus (300) for the fourth network node according to any of claims 47 to 52,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication; andwherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository.54.An apparatus (310) for a fifth network node for an avatar communication between a first terminal device and a second terminal device, comprising:at least one processor (3102) ; andat least one memory (3104) including computer program code;the at least one memory (3104) and the computer program code configured to, with the at least one processor (3102) , cause the apparatus (310) for the fifth network node at least to perform:generating (S1402) a token for accessing the avatar data of the second terminal device;transmitting (S1404) the token to the first terminal device via a first network node, or to the second terminal device via a fourth network node.55.The apparatus (310) for the fifth network node according to any of claim 54,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication;wherein the first network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in a terminating or receiving side of the avatar communication;wherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository; andwherein the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.56.The apparatus (310) for the fifth network node according to claim 55,wherein the IMS core network node comprises at least one of:an Internet Protocol Multimedia Subsystem Application Server, IMS AS;a Proxy Call Session Control Function, P-CSCF;an Interrogating Call Session Control Function, I-CSCF;a Serving Call Session Control Function, S-CSCF; and / oran Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.57.An apparatus (320) for a second terminal device for an avatar communication between a first terminal device and the second terminal device, comprising:at least one processor (3202) ; andat least one memory (3204) including computer program code;the at least one memory (3204) and the computer program code configured to, with the at least one processor (3202) , cause the apparatus (320) for the second terminal device at least to perform:receiving (S1502) a third credential from a fourth network node;performing (S1504) a security procedure with a second network node, based at least on the third credential; andcommunicating (S1506) with the first terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.58.The apparatus (320) for the second terminal device according to claim 57, further caused to perform:storing (S1508) the third credential before the avatar communication.59.The apparatus (320) for the second terminal device according to claim 57 or 58, further caused to perform:receiving (S1512) the avatar data of the second terminal device from the second network node after the successful security procedure with the second network node, when the avatar data of the second terminal device is not locally available at the second terminal device.60.The apparatus (320) for the second terminal device according to any of claims 57 to 59, wherein communicating (S1506) with the first terminal device comprises:starting (S15062) an avatar rendering process, based at least on the avatar data;wherein the avatar communication between the first terminal device and the second terminal device is with or without a data channel.61.The apparatus (320) for the second terminal device according to any of claims 57 to 60,wherein the security procedure comprises a mutual authentication procedure, such as mutual-Transport Layer Security, mTLS, procedure; orwherein the security procedure comprises an Extensible Authentication Protocol-TLS, EAP-TLS.62.The apparatus (320) for the second terminal device according to any of claims 57 to 61,wherein the security procedure comprises an authentication procedure;wherein performing (S1504) the security procedure with the second network node comprises:transmitting (S15042) the third credential to the second network node for authentication;receiving (S15044) a second credential from the second network node; andauthenticating (S15046) the second network node, based at least on the second credential;wherein the third credential comprises a client certificate; andwherein the second credential comprises a server certificate.63.The apparatus (320) for the second terminal device according to claim 62,wherein the second terminal device receives a root certificate and / or a fingerprint of the second network node; andwherein the second terminal device performs the security procedure with the second network node, further based on the received root certificate and / or the received fingerprint.64.The apparatus (320) for the second terminal device according to any of claims 57 to 63,wherein the security procedure comprises an authorization procedure;wherein performing (S1504) the security procedure with the second network node comprises:receiving (S15048) a token for accessing the avatar data of the second terminal device; andtransmitting (S15410) the token to the second network node, for an authorization.65.The apparatus (320) for the second terminal device according to claim 64,wherein the token is generated by the fourth network node.66.The apparatus (320) for the second terminal device according to any of claims 57 to 65,wherein the first terminal device comprises a terminating or receiving user equipment, UE, of the avatar communication;wherein the second terminal device comprises an originating or transmitting UE of the avatar communication;wherein the second network node comprises: a Digital Asset Container, DAC, or an Avatar Repository, or a Base Avatar Repository;wherein the fourth network node comprises: an Internet Protocol Multimedia Subsystem, IMS, core network node in an originating or transmitting side of the avatar communication.67.The apparatus (320) for the second terminal device according to claim 66,wherein the IMS core network node comprises at least one of:an Internet Protocol Multimedia Subsystem Application Server, IMS AS;a Proxy Call Session Control Function, P-CSCF;an Interrogating Call Session Control Function, I-CSCF;a Serving Call Session Control Function, S-CSCF; and / oran Internet Protocol Multimedia Subsystem Access Gateway, IMS AGW.68.A method (900) performed by a first terminal device for an avatar communication between the first terminal device and a second terminal device, comprising:receiving (S902) a first credential from a first network node;performing (S904) a security procedure with a second network node, based at least on the first credential; andcommunicating (S906) with the second terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.69.The method (900) according to claim 68, performed by the apparatus (260) according to any of claims 1 to 15.70.A method (1000) performed by a first network node for an avatar communication between a first terminal device and a second terminal device, comprising:exchanging (S1002) a root certificate with a fourth network node; andtransmitting (S1006) a first credential to the first terminal device and / or a second network node, for a security procedure.71.The method (1000) according to claim 70, performed by the apparatus (270) according to any of claims 16 to 24.72.A method (1100) performed by a second network node for an avatar communication between a first terminal device and a second terminal device, comprising:receiving (S1102) a second credential for the second network node, from a third network node or a fourth network node;receiving (S1104) a first credential for the first terminal device, from the first terminal device or a first network node; andperforming (S1106) a security procedure for the first terminal device or the first network node, based at least on the first credential and the second credential.the method according to any of claims 25 to 40.73.The method (1100) according to claim 72, performed by the apparatus (280) according to any of claims 25 to 40.74.A method (1200) performed by a third network node for an avatar communication between a first terminal device and a second terminal device, comprising:generating (S1202) a first credential for a first terminal device, and / or a second credential for a second network node;wherein the first credential and the second credential are for a security procedure between the first terminal device and the second network node.75.The method (1200) according to claim 74, performed by the apparatus (290) according to any of claims 41 to 46.76.A method (1300) performed by a fourth network node for an avatar communication between a first terminal device and a second terminal device, comprising:generating (S1302) a second credential for a second network node;transmitting (S1304) the second credential to the second network node, for a security procedure between the first terminal device and the second network node.77.The method (1300) according to claim 76, performed by the apparatus (300) according to any of claims 47 to 53.78.A method (1400) performed by a fifth network node for an avatar communication between a first terminal device and a second terminal device, comprising:generating (S1402) a token for accessing the avatar data of the second terminal device;transmitting (S1404) the token to the first terminal device via a first network node, or to the second terminal device via a fourth network node.79.The method (1400) according to claim 78, performed by the apparatus (310) according to any of claims 54 to 56.80.A method (1500) performed by a second terminal device for an avatar communication between a first terminal device and the second terminal device, comprising:receiving (S1502) a third credential from a fourth network node;performing (S1504) a security procedure with a second network node, based at least on the third credential; andcommunicating (S1506) with the first terminal device, by using at least avatar data of the second terminal device, after a successful security procedure with the second network node.81.The method (1500) according to claim 80, performed by the apparatus (320) according to any of claims 57 to 67.82.A computer-readable storage medium (330) storing instructions (331) , which when executed by at least one processor of an apparatus, cause the at least one processor of the apparatus to at least perform the method according to any of claims 68 to 81.

Citation Information

Patent Citations

  • Identity verification in virtual worlds using encoded data

    US20100299747A1

  • Digital asset transfers in a virtual environment based on a physical object

    US20230360044A1

  • Authenticating a virtual entity in a virtual environment

    US20240022553A1