Resource owner-aware northbound API access authorization method, apparatus, and device

By receiving and verifying API caller requests through the first network function and determining their access permissions based on resource owner authorization information, this solves the problems of low efficiency and insufficient privacy protection in the authorization of northbound API access by resource owners in the prior art, and achieves efficient resource access and privacy protection.

WO2026061272A1PCT designated stage Publication Date: 2026-03-26CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

In existing technologies, northbound API access authorization perceived by resource owners is only executed based on the API caller's contract information, which cannot effectively support API callers to access resources of other resource owners. Especially in 5G C-V2X scenarios, such as vehicle health monitoring in fleet management, there is a lack of effective authorization verification and user privacy protection.

Method used

A resource owner-aware northbound API access authorization method is provided. The method receives the request message from the API caller through a first network function, determines whether the API caller is authorized to access the resource owner's resources based on the resource owner's authorization information, and returns a response message, thereby protecting the resource owner's privacy and improving authorization efficiency.

Benefits of technology

It improves the efficiency of northbound API call authorization that is aware of resource owners, protects the privacy and security of resource owners, supports API callers to access resources of other resource owners, and meets the application needs of fleet management such as vehicle health monitoring in 5G C-V2X scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025119266_26032026_PF_FP_ABST
    Figure CN2025119266_26032026_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a resource owner-aware northbound API access authorization method, an apparatus, and a device. The method is applied to a first network function, and comprises: receiving a first request message sent by an API invoker; determining whether the API invoker is authorized to access a resource of a resource owner; and sending a first response message to the API invoker. In this way, the problem in the prior art that an authorization request from an API invoker is validated only on the basis of subscription information of the API invoker is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Resource owner aware northbound API access authorization method, device and equipment

[0001] Cross-reference to Related Applications

[0002] The present application claims priority to the Chinese patent application No. 202411302912.4, filed on September 18, 2024, and entitled "Resource owner aware northbound API access authorization method, device and equipment", the entire content of which is incorporated herein by reference. TECHNICAL FIELD

[0003] The present application relates to the technical field of wireless communication, in particular to a resource owner aware northbound API access authorization method, device and equipment. BACKGROUND

[0004] From 3GPP (3rd Generation Partnership Project, third generation partnership project) Release version 18, in the resource owner aware northbound API (Application Program Interface, application program interface) access (RNAA (Radio Access Network Access, radio access network access)), the calling range of the API caller on the UE (User Equipment, user equipment) is limited to accessing its own resources, that is, the resource owner as the user of the UE hosting the API caller, the resource owner can authorize the API to access the resources on the UE. However, in 3GPP Release 19, it is required to support the API caller deployed on the UE to access the resources of other resource owners (users), for example, in the 5G C-V2X (Cellular Vehicle-to-Everything, cellular vehicle-to-everything) scenario, involving vehicle health monitoring in vehicle fleet management, in which the application client on UE 1 can request to access UE 2 in order to obtain the location and / or vehicle health problem from another user (UE 2). The authorization verification and user privacy protection of this application scenario are also one of the key problems to be standardized urgently.

[0005] In the standardization scheme of 3GPP TS 33.122, for the resource owner-aware northbound API access scenario, it is limited that the API invoker can only access the resources of its own UE, and the application scenario that the API invoker requests to access the resources of other resource owners (UE) is not considered. The authorization request of the API invoker is only based on the subscription information of the API invoker to perform authorization request verification in the CAPIF (Common API Framework for 3GPP Northbound APIs, common API exposure framework) core function. SUMMARY

[0006] The purpose of the present application is to provide a resource owner-aware northbound API access authorization method, device and equipment, which solves the problem that the existing processing of the authorization request of the API invoker is only based on the subscription information of the API invoker to perform authorization request verification.

[0007] In a first aspect, the embodiments of the present application provide a resource owner-aware northbound API access authorization method, which is applied to a first network function, and the method comprises:

[0008] receiving a first request message sent by an API invoker;

[0009] determining whether the API invoker is authorized to access the resources of a resource owner;

[0010] sending a first response message to the API invoker.

[0011] In some possible embodiments, the first request message is used to obtain authorization to access the resources of a resource owner provided by a service API, or is used to obtain service API authorization, or is used to obtain an access token.

[0012] In some possible embodiments, determining whether the API invoker is authorized to access the resources of the resource owner comprises:

[0013] determining whether the API invoker is authorized to access the resources of the resource owner based on resource owner authorization information;

[0014] The resource owner authorization information is stored in the first network function.

[0015] Or the resource owner authorization information is obtained by the first network function from the resource owner through a secure interface.

[0016] In some possible embodiments, the resource owner authorization information is a set of information indicating whether the API invoker is authorized to access a specific one or more resources of the resource owner.

[0017] In some possible embodiments, the first request message comprises at least one of the following information:

[0018] API invoker identity, resource owner identity, service API information, resource information.

[0019] In some possible embodiments, the service API information and / or resource information comprises at least one of the following information:

[0020] a parameter or a string for identifying a resource owner resource that the API invoker requests to access;

[0021] a parameter or a string for describing a resource owner resource that the API invoker requests to access;

[0022] a parameter or a string for naming a resource owner resource that the API invoker requests to access;

[0023] resource identity, resource name, resource operation identity, resource operation name, resource operation description, resource processing purpose, resource processing description.

[0024] In some possible embodiments, the resource owner authorization information is obtained according to the information comprised in the first request message.

[0025] In some possible embodiments, the first request message is sent directly by the API invoker; or

[0026] the first request message is sent indirectly by the API invoker through a proxy;

[0027] the first response message is sent directly to the API invoker, or

[0028] the first response message is sent indirectly to the API invoker through a proxy.

[0029] In some possible embodiments, the resource owner authorization information comprises at least one of the following information:

[0030] resource information;

[0031] a description indicating whether to authorize;

[0032] a description indicating whether to authorize a resource to be accessed;

[0033] a description indicating whether to authorize a resource identified by the resource information to be accessed;

[0034] a description indicating whether to authorize a resource identified by the resource information to be performed with a corresponding operation.

[0035] In some possible embodiments, the resource owner authorization information further comprises at least one of the following:

[0036] a description indicating whether the resource is authorized under certain conditions;

[0037] a description indicating whether the resource is authorized to be acquired under certain conditions;

[0038] a description indicating whether the resource identified by the resource information is authorized to be acquired under certain conditions;

[0039] a description indicating whether the resource identified by the resource information is authorized to perform a corresponding operation under certain conditions;

[0040] a validity period.

[0041] In some possible embodiments, the certain conditions comprise at least one of the following:

[0042] a limitation on an API invoker;

[0043] a limitation on an API invoker identifier;

[0044] a limitation on a group or organization to which an API invoker belongs;

[0045] a limitation on a geographic location where an API invoker is located;

[0046] a limitation on an access network to which an API invoker belongs;

[0047] a limitation on a service API access range.

[0048] In some possible embodiments, the resource information in the resource owner authorization information comprises at least one of the following information:

[0049] a parameter or a string for identifying a resource owner resource requested to be accessed by an API invoker;

[0050] a parameter or a string for describing a resource owner resource requested to be accessed by an API invoker;

[0051] a parameter or a string for naming a resource owner resource requested to be accessed by an API invoker;

[0052] a resource identifier, a resource name, a resource operation identifier, a resource operation name, a resource operation description, a resource processing purpose, and a resource processing description.

[0053] In some possible embodiments, the first network function retrieves corresponding resource information and / or authorization information in the resource owner authorization information based on the service API information and / or the resource information in the first request message and the resource owner identifier.

[0054] In some possible embodiments, the first network function retrieves corresponding resource information and / or authorization information in the resource owner authorization information based on the service API information and / or resource information in the first request message.

[0055] In some possible embodiments, a specific resource of a specific resource owner can be identified by a combination of resource owner identification and resource information.

[0056] In some possible embodiments, a specific resource of a specific resource owner can be identified by resource information containing a specific resource owner identification, such as a string of resource information composed of resource owner identification + resource name / resource code.

[0057] In some possible embodiments, the first response message includes at least one of the following information:

[0058] API caller identification, resource owner identification, authorization code, access token, authorization scope, service API information, resource information, and validity period.

[0059] In some possible embodiments, the first request message indicates whether the API caller requests to access resources of other resource owners.

[0060] In some possible embodiments, determining whether the API caller is authorized to access the resources of the resource owner includes:

[0061] According to the API caller identification and the resource owner identification in the first request message, it is determined whether to request to access resources of other resource owners.

[0062] In some possible embodiments, determining whether the API caller is authorized to access the resources of the resource owner includes:

[0063] According to the first request message, when it is determined that the request includes authorization of one or more target resources, the resource owner authorization information corresponding to each target resource is obtained.

[0064] Based on the resource owner authorization information corresponding to each target resource, it is determined whether the API caller is authorized to access the resources of the resource owner.

[0065] In some possible embodiments, the method further includes:

[0066] Receiving a resource owner authorization revocation request message sent by the resource owner triggers the execution of the authorization revocation process.

[0067] In some possible embodiments, the method further includes:

[0068] receiving a resource owner authorization revocation request message sent by the resource owner, sending a resource owner authorization revocation response message to the resource owner, and performing an authorization revocation procedure.

[0069] In some possible embodiments, the authorization revocation procedure is a service API authorization revocation procedure or an API invoker authorization revocation procedure.

[0070] In some possible embodiments, the method further comprises:

[0071] receiving a resource access authorization change or revocation message sent by the resource owner through the secure interface;

[0072] or receiving a resource access consent change or revocation message sent by the resource owner through the secure interface;

[0073] or receiving a resource owner authorization change or revocation message sent by the resource owner through the secure interface.

[0074] In some possible embodiments, before triggering the execution of the service API authorization revocation procedure, the method further comprises:

[0075] receiving a resource owner authorization revocation request message sent by the resource owner, and determining the target API invoker identifier and / or the target service API information associated with the revocation authorization operation.

[0076] In some possible embodiments, before triggering the execution of the service API authorization revocation procedure, the method further comprises:

[0077] sending an authorization revocation request message to a third network function;

[0078] The authorization revocation request message comprises at least one of the following information: API invoker identifier, resource owner identifier, service API information, resource information, access token, and reason.

[0079] In some possible embodiments, the method further comprises:

[0080] determining the resource owner identifier, and determining whether the API invoker requests to access resources of other resource owners according to whether the resource owner identifier is different from the API invoker identifier.

[0081] In some possible embodiments, whether the API invoker requests to access resources of other resource owners is determined according to whether the GPSI of the resource owner is different from the GPSI mapped by the API invoker identifier.

[0082] In some possible embodiments, the determination of whether the API invoker is authorized to access the resources of the resource owner comprises:

[0083] According to the API caller identity and the resource owner identity, it is determined that the API caller and the resource owner belong to different domains;

[0084] According to the first request message, a second network function corresponding to the domain to which the resource owner belongs is searched, and the second network function corresponding to the domain to which the resource owner belongs is communicated to determine whether the API caller is authorized to access the resource of the resource owner.

[0085] In some possible embodiments, according to the first request message, a second network function corresponding to the domain to which the resource owner belongs is searched, and the second network function corresponding to the domain to which the resource owner belongs is communicated to determine whether the API caller is authorized to access the resource of the resource owner, comprising:

[0086] The first network function forwards the first request message to the second network function in the domain to which the resource owner belongs based on the resource owner identity in the first request message, and the second network function receives the first request message and determines whether the API caller is authorized to access the resource of the resource owner based on the resource owner authorization information;

[0087] Or the first network function forwards the first request message to the second network function in the domain to which the resource owner belongs based on the routing information in the first request message, and the second network function receives the first request message and determines whether the API caller is authorized to access the resource of the resource owner based on the resource owner authorization information;

[0088] A second response message returned by the second network function is received.

[0089] In a second aspect, the embodiments of the present application provide a resource owner-aware northbound API access authorization method, which is applied to an API caller, and the method comprises:

[0090] A first request message is sent to a first network function;

[0091] A first response message returned by the first network function after determining whether the API caller is authorized to access the resource of the resource owner is received.

[0092] The first request message is used to obtain authorization to access a resource of a resource owner provided by a service API, or is used to obtain authorization of a service API, or is used to obtain an access token.

[0093] In some possible embodiments, the first request message is used to obtain authorization to access a resource of a resource owner provided by a service API, or is used to obtain authorization of a service API, or is used to obtain an access token.

[0094] In some possible embodiments, the service API information and / or resource information comprises at least one of the following information:

[0095] a parameter or a string for identifying a resource owner resource requested to be accessed by the API invoker;

[0096] a parameter or a string for describing a resource owner resource requested to be accessed by the API invoker;

[0097] a parameter or a string for naming a resource owner resource requested to be accessed by the API invoker;

[0098] a resource identifier, a resource name, a resource operation identifier, a resource operation name, a resource operation description, a resource processing purpose, and a resource processing description.

[0099] In some possible embodiments, the method further comprises:

[0100] determining, based on the first response message, that the first request message is authorized to pass, or that the access token is carried in the first response message, and sending, to a third network function, a service API invocation request carrying the access token.

[0101] In some possible embodiments, the service API invocation request is used to request access to a resource owner resource provided through a service API.

[0102] In some possible embodiments, the first response message comprises at least one of the following information:

[0103] an API invoker identifier, a resource owner identifier, an authorization code, an access token, an authorization scope, service API information, resource information, and a validity period.

[0104] In a third aspect, another embodiment of the present application further provides a resource owner-aware northbound API access authorization apparatus, comprising:

[0105] a request receiving module configured to receive a first request message sent by an API invoker;

[0106] an authorization checking module configured to determine whether the API invoker is authorized to access a resource owner resource;

[0107] a response sending module configured to send a first response message to the API invoker.

[0108] In a fourth aspect, another embodiment of the present application further provides a resource owner-aware northbound API access authorization apparatus, comprising:

[0109] a request sending module configured to send a first request message to a first network function;

[0110] a response receiving module, configured to receive a first response message returned by the first network function after determining whether the API invoker is authorized to access the resource of the resource owner.

[0111] In a fifth aspect, another embodiment of the present application further provides a resource owner-aware northbound API access authorization device, including at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform any of the resource owner-aware northbound API access authorization methods provided by the embodiments of the present application.

[0112] In a sixth aspect, another embodiment of the present application further provides a computer storage medium, which stores a computer program for causing a computer to execute any of the resource owner-aware northbound API access authorization methods provided by the embodiments of the present application.

[0113] The resource owner-aware northbound API access authorization method, device and equipment provided by the embodiments of the present application, after receiving the first request message of the API invoker, determine whether the API invoker is authorized to access the resource of the resource owner, and return the first response message to the API invoker; improve the efficiency of the resource owner-aware northbound API invoker authorization through the centralized information advantage, and protect the privacy and security of the resource owner.

[0114] Other features and advantages of the present application will be described in the following description and will be apparent from the description, or will be learned from the practice of the application. The purposes and other advantages of the application will be realized and attained by the structure particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF DRAWINGS

[0115] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. Obviously, the drawings to be introduced below are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0116] FIG. 1 is a flow chart of a resource owner-aware northbound API access authorization method in the related art;

[0117] FIG. 2 is a schematic diagram of a CAPIF architecture supporting an RNAA function security model;

[0118] FIG. 3 is a resource owner-aware northbound API access authorization method flow chart applied to a first network function according to an embodiment of the present application;

[0119] FIG. 4 is a resource owner-aware northbound API access authorization method flow chart applied to an API invoker according to an embodiment of the present application;

[0120] FIG. 5 is a resource owner-aware northbound API access authorization method detailed flow chart according to an embodiment of the present application;

[0121] FIG. 6 is a service API authorization revocation flow chart triggered by resource owner authorization information change according to an embodiment of the present application;

[0122] FIG. 7 is a resource owner-aware northbound API access authorization device structure diagram as a first network function according to an embodiment of the present application;

[0123] FIG. 8 is a resource owner-aware northbound API access authorization device structure diagram as an API invoker according to an embodiment of the present application;

[0124] FIG. 9 is a resource owner-aware northbound API access authorization device diagram according to an embodiment of the present application. DETAILED DESCRIPTION

[0125] To further illustrate the technical solutions provided by the embodiments of the present application, the following will be described in detail in conjunction with the drawings and specific embodiments. Although the embodiments of the present application provide the following method operation steps as shown in the embodiments or drawings, more or fewer operation steps can be included in the method based on conventional or non-creative labor. The execution order of the steps is not limited to the execution order provided by the embodiments of the present application in the logical sense. The method can be executed in sequence or in parallel when the method is executed in the actual processing process or by the control device.

[0126] As shown in FIG. 1, the resource owner-aware northbound API access authorization method flow in the related art mainly includes:

[0127] Step 1, the API invoker communicates with the first CCF (CAPIF (Common API Framework for 3GPP Northbound APIs, Common API Exposure Framework) core function), and performs CAPIF-1e authentication and security session establishment;

[0128] Step 2, the API invoker sends an access token request based on Oauth 2.0 to the first CCF, and the access token request is an authorization request;

[0129] Step 3, the first CCF performs a verify access token request;

[0130] Step 4, the API invoker receives and uses an Oauth 2.0 access token response;

[0131] Step 5, the API invoker performs a TLS (Transport Layer Security) connection establishment with the API development function;

[0132] Step 6, the API invoker uses the Oauth 2.0 access token to call a northbound API;

[0133] Step 7, the API development function verifies the access token, declares authorization in the token, and performs a northbound API request;

[0134] Step 8, the API development function responds to the API invoker for the northbound API call.

[0135] In view of the fact that in step 3, the first CCF processes the API invoker's authorization request only based on the API invoker's subscription information to perform authorization request verification, the embodiments of the present application provide a resource owner-aware northbound API access authorization method, device and equipment, and a CAPIF architecture supporting an RNAA function security model as shown in FIG. 2 is the application scenario of the embodiments of the present application.

[0136] The embodiments of the present application provide a resource owner-aware northbound API access authorization method, which is applied to a first network function. The first network function can be a CAPIF core function (i.e., a CCF), or an authorization function in the CAPIF core function, or an authorization server. The first network function and an API invoker belong to the same domain, the API invoker is onboarded into the first network function, and the first network function supports management of resource owner authorization information of different resource owners. As shown in FIG. 3, the method comprises:

[0137] Step 301, receiving a first request message sent by an API invoker;

[0138] The first network function in the embodiments of the present application can receive the first request message in any one of the following two ways:

[0139] Way 1, the first request message is sent directly by the API invoker, and the first network function directly receives the first request message from the API invoker;

[0140] The API invoker has established a secure interface with the first network function before sending the first request message, and implements mutual authentication and data transmission protection based on the secure interface, such as ensuring the confidentiality, integrity, and anti-replay protection of data. The secure interface can be TLS protection at the transport layer or IPSec protection at the network layer.

[0141] In mode 2, the first request message is sent indirectly by the API invoker through a proxy, and the first network function indirectly receives the first request message through the proxy.

[0142] In the case of indirect sending, the original API invoker can be regarded as the front end of the API invoker, and the proxy can be regarded as the back end of the API invoker. At this time, it is assumed that the back end of the API invoker has a secure interface with the first network function (CCF), the front end of the API invoker communicates with the back end of the API invoker, and the first network function communicates with the back end of the API invoker through the secure interface, thereby realizing the secure sending of the first request message.

[0143] The API invoker has established a secure interface with the first network function before sending the first request message, and implements mutual authentication and data transmission protection based on the secure interface. The secure interface can be TLS protection at the transport layer or IPSec protection at the network layer.

[0144] The first request message is a message for requesting related authorization, which can be, but is not limited to, a message for obtaining authorization to access resources owned by a resource owner of a service API, a message for obtaining service API authorization, or a message for obtaining an access token. After obtaining the authorization to access the resources owned by the resource owner of the service API, the resources provided by the resource owner through the service API can be accessed; after obtaining the service API authorization, the authorized service API can be called; and after obtaining the access token, a northbound API request can be initiated to an AEF (API Exposing Function) by carrying the access token.

[0145] The first request message can include, but is not limited to, at least one of the following information:

[0146] API invoker identifier, resource owner identifier, service API information, and resource information.

[0147] The API caller identifier can be used to determine the API caller initiating the first request message, and the resource owner identifier can be used to determine the owner of the resource requested by the API caller. The service API information and / or resource information indicates that the requested service API includes obtaining the resource of a specific service-related resource owner or performing a specific operation on the resource of a specific service-related resource owner. The service API information and / or resource information includes at least one of the following information:

[0148] A parameter or string used to identify the resource owner resource accessed by the API caller;

[0149] A parameter or string used to describe the resource owner resource accessed by the API caller;

[0150] A parameter or string used to name the resource owner resource accessed by the API caller;

[0151] Resource identifier, resource name, resource operation identifier, resource operation name, resource operation description, resource processing purpose, and resource processing description.

[0152] Step 302, determining whether the API caller is authorized to access the resource owner resource;

[0153] In the embodiments of the present application, authorized can also be replaced by allowed or permitted. In the embodiments of the present application, authorized can also be replaced by allowed or permitted. In the following, it will not be explained one by one. The first network function manages resource owner authorization information of different resource owners in the embodiments of the present application. The first network function determines whether the API caller is authorized / allowed / permitted to access the resource owner resource based on the resource owner authorization information. The resource owner authorization information is stored in the first network function. Therefore, when the first network function performs resource owner authorization / allowance / permission check, the stored resource owner authorization information is directly obtained. Alternatively, the resource owner authorization information is obtained by the first network function from the resource owner through a secure interface. The resource owner can send the resource owner authorization information based on the request of the first network function or actively. When there is new resource owner authorization information or the resource owner authorization information is updated, the resource owner actively sends the resource owner authorization information.

[0154] The resource owner authorization information is a set of information indicating whether the API caller is authorized to access a specific resource or resources of the resource owner.

[0155] Before the first network function interacts with the resource owner, a secure interface has been established between them, and bidirectional authentication and data transmission protection such as confidentiality, integrity, and anti-replay protection are realized based on the secure interface. The secure interface can be TLS protection at the transport layer or IPSec protection at the network layer.

[0156] The resource owner authorization information includes at least one of the following information:

[0157] Resource information, specifically, information related to the resource, including specific resource and related access information;

[0158] A description indicating whether to authorize, such as authorization or non-authorization of the request;

[0159] A description indicating whether to authorize the resource to be accessed, such as allowing access or not allowing access;

[0160] A description indicating whether to authorize the resource identified by the resource information to be accessed, such as allowing access + resource information identification or not allowing access + resource information identification;

[0161] A description indicating whether to authorize the resource identified by the resource information to perform a corresponding operation, such as authorization or non-authorization of the operation + resource information identification.

[0162] Based on the resource owner authorization information, it is determined whether the API caller is authorized to access the resource owner's resource, which can be matching the authorization requested by the first request message with the resource owner authorization information, and determining whether the API caller is authorized to access the resource owner's resource according to the matching result.

[0163] In some possible embodiments, the resource information in the resource owner authorization information includes at least one of the following information: a parameter or a string for identifying the resource owner resource requested to be accessed by the API caller; a parameter or a string for describing the resource owner resource requested to be accessed by the API caller; a parameter or a string for naming the resource owner resource requested to be accessed by the API caller; resource identification, resource name, resource operation identification, resource operation name, resource operation description, resource processing purpose, and resource processing description. The first request message can request authorization of the corresponding resource and / or resource-related access through the above resource information.

[0164] The resource operation description may, for example, be open positioning information.

[0165] The description indicating whether to authorize the resource identified by the resource information to be accessed represents allowing or not allowing "resource information identification + allowing access / not allowing access", for example, allowing or not allowing the resource information identification corresponding resource (such as positioning information) to be accessed by other API callers.

[0166] In some possible embodiments, the resource owner authorization information further includes at least one of the following:

[0167] a description indicating whether to authorize under certain conditions, such as certain conditions + allow or not allow;

[0168] a description indicating whether to authorize the resource to be acquired under certain conditions, such as certain conditions + allow acquisition or not allow acquisition;

[0169] a description indicating whether to authorize the resource identified by the resource information to be acquired under certain conditions, such as certain conditions + allow acquisition + resource information identifier, or certain conditions + not allow acquisition + resource information identifier;

[0170] a description indicating whether to authorize the resource identified by the resource information to perform a corresponding operation under certain conditions, such as certain conditions + authorize / allow / permit operation + resource information identifier, or certain conditions + not authorize / allow / permit operation + resource information identifier;

[0171] a validity period;

[0172] The above-mentioned certain conditions in the embodiments of the application are a limitation on the API caller and / or API call request range, that is, the API caller and / or API call request range meeting the certain conditions are allowed or not allowed to perform a certain operation / process on the resource. The above-mentioned certain conditions include at least one of the following:

[0173] a limitation on the API caller, that is, the API caller needs to meet the relevant limitation, and the relevant limitation can be defined from various aspects;

[0174] a limitation on the API caller identifier, that is, the API caller identifier needs to be a limited identifier;

[0175] a limitation on the group or organization to which the API caller belongs, that is, the group or organization to which the API caller belongs needs to meet the relevant limitation, and the relevant limitation can be defined from various aspects;

[0176] a limitation on the geographic location where the API caller is located, that is, the geographic location where the API caller is located needs to be a limited geographic location;

[0177] a limitation on the access network to which the API caller belongs, that is, the access network to which the API caller belongs needs to be a limited network;

[0178] a limitation on the service API access range, that is, the API caller access range needs to be a limited range.

[0179] The above-mentioned description indicating whether to authorize the resource identified by the resource information to be acquired under certain conditions is embodied as "allow or not allow acquisition + resource information identifier" under certain conditions, for example, allowing or not allowing to open the positioning information of the resource corresponding to the resource information identifier under certain conditions

[0180] The following gives the content of the resource owner authorization information for resource A.

[0181] For resource A, the authorization information at least includes:

[0182] Resource information, at least including one of resource identification, resource name, resource operation identification, resource operation name, resource operation description, resource processing purpose, resource processing description, etc.

[0183] An indication of whether the resource information is authorized;

[0184] An indication of whether the resource identified by the resource information is authorized to be accessed;

[0185] An indication of whether the resource identified by the resource information is authorized to be executed with the corresponding operation, specifically including allowing or not allowing "resource A + resource operation identification / resource operation name / resource operation description / resource processing purpose / resource processing description", for example, allowing or not allowing resource A (location information) to be acquired by other API callers.

[0186] Optionally, it can include allowing or not allowing "resource A + resource operation identification / resource operation name / resource operation description / resource processing purpose / resource processing description" under certain conditions, for example, allowing or not allowing the open location information of resource A under certain conditions. The above-mentioned specific conditions are described in the above-mentioned embodiments, which will not be repeated here.

[0187] Step 303, sending a first response message to the API caller;

[0188] The first response message is used to indicate whether the resource owner authorizes the request of the first request message, and the above-mentioned authorization can also be understood as allowing or permitting.

[0189] The first response message is directly sent to the API caller, or the first response message is indirectly sent to the API caller through an agent. The first network function directly sends the first response message to the API caller, and sends the first response message to the API caller based on a pre-established security interface; the first network function indirectly sends to the API caller through an agent, and sends the first response message to the API caller based on the security interface between the agent and the first network function. The security interface can be TLS protection at the transport layer, or IPSec protection at the network layer.

[0190] The first network function in the embodiments of the present application retrieves corresponding resource information and / or authorization information in the resource owner authorization information based on the service API information and / or resource information and the resource owner identifier in the first request message, and determines whether the API invoker is authorized to access the target resource of the target resource owner. The first network function sends a first response message to the API invoker, and the first response message contains the authorization confirmation result explicitly or implicitly. If the first request message is a service API authorization request for accessing the northbound API perceived by the resource owner, the first response message contains an authorization code or an access token when the request authorization of the first request message is requested, and if the first request message is an access token request for accessing the northbound API perceived by the resource owner, the first response message contains an access token when the request authorization of the first request message is requested.

[0191] The resource owner perceived northbound API access authorization method provided by the embodiments of the present application further includes: the first network function acquires resource owner authorization information according to information included in the first request message, which can be but is not limited to resource owner identifier and / or resource information. After receiving the first request message of the API invoker, the first network function decides to retrieve corresponding resource information and / or authorization information in the resource owner authorization information; the CAPIF-8 reference point is used to manage the resource owner authorization information, and the first response message is returned to the API invoker by confirming whether the API invoker is authorized to access the resource of the resource owner based on the result of the resource owner authorization information.

[0192] The embodiments of the present application manage the resource owner authorization information by the first network function, and perform resource owner authorization / permission / permission check based on the resource owner authorization information, thereby improving the efficiency of the resource owner perceived northbound API invoker authorization through the centralized information advantage, and protecting the privacy and security of the resource owner.

[0193] The resource owner perceived northbound API access authorization method provided by the embodiments of the present application can be but is not limited to applied to the following application scenarios:

[0194] In the 5G C-V2X (5th generation promotion group cellular vehicle connection) use case and scenario, specifically for vehicle health monitoring in fleet management, an application client on UE 1 can send a first request message to obtain the location and / or vehicle health problem of another user UE 2;

[0195] In the 5G ranging, unmanned aerial vehicle (UAV) and other scenarios, such as a certain UE needs to obtain the two-dimensional, three-dimensional positioning information, speed information and the like of another UE in the network through the RAN A architecture;

[0196] Low-altitude economy application scenarios.

[0197] In some possible embodiments, the service API information and / or the resource information in the first request message described above have a corresponding relationship with the resource information in the resource owner authorization information.

[0198] The service API information and / or the resource information carried in the first request message described above represent description information of a request to invoke a resource, and the resource owner authorization information should include description information of whether the API invoker is authorized to access the target resource of the target resource owner, in order to match successfully when performing the resource owner authorization / permission / permission check based on the resource owner authorization information. The two descriptions should adopt a consistent content format and content definition manner and belong to the same granularity description, so as to support the first network function to make an accurate judgment.

[0199] In some possible embodiments, the first request message indicates whether the API invoker requests to access the resource of another resource owner. The first network function determines whether the API invoker is authorized to access the resource of the resource owner, including: determining whether the API invoker requests to access the resource of another resource owner according to the API invoker identifier and the resource owner identifier in the first request message, and if it is determined that the API invoker requests to access the resource of another resource owner, determining whether the API invoker is authorized to access the resource of the resource owner; the other resource owner is a resource owner other than a terminal where the API invoker is deployed.

[0200] In the embodiments of the present application, if the first network function determines that the API invoker is requesting to access the resource of another or more resource owners (users), it is determined whether the API invoker is authorized to access the resource of the resource owner. Based on the first request message, it is determined whether the API invoker (UE) requests to access the resource of another or more resource owners (users) to judge whether to perform resource owner authorization information retrieval, and then determine whether the API invoker is authorized to access the resource of the resource owner. Thus, the capability opening security of the scenario that the API invoker accesses the resource of other resource owners is supported.

[0201] When it is determined based on the first request message that the API invoker requests to access the resource of another or more resource owners, the resource owner authorization information stored in the first network function is obtained based on the resource owner identifier in the first request message, so as to determine whether to agree with the authorization requested by the first request message by using the obtained resource owner authorization information. The resource owner authorization information is stored in the first network function, and in one possible case, the resource owner authorization information is stored in an authentication AU (Authentication) function in the CCF of the first network function.

[0202] In some possible embodiments, determining whether the API invoker is authorized to access the resource owner's resources comprises:

[0203] According to the first request message, when it is determined that the request includes authorization of one or more target resources, resource owner authorization information corresponding to each target resource is obtained;

[0204] Based on the resource owner authorization information corresponding to each target resource, it is determined whether the API invoker is authorized to access the resource owner's resources.

[0205] In the embodiments of the present application, if the first request message involves accessing multiple resources of a resource owner, the first network function (CCF) obtains multiple resource authorization information of the resource owner to perform resource owner authorization / permission / permission check. Wherein, AUF (Authentication Function) is a part of the first network function, which receives and manages the resource owner authorization information of the resource owner through the CAPIF-8 reference point.

[0206] In the embodiments of the present application, the first network function obtains the resource owner authorization information stored in the authorization function (AUF) based on the resource owner identifier in the first request message, and determines whether to agree to the authorization requested by the first request message. If the first request message involves accessing multiple resources of a resource owner, the first network function (AUF) obtains multiple resource authorization information of the resource owner to perform authorization / permission / permission check. By centralizing the information advantage of the first network function, the efficiency of the northbound API call authorization perceived by the resource owner is improved, while the privacy and security of the resource owner are protected.

[0207] In some possible embodiments, the above-mentioned method provided by the embodiments of the present application further comprises: receiving a resource owner authorization revocation request message sent by a resource owner, triggering the execution of an authorization revocation process.

[0208] The first network function (AUF) receives a resource owner authorization revocation request message from a resource owner through the CAPIF-8 reference point, and triggers the execution of an authorization revocation process according to the resource owner authorization revocation request message.

[0209] The authorization revocation process is a service API authorization revocation process or an API invoker authorization revocation process. Through the service API authorization revocation process, the API invoker is not authorized to call the related service API. Through the API invoker authorization process, the authorization of the corresponding API invoker is revoked, and the corresponding API invoker no longer has the authorization requested by the first request message.

[0210] In some possible embodiments, the method further includes: receiving a resource owner authorization revocation request message sent by the resource owner, sending a resource owner authorization revocation response message to the resource owner, and performing an authorization revocation process, specifically, sending the resource owner authorization revocation response message to the resource owner through the CAPIF-8 reference point.

[0211] To obtain the change or revocation of the above resource owner authorization information, the following methods can be used:

[0212] receiving a resource access authorization change or revocation message sent by the resource owner through a secure interface, wherein the resource owner notifies the first network function through a message when determining that the access authorization of certain resources changes or is revoked;

[0213] or receiving a resource access consent change or revocation message sent by the resource owner through a secure interface, wherein the resource owner notifies the first network function through a message when determining that the access consent of certain resources changes or is revoked;

[0214] or receiving a resource owner authorization change or revocation message sent by the resource owner through a secure interface, wherein the resource owner notifies the first network function through a message when determining that the result of the authorization of the first request message changes or is revoked.

[0215] In the embodiments of the application, the first network function (AUF) receives a resource access authorization change or revocation message sent by the resource owner through a secure interface from the resource owner through the CAPIF-8 reference point, or receives a resource access consent change or revocation message sent by the resource owner through a secure interface, or receives a resource owner authorization change or revocation message sent by the resource owner through a secure interface, and decides whether to trigger the execution of the authorization revocation process. In some possible embodiments, before triggering the execution of the service API authorization revocation process, the method further includes: receiving a resource owner authorization revocation request message sent by the resource owner, and determining the target API invoker identifier and / or the target service API information associated with the revocation authorization operation. Specifically, based on the change or revocation of the resource owner authorization information, the target API invoker identifier and / or the target service API information associated with the revocation authorization operation can be determined. Based on the above description of the content of the resource owner authorization information and the content of the change, the API invoker associated with the revocation operation and / or the service API information can be determined. Or, based on the change or revocation of the resource owner authorization information and the authorization information of the API invoker, the target API invoker identifier and / or the target service API information associated with the revocation authorization operation are determined. The first network function initiates the related service API authorization revocation process after determining that the resource owner authorization information changes, which can prevent the resources of the resource owner from being accessed without authorization.

[0216] In some possible embodiments, the method provided by the embodiments of the present application further includes: sending an authorization revocation request message to a third network function; the third network function is an API exposure function (AEF) or a capability exposure function. The authorization revocation request message includes at least one of the following information: API invoker identification, resource owner identification, service API information, resource information, access token, and reason explanation. In this way, after receiving the authorization revocation request message, the third network function rejects the target API invoker to call the target service API resource when the target API invoker initiates a subsequent northbound API call request.

[0217] In some possible embodiments, the first response message includes at least one of the following information:

[0218] API invoker identification, resource owner identification, authorization code, access token, authorization scope, service API information, resource information, and validity period.

[0219] The service API information and the resource information are described above in the description of the service API information and the resource information in the first request message, and are not repeated here. The validity period described above is used to indicate the valid time of the API invoker to use the service API / resource information of the resource owner.

[0220] In the embodiments of the present application, the API invoker successfully completes the mutual authentication and the establishment of a secure session with the first network function before sending the first request message. If the API invoker is deployed on a UE, the first network function obtains the generic public subscription identifier (GPSI) of the API invoker in the authentication process, and if the API invoker identification is different from the GPSI of the API invoker, the mapping relationship information between the API invoker ID and the GPSI of the API invoker is stored.

[0221] The API invoker GPSI can include an external GPSI and an internal GPSI, and the API invoker ID and the API invoker GPSI can be in a one-to-one or many-to-one relationship.

[0222] The method provided by the embodiments of the present application further includes: obtaining the generic public subscription identifier (GPSI) of the API invoker; and if the API invoker identification is different from the GPSI of the API invoker, storing the mapping relationship between the API invoker identification and the GPSI of the API invoker.

[0223] In some possible embodiments, the first network entity determines the resource owner identity, determines whether the API invoker requests to access resources of other resource owners according to whether the resource owner identity is different from the API invoker identity. If the resource owner identity is the same as the API invoker identity, it is determined that resources of the self are requested, and if the resource owner identity is different from the API invoker identity, it is determined that resources of other resource owners are requested.

[0224] If the resource owner identity is a GPSI, it is determined whether the API invoker requests to access resources of other resource owners according to whether the GPSI mapped by the resource owner GPSI is different from the API invoker identity, if the GPSI mapped by the resource owner GPSI is the same as the API invoker identity, it is determined that resources of the self are requested, and if the GPSI mapped by the resource owner GPSI is different from the API invoker identity, it is determined that resources of other resource owners are requested.

[0225] In the embodiments of the present application, whether the API invoker is authorized to access the resources of the resource owner is determined, including:

[0226] According to the API invoker identity and the resource owner identity, it is determined that the API invoker and the resource owner belong to different domains, and the different domains can be different trust domains, API provider domains or capabilities provider domains. In actual deployment, it can also mean that the API invoker and the resource owner are respectively registered or contracted to different service capability / network capability exposure platforms, and the platforms belong to a same level relationship rather than a subordinate relationship.

[0227] According to the first request message, a second network function to which a domain to which the resource owner belongs is searched, and the second network function to which the domain to which the resource owner belongs is communicated, to determine whether the API invoker is authorized to access the resources of the resource owner.

[0228] The second network function can be a CAPIF core function, or an authorization function in the CAPIF core function, or an authorization server; the first network function and the API invoker belong to the same domain, and the API invoker is onboarded into the first network function. When the API invoker and the resource owner belong to the same domain, the first network function and the second network function are the same. When the API invoker and the resource owner belong to different domains, the first network function and the second network function also belong to different domains, and they are interconnected through a secure interface.

[0229] In implementation, the first network function of the API invoker performs resource owner authorization / permission / allowance check based on resource owner authorization information with the second network function of the domain to which the resource owner belongs through the CAPIF-6 / 6e reference point. The first network function of the API invoker finds the second network function of the domain to which the resource owner belongs according to the resource owner identifier in the first request message, for example, retrieves PLMN (Public Land Mobile Network) information based on GPSI.

[0230] In some possible embodiments, the first network function finds the second network function of the domain to which the corresponding resource owner belongs according to the first request message, communicates with the second network function of the domain to which the resource owner belongs, and determines whether the API invoker is authorized to access the resource of the resource owner, including:

[0231] The first network function forwards the first request message to the second network function of the domain to which the resource owner belongs based on the resource owner identifier in the first request message, receives the first request message by the second network function, and determines whether the API invoker is authorized to access the resource of the resource owner based on the resource owner authorization information;

[0232] The resource owner identifier contains routing information, such as a field or a string that identifies the domain to which it belongs; or the resource owner identifier itself is associated with different domains, and based on a preset rule, the domain to which the resource owner identifier belongs can be distinguished by determining the composition of the resource owner identifier, but the identifier itself does not explicitly define the routing information field.

[0233] Or the first network function forwards the first request message to a second network function of a domain to which the resource owner belongs based on routing information in the first request message, and the second network function receives the first request message and determines whether the API invoker is authorized to access the resource owner's resource based on the resource owner authorization information. The routing information can be an indicator or a parameter.

[0234] The second network function performs the determination of whether the API invoker is authorized to access the resource owner's resource in the manner described in the above embodiment of the first network function performing the resource owner consent authorization / grant / permission implementation, which will not be repeated here.

[0235] The second network function performs the determination of whether the API invoker is authorized to access the resource owner's resource in the manner described in the above embodiment of the first network function performing the resource owner consent authorization / grant / permission implementation, which will not be repeated here.

[0236] Based on the same inventive concept, the embodiments of the present application also provide a resource owner-aware northbound API access authorization method, which is applied to an API invoker, as shown in FIG. 4, and the method comprises the following steps:

[0237] Step 401: sending a first request message to a first network function;

[0238] Step 402: receiving a first response message returned by the first network function after determining whether the API invoker is authorized to access the resource owner's resource.

[0239] In some possible embodiments, the first request message is used to obtain authorization to access a resource owner's resource provided by a service API, or is used to obtain service API authorization, or is used to obtain an access token.

[0240] In some possible embodiments, the first request message is used to obtain authorization to access a resource owner's resource provided by a service API, or is used to obtain service API authorization, or is used to obtain an access token.

[0241] The service API information and / or resource information comprises at least one of the following information:

[0242] A parameter or a string used to identify the resource owner's resource requested to be accessed by the API invoker;

[0243] A parameter or a string used to describe the resource owner's resource requested to be accessed by the API invoker;

[0244] A parameter or a string used to name the resource owner's resource requested to be accessed by the API invoker;

[0245] Resource identifier, resource name, resource operation identifier, resource operation name, resource operation description, resource processing purpose, resource processing description.

[0246] In some possible embodiments, the method further includes:

[0247] When it is determined based on the first response message that the first request message is authorized to pass or that an access token is carried in the first response message, a service API invocation request is sent to a third network function, and the service API invocation request carries the access token.

[0248] In some possible embodiments, the service API invocation request is used to request access to resources of a resource owner provided through a service API.

[0249] The third network function described above can be, but is not limited to, an AEF. When the API invoker obtains authorization, the AEF initiates a service API invocation request to request access to resources of a resource owner.

[0250] The AEF verifies the service API invocation request and decides whether to trigger a resource owner authorization confirmation / checking process based on a policy (operator policy / service policy).

[0251] In some cases, the granularity of the authorization scope in the access token issued by the CCF is not enough, and the AEF cannot make an accurate judgment after receiving the resource access detailed request included in the service API invocation request, and therefore needs to trigger the resource owner authorization confirmation / checking process again.

[0252] The AEF forwards the service API invocation request to the CCF / AUF. The CCF / AUF confirms whether the service API invocation request meets the authorization requirement based on the locally stored resource owner authorization information, and returns an authorization confirmation / checking result to the AEF. Alternatively, the AEF forwards the service API invocation request to the CCF / AUF, and the CCF / AUF forwards the service API invocation request to the resource owner. The resource owner confirms whether the service API invocation request meets the authorization requirement based on the resource owner authorization information, and returns an authorization confirmation / checking result to the AEF through the CCF / AUF.

[0253] In some possible embodiments, the first response message includes at least one of the following information:

[0254] API invoker identifier, resource owner identifier, authorization code, access token, authorization scope, service API information, resource information, and validity period.

[0255] A detailed flowchart of the resource owner-aware northbound API access authorization method of the embodiments of the present application is given below, as shown in FIG. 5, and mainly includes the following steps:

[0256] Step 1, the API invoker successfully completes CAPIF 1e identity verification and security session establishment with the first network function.

[0257] If the API invoker is deployed on the UE, the first network function obtains the GPSI of the API invoker in the authentication process, and stores the mapping relationship information of the API invoker ID and the API invoker GPSI.

[0258] Step 2, the API invoker sends an access token request message based on Oauth 2.0 to the first network function, and the access token request message includes API invoker identification, resource owner identification, service API information, and resource information. For specific explanations, refer to the above embodiment description.

[0259] In the access token request message in this embodiment, the other information in addition to the API invoker identification and the resource owner identification is taken as the token scope of the request, which can specifically include:

[0260] Service API exposure function information, such as AEF identification;

[0261] Service API information, such as service API identification, name, and detailed description;

[0262] Resource information, such as service API involved resource identification, resource name, resource operation identification, resource operation name, resource operation description, resource processing purpose, and resource processing description.

[0263] In a specific capability exposure architecture, the resource information in the token declaration scope and the resource information in the resource owner authorization information adopt consistent format and content definition methods, so as to ensure that the first network function can accurately associate the access token request and the resource owner authorization information.

[0264] Step 3a, after receiving the access token request message, the first network function verifies the authenticity of the access token request message. The specific verification method can adopt the existing method, which will not be described here.

[0265] 3b. The first network function shall determine whether the API invoker (UE) requests access to the resource of another or multiple resource owners (users) based on the access token request message to decide whether to perform the resource owner authorization / permission / allowance check based on the resource owner authorization information. If the API invoker (UE) requests access to the resource of another or multiple resource owners (users), the first network function performs the resource owner authorization / permission / allowance check based on the resource owner authorization information. Based on the resource owner identification, the resource owner authorization information stored in the authorization function (AUF) is retrieved, the access token request message is matched with the resource owner authorization information, and it is determined whether the API invoker agrees to use the resource of the resource owner when the API invoker invokes the API service. If the access token request message involves access to multiple resources of a resource owner, the first network function (AUF) obtains the multiple resource authorization information of the resource owner to perform the authorization / permission / allowance check.

[0266] If the resource owner identification is a GPSI, the first network function shall check whether the GPSI associated with the API invoker identification is different from the resource owner identification to determine whether the API invoker (UE) is accessing the resource of other resource owners (users).

[0267] If the API invoker and the resource owner belong to different CAPIF providing domains, the first network function of the API invoker performs the resource owner authorization / permission / allowance check based on the resource owner authorization information with the second network function of the domain to which the resource owner belongs through the CAPIF-6 / 6e reference point.

[0268] Step 4, if the resource owner authorization / permission / allowance check passes, the first network function sends an Oauth 2.0 access token response message to the API invoker, and the access token response message token includes at least the API invoker identification, the resource owner identification, the service API information, the resource information, and the validity period.

[0269] Step 5, the API invoker establishes a TLS secure connection with the API exposure function (AEF);

[0270] Step 6, the API invoker sends an access resource owner-aware northbound API invocation request to the AEF, and the request includes an access token, which includes an authorization statement determined according to the result of the resource owner authorization / permission / allowance check, i.e., a statement of the resource of the resource owner that the API invoker can access when invoking the API service.

[0271] Step 7, the AEF shall handle the northbound API invocation request to access the resource owner resource, authorization / permission / allowance check based on the resource owner authorization information, including verifying the integrity of the access token, authorization claims in the access token, performing the northbound API request, wherein the access token in the northbound API invocation request is verified by verifying the first network function signature to check the integrity of the access token; the authorization claim verification is an optional step, which specifically includes:

[0272] Step 7a, the above access token should be able to limit the API invoker to access specific resources of the resource owner (such as location, QoS, PDN (Public Data NetWorks) connection status), and the AEF should verify the northbound API invocation request of the API invoker according to the authorization claims in the access token to ensure that the API invoker has access to the requested service API.

[0273] Step 7b, if the AEF confirms that the API invoker requests the resource owner to perceive the northbound API invocation to access the resources of other resource owners (users), the AEF should communicate with the first network function and perform resource owner authorization / permission / allowance check based on resource owner authorization information.

[0274] Specifically, the AEF should check whether the GSPI associated with the API invoker identity in the API invocation request is consistent with the resource owner identity in the access token, if not, it is considered that the access to the resources of other resource owners (users) is communicated with the first network function to perform resource owner authorization / permission / allowance check, which can be to obtain the resource owner authorization / permission / allowance check result from the first network function, or to send the first request message to the first network function, and return the check result after the first network function performs the resource owner authorization / permission / allowance check.

[0275] Step 7c, if the AEF successfully completes the authorization permission / allowance check of the API invocation request, the AEF can trigger the notification of the resource owner through the first network function.

[0276] Step 8, the AEF performs API invocation logic;

[0277] Step 9, the AEF returns the API invocation response to the API invoker.

[0278] The service API authorization revocation process triggered by the change of the resource owner authorization information is shown in Figure 6, which mainly includes:

[0279] Step 0, the resource owner has registered to the first network function, and provides its own resource owner authorization information to the first network function (AUF) through the secure connection of CAPIF-8 reference point, the first network function (AUF) locally stores and manages the resource owner information, including the resource owner authorization information.

[0280] In the CAPIF interconnection scenario, the second network function of the domain to which the resource owner belongs can also share the resource owner authorization information with the first network function of the API invoker.

[0281] Step 1, when the resource owner authorization information changes, the resource owner sends a resource owner authorization change / cancellation request message to the first network function (AUF), which can be a message to change or cancel resource access authorization, or a message to change or cancel resource access consent. After receiving the resource owner authorization change / cancellation request, the first network function (AUF) changes the locally stored resource owner authorization information according to the indication. The resource owner authorization change / cancellation request message should include the resource owner authorization change / cancellation indication, for example, indicating that the source authorization information of a certain resource is changed to the target authorization information.

[0282] Step 2, the first network function sends a resource owner authorization change / cancellation response message to the resource owner.

[0283] Step 3, the first network function should decide whether to perform the service API authorization cancellation process based on the change / cancellation of the resource owner authorization information, and decide which service API authorization of which API invoker needs to be cancelled.

[0284] The first network function determines the target API invoker identifier and / or target service API information associated with the revocation authorization operation based on the change of the resource owner authorization information; or determines the target API invoker identifier and / or target service API information associated with the revocation authorization operation based on the change of the resource owner authorization information and the authorization information of the API invoker (including the granted access token information).

[0285] In the resource owner-aware northbound interface invocation architecture, the access token granted by the first network function to the API invoker includes the declaration of allowing the API invoker to call a specific service API to obtain a specific resource of a specific resource owner.

[0286] Step 4, according to the received resource owner authorization change / cancellation request message, the first network function sends an authorization cancellation request message to the AEF, including API invoker identifier, service API information, resource information, and revocation authorization reason description, for example, the change of the resource owner authorization.

[0287] The resource information involved in revoking the authorization can be provided as a separate parameter, or can exist as specific content in the service API information or revocation of authorization reason description.

[0288] Step 5, after receiving the authorization revocation request message, the AEF revokes the API invoker authorization corresponding to the service API and the resource.

[0289] Step 6, the AEF sends a service API authorization revocation response message to the first network function.

[0290] Step 7, the first network function revokes the API invoker authorization corresponding to the service API and the resource, thereby invalidating the authorization of the API invoker to the service API and the resource.

[0291] Step 8, the first network function sends a service API authorization revocation notification to the API invoker that accesses the service API and the resource whose authorization has been revoked.

[0292] Based on the same inventive concept, the embodiments of the present application provide a resource owner-aware northbound API access authorization device, as shown in FIG. 7, which comprises:

[0293] The request receiving module 701 is configured to receive a first request message sent by an API invoker;

[0294] The authorization checking module 702 is configured to determine whether the API invoker is authorized to access the resource owner's resource;

[0295] The response sending module 703 is configured to send a first response message to the API invoker.

[0296] In some possible embodiments, the first request message is used to obtain authorization to access the resource owner's resource provided by a service API, or is used to obtain service API authorization, or is used to obtain an access token.

[0297] In some possible embodiments, the authorization checking module determines whether the API invoker is authorized to access the resource owner's resource based on resource owner authorization information;

[0298] The resource owner authorization information is stored in the first network function;

[0299] Or the resource owner authorization information is obtained by the first network function from the resource owner through a secure interface.

[0300] In some possible embodiments, the resource owner authorization information is a set of information indicating whether the API invoker is authorized to access a specific one or more resources of the resource owner.

[0301] In some possible embodiments, the first request message comprises at least one of the following information:

[0302] API invoker identification, resource owner identification, service API information, resource information.

[0303] In some possible embodiments, the service API information and / or resource information comprises at least one of the following information:

[0304] a parameter or a string for identifying a resource owner resource that the API invoker requests to access;

[0305] a parameter or a string for describing a resource owner resource that the API invoker requests to access;

[0306] a parameter or a string for naming a resource owner resource that the API invoker requests to access;

[0307] resource identification, resource name, resource operation identification, resource operation name, resource operation description, resource processing purpose, resource processing description.

[0308] In some possible embodiments, the authorization checking module is further configured to acquire resource owner authorization information according to the information comprised in the first request message.

[0309] In some possible embodiments, the first request message is sent directly by the API invoker; or

[0310] the first request message is sent indirectly by the API invoker through a proxy;

[0311] the first response message is sent directly to the API invoker, or

[0312] the first response message is sent indirectly to the API invoker through a proxy.

[0313] In some possible embodiments, the resource owner authorization information comprises at least one of the following information:

[0314] resource information;

[0315] a description indicating whether to authorize;

[0316] a description indicating whether to authorize a resource to be accessed;

[0317] a description indicating whether to authorize a resource identified by the resource information to be accessed;

[0318] a description indicating whether to authorize a resource identified by the resource information to be performed with a corresponding operation.

[0319] In some possible embodiments, the resource owner authorization information further comprises at least one of:

[0320] a description indicating whether to authorize under certain conditions;

[0321] a description indicating whether to authorize the resource to be acquired under certain conditions;

[0322] a description indicating whether to authorize the resource identified by the resource information to be acquired under certain conditions;

[0323] a description indicating whether to authorize the resource identified by the resource information to perform a corresponding operation under certain conditions;

[0324] a validity period.

[0325] In some possible embodiments, the certain conditions comprise at least one of:

[0326] a limitation on an API invoker;

[0327] a limitation on an API invoker identifier;

[0328] a limitation on a group or organization to which an API invoker belongs;

[0329] a limitation on a geographic location where an API invoker is located;

[0330] a limitation on an access network to which an API invoker belongs;

[0331] a limitation on a service API access range.

[0332] In some possible embodiments, the resource information in the resource owner authorization information comprises at least one of the following information:

[0333] a parameter or a string for identifying a resource owner resource requested to be accessed by an API invoker;

[0334] a parameter or a string for describing a resource owner resource requested to be accessed by an API invoker;

[0335] a parameter or a string for naming a resource owner resource requested to be accessed by an API invoker;

[0336] a resource identifier, a resource name, a resource operation identifier, a resource operation name, a resource operation description, a resource processing purpose, and a resource processing description.

[0337] In some possible embodiments, the authorization checking module retrieves corresponding resource information and / or authorization information in the resource owner authorization information based on the service API information and / or the resource information in the first request message and the resource owner identifier.

[0338] In some possible embodiments, the first response message comprises at least one of the following information:

[0339] API invoker identity, resource owner identity, authorization code, access token, authorization scope, service API information, resource information, validity period.

[0340] In some possible embodiments, the first request message indicates whether the API invoker requests to access resources of other resource owners.

[0341] In some possible embodiments, the authorization checking module determines whether the API invoker is authorized to access the resources of the resource owner, comprising:

[0342] According to the API invoker identity and the resource owner identity in the first request message, it is determined whether to request to access resources of other resource owners.

[0343] In some possible embodiments, the authorization checking module determines whether the API invoker is authorized to access the resources of the resource owner, comprising:

[0344] According to the first request message, when it is determined that the request comprises authorization of one or more target resources, the resource owner authorization information corresponding to each target resource is obtained;

[0345] Based on the resource owner authorization information corresponding to each target resource, it is determined whether the API invoker is authorized to access the resources of the resource owner.

[0346] In some possible embodiments, further comprising:

[0347] The authorization revocation module is configured to receive a resource owner authorization revocation request message sent by the resource owner, and trigger execution of an authorization revocation process.

[0348] In some possible embodiments, the authorization revocation module is further configured to receive a resource owner authorization revocation request message sent by the resource owner, send a resource owner authorization revocation response message to the resource owner, and execute the authorization revocation process.

[0349] In some possible embodiments, the authorization revocation process is a service API authorization revocation process or an API invoker authorization revocation process.

[0350] In some possible embodiments, the authorization revocation module is further configured to receive a resource access authorization change or revocation message sent by the resource owner through a secure interface;

[0351] or receive a resource access consent change or revocation message sent by the resource owner through a secure interface;

[0352] or receiving a resource owner authorization change or revocation message sent by the resource owner through the secure interface.

[0353] In some possible embodiments, before triggering the service API authorization revocation procedure, the authorization revocation module further comprises:

[0354] receiving a resource owner authorization revocation request message sent by the resource owner, and determining the target API invoker identifier and / or the target service API information associated with the revocation authorization operation.

[0355] In some possible embodiments, the authorization revocation module

[0356] In some possible embodiments, before triggering the service API authorization revocation procedure, the authorization revocation module further comprises:

[0357] sending an authorization revocation request message to a third network function;

[0358] The authorization revocation request message comprises at least one of the following information: API invoker identifier, resource owner identifier, service API information, resource information, access token, and reason.

[0359] In some possible embodiments, the authorization check module is further configured to determine the resource owner identifier, and determine whether the API invoker requests to access resources of other resource owners according to whether the resource owner identifier is different from the API invoker identifier.

[0360] In some possible embodiments, the authorization check module is further configured to determine whether the API invoker requests to access resources of other resource owners according to whether the GPSI of the resource owner is different from the GPSI mapped by the API invoker identifier.

[0361] In some possible embodiments, the authorization check module determines whether the API invoker is authorized to access resources of the resource owner, comprising:

[0362] determining that the API invoker and the resource owner belong to different domains according to the API invoker identifier and the resource owner identifier;

[0363] According to the first request message, the second network function corresponding to the domain to which the resource owner belongs is found, and the second network function in the domain to which the resource owner belongs is communicated to determine whether the API invoker is authorized to access resources of the resource owner.

[0364] In some possible embodiments, the authorization check module is further configured to determine whether the API invoker is authorized to access resources of the resource owner according to the first request message, find a second network function corresponding to a domain to which the resource owner belongs, and communicate with the second network function in the domain to which the resource owner belongs.

[0365] The first network function forwards the first request message to a second network function of a domain to which the resource owner belongs based on a resource owner identifier in the first request message, receives the first request message by the second network function, and determines whether the API invoker is authorized to access the resource owner's resource based on the resource owner authorization information;

[0366] Or the first network function forwards the first request message to a second network function of a domain to which the resource owner belongs based on routing information in the first request message, receives the first request message by the second network function, and determines whether the API invoker is authorized to access the resource owner's resource based on the resource owner authorization information;

[0367] Receiving a second response message returned by the second network function.

[0368] Based on the same inventive concept, an embodiment of the present application provides a resource owner-aware northbound API access authorization apparatus, as shown in FIG. 8, which comprises:

[0369] The request sending module 801 is configured to send a first request message to a first network function;

[0370] The response receiving module 802 is configured to receive a first response message returned by the first network function after determining whether the API invoker is authorized to access the resource owner's resource.

[0371] In some possible embodiments, the apparatus further comprises:

[0372] The API invoker request module is configured to send a service API invoker request to the AEF based on the first response message determining that the authorization request is passed, or the first response message carrying an access token, and the service API invoker request carries the access token.

[0373] In some possible embodiments, the first request message is used to obtain authorization to access a resource owner's resource provided by a service API, or to obtain service API authorization, or to obtain an access token.

[0374] In some possible embodiments, the first request message is used to obtain authorization to access a resource owner's resource provided by a service API, or to obtain service API authorization, or to obtain an access token.

[0375] In some possible embodiments, the service API information and / or resource information comprises at least one of the following information:

[0376] A parameter or a string used to identify a resource owner's resource requested to be accessed by the API invoker;

[0377] a parameter or a string used to describe a resource owner resource that an API invoker requests to access;

[0378] a parameter or a string used to name a resource owner resource that an API invoker requests to access;

[0379] a resource identifier, a resource name, a resource operation identifier, a resource operation name, a resource operation description, a resource processing purpose, and a resource processing description.

[0380] In some possible embodiments, the resource owner aware northbound API access authorization device further comprises:

[0381] a request forwarding module, configured to determine, based on the first response message, that the first request message is authorized to pass through, or that the access token is carried in the first response message, and send a service API invocation request to a third network function, the service API invocation request carrying the access token.

[0382] In some possible embodiments, the service API invocation request is used to request access to a resource owner resource provided by a service API.

[0383] In some possible embodiments, the first response message comprises at least one of the following information:

[0384] an API invoker identifier, a resource owner identifier, an authorization code, an access token, an authorization scope, service API information, resource information, and a validity period.

[0385] The resource owner aware northbound API access authorization device 190 according to this implementation of the present application will be described below with reference to FIG. 9. FIG. 9 shows only one example of the resource owner aware northbound API access authorization device 190, and should not be taken to limit the function and scope of use of the embodiments of the present application.

[0386] As shown in FIG. 9, the resource owner aware northbound API access authorization device 190 is in the form of a general electronic device. The components of the resource owner aware northbound API access authorization device 190 can include, but are not limited to, the at least one processor 191, the at least one memory 192, and the bus 193 connecting different system components, including the memory 192 and the processor 191. The memory 192 stores instructions executable by the processor 191, and the instructions are executed by the processor 191 to enable the processor 191 to perform any resource owner aware northbound API access authorization provided by the above-described embodiments.

[0387] Bus 193 generally represents what in the art more generally can be referred to as an interconnection medium or bus structure. As shown in FIG. 9, one possible configuration of bus 193 is bus 193 is represented as including a memory bus or memory controller, a peripheral bus, an external bus, and / or a local bus using any of a variety of bus architectures.

[0388] Memory 192 can include a read-only memory (ROM) 1923 in the form of flash memory or other suitable technology, and a random access memory (RAM) 1921, which can include one or more levels of cache memory 1922.

[0389] Memory 192 can also include a program / utility 1925 having a set (at least one) of program modules 1924, including an operating system, one or more application programs, other program modules, and program data, each of which can generally be embodied on any suitable computer readable medium and made available to computer system 190 through appropriate means, such as storage or download. Thus, resource owner aware northbound API access authorization device 190 can be a general purpose computing device with or without special capabilities.

[0390] Resource owner aware northbound API access authorization device 190 can also communicate with one or more external devices 194 such as a keyboard or pointing device, through an input / output (I / O) interface(s) 195. Note that other implementations can include other peripheral devices and / or interfaces not shown in FIG. 9. Resource owner aware northbound API access authorization device 190 can also communicate with one or more devices or devices that enable a user to interact with resource owner aware northbound API access authorization device 190, and / or one or more devices (e.g., a router, a modem, a server, etc.) that enable resource owner aware northbound API access authorization device 190 to communicate with one or more other electronic devices. For example, resource owner aware northbound API access authorization device 190 can communicate with an audio device, a video device, a display screen, a keypad, a speaker, a microphone, etc. Such communication can occur via input / output (I / O) interface(s) 195. Still yet, resource owner aware northbound API access authorization device 190 can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or the Internet, through a network adapter 196. As depicted, network adapter 196 communicates with the other components of resource owner aware northbound API access authorization device 190 via bus 193. It should be understood that although not shown, other hardware and / or software components that can be used in conjunction with resource owner aware northbound API access authorization device 190 can include, but are not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.

[0391] In some possible embodiments, various aspects of a resource owner aware northbound API access authorization method provided by the present application can also be implemented as a program product including a program code, which, when run on a computer device, causes the computer device to execute steps of a resource owner aware northbound API access authorization method according to various exemplary embodiments of the present application described above in the specification.

[0392] The program product of the embodiments of the present application for resource owner-aware northbound API access authorization can employ a portable compact disc read-only memory (CD-ROM) and include a program code, and can be run on an electronic device. However, the program product of the present application is not limited thereto, and in the present document, a readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus or device.

[0393] The program product of the embodiments of the present application for resource owner-aware northbound API access authorization can employ a portable compact disc read-only memory (CD-ROM) and include a program code, and can be run on an electronic device. However, the program product of the present application is not limited thereto, and in the present document, a readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus or device.

[0394] The readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, in which a readable program code is carried. Such a propagated data signal can take multiple forms, including but not limited to electro-magnetic, optical, or any suitable combination thereof. The readable signal medium can also be any readable medium that can send, propagate or transfer a program for use by or in connection with an instruction execution system, apparatus or device.

[0395] The program code contained in the readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0396] The program code may, through the use of program components, be implemented in any of various ways, including procedure-based execution, object-oriented execution, and / or virtual machine-based execution. A program component or other component may, for example, be implemented in hardware or software in combination with off-the-shelf components, or custom components. Additionally or alternatively, the program code may be implemented in transitory or non-transitory forms.

[0397] It should be noted that, although the above detailed description refers to several units or sub-units of the apparatus, such a division is merely exemplary and not mandatory. Indeed, according to an embodiment of the application, the features and functionalities of two or more units described above can be embodied in one unit. Conversely, the features and functionalities of one unit described above can be further divided into several units embodied by several units.

[0398] Moreover, while operations of the methods of the present application are described in a particular order in the figures, this is not required or implied in any particular order for performing the operations to achieve the desired results. Additionally or alternatively, certain steps can be omitted, combined into fewer steps, and / or separated into additional steps.

[0399] Those skilled in the art will appreciate that embodiments of the present application can be devised for a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer readable program code.

[0400] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks.

[0401] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks.

[0402] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks.

[0403] While the preferred embodiments of the application have been described, it should be apparent that various modifications, adaptations and variations of these embodiments can be made and will be apparent to those skilled in the relevant arts in light of the foregoing description. Accordingly, the appended claims are intended to cover all adaptations and modifications as would be expected by those in the art. While the preferred embodiments have been described above, it should be understood that they have been presented by way of example only, and not limitation. Numerous changes to the embodiments can be made in accordance with the disclosure herein without departing from the spirit or scope of the application. Other aspects, features, and advantages of the application are apparent from the above disclosure.

[0404] Obviously, many modifications and variations of this application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.

Claims

1. A resource owner-aware northbound API access authorization method, the method is applied to a first network function, characterized in that, The method comprises: receiving a first request message sent by an API invoker; determining whether the API invoker is authorized to access a resource of a resource owner; sending a first response message to the API invoker.

2. The method of claim 1, wherein: the first request message is for obtaining authorization to access a resource of a resource owner provided by a service API, or for obtaining service API authorization, or for obtaining an access token.

3. The method of claim 1, wherein, determining whether the API invoker is authorized to access the resource of the resource owner comprises: based on resource owner authorization information, determining whether the API invoker is authorized to access the resource of the resource owner; the resource owner authorization information is stored in a first network function; or the resource owner authorization information is obtained by the first network function from the resource owner through a secure interface.

4. The method of claim 3, wherein: the resource owner authorization information is a set of information indicating whether the API invoker is authorized to access a specific one or more resources of the resource owner.

5. The method of claim 1, wherein, the first request message comprises at least one of the following information: API invoker identification, resource owner identification, service API information, resource information.

6. The method of claim 5, wherein, the service API information and / or resource information comprises at least one of the following information: a parameter or a string for identifying the resource of the resource owner that the API invoker requests to access; a parameter or a string for describing the resource of the resource owner that the API invoker requests to access; a parameter or a string for naming the resource of the resource owner that the API invoker requests to access; resource identification, resource name, resource operation identification, resource operation name, resource operation description, resource processing purpose, resource processing description.

7. The method of claim 5, wherein, further comprising: obtaining the resource owner authorization information according to the information included in the first request message.

8. The method of claim 1, wherein: the first request message is sent directly by the API invoker; or the first request message is indirectly sent by the API invoker through a proxy; the first response message is sent directly to the API invoker, or the first response message is indirectly sent to the API invoker through a proxy.

9. The method according to claim 3 or 4 or 7, characterized in that, the resource owner authorization information comprises at least one of the following information: resource information; a description indicating whether authorization is granted; a description indicating whether the resource is authorized to be accessed; a description indicating whether the resource identified by the resource information is authorized to be accessed; a description indicating whether the resource identified by the resource information is authorized to be performed with a corresponding operation.

10. The method of claim 9, wherein, the resource owner authorization information further comprises at least one of the following: a description indicating whether authorization is granted under certain conditions; a description indicating whether the resource is authorized to be obtained under certain conditions; a description indicating whether the resource identified by the resource information is authorized to be obtained under certain conditions; a description indicating whether the resource identified by the resource information is authorized to be performed with a corresponding operation under certain conditions; a validity period.

11. The method of claim 10, wherein, the certain conditions comprise at least one of the following: a limitation on the API invoker; a limitation on the API invoker identification; a limitation on the group or organization to which the API invoker belongs. a limitation on a geographical location where the API invoker is located; a limitation on an access network where the API invoker is located; a limitation on a service API access scope.

12. The method of claim 9, wherein, The resource information in the resource owner authorization information comprises at least one of the following: a parameter or a string used for identifying a resource owner resource requested to be accessed by the API invoker; a parameter or a string used for describing a resource owner resource requested to be accessed by the API invoker; a parameter or a string used for naming a resource owner resource requested to be accessed by the API invoker. a resource identifier, a resource name, a resource operation identifier, a resource operation name, a resource operation description, a resource processing purpose, and a resource processing description.

13. The method of claim 9, wherein, The first network function retrieves corresponding resource information and / or authorization information in the resource owner authorization information based on the service API information and / or the resource information in the first request message and the resource owner identifier.

14. The method of claim 1, wherein, The first response message comprises at least one of the following: an API invoker identifier, a resource owner identifier, an authorization code, an access token, an authorization scope, service API information, resource information, and a validity period.

15. The method of claim 1, wherein, The first request message indicates whether the API invoker requests to access resources of other resource owners.

16. The method of claim 1, wherein, Determining whether the API invoker is authorized to access the resource owner's resources comprises: determining whether the API invoker requests to access resources of other resource owners according to the API invoker identifier and the resource owner identifier in the first request message.

17. The method of claim 1, wherein, Determining whether the API invoker is authorized to access the resource owner's resources comprises: when it is determined that the request comprises authorization of one or more target resources, obtaining resource owner authorization information corresponding to each target resource according to the first request message; and determining whether the API invoker is authorized to access the resource owner's resources based on the resource owner authorization information corresponding to each target resource.

18. The method of claim 1, wherein, Further comprising: receiving a resource owner authorization revocation request message sent by the resource owner, and triggering execution of an authorization revocation process.

19. The method of claim 18, wherein, Further comprising: receiving a resource owner authorization revocation request message sent by the resource owner, sending a resource owner authorization revocation response message to the resource owner, and executing an authorization revocation process.

20. The method of claim 18, wherein the authorization revocation process is a service API authorization revocation process or an API invoker authorization revocation process.

21. The method of claim 18, wherein, Further comprising: receiving a resource access authorization change or revocation message sent by the resource owner through a secure interface; or receiving a resource access consent change or revocation message sent by the resource owner through a secure interface; or receiving a resource owner authorization change or revocation message sent by the resource owner through a secure interface.

22. The method of claim 18, wherein, Before triggering execution of the service API authorization revocation process, further comprising: receiving a resource owner authorization revocation request message sent by the resource owner, and determining a target API invoker identifier and / or target service API information associated with the revocation authorization operation.

23. The method of claim 18, wherein, Triggering execution of the service API authorization revocation process further comprises: sending an authorization revocation request message to a third network function; The authorization revocation request message includes at least one of the following information: API caller identification, resource owner identification, service API information, resource information, access token, and reason.

24. The method of claim 5 or 16, wherein, Further comprising: Determining the resource owner identification, and determining whether the API caller requests to access resources of other resource owners according to whether the resource owner identification is different from the API caller identification.

25. The method of claim 24, wherein, Further comprising: Determining whether the API caller requests to access resources of other resource owners according to whether the GPSI of the resource owner is different from the GPSI mapped by the API caller identification.

26. The method of claim 5, wherein, Determining whether the API caller is authorized to access resources of the resource owner, comprising: Determining whether the API caller and the resource owner belong to different domains according to the API caller identification and the resource owner identification; According to the first request message, finding a second network function corresponding to the domain to which the resource owner belongs, communicating with the second network function of the domain to which the resource owner belongs, and determining whether the API caller is authorized to access resources of the resource owner.

27. The method of claim 26, wherein, According to the first request message, finding a second network function corresponding to the domain to which the resource owner belongs, communicating with the second network function of the domain to which the resource owner belongs, and determining whether the API caller is authorized to access resources of the resource owner, comprising: The first network function forwards the first request message to the second network function of the domain to which the resource owner belongs based on the resource owner identification in the first request message, and the second network function receives the first request message and determines whether the API caller is authorized to access resources of the resource owner based on the resource owner authorization information; Or the first network function forwards the first request message to the second network function of the domain to which the resource owner belongs based on the routing information in the first request message, and the second network function receives the first request message and determines whether the API caller is authorized to access resources of the resource owner based on the resource owner authorization information. Receiving a second response message returned by the second network function.

28. A resource owner-aware northbound API access authorization method, applied to an API invoker, characterized in that, The method comprises: Sending a first request message to a first network function; Receiving a first response message returned by the first network function after determining whether the API caller is authorized to access resources of the resource owner.

29. The method of claim 28, wherein: The first request message is used to obtain authorization to access resources of a resource owner provided by a service API, or is used to obtain service API authorization, or is used to obtain an access token.

30. The method of claim 28 or 29, wherein, The first request message is used to obtain authorization to access resources of a resource owner provided by a service API, or is used to obtain service API authorization, or is used to obtain an access token.

31. The method of claim 30, wherein, The service API information and / or resource information includes at least one of the following information: A parameter or a string used to identify the resource owner resource requested to be accessed by the API caller; A parameter or a string used to describe the resource owner resource requested to be accessed by the API caller; A parameter or a string used to name the resource owner resource requested to be accessed by the API caller; Resource identifier, resource name, resource operation identifier, resource operation name, resource operation description, resource processing purpose, resource processing description.

32. The method of claim 28, wherein, Further comprising: determining that the first request message is authorized to pass based on the first response message, or that an access token is carried in the first response message, and sending a service API invocation request to a third network function, the service API invocation request carrying the access token.

33. The method of claim 32, wherein, The service API invocation request is used to request access to the resource owner's resources provided through the service API.

34. The method of claim 28, wherein, The first response message includes at least one of the following information: API invoker identifier, resource owner identifier, authorization code, access token, authorization scope, service API information, resource information, validity period.

35. A resource owner aware northbound API access authorization apparatus, characterized in that, Comprising: request receiving module, used for receiving the first request message sent by the API invoker; authorization checking module, used for determining whether the API invoker is authorized to access the resource owner's resources; response sending module, used for sending the first response message to the API invoker.

36. A resource owner aware northbound API access authorization apparatus, characterized in that, Comprising: request sending module, used for sending the first request message to the first network function; response receiving module, used for receiving the first response message returned by the first network function after determining whether the API invoker is authorized to access the resource owner's resources.

37. A resource owner aware northbound API access authorization device, comprising: comprising at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-27, or perform the method of any one of claims 28-34.

38. A computer storage medium, comprising, The computer storage medium stores a computer program, and the computer program is used to enable a computer to perform the method of any one of claims 1-27, or perform the method of any one of claims 28-34.

Citation Information

Patent Citations

  • Using method, call method, device and system of Oauth application programming interface (API)

    CN103220259A

  • Application programming interface (API) access management in wireless systems

    CN118614098A

  • Northbound application programming interface (API) invoking method and apparatus

    WO2024031722A1

  • Communication method and communication apparatus

    WO2024032226A1

  • API invoking method, apparatus, device, and storage medium

    WO2024065564A1