Communication methods, API caller, ROF, CCF, communication system and storage medium

By searching for tokens in the user device and sending requests to the core functionality of the general API framework, multiple authorizations for different applications on the same user device are enabled, solving the problem of duplicate authentication of resource owners, improving communication efficiency and saving wireless resources.

WO2026073452A1PCT designated stage Publication Date: 2026-04-09BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-04
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Under the general API framework, when different applications on the same user device request access to resources related to the resource owner, the resource owner needs to repeatedly perform authentication and authorization, resulting in low communication efficiency and waste of wireless resources.

Method used

By enabling API callers to search for tokens on user devices and send requests to the core functionality of the general API framework, token requests for authorizing multiple applications at once can be made, simplifying the authentication and authorization process.

Benefits of technology

It reduces redundant authentication and authorization for resource owners, improves communication efficiency, and avoids the waste of wireless resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024123254_09042026_PF_FP_ABST
    Figure CN2024123254_09042026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to communication methods, an API caller, an ROF, a CCF, a communication system and a storage medium. A method comprises: on the basis of a first identifier and a requested first range, searching for a first token in a user equipment (UE), the first identifier being an identifier of a resource owner requested to be accessed by an API caller; and when the first token is found, sending to a common API framework core function (CCF) a second request, wherein the second request comprises the first token, the second request is used for requesting a second token, the first token comprises the identifier of the resource owner and a second range, the second range comprising the first range, and the second token is used for indicating that the API caller is authorized to access RO-related ranges. The embodiments of the present disclosure can improve communication efficiency and avoid waste of wireless resources.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, API invoker, ROF, CCF, communication system and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, an API invoker, a ROF, a CCF, a communication system and a storage medium. BACKGROUND

[0002] In the context of Common API Framework (CAPIF) Resource Owner Aware Northbound API Access (RNAA), a resource owner (RO) participates in authorizing API invokers (e.g., application servers, applications on user equipment) to request resources (e.g., location information) related to the owner. The RO is a user / 3GPP subscriber. The user can be a natural person. The 3GPP subscriber can be a corporate entity or a natural person.

[0003] Currently, if a game application (i.e., an API invoker) wants to access location information, the RO needs to be authenticated first and then participate in the authorization process. If another API invoker on the same user equipment, such as a weather application, also wants to access location information, the RO needs to be authenticated and authorized again.

[0004] SUMMARY

[0005] Embodiments of the present disclosure provide a communication method, an API invoker, a ROF, a CCF, a communication system and a storage medium. The RO can perform a one-time authorization procedure to authorize multiple requests from different applications running on the same user equipment, the RNAA process is simplified, redundant authentication and authorization of the RO are reduced, communication efficiency is improved, and waste of wireless resources is avoided.

[0006] In a first aspect, embodiments of the present disclosure provide a communication method, executed by an API invoker, the method comprising:

[0007] searching for a first token in a user equipment (UE) according to a first identifier and a first range of a request, the first identifier being an identifier of a resource owner (RO) that the API invoker requests to be authorized;

[0008] when the first token is found, sending a second request to a Common API Framework Core Function (CCF), the second request including the first token, the second request being used to request a second token;

[0009] wherein the first token includes an identifier of the resource owner and a second range, and the second range includes the first range.

[0010] The second token is used to indicate that the API caller has the permission to access the range related to the RO.

[0011] In a second aspect, the embodiments of the present disclosure provide a communication method, executed by a ROF, comprising:

[0012] receiving a first request sent by an API caller, the first request being used to request to obtain a first token;

[0013] The first request is sent by the API caller according to a first identifier and a first range requested, and the first token is not searched in a user equipment (UE).

[0014] The first identifier is an identifier of a resource owner (RO) requested to be authorized by the API caller.

[0015] The first token comprises an identifier of the resource owner and a second range allowed by the resource owner, and the second range comprises the first range.

[0016] In a third aspect, the embodiments of the present disclosure provide a communication method, executed by a CCF, comprising:

[0017] receiving a second request sent by the API caller;

[0018] The second request is sent by the API caller according to the first identifier and the first range requested, and the first token is searched in the UE. The second request comprises the first token, and the second request is used to request a second token. The second token is used to indicate that the API caller has the permission to access the range related to the RO.

[0019] The first identifier is an identifier of a resource owner (RO) requested to be authorized by the API caller.

[0020] The first token comprises an identifier of the resource owner and a second range, and the second range comprises the first range.

[0021] In a fourth aspect, the embodiments of the present disclosure provide a first communication device, comprising:

[0022] The processing module is configured to search a first token in a user equipment (UE) according to a first identifier and a first range requested, and the first identifier is an identifier of a resource owner (RO) requested to be authorized by the API caller.

[0023] The transceiver module is configured to search the first token, and send a second request to a common API framework core function (CCF), the second request comprising the first token, and the second request being used to request a second token.

[0024] The first token includes an identifier of the resource owner and a second range, and the second range includes the first range.

[0025] The second token is used to indicate that the API caller has the permission to access the RO-related range.

[0026] In a fifth aspect, an embodiment of the present disclosure provides a second communication device, including:

[0027] The transceiver is configured to receive a first request sent by an API caller, and the first request is used to request the first token.

[0028] The first request is sent by the API caller according to a first identifier and a requested first range, and the first token is not searched in the UE.

[0029] The first identifier is an identifier of a resource owner RO requested by the API caller to obtain authorization.

[0030] The first token includes an identifier of the resource owner and a second range, and the second range includes the first range.

[0031] In a sixth aspect, an embodiment of the present disclosure provides a third communication device, including:

[0032] The transceiver is configured to receive a second request sent by the API caller.

[0033] The second request is sent by the API caller according to a first identifier and a requested first range, and the first token is searched in the UE. The second request includes the first token, and the second request is used to request a second token. The second token is used to indicate that the API caller has the permission to access the RO-related range.

[0034] The first identifier is an identifier of a resource owner RO requested by the API caller to obtain authorization.

[0035] The first token includes an identifier of the resource owner and a second range, and the second range includes the first range.

[0036] In a seventh aspect, an embodiment of the present disclosure provides a communication device, including one or more processors.

[0037] The processor is configured to call instructions to enable the communication device to perform the method in the first aspect, the second aspect or the third aspect.

[0038] In an eighth aspect, an embodiment of the present disclosure provides a communication system, comprising an API invoker, a ROF and a CCF; wherein the API invoker is configured to implement the method in any one of the first aspect of the present disclosure; the ROF is configured to implement the method in any one of the second aspect of the present disclosure; and the CCF is configured to implement the method in any one of the third aspect of the present disclosure.

[0039] In a ninth aspect, an embodiment of the present disclosure provides a storage medium, which, when instructions run on a communication device, causes the communication device to perform the method in any one of the embodiments of the present disclosure.

[0040] In a tenth aspect, an embodiment of the present disclosure provides a program product, which, when executed by a communication device, performs the method in any one of the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0042] FIG. 1 is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure;

[0043] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure;

[0044] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure;

[0045] FIG. 3A is a flow schematic diagram of a communication method performed by an API invoker according to an embodiment of the present disclosure;

[0046] FIG. 3B is a flow schematic diagram of a communication method performed by an API invoker according to an embodiment of the present disclosure;

[0047] FIG. 4 is a flow schematic diagram of a communication method performed by a ROF according to an embodiment of the present disclosure;

[0048] FIG. 5A is a flow schematic diagram of a communication method performed by a CCF according to an embodiment of the present disclosure

[0049] FIG. 5B is a flow schematic diagram of a communication method performed by a CCF according to an embodiment of the present disclosure;

[0050] FIG. 6A is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;

[0051] FIG. 6B is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;

[0052] FIG. 7A is a flow diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;

[0053] FIG. 7B is a flow diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;

[0054] FIG. 7C is a flow diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;

[0055] FIG. 8A is a structural diagram of a first communication apparatus according to an embodiment of the present disclosure;

[0056] FIG. 8B is a structural diagram of a second communication apparatus according to an embodiment of the present disclosure;

[0057] FIG. 8C is a structural diagram of a third communication apparatus according to an embodiment of the present disclosure;

[0058] FIG. 9A is a structural diagram of a communication device according to an embodiment of the present disclosure;

[0059] FIG. 9B is a structural diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0060] Embodiments of the present disclosure provide a communication method, a UE, a NW, a system and a storage medium.

[0061] In a first aspect, embodiments of the present disclosure provide a communication method, performed by an API invoker, comprising:

[0062] searching, according to a first identifier and a requested first scope, for a first token in a user equipment (UE), the first identifier being an identifier of a resource owner (RO) for which the API invoker requests authorization;

[0063] in response to finding the first token, sending a second request to a common API framework core function (CCF), the second request including the first token, the second request being used to request a second token;

[0064] wherein the first token includes the first identifier and a second scope, and the second scope includes the first scope.

[0065] The second token is used to indicate that the API invoker has the permission to access the scope related to the RO.

[0066] In the above embodiment, the API invoker searches for the first token in the UE according to the first identity and the first scope of the request, and if the first token is found, it indicates that the resource owner has been requested by another API invoker, and a second request is sent to the CCF, the second request including the first token, so that the CCF can generate a second token according to the first token, realizing CAPIF to support the resource owner to perform a one-time identity authentication and authorization process for multiple token requests from different application programs (API invokers) running on the same UE.

[0067] In combination with some embodiments of the first aspect, in some embodiments, the second request includes the third token, and the third token is used for online subscription.

[0068] In the above embodiment, the API invoker has obtained the third token in advance, and therefore directly sends the second request including the third token and the first token to the CCF, so that the CCF obtains the identity of the API invoker according to the third token, and further obtains the second token in combination with the first token.

[0069] In combination with some embodiments of the first aspect, in some embodiments, the second request further includes a fourth token, and the fourth token is used to indicate the identity of the API invoker authenticated by the CCF.

[0070] In the above embodiment, the API invoker has not obtained the third token in advance, and obtains the fourth token through mutual authentication with the CCF, and then sends the second request including the fourth token and the first token to the CCF, so that the CCF obtains the identity of the API invoker according to the fourth token, and further obtains the second token in combination with the first token.

[0071] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:

[0072] sending a third request to the CCF, the third request being used to request the fourth token;

[0073] receiving the fourth token sent by the CCF.

[0074] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:

[0075] receiving the second token sent by the CCF.

[0076] In the above embodiment, after the API invoker sends the second request to the CCF, the API invoker further receives the second token sent by the CCF, so as to access the first scope according to the second token.

[0077] In combination with some embodiments of the first aspect, in some embodiments, the second token is obtained by the CCF in combination with the identity of the API invoker in the first token.

[0078] In the above embodiment, the second token is obtained in a simple and efficient manner, and the CCF can obtain the token by adding the identifier of the API caller in the first token, which can improve the authorization efficiency.

[0079] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:

[0080] In response to the first token not being searched, sending a first request to the ROF, the first request being used to request the first token;

[0081] Receiving the first token sent by the CCF.

[0082] In the above embodiment, in response to the first token not being searched, the API caller sends a first request to the ROF to request the first token, and then receives the first token sent by the CCF.

[0083] In combination with some embodiments of the first aspect, in some embodiments, receiving the first token sent by the CCF includes:

[0084] Receiving at least one of the first token and a first indication sent by the CCF;

[0085] The first indication indicates at least one of the API caller storing the first token and the API caller sharing the first token;

[0086] The method further includes storing the first token in the UE.

[0087] In the above embodiment, the API caller also receives a first indication, which indicates at least one of the API caller storing the first token and the API caller sharing the first token, so that the API caller stores the first token in the UE after receiving the first indication, and the first token is used by other API callers when requesting the same range, thereby improving the authorization efficiency.

[0088] In a second aspect, the embodiments of the present disclosure provide a communication method, executed by an ROF, including:

[0089] Receiving a first request sent by an API caller, the first request being used to request a first token;

[0090] The first request is sent by the API caller in response to a first identifier and a requested first range, and the first token is not searched in the UE;

[0091] The first identifier is an identifier of a resource owner RO requested by the API caller to obtain authorization;

[0092] The first token includes the first identifier and a second range allowed by the resource owner, and the second range includes the first range.

[0093] In the above embodiment, when the API caller sends a first request to the ROF, the first request is used to request to obtain the first token, so that the ROF assists the API caller and the CCF to interact, and lays a foundation for the CCF to return the first token to the API caller subsequently.

[0094] In combination with some embodiments of the second aspect, in some embodiments, the resource owner allows the second token to be obtained based on the first token, and the first list is sent to the CCF;

[0095] The first list includes an identifier of at least one API caller allowed to obtain the second token based on the first token.

[0096] In the above embodiment, the ROF sends the first list to the CCF, and the first list includes an identifier of at least one API caller allowed to obtain the second token based on the first token, so as to lay a foundation for the CCF to judge whether to send the second token to the API caller according to the first list subsequently.

[0097] In a third aspect, the embodiments of the present disclosure provide a communication method, executed by a CCF, and the method comprises:

[0098] receiving a second request sent by the API caller;

[0099] The second request is sent by the API caller according to the first identifier and a requested first range, and the second request includes the first token; the second request is used to request a second token; and the second token is used to indicate that the API caller has an access right to a range related to the RO.

[0100] The first identifier is an identifier of a resource owner (RO) requested by the API caller to obtain authorization;

[0101] The first token includes the first identifier and a second range, and the second range includes the first range.

[0102] In the above embodiments, the CCF receives a second request sent by an API invoker, the second request being sent by the API invoker according to the first token and a first scope of the request, and the second request includes the first token and is used to request a second token, the second token being used to indicate that the API invoker has the permission to access the scope related to the RO, and the embodiments of the present disclosure lay a foundation for the CCF to quickly generate the second token of the API invoker based on the first token in the second request, and can improve the authorization efficiency for multiple API invokers of the same scope.

[0103] In combination with some embodiments of the third aspect, in some embodiments, the second request includes a third token and the first token, and the third token is used for online subscription.

[0104] In combination with some embodiments of the third aspect, in some embodiments, the second request includes a fourth token and the first token, and the fourth token is used to indicate the identity of the API invoker authenticated by the CCF.

[0105] In combination with some embodiments of the third aspect, in some embodiments, the method further includes:

[0106] receiving a third request sent by an API invoker, the third request being used to request the fourth token;

[0107] sending the fourth token to the API invoker.

[0108] In combination with some embodiments of the third aspect, in some embodiments, the second token is sent to the API invoker.

[0109] The second token is used to indicate that the API invoker has the permission to access the scope related to the RO.

[0110] The second token is obtained by the CCF from the first token by adding the identity of the API invoker.

[0111] In combination with some embodiments of the third aspect, in some embodiments, the second token is sent to the API invoker, including:

[0112] obtaining the first identity from the first token;

[0113] obtaining a first list related to the resource owner according to the first identity, the first list including the identity of at least one API invoker allowed to obtain the second token based on the first token;

[0114] determining that the first list includes the identity of the API invoker.

[0115] In some embodiments of the third aspect, in some embodiments, the method further comprises:

[0116] The first list does not include an identity of the API invoker to which the failure message is sent.

[0117] The first list includes an identity of at least one API invoker that is allowed to obtain the second token based on the first token.

[0118] In some embodiments of the third aspect, in some embodiments, the method further comprises:

[0119] Receiving authorization information sent by the ROF;

[0120] The authorization information includes a first list.

[0121] The first list includes an identity of at least one API invoker that is allowed to obtain the second token based on the first token.

[0122] In some embodiments of the third aspect, in some embodiments, the method further comprises:

[0123] Sending at least one of the first token and a first indication to the API invoker;

[0124] The first indication is used to indicate at least one of that the API invoker stores the first token and that the API invoker shares the first token.

[0125] A fourth aspect, the embodiments of the present disclosure provide a first communication device, comprising:

[0126] A processing module configured to search for a first token in a user equipment (UE) according to a first identity and a first range of a request, the first identity being an identity of a resource owner (RO) that the API invoker requests to obtain authorization;

[0127] A transceiver configured to search for the first token, and send a second request to a common API framework core function (CCF), the second request including the first token, the second request being used to request a second token;

[0128] The first token includes the first identity and a second range, and the second range includes the first range.

[0129] The second token is used to indicate that the API invoker has permission to access a range related to the RO.

[0130] A fifth aspect, the embodiments of the present disclosure provide a second communication device, comprising:

[0131] The transceiving module is configured to receive a first request sent by an API invoker, the first request being used to request the first token;

[0132] The first request is sent by the API invoker according to a first identifier and a first range requested, and the first token is not searched in the UE.

[0133] The first identifier is an identifier of a resource owner (RO) for which the API invoker requests authorization.

[0134] The first token includes the first identifier and a second range allowed by the RO, and the second range includes the first range.

[0135] In a sixth aspect, an embodiment of the present disclosure provides a third communication device, including:

[0136] The transceiving module is configured to receive a second request sent by the API invoker.

[0137] The second request is sent by the API invoker according to the first identifier and the first range requested, and the first token is searched in the UE. The second request includes the first token, and the second request is used to request a second token. The second token is used to indicate that the API invoker has the permission to access the range related to the RO.

[0138] The first identifier is an identifier of a resource owner (RO) for which the API invoker requests authorization.

[0139] The first token includes the first identifier and a second range, and the second range includes the first range.

[0140] In a seventh aspect, an embodiment of the present disclosure provides a communication device including one or more processors.

[0141] The processor is configured to invoke instructions to cause the communication device to perform the method of the first aspect, the second aspect, or the third aspect.

[0142] In an eighth aspect, an embodiment of the present disclosure provides a storage medium, when instructions are run on a communication device, the communication device performs the method of any one of the embodiments of the present disclosure.

[0143] In a ninth aspect, an embodiment of the present disclosure provides a program product, the program product is executed by a communication device to perform the method of any one of the embodiments of the present disclosure.

[0144] It can be understood that the API caller, the ROF, the CCF, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are used to execute the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be repeated here.

[0145] The embodiments of the present disclosure propose a communication method, an API caller, a ROF, a CCF, a communication system and a storage medium. In some embodiments, the terms of the communication method, the signal sending method, the wireless frame sending method, the authorization method, etc. can be replaced with each other, and the terms of the information processing system, the communication system, etc. can be replaced with each other.

[0146] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.

[0147] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0148] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.

[0149] In the embodiments of the present disclosure, "multiple" refers to two or more.

[0150] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", etc. can be replaced with each other.

[0151] In some embodiments, "at least one of A, B", "A and / or B", "in one case A, in another case B", "responsive to case A, responsive to case B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option), in some embodiments, A and B (both A and B are performed).

[0152] In some embodiments, "A or B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option).

[0153] In some embodiments, the prefix words "first", "second" and the like in the disclosure do not limit the position, order, priority, number or content of the described objects, and the description of the described objects should be referred to the context of the claims or embodiments, and should not be construed as redundant limitations. For example, the described objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified by them are in the same message or not, nor limit the order of "first field" and "second field". For another example, the described objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the number of the described objects is not limited by the ordinal words, and can be one or more. For example, "first device", where the number of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the described objects are "devices", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the described objects are "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.

[0154] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0155] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0156] In some embodiments, the terms “greater than”, “less than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, “above”, and the like can be replaced with each other, and the terms “less than”, “less than or equal to”, “not greater than”, “fewer than”, “fewer than or equal to”, “not more than”, “lower than”, “lower than or equal to”, “not higher than”, “below”, and the like can be replaced with each other.

[0157] In some embodiments, apparatuses and devices can be interpreted as physical, as well as virtual, and their names are not limited to the names described in the embodiments, and in some cases, can also be understood as “equipment”, “device”, “circuit”, “device”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, “subject”, and the like.

[0158] In some embodiments, the terms “access network device (AN device)”, “wireless access network device (radio access network device, RAN device)”, “base station (BS)”, “radio base station”, “fixed station”, “node”, “access point”, “transmission point (TP)”, “reception point (RP)”, “transmission / reception point (TRP)”, “panel”, “antenna panel”, “antenna array”, “cell”, “macro cell”, “small cell”, “femto cell”, “pico cell”, “sector”, “cell group”, “carrier”, “component carrier”, “bandwidth part (BWP)”, and the like can be replaced with each other.

[0159] In some embodiments, the terms “access network device (AN device)”, “wireless access network device (radio access network device, RAN device)”, “base station (BS)”, “radio base station”, “fixed station”, “node”, “access point”, “transmission point (TP)”, “reception point (RP)”, “transmission / reception point (TRP)”, “panel”, “antenna panel”, “antenna array”, “cell”, “macro cell”, “small cell”, “femto cell”, “pico cell”, “sector”, “cell group”, “carrier”, “component carrier”, “bandwidth part (BWP)”, and the like can be replaced with each other.

[0160] In some embodiments, the terms "terminal," "terminal device," "user equipment," "user terminal," "mobile station," "mobile terminal," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and the like can be used interchangeably.

[0161] In some embodiments, an access network device, or a network device can be replaced with a terminal. For example, for a structure in which communication between an access network device, or a network device and a terminal is replaced with communication between a plurality of terminals (e.g., also referred to as device-to-device (D2D), vehicle-to-everything (V2X), and the like), embodiments of the present disclosure can also be applied. In this case, a structure in which a terminal has all or part of the functions of an access network device, or a network device can also be provided. Further, the language of "uplink," "downlink," and the like can also be replaced with language corresponding to communication between terminals (e.g., "side"). For example, an uplink channel, a downlink channel, and the like can be replaced with a side channel, and an uplink, a downlink, and the like can be replaced with a side link.

[0162] In some embodiments, a terminal can be replaced with an access network device, or a network device. In this case, a structure in which an access network device, or a network device has all or part of the functions of a terminal can also be provided.

[0163] In some embodiments, the terms “uplink”, “uplink”, “physical uplink” and the like can be replaced with each other, the terms “downlink”, “downlink”, “physical downlink” and the like can be replaced with each other, and the terms “side”, “sidelink”, “sidelink communication”, “sidelink communication”, “direct connection”, “direct connection link”, “direct connection communication”, “direct connection link communication” and the like can be replaced with each other.

[0164] In some embodiments, the terms “downlink control information (DCI)”, “downlink (DL) assignment”, “DL DCI”, “uplink (UL) grant”, “UL DCI” and the like can be replaced with each other.

[0165] In some embodiments, the terms “physical downlink shared channel (PDSCH)”, “DL data” and the like can be replaced with each other, and the terms “physical uplink shared channel (PUSCH)”, “UL data” and the like can be replaced with each other.

[0166] In some embodiments, the terms “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” and the like can be replaced with each other, and can be interpreted as receiving from other subjects, obtaining from protocols, obtaining by oneself, implementing autonomously and the like.

[0167] In some embodiments, the terms “send”, “transmit”, “report”, “issue”, “transmit”, “bidirectional transmission”, “send and / or receive” and the like can be replaced with each other.

[0168] In some embodiments, “predetermined” and “preset” can be interpreted as being previously specified in protocols and the like, or can be interpreted as being previously set by devices and the like.

[0169] In some embodiments, the acquisition of data, information and the like can comply with the laws and regulations of the country where the device is located.

[0170] In some embodiments, data, information and the like can be acquired after obtaining the consent of the user.

[0171] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of elements, rows, and columns can also be implemented as an independent embodiment.

[0172] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1, the communication system 100 includes a terminal 101 and a network device 102.

[0173] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like, but is not limited thereto. The terminal 101 can run the ROF and one or more API callers.

[0174] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.

[0175] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0176] In some embodiments, the core network device can be one device, or a plurality of devices or device groups. The core network device can include one or more network elements, which can be virtual or physical. The core network includes, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0177] The CCF of the embodiments of the present disclosure is a function in CAPIF, which can be deployed by an operator, and the CCF can be regarded as part of the core network. In some embodiments, CAPIF can also be deployed by a third party (for example, a third party enterprise), at this time, the CCF is not part of the core network.

[0178] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed in the embodiments of the present disclosure are also applicable to similar technical problems.

[0179] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1, or part of the main bodies, but are not limited thereto. The main bodies shown in FIG. 1 are illustrative, and the communication system can include all or part of the main bodies in FIG. 1, or other main bodies other than those in FIG. 1. The number and form of each main body is arbitrary, and the connection relationship between the main bodies is illustrative. The main bodies can be connected or not connected, and the connection can be in any manner, can be direct or indirect, and can be wired or wireless.

[0180] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), 5G-Advanced (5G-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, or the like. Further, a plurality of systems can be combined (for example, combination of LTE or LTE-A and 5G, or the like).

[0181] In the context of Common API Framework (CAPIF) Resource Owner Aware Northbound API Access (RNAA), a Resource Owner (RO) participates in authorizing API callers (e.g., application servers, applications on user equipment) requests for resources (e.g., location information) related to the RO. The RO is a user / 3GPP subscriber. A user can be a natural person. A 3GPP subscriber can be a corporate entity or a natural person.

[0182] Currently, if a game application (i.e., an API caller) wants to access location information, the RO needs to be authenticated first and then participate in the authorization process. If another API caller, e.g., a weather application, on the same user equipment also wants to access location information, the RO needs to be authenticated and authorized again.

[0183] If the RO can perform a one-time authentication and authorization procedure to authorize multiple token requests from different applications running on the same UE, the commercialization process of RNAA will be much smoother.

[0184] An embodiment of the present disclosure solves the above problem by having one API caller obtain its own token by providing a token of another API caller.

[0185] FIG. 2A is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2A, the present disclosure relates to a communication method for a communication system 100, the method comprising:

[0186] S2101, the API caller sends a first request.

[0187] The API caller of the present disclosure searches for a first token in the UE according to the first identity and a first scope of the request. Illustratively, the scope of the request can be at least one of adjusting QoS, geographic location, recording permission, taking a photo permission, obtaining a contact list permission, and storage permission. Illustratively, the API caller searches for the first token in the UE according to the first identity and the first scope of the request when the API caller needs to request a resource owner corresponding to the first identity in relation to the first scope (e.g., the API caller needs to request location information of the resource owner corresponding to the first identity, the API caller searches for the first token according to the first identity and the request for location information).

[0188] In some embodiments, the API caller searches for the first token in a secure environment of the UE.

[0189] In some embodiments, the first identifier is an identifier of the RO that the API invoker needs to request authorization.

[0190] In some embodiments, the API invoker needs to access location information of a certain RO, and the access to the location information needs authorization of the RO, and the identifier of the RO is the first identifier.

[0191] In some embodiments, the first request is sent when the API invoker fails to search for the first token.

[0192] In some embodiments, the first request is used to request the first token. For example, the first request includes at least one of the first identifier, an identifier of the API invoker, and a requested range.

[0193] In some embodiments, the UE can pre-store one or more tokens shared by various API invokers. The sharing means that the various API invokers can search for the token. Each token includes an identifier of a RO and a second range. It should be noted that the second range can be a range allowed by the RO, a range allowed by the CCF, or a range allowed by the RO and the CCF.

[0194] In some embodiments, the first token is a token stored by the UE, which includes the first identifier and a second range including the first range requested by the API invoker.

[0195] In some embodiments, the API invoker searches for the first token according to only the identifier of the RO in the searching process of the first token.

[0196] In some embodiments, the ROF receives the first request.

[0197] S2102, the ROF sends authorization information.

[0198] In some embodiments, the CCF receives the authorization information.

[0199] In some embodiments, the authorization information is sent by the RO through the ROF.

[0200] In some embodiments, the authorization information is used to indicate that the RO agrees or disagrees with the range requested by the API invoker. It should be understood that if the RO disagrees with the range requested by the API invoker, the ROF ends the process, or sends a call failure message to the API invoker and then ends the process, or the CCF sends a call failure message to the API invoker and then ends the process.

[0201] In some embodiments, when the authorization information is used to indicate that the RO agrees with the scope requested by the API invoker, the authorization information further comprises a first list related to the RO. The first list comprises the identification of at least one API invoker allowed to obtain a second token based on a first token, the at least one API invoker each requesting the same scope.

[0202] In some embodiments, the authorization information comprises a first list related to the RO. The first list comprises the identification of at least one API invoker allowed to obtain a second token based on a first token, the RO corresponding to the first identification, the first token and the second token each comprising the first identification.

[0203] In some embodiments, the RO additionally sends the first list related to the RO when sending the authorization information, i.e., the first list can not belong to the authorization information. The first list comprises the identification of at least one API invoker allowed to obtain a second token based on a first token, the RO corresponding to the first identification, the first token and the second token each comprising the first identification.

[0204] It should be noted that when the RO allows multiple API invokers requesting the same scope to apply the token exchange mechanism, the RO additionally provides a list of API invoker IDs (i.e., the first list) using the token exchange mechanism related to the RO.

[0205] In some embodiments, when the RO allows multiple API invokers requesting a token comprising the identification of the RO to apply the token exchange mechanism, the RO additionally provides a list of API invoker IDs (i.e., the first list) using the token exchange mechanism related to the RO.

[0206] In some embodiments, the token exchange mechanism refers to a mechanism of replacing a shared token related to one RO with a token specific to each of multiple API invokers requesting the same scope of resource access, the specific token being used to indicate that the corresponding API invoker has the right to request the same scope from the RO.

[0207] In some embodiments, the token exchange mechanism refers to a mechanism of replacing a shared token comprising a specific RO identification, a specific scope of access, and a specific scope of access, with a token specific to each of multiple API invokers requesting the same RO to authorize and the same scope of access, the specific token comprising the identification of the API invoker requesting the same scope of access and requesting the same RO to authorize.

[0208] In some embodiments, the token exchange mechanism refers to a mechanism of replacing a token containing a specific RO identifier, containing a specific access scope, and shared by multiple API callers requesting authorization from the RO with a token exclusive to each API caller requesting authorization from the RO.

[0209] S2103, the CCF sends the first token.

[0210] In some embodiments, the API caller receives the first token.

[0211] In some embodiments, when the authorization information is used to indicate that the RO agrees with the scope requested by the API caller, the CCF additionally sends a first indication when sending the first token, the first indication being used to indicate at least one of storing the first token and sharing the first token by the API caller. Accordingly, when the API caller receives the first indication, the first token is stored in the secure environment of the UE.

[0212] In some embodiments, the CCF additionally sends a first indication when sending the first token, the first indication being used to indicate at least one of storing the first token and sharing the first token by the API caller. Accordingly, when the API caller receives the first indication, the first token is stored in the secure environment of the UE.

[0213] According to the communication method of the embodiments of the present disclosure, the API caller searches for the first token in the UE according to the first identifier and the requested scope, so as to find the token (i.e., the first token) that can match the requested RO and the requested scope first. If the first token is not found, it indicates that no other API caller has requested the same RO and the same scope currently. The API caller sends a first request to the ROF, the first request being used to request the first token, which can improve the access efficiency and lay a foundation for supporting the RO to perform the one-time identity verification and authorization procedure and authorize multiple token requests from different API callers running on the same UE subsequently.

[0214] According to the communication method of the embodiments of the present disclosure, the API caller searches for the first token in the UE according to the first identifier and the requested scope, so as to find the token (i.e., the first token) that can match the requested RO and the requested scope first. If the first token is not found, it indicates that no other API caller has requested the same RO and the same scope currently. The API caller sends a first request to the ROF, the first request being used to request the first token, which can improve the access efficiency and lay a foundation for supporting the RO to perform the one-time identity verification and authorization procedure and authorize multiple token requests from different API callers running on the same UE subsequently.

[0215] FIG. 2B is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2B, an embodiment of the present disclosure relates to a communication method for the communication system 100, and the method comprises:

[0216] S2201, the API invoker sends a second request.

[0217] The API invoker according to an embodiment of the present disclosure searches for the shared first token in the UE according to the first identity and the requested scope. Exemplarily, the requested scope can be at least one of changing QoS, geographical location, recording permission, photographing permission, obtaining contact list permission, and storage permission.

[0218] In some embodiments, the API invoker searches for the shared first token in the secure environment of the UE.

[0219] In some embodiments, the API invoker searches for the first token in the UE according to the first identity and the first scope of the request. Exemplarily, the first scope of the request can be at least one of adjusting QoS, geographical location, recording permission, photographing permission, obtaining contact list permission, and storage permission. Exemplarily, the API invoker searches for the first token in the UE according to the first identity and the first scope of the request when the first scope of the request is related to the resource owner corresponding to the first identity (for example, the API invoker searches for the first token according to the first identity and the request for location information when the API invoker needs to request the location information of the resource owner corresponding to the first identity). In some embodiments, the first identity is the identity of the RO that the API invoker needs to request authorization from, i.e., the API invoker needs to obtain authorization from the RO.

[0220] In some embodiments, the API invoker sends the second request when the first token is searched.

[0221] In some embodiments, the second request is used to request a second token related to the API invoker.

[0222] In some embodiments, the second request is used to request a second token related to the API invoker based on the first token.

[0223] In some embodiments, the second token is used to indicate that the corresponding API invoker has the permission to access the requested resource access scope of the resource owner.

[0224] In some embodiments, the second token is used to indicate that the corresponding API invoker has the permission to access the scope related to the resource owner, for example, the scope can be requesting location information, and the second token is used to indicate that the corresponding API invoker has the permission to access the location information of the resource owner.

[0225] The API invoker of the embodiments of the present disclosure has two ways to obtain the second token:

[0226] The first way is that the second request includes the first token and a third token for online signing, so that the CCF obtains the identity of the API invoker according to the third token. The online signing corresponds to the onboarding process related to the API invoker supported by CAPIF. The third token for online signing means that the original purpose of the third token is to be used in the onboarding process. The CCF adds the identity of the API invoker in the first token to obtain the second token. It should be noted that the new identity of the API invoker is added in the first token while the original identity of the API invoker in the first token is deleted. In other embodiments, the new identity of the API invoker is added in the first token without deleting the identity of the API invoker in the original first access token.

[0227] The second way is that the second request includes the first token and a fourth token, and the fourth token is used to indicate the identity of the API invoker authenticated by the CCF. In this way, the API invoker does not have a third token for online signing to prove his identity, so he actively applies for a fourth token to the CCF to prove his identity later.

[0228] The third way is that the second request includes the first token and a fourth token, and the fourth token is used to indicate the identity of the API invoker authenticated by the CCF. In this way, the API invoker actively applies for a fourth token to the CCF to prove his identity later.

[0229] In some embodiments, the API invoker and the CCF mutually authenticate each other, the CCF obtains the identity of the API invoker, the API invoker sends a third request to the CCF, the third request is used to request a fourth token, and the CCF sends the fourth token to the API invoker. The subject (sub) declaration of the fourth token is the API invoker identity of the authenticated API invoker. The audience (aud) declaration of the token includes the ID information of the CCF.

[0230] In some embodiments, the API invoker and the CCF mutually authenticate each other, the CCF obtains the identity of the API invoker, the API invoker sends a third request to the CCF, the third request is used to request a fourth token, and the CCF sends the fourth token to the API invoker. The subject (sub) declaration of the fourth token is the API invoker identity of the authenticated API invoker.

[0231] In some embodiments, the CCF obtains the identity of the API invoker, the API invoker sends a third request to the CCF, the third request is used to request a fourth token, and the CCF sends the fourth token to the API invoker.

[0232] S2202. The CCF sends the second token or a failure message.

[0233] In some embodiments, the API invoker receives the second token or the failure message.

[0234] In some embodiments, the second request is used to request the second token based on the first token.

[0235] In some embodiments, the CCF can establish and maintain a mapping relationship between the identity of the RO, the authorization information, and the first list.

[0236] In some embodiments, the CCF can establish and maintain a mapping relationship between at least two of the identity of the RO, the authorization information, and the first list. In some embodiments, the CCF obtains the first identity from the first token; obtains the first list related to the resource owner according to the first identity, and if it is determined that the first list includes the identity of the API invoker, generates the second token, and if the first list does not include the identity of the API invoker, generates a failure message.

[0237] In some embodiments, the CCF obtains the first identity from the first token; obtains the first list related to the resource owner according to the first identity, and if the first list does not include the identity of the API invoker, sends a failure message, the failure message is used to indicate that the API invoker cannot perform token exchange for the resource owner corresponding to the first identity or the API invoker cannot perform the operation of obtaining the second token based on the first token for the resource owner corresponding to the first identity.

[0238] In some embodiments, the second request includes a third token used for online signing and the first token, and the CCF obtains the identity of the API invoker based on the third token. It should be noted that the second request can only include the first token, and if the CCF authenticates the identity or identity of the API invoker, the CCF can send the API invoker a second response including the second token even if the third token is not included in the second request. The second token is a token obtained by adding the identity of the API invoker to the first token.

[0239] In some embodiments, the second request comprises a third token for online signing and the first token, and the CCF obtains the identity of the API invoker based on the third token. It should be noted that the second request can only comprise the first token, and if the CCF authenticates the identity or identity of the API invoker, the CCF can send the second response comprising the second token to the API invoker even if the second request does not comprise the third token. The second token is a token in which the original API invoker identity is deleted in the first token and the identity of the API invoker that has been authenticated by the CCF is added.

[0240] In some embodiments, the second request comprises the first token and a fourth token, the fourth token is an identity of the API invoker sent by the CCF to the API invoker under the condition that the CCF authenticates the API invoker, the subject (sub) declaration of the second token is the identity of the authenticated API invoker determined according to the fourth token, and the audience (aud) declaration of the token comprises the identity of the CCF. The second token is used to indicate at least one of the following:

[0241] The identity of the API invoker has been authenticated by the CCF;

[0242] The identity of the CCF;

[0243] The receiver of the second token is the CCF.

[0244] The communication method of the embodiments of the present disclosure, the API invoker searches for a shared first token in the UE according to a first identity and a requested scope, and if the first token is searched, a second request is sent to the CCF, the second request is used to request to obtain a second token related to the API invoker, the second token is used to indicate that the corresponding API invoker has the permission to access the scope related to the resource owner, and the effect that the CAPIF can support the RO to perform the one-time identity authentication and authorization process only once for multiple token requests from different application programs running on the same UE is realized in the case of searching for the first token.

[0245] FIG. 3A is a flow diagram of a communication method according to an embodiment of the present disclosure, as shown in FIG. 3A, the embodiment of the present disclosure is performed by an API invoker, and the above method comprises:

[0246] S3101, searching for a shared first token in the UE according to a first ID and a requested scope.

[0247] The optional implementation of step S3101 can refer to the optional implementation of step S2101 of FIG. 2A and the optional implementation of step S2201 of FIG. 2B, and other associated parts in the embodiments involved in FIG. 2A, which will not be described here.

[0248] S3102. If the first token is not found, a first request is sent to the ROF.

[0249] The optional implementation of step S3102 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0250] S3103. The first token sent by the CCF is received.

[0251] The optional implementation of step S3103 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0252] The communication method involved in the embodiments of the present disclosure can include at least one of steps S3101-S3103. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, and step S3103 can be implemented as an independent embodiment, but is not limited thereto.

[0253] It should be noted that S3101, S3102 and S3103 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0254] FIG. 3B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the method is performed by an API caller, and includes:

[0255] S3201. A first token shared in the UE is searched according to a first ID and a requested range.

[0256] The optional implementation of step S3201 can refer to the optional implementation of step S2101 in FIG. 2A and the optional implementation of step S2201 in FIG. 2B, as well as other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0257] S3202. If the first token is found, a second request is sent to the CCF.

[0258] The optional implementation of step S3202 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.

[0259] S3203. The second token sent by the CCF is received.

[0260] The optional implementation of step S3203 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.

[0261] The communication method related to the embodiments of the present disclosure can include at least one of steps S3201-S3202. For example, step S3201 can be implemented as an independent embodiment, step S3202 can be implemented as an independent embodiment, and step S3203 can be implemented as an independent embodiment, but is not limited thereto.

[0262] It should be noted that S3201, S3202 and S3203 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0263] FIG. 4 is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 4, the embodiments of the present disclosure are performed by the ROF, and the above method includes:

[0264] S4101, receiving a first request sent by an API caller.

[0265] The optional implementation of step S4101 can refer to the optional implementation of steps S2101 and S2102 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0266] S4102, sending authorization information to the CCF.

[0267] The optional implementation of step S4101 can refer to the optional implementation of step S2102 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0268] The communication method related to the embodiments of the present disclosure can include at least one of steps S4101-S4102. For example, step S4101 can be implemented as an independent embodiment, and step S4102 can be implemented as an independent embodiment, but is not limited thereto.

[0269] It should be noted that S4101 and S4102 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0270] FIG. 5A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5A, the embodiments of the present disclosure are performed by the CCF, and the above method includes:

[0271] S5101, receiving authorization information sent by the ROF.

[0272] The optional implementation of step S5101 can refer to the optional implementation of step S2102 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0273] S5102. Send the first token to the API invoker.

[0274] The optional implementation of step S5102 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0275] The communication method involved in the embodiments of the present disclosure can include at least one of steps S5101-S5102. For example, step S5101 can be implemented as an independent embodiment, and step S5102 can be implemented as an independent embodiment, but is not limited thereto.

[0276] It should be noted that S5101 and S5102 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0277] FIG. 5B is a flow diagram of a communication method according to an embodiment of the present disclosure, as shown in FIG. 5B, the method is performed by the CCF and includes:

[0278] S5201. Receive a second request sent by the API invoker.

[0279] The optional implementation of step S5201 can refer to the optional implementation of step S2201 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.

[0280] S5202. Send the second token to the API invoker.

[0281] The optional implementation of step S5202 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.

[0282] The communication method involved in the embodiments of the present disclosure can include at least one of steps S5201-S5202. For example, step S5201 can be implemented as an independent embodiment, and step S5202 can be implemented as an independent embodiment, but is not limited thereto.

[0283] It should be noted that S5201 and S5202 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0284] FIG. 6A is a flow diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system and includes:

[0285] S6101. The API invoker searches for a shared first token in the UE according to the first identifier and the range of the request.

[0286] The optional implementation of step S6101 can refer to the optional implementation of step S2101 in FIG. 2A, the optional implementation of step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A and FIG. 3A, which are not described herein again.

[0287] S6102, the API invoker does not search for the first token, and sends a first request to the ROF.

[0288] The optional implementation of step S6102 can refer to the optional implementation of step S2101 in FIG. 2A, the optional implementation of step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A and FIG. 3A, which are not described herein again.

[0289] S6103, the ROF sends authorization information to the CCF.

[0290] The optional implementation of step S6103 can refer to the optional implementation of step S2102 in FIG. 2A, the optional implementation of step S4102 in FIG. 4, and other associated parts in the embodiments related to FIG. 2A, FIG. 3A and FIG. 4, which are not described herein again.

[0291] S6104, the CCF sends the first token and a first indication to the API invoker.

[0292] The optional implementation of step S6105 can refer to the optional implementation of step S2103 in FIG. 2A, the optional implementation of step S3103 in FIG. 3A, the optional implementation of step S5102 in FIG. 5A, and other associated parts in the embodiments related to FIG. 2A, FIG. 3A and FIG. 5A, which are not described herein again.

[0293] S6105, the API invoker stores the first token in a secure environment of the UE.

[0294] The optional implementation of step S6105 can refer to the optional implementation of step S2103 in FIG. 2A, the optional implementation of step S3103 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 3A and FIG. 3B, which are not described herein again.

[0295] The communication method related to the embodiments of the present disclosure can include at least one of steps S6101 to S6105. For example, step S6101 can be implemented as an independent embodiment, step S6102 can be implemented as an independent embodiment, step S6103 can be implemented as an independent embodiment, step S6104 can be implemented as an independent embodiment, and step S6105 can be implemented as an independent embodiment, but is not limited thereto.

[0296] In some embodiments, step S6101 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0297] In some embodiments, step S6102 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0298] In some embodiments, step S6103 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0299] In some embodiments, step S6104 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0300] In some embodiments, step S6105 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0301] It should be noted that S6101-S6105 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0302] FIG. 6B is a flow diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method comprises:

[0303] S6201, the API caller searches for a shared first token in the UE according to the first identifier and the requested range.

[0304] The optional implementation of step S6201 can refer to the optional implementation of step S2201 of FIG. 2B, step S3201 of FIG. 3B, and other associated parts in the embodiments related to FIG. 2A and FIG. 3B, which will not be repeated here.

[0305] S6202, the API caller searches for the first token and sends a second request to the CCF.

[0306] The optional implementation of step S6202 can refer to the optional implementation of step S2201 of FIG. 2B, step S3201 of FIG. 3B, and other associated parts in the embodiments related to FIG. 2A and FIG. 3B, which will not be repeated here.

[0307] S6203, the CCF sends a second token to the API caller.

[0308] The optional implementation of step S6203 can refer to the optional implementation of step S2103 of FIG. 2B, step S5202 of FIG. 5B, and other associated parts in the embodiments related to FIG. 2A and FIG. 3B, which will not be repeated here.

[0309] The communication method related to the embodiments of the present disclosure can include at least one of steps S6201-S6205. For example, step S6201 can be implemented as an independent embodiment, step S6202 can be implemented as an independent embodiment, and step S6203 can be implemented as an independent embodiment, but is not limited thereto.

[0310] In some embodiments, step S6201 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0311] In some embodiments, step S6202 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0312] In some embodiments, step S6203 is optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0313] It should be noted that S6201-S6203 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0314] FIG. 7A is an interaction diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method includes:

[0315] S7101, the API caller sends a first request to the ROF.

[0316] Before the token for accessing the resource of the specific RO is requested, the API caller first searches for a first token in the security environment of the UE according to the identifier of the RO and the scope of the request.

[0317] If the API caller does not search for the first token, the API caller sends the first request to the ROF.

[0318] In some embodiments, the first request includes an API caller identifier, a resource owner identifier, and a requested scope.

[0319] The optional implementation of step S7101 can refer to the optional implementation of step S2101 of FIG. 2A and other related parts of the embodiments related to FIG. 2A, which will not be described here.

[0320] S7102, the ROF sends authorization information related to the API caller to the CCF.

[0321] If the RO allows the token exchange mechanism to be applied to multiple API callers requesting the same scope (e.g. location), the RO can provide to the CCF a list of API caller identities that are allowed to use the token exchange mechanism related to the resource owner, it should be understood that the multiple callers are targeting the same scope.

[0322] In some embodiments, the token exchange mechanism related to the resource owner means that an API caller A can provide to the CCF a token including the resource owner identity, a scope B, and an identity of another API caller C, and the CCF sends to the API caller A a token including the resource owner identity, the scope B, and the identity of the API caller A according to the received token. The token exchange mechanism only changes the API caller identity in the token.

[0323] The optional implementation of step S7102 can refer to the optional implementation of step S2102 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0324] S7103, the CCF and the RO authenticate each other.

[0325] The CCF and the RO authenticate each other through the ROF. After successful authentication, the CCF stores a first list.

[0326] The optional implementation of step S7103 can refer to the optional implementation of step S2102 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0327] S7104, the CCF sends a response related to authorization to the ROF.

[0328] In some embodiments, the response can include an authorization code.

[0329] S7105, the ROF sends a response related to authorization to the API caller.

[0330] In some embodiments, the response can include an authorization code.

[0331] S7106, the API caller sends a request related to a token to the CCF, the request including an authorization code.

[0332] S7107, the CCF sends a first token to the API caller.

[0333] In some embodiments, the CCF additionally sends a first indication to the API caller, the first indication indicating at least one of that the API caller stores the first token and that the API caller shares the first token.

[0334] The optional implementation of step S7103 can refer to the optional implementation of step S2103 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0335] S7108, the API invoker decides to store the token in the secure environment of the UE according to the storage indication of the CCF or if the access token is not obtained through the token exchange process.

[0336] The optional implementation of step S7108 can refer to the optional implementation of step S2103 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0337] FIG. 7B is an interaction diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method comprises:

[0338] S7201, the API invoker searches for the first token in the secure environment of the UE.

[0339] The optional implementation of step S7201 can refer to the optional implementation of step S2201 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0340] S7202, the API invoker sends a second request to the CCF.

[0341] The second request is used to request to obtain the second token according to the first token; the second request comprises at least one of a third token for online subscription and the first token; wherein the CCF obtains the identity of the API invoker based on the third token.

[0342] The optional implementation of step S7202 can refer to the optional implementation of step S2201 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0343] S7203, the CCF obtains the identity of the API invoker according to the third token.

[0344] The identity of the API invoker is included in the third token.

[0345] The optional implementation of step S7203 can refer to the optional implementation of step S2202 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0346] S7204, the CCF checks whether the identity of the API invoker is recorded in the first list.

[0347] The CCF of the embodiments of the present disclosure determines whether the API invoker can use a token exchange mechanism to obtain authorization related to a specific resource owner identifier by checking whether the identifier of the API invoker is recorded in the first list.

[0348] The optional implementation of step S7204 can refer to the optional implementation of step S2202 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0349] S7205, the CCF sends a second token to the API invoker.

[0350] The second token of the embodiments of the present disclosure is obtained by the CCF adding the identifier of the API invoker in the first token.

[0351] The optional implementation of step S7205 can refer to the optional implementation of step S2202 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0352] FIG. 7C is an interaction diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method comprises:

[0353] S7301, the API invoker and the CCF authenticate each other.

[0354] The CCF obtains the identifier of the API invoker.

[0355] S7302, the API invoker sends a third request to the CCF.

[0356] The optional implementation of step S7302 can refer to the optional implementation of step S2202 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0357] S7303, the CCF sends a fourth token to the API invoker.

[0358] The CCF sends a response to the API invoker, and the response contains an actor token, which can be the fourth token, the sub of the actor token declares the identifier of the authenticated API invoker, and the aud of the token contains the identifier of the CCF.

[0359] The optional implementation of step S7303 can refer to the optional implementation of step S2202 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0360] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, a device comprising units or modules for implementing the steps performed by the API caller in any of the above methods. For another example, another device is further provided, comprising units or modules for implementing the steps performed by the ROF in any of the above methods. For another example, another device is further provided, comprising units or modules for implementing the steps performed by the CCF in any of the above methods.

[0361] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of the units or modules can be integrated into one physical entity or physically separated in actual implementation. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device comprises a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of the hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship of the elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0362] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0363] FIG. 8A is a structural schematic diagram of a first communication apparatus according to an embodiment of the present disclosure. As shown in the figure, the first communication apparatus can include a processing module 8011 and a transceiver module 8012.

[0364] In some embodiments, the processing module 8011 is configured to search for a first token in a user equipment (UE) according to a first identifier and a first range requested by an API caller, the first identifier being an identifier of a resource owner (RO) for which the API caller requests authorization;

[0365] The transceiver module 8012 is configured to search for the first token, and send a second request to a common component framework (CCF), the second request including the first token, the second request being used to request a second token.

[0366] The first token includes the first identifier and a second range, and the second range includes the first range.

[0367] The second token is used to indicate that the API caller has the permission to access the range related to the RO.

[0368] FIG. 8B is a structural schematic diagram of a second communication apparatus according to an embodiment of the present disclosure. As shown in the figure, the second communication apparatus can include a transceiver 8021.

[0369] In some embodiments, the transceiver 8021 is configured to receive a first request sent by an API invoker, the first request being used to request obtaining a first token;

[0370] The first request is sent by the API invoker according to a first identifier and a first range requested, and the first token is not searched in the UE.

[0371] The first identifier is an identifier of a resource owner (RO) for which the API invoker requests authorization;

[0372] The first token includes the first identifier and a second range allowed by the RO, and the second range includes the first range.

[0373] FIG. 8C is a structural schematic diagram of a second communication apparatus according to an embodiment of the present disclosure. As shown in the figure, the second communication apparatus can include a transceiver 8031.

[0374] In some embodiments, the transceiver 8031 is configured to receive a second request sent by the API invoker;

[0375] The second request is sent by the API invoker according to a first identifier and a first range requested, and the first token is searched in the UE. The second request includes the first token, and the second request is used to request a second token. The second token is used to indicate that the API invoker has the permission to access the range related to the RO.

[0376] The first identifier is an identifier of a resource owner (RO) for which the API invoker requests authorization;

[0377] The first token includes the first identifier and a second range, and the second range includes the first range.

[0378] FIG. 9A is a structural schematic diagram of a communication device 9100 according to an embodiment of the present disclosure. The communication device 9100 can be a network device (for example, an access network device, etc.), can be an Internet of Things device, can be a chip, a chip system, or a processor supporting the network device to implement any of the above methods, and can also be a chip, a chip system, or a processor supporting the Internet of Things device to implement any of the above methods. The communication device 9100 can be used to implement the methods described in the above method embodiments, and specific reference can be made to the descriptions in the above method embodiments.

[0379] As shown in FIG. 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general processor or a special-purpose processor, etc., such as a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control a communication apparatus (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU, or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 9100 is configured to perform any of the above methods. Optionally, the one or more processors 9101 are configured to invoke instructions to cause the communication device 9100 to perform any of the above methods.

[0380] In some embodiments, the communication device 9100 further includes one or more transceivers 9102. When the communication device 9100 includes one or more transceivers 9102, the transceiver 9102 performs at least one of the communication steps (e.g., step S2101, but not limited to) in the above methods, and the processor 9101 performs at least one of the other steps (e.g., step S2102, but not limited to). In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced by each other, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[0381] In some embodiments, the communication device 9100 further includes one or more memories 9103 for storing data. Optionally, all or part of the memory 9103 can also be outside the communication device 9100. In optional embodiments, the communication device 9100 can include one or more interface circuits 9104. Optionally, the interface circuit 9104 is connected to the memory 9103, and the interface circuit 9104 can be configured to receive data from the memory 9103 or other devices, and can be configured to send data to the memory 9103 or other devices. For example, the interface circuit 9104 can read data stored in the memory 9103 and send the data to the processor 9101.

[0382] The communication device 9100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0383] FIG. 9B is a structural schematic diagram of a chip 9200 according to an embodiment of the present disclosure. For the case where the communication device 9100 is a chip or a chip system, the structural schematic diagram of the chip 9200 shown in FIG. 9B can be referred to, but is not limited thereto.

[0384] The chip 9200 includes one or more processors 9201. The chip 9200 is configured to perform any of the above methods.

[0385] In some embodiments, the chip 9200 further includes one or more interface circuits 9202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 9200 further includes one or more memories 9203 for storing data. Optionally, all or part of the memory 9203 can be outside the chip 9200. Optionally, the interface circuit 9202 is connected to the memory 9203, and the interface circuit 9202 can be configured to receive data from the memory 9203 or other devices, and the interface circuit 9202 can be configured to send data to the memory 9203 or other devices. For example, the interface circuit 9202 can read data stored in the memory 9203 and send the data to the processor 9201.

[0386] In some embodiments, the interface circuit 9202 performs at least one of the communication steps (for example, step S2101, but not limited thereto) of transmitting and / or receiving in the above methods. The interface circuit 9202 performing the communication steps such as transmitting and / or receiving in the above methods means that the interface circuit 9202 performs data interaction between the processor 9201, the chip 9200, the memory 9203, or a transceiver device. In some embodiments, the processor 9201 performs at least one of the other steps (for example, step S2102, but not limited thereto).

[0387] The present disclosure further provides a storage medium having stored instructions which, when executed on the communication device 9100, cause the communication device 9100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and can also be a storage medium readable by other apparatuses. Optionally, the storage medium can be a non-transitory storage medium, but is not limited thereto and can also be a transitory storage medium.

[0388] The present disclosure further provides a program product which, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0389] The present disclosure further provides a computer program which, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method characterized by comprising: The method is executed by an application program interface (API) invoker, and comprises: searching, according to a first identifier and a first range requested by the API invoker, a first token in a user equipment (UE), the first identifier being an identifier of a resource owner (RO) for which the API invoker requests authorization; after the first token is searched, sending a second request to a common API framework core function (CCF), the second request comprising the first token, the second request being used for requesting a second token; wherein the first token comprises the first identifier and a second range, the second range comprising the first range; the second token is used for indicating that the API invoker has the permission to access the range related to the RO.

2. The method of claim 1, wherein, The second request further comprises a third token, the third token being used for online signing.

3. The method of claim 1, wherein, The second request further comprises a fourth token, the fourth token being used for indicating an identifier of the API invoker authenticated by the CCF.

4. The method of claim 3, wherein, Further comprising: sending a third request to the CCF, the third request being used for requesting the fourth token; receiving the fourth token sent by the CCF.

5. The method according to any one of claims 1 to 4, characterized in that, Further comprising: receiving the second token sent by the CCF.

6. The method according to any one of claims 1 to 5, characterized in that, The second token is obtained by the CCF adding an identifier of the API invoker in the first token.

7. The method of claim 1, wherein, Further comprising: after the first token is not searched, sending a first request to an ROF, the first request being used for requesting the first token; receiving the first token sent by the CCF.

8. The method of claim 7, wherein, Receiving the first token sent by the CCF comprises: receiving at least one of the first token and a first indication sent by the CCF; wherein the first indication is used for at least one of indicating that the API invoker stores the first token and indicating that the API invoker shares the first token; The method further comprises: storing the first token in the UE.

9. A communication method characterized by comprising: The method is executed by an ROF, and comprises: receiving a first request sent by an API invoker, the first request being used for requesting a first token; wherein the first request is sent by the API invoker according to a first identifier and a first range requested by the API invoker, the first token not being searched in a UE; the first identifier being an identifier of a resource owner (RO) for which the API invoker requests authorization; the first token comprising the first identifier and a second range allowed by the resource owner, the second range comprising the first range.

10. The method of claim 9, wherein, Further comprising: the resource owner allowing a second token to be obtained based on the first token, sending a first list to a common API framework core function (CCF); wherein the first list comprises identifiers of at least one API invoker allowed to obtain the second token based on the first token.

11. A communication method, comprising: The method is executed by a CCF, and comprises: receiving a second request sent by an API invoker; wherein the second request is sent by the API invoker according to a first identifier and a first range requested by the API invoker, the first token being searched in a UE; the second request comprising the first token, the second request being used for requesting a second token; the second token being used for indicating that the API invoker has the permission to access the range related to the RO; The first identifier is an identifier of a resource owner (RO) for which the API caller requests authorization; The first token includes the first identifier and a second range, and the second range includes the first range.

12. The method of claim 11, wherein, The second request includes a third token, and the third token is used for online signing.

13. The method of claim 11, wherein, The second request includes a fourth token, and the fourth token is used for indicating an identifier of an API caller authenticated by the CCF.

14. The method of claim 13, wherein, Further comprising: receiving a third request sent by an API caller, the third request being used for requesting the fourth token; sending the fourth token to the API caller.

15. The method according to any one of claims 11-14, characterized in that, Further comprising: sending the second token to the API caller; The second token is used for indicating that the API caller has the permission to access a range related to the RO. The second token is obtained by the CCF from the first token by adding the identifier of the API caller.

16. The method of claim 15, wherein, Sending the second token to the API caller comprises: obtaining the first identifier from the first token; obtaining a first list related to the resource owner according to the first identifier, the first list including identifiers of at least one API caller allowed to obtain the second token based on the first token; determining that the first list includes the identifier of the API caller.

17. The method of any one of claims 11-13, wherein, Further comprising: if the first list does not include the identifier of the API caller, sending a failure message to the API caller; The first list includes identifiers of at least one API caller allowed to obtain the second token based on the first token.

18. The method of claim 11, wherein, Further comprising: receiving authorization information sent by an ROF; The authorization information includes a first list; The first list includes identifiers of at least one API caller allowed to obtain the second token based on the first token.

19. The method of claim 18, wherein, Further comprising: sending at least one of the first token and a first indication to the API caller; The first indication is used for at least one of indicating the API caller to store the first token and indicating the API caller to share the first token.

20. A first communications device, characterized by: Comprising: a processing module configured to search for a first token in a user equipment (UE) according to a first identifier and a requested first range, the first identifier being an identifier of a resource owner (RO) for which an API caller requests authorization; a transceiver module configured to search for the first token and send a second request to a common API framework core function (CCF), the second request including the first token, and the second request being used for requesting a second token; The first token includes the first identifier and a second range, and the second range includes the first range. The second token is used for indicating that the API caller has the permission to access a range related to the RO.

21. A second communications device, characterized by Comprising: a transceiver module configured to receive a first request sent by an API caller, the first request being used for requesting a first token; The first request is sent by the API caller according to a first identifier and a requested first range, and the first identifier is an identifier of a resource owner (RO) for which the API caller requests authorization. ​ The first token includes the first identity and a second range allowed by the resource owner, and the second range includes the first range.

22. A third communication device, characterized in that, Comprise: The transceiver module is configured to receive a second request sent by an API caller; The second request is sent by the API caller according to the first identity and a first range of the request, and the first token is searched in the UE; The second request includes the first token, and the second request is used to request a second token; The second token is used to indicate that the API caller has the permission to access the range related to the RO; The first identity is the identity of the resource owner RO requested by the API caller to obtain authorization; The first token includes the first identity and a second range, and the second range includes the first range.

23. A communications device, characterized by Comprise: One or more processors; The processor is configured to call instructions to enable the communication device to perform the communication method of any one of claims 1-8, 9-10, 11-19.

24. A communication system, characterized by Comprise: The API caller is configured to implement the method of any one of claims 1-8; The ROF is configured to implement the method of any one of claims 9-10; The CCF is configured to implement the method of any one of claims 11-19.

25. A storage medium, the storage medium storing instructions, wherein, When the instructions run on the communication device, the communication device executes the method of any one of claims 1-19.

26. A program product, characterized by The program product is executed by the communication device to implement the method of any one of claims 1-19.

Citation Information

Patent Citations

  • Communication method and communication device

    CN117641358A

  • Application program interface (API) calling method and device

    CN117882335A

  • Communication method and communication device

    CN117998362A

  • API calling method and device, equipment and storage medium

    CN118120176A

  • Resource calling method and device

    CN118120199A