Communication methods, API caller, ROF, CCF, communication system, and storage medium
By sending requests to ROF or CCF by API callers, context and resource owner identity information related to authorization for multiple API callers are created, solving the problem of redundant authentication for different applications on the same user device and achieving efficient authorization processes and resource utilization.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-04
- Publication Date
- 2026-04-09
AI Technical Summary
In existing technologies, when different applications on the same user device access resources related to the resource owner, they need to perform authentication and authorization separately, resulting in redundant operations and waste of wireless resources.
By having API callers send requests to ROF or CCF, instructing the creation of context and resource owner identity information related to the authorization of multiple API callers, the authorization process can be simplified and redundant authentication can be reduced.
It enables one-time authorization of different applications on the same user device, improving communication efficiency, reducing the number of repeated authentication and authorization steps, and enhancing the user experience.
Smart Images

Figure CN2024123255_09042026_PF_FP_ABST
Abstract
Description
Communication method, API invoker, ROF, CCF, communication system and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, an API invoker, a ROF, a CCF, a communication system and a storage medium. BACKGROUND
[0002] In the context of Common API Framework (CAPIF) Resource Owner Aware Northbound API Access (RNAA), a resource owner (RO) participates in authorizing API invokers (e.g., application servers, applications on user devices) to request resources (e.g., location information) related to the owner. The RO is a user / 3GPP subscriber. The user can be a natural person. The 3GPP subscriber can be a corporate entity or a natural person.
[0003] Currently, if a game application (i.e., an API invoker) wants to access location information, the RO needs to be authenticated first and then participate in the authorization process. If another API invoker on the same user device, such as a weather application, also wants to access location information, the RO needs to be authenticated and authorized again.
[0004] SUMMARY
[0005] Embodiments of the present disclosure provide a communication method, an API invoker, a ROF, a CCF, a communication system and a storage medium, the RO can perform a one-time authorization procedure to authorize multiple requests from different applications running on the same user device, the RNAA process is simplified, redundant authentication and authorization of the RO are reduced, communication efficiency is improved, and waste of wireless resources is avoided.
[0006] In a first aspect, embodiments of the present disclosure provide a communication method, executed by an API invoker, the method comprising:
[0007] sending a first request to a ROF or a Common API Framework Core Function (CCF);
[0008] wherein, when the API invoker does not obtain first information, the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information.
[0009] The first information is used to indicate at least one of an identifier of a resource owner (RO), a login state of the RO and an authentication state of the RO.
[0010] In a second aspect, the embodiments of the present disclosure provide a communication method, executed by a ROF, comprising:
[0011] receiving an authorization request sent by an API invoker;
[0012] sending a first request to a CCF;
[0013] wherein the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information when the ROF or the API invoker fails to obtain the first information;
[0014] the first information is used to indicate at least one of an identifier of a resource owner RO, a login state of the RO and an authentication state of the RO.
[0015] In a third aspect, the embodiments of the present disclosure provide a communication method, executed by a CCF, comprising:
[0016] receiving a first request sent by an API invoker or a ROF,
[0017] wherein the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information when the ROF or the API invoker fails to obtain the first information;
[0018] the first information is used to indicate at least one of an identifier of a resource owner RO, a login state of the RO and an authentication state of the RO.
[0019] In a fourth aspect, the embodiments of the present disclosure provide a first communication device, comprising:
[0020] a transceiver, configured to send a first request to a resource owner function ROF or a common API framework core function CCF;
[0021] wherein the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information when the API invoker fails to obtain the first information;
[0022] the first information is used to indicate at least one of an identifier of a resource owner RO, a login state of the RO and an authentication state of the RO.
[0023] In a fifth aspect, the embodiments of the present disclosure provide a second communication device, comprising:
[0024] a transceiver, configured to receive an authorization request sent by an API invoker, and send a first request to a CCF;
[0025] The first request is used to instruct the CCF to create at least one of the following: a context related to authorization of a plurality of API callers and the first information, when the ROF or the API caller does not obtain the first information.
[0026] The first information is used to indicate at least one of the following: an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0027] In a sixth aspect, an embodiment of the present disclosure provides a third communication device, including:
[0028] a transceiver, configured to receive a first request sent by an API caller or an ROF,
[0029] The first request is used to instruct the CCF to create at least one of the following: a context related to authorization of a plurality of API callers and the first information, when the ROF or the API caller does not obtain the first information.
[0030] The first information is used to indicate at least one of the following: an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0031] In a seventh aspect, an embodiment of the present disclosure provides a communication device, including one or more processors.
[0032] The processor is configured to invoke instructions to cause the communication device to perform the method of the first aspect, the second aspect, or the third aspect.
[0033] In an eighth aspect, an embodiment of the present disclosure provides a communication system, including an API caller, an ROF, and a CCF; the API caller is configured to implement the method of any one of the first aspect of the present disclosure; the ROF is configured to implement the method of any one of the second aspect of the present disclosure; and the CCF is configured to implement the method of any one of the third aspect of the present disclosure.
[0034] In a ninth aspect, an embodiment of the present disclosure provides a storage medium, when instructions run on a communication device, causing the communication device to perform the method of any one of the embodiments of the present disclosure.
[0035] In a tenth aspect, an embodiment of the present disclosure provides a program product, which is executed by a communication device to perform the method of any one of the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.
[0037] FIG. 1 is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure;
[0038] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure;
[0039] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure;
[0040] FIG. 3A is a flow schematic diagram of a communication method performed by an API caller according to an embodiment of the present disclosure;
[0041] FIG. 3B is a flow schematic diagram of a communication method performed by a ROF according to an embodiment of the present disclosure;
[0042] FIG. 3C is a flow schematic diagram of a communication method performed by a CCF according to an embodiment of the present disclosure;
[0043] FIG. 4A is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0044] FIG. 4B is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0045] FIG. 5A is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0046] FIG. 5B is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0047] FIG. 5C is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0048] FIG. 5D is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0049] FIG. 5E is a flow schematic diagram of a communication method performed by a communication system according to an embodiment of the present disclosure;
[0050] FIG. 6A is a structural schematic diagram of a first communication apparatus according to an embodiment of the present disclosure;
[0051] FIG. 6B is a structural schematic diagram of a second communication apparatus according to an embodiment of the present disclosure;
[0052] FIG. 6C is a structural schematic diagram of a third communication apparatus according to an embodiment of the present disclosure;
[0053] FIG. 7A is a structural schematic diagram of a communication device according to an embodiment of the present disclosure;
[0054] FIG. 7B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0055] The embodiments of the present disclosure provide a communication method, a UE, a NW, a system and a storage medium.
[0056] In a first aspect, the embodiments of the present disclosure provide a communication method, executed by an API invoker, comprising:
[0057] sending a first request to a ROF or a CCF;
[0058] When the API invoker does not obtain the first information, the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information.
[0059] The first information is used to indicate at least one of an identity of a resource owner (RO), a login state of the RO and an authentication state of the RO.
[0060] In the above embodiment, the first information is used to indicate at least one of the identity of the RO, the login state of the RO and the authentication state of the RO, and the first information can enable the API invoker to know the basic situation of the RO. If the API invoker does not obtain the first information, it indicates that the RO has not been authorized by multiple API invokers, and the first request is sent. The first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information. The API invoker can send the first request to the ROF, which further instructs the CCF to construct the first information, or directly send the first request to the CCF, thereby enhancing the flexibility of authorization.
[0061] In combination with some embodiments of the first aspect, in some embodiments, the first request comprises at least one of:
[0062] a first instruction, used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information;
[0063] an identity of the API invoker;
[0064] an identity of the RO;
[0065] a range of a request call;
[0066] authorization information, used to indicate a calling right possessed by the API invoker;
[0067] a first list, comprising at least one identity of an API invoker.
[0068] In the above embodiments, the first request can include a first indication indicating that the CCF creates at least one of a context related to multiple API caller authorizations and the first information, can include an identity of the API caller indicating an identity of the API caller, can include a scope of the request, can include authorization information indicating a calling right of the API caller, to facilitate a judgment of whether to perform authorization, and can further include a first list including at least one identity of an API caller. The API caller in the first list can be an API caller having a multiple API caller authorization, to lay a foundation for simplifying a subsequent authorization process.
[0069] In combination with some embodiments of the first aspect, in some embodiments, the API caller does not obtain the first information, and the first information is not searched for in a security environment of the UE or the ROF.
[0070] In the above embodiments, the first information can be stored in the security environment of the UE or in the ROF, to achieve diversity of storage manners. Accordingly, the API caller can search for the first information in the security environment of the UE or in the ROF. If the first information is not searched for, it is indicated that the first information is not obtained.
[0071] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:
[0072] receiving a first response sent by the ROF or the CCF;
[0073] The first response includes an authorization code and the first information.
[0074] In the above embodiments, the API caller can receive the first response sent by the ROF or the CCF, to improve flexibility of interaction. The first response includes the authorization code and the first information, and the API caller receives the first information, to lay a foundation for a subsequent authorization process after the CCF skips identity verification of the RO.
[0075] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:
[0076] storing the first information in the security environment of the UE.
[0077] In the above embodiments, the API caller further stores the first information in the security environment of the UE after receiving the first information, to provide convenience for searching for matched first information for a subsequent authorization request of another API caller.
[0078] In some embodiments of the first aspect, when the API invoker obtains the first information, the first request is configured to instruct the CCF to perform authorization of the API invoker according to the context, or to instruct the CCF to determine whether the RO needs to be authenticated according to the first information.
[0079] In the above embodiments, when the API invoker obtains the first information, the first request sent by the API invoker to the ROF or the CCF can instruct the CCF to perform authorization of the API invoker according to the context, or to instruct the CCF to determine whether the RO needs to be authenticated according to the first information, thereby laying a foundation for fast authorization or skipping authentication of the RO.
[0080] In some embodiments of the first aspect, when the first request is configured to instruct the CCF to perform authorization of the API invoker according to the context, the first request comprises at least one of the following:
[0081] a second instruction configured to instruct the CCF to perform authorization of the API invoker according to the context;
[0082] an identifier of the API invoker;
[0083] a range of the requested call;
[0084] an identifier of the RO.
[0085] In the above embodiments, the first request can comprise at least one of the second instruction, the identifier of the API invoker, the identifier of the RO, and the range of the requested call, wherein the second instruction is configured to instruct the CCF to perform authorization of the API invoker according to the context, and the identifier of the API invoker and the range of the requested call can explicitly indicate the subject and the range of the requested call.
[0086] In some embodiments of the first aspect, the API invoker obtains the first information in a security environment of the UE or in the ROF.
[0087] In some embodiments of the first aspect, the second response sent by the ROF or the CCF is received.
[0088] The second response comprises the authorization code or a message indicating that the authorization fails.
[0089] In the above embodiments, when the API invoker sends the first request, the API invoker can receive the authorization code sent by the ROF or the CCF, or can receive the message indicating that the authorization fails sent by the ROF or the CCF, so that the API invoker determines whether the authorization is successful by receiving the second response.
[0090] Secondly, embodiments of this disclosure provide a communication method executed by ROF, the method comprising:
[0091] Receive authorization requests sent by API callers;
[0092] Send the first request to the CCF;
[0093] Wherein, if the ROF or the API caller does not obtain the first information, the first request is used to instruct the CCF to create at least one of the following: a context related to the authorization of multiple API callers and the first information;
[0094] The first information is used to indicate at least one of the identifier of the resource owner (RO), the login status of the RO, and the authentication status of the RO.
[0095] In the above embodiments, the ROF can receive an authorization request sent by an API caller, and then send a first request to the CCF. When the ROF or the API caller does not obtain the first information, the first request is used to instruct the CCF to create a context related to the authorization of multiple API callers and at least one of the first information, making the use of the first request more flexible. The first information is used to indicate at least one of the RO's identifier, the RO's login status, and the RO's authentication status, thereby comprehensively representing the RO's situation.
[0096] In conjunction with some embodiments of the second aspect, in some embodiments, the first request includes at least one of the following:
[0097] The first instruction is used to instruct the CCF to create a context related to the authorization of multiple API callers and at least one of the first pieces of information;
[0098] The identifier of the API caller;
[0099] RO markings;
[0100] The scope of the requested call;
[0101] Authorization information, used to indicate the calling permissions that the API caller has;
[0102] The first list includes the identifier of at least one API caller.
[0103] In conjunction with some embodiments of the second aspect, some embodiments further include:
[0104] Receive the first response sent by the CCF;
[0105] The first response includes an authorization code and the first information.
[0106] In some embodiments of the second aspect, in some embodiments, the ROF or the API invoker does not obtain the first information in any of the following manners:
[0107] the ROF does not retrieve the first information locally in the ROF;
[0108] the API invoker does not search for the first information in a secure environment of the UE or the ROF.
[0109] In some embodiments of the second aspect, in some embodiments, the ROF or the API invoker obtains the first information in that the API invoker does not search for the first information in a secure environment of the UE or the ROF;
[0110] The authorization request is used to indicate that the CCF creates at least one of the context related to the authorization of the plurality of API invokers and the first information, or the authorization request includes a first indication, and the first indication is used to indicate that the CCF creates at least one of the context related to the authorization of the plurality of API invokers and the first information.
[0111] The authorization request of the embodiments of the present disclosure can directly indicate that the CCF creates at least one of the context related to the authorization of the plurality of API invokers and the first information, or the first indication carried by the authorization request indicates the above information.
[0112] In some embodiments of the second aspect, in some embodiments, the first request is used to indicate that the CCF performs authorization of the API invoker according to the context, and the first request includes at least one of the following:
[0113] a second indication, and the second indication is used to indicate that the CCF performs authorization of the API invoker according to the context;
[0114] an identifier of the API invoker;
[0115] a range of the request call;
[0116] an identifier of the RO.
[0117] In some embodiments of the second aspect, in some embodiments, the method further includes:
[0118] receiving a second response sent by the CCF;
[0119] The second response includes the authorization code or a message indicating that the authorization fails.
[0120] In some embodiments of the second aspect, in some embodiments, the ROF or the API invoker obtains the first information in any of the following manners:
[0121] The ROF locally retrieves the first information at the ROF.
[0122] The API invoker searches for the first information in a secure environment of the UE or the ROF.
[0123] The ROF or the API invoker acquires the first information, and the API invoker searches for the first information in a secure environment of the UE or the ROF.
[0124] The authorization request is used to indicate that the CCF performs authorization of the API invoker according to the context, or the authorization request includes a second indication, and the second indication is used to indicate that the CCF performs authorization of the API invoker according to the context.
[0125] In a third aspect, the embodiments of the present disclosure provide a communication method, performed by a CCF, and the method comprises:
[0126] receiving a first request sent by an API invoker or an ROF,
[0127] When the ROF or the API invoker does not acquire the first information, the first request is used to instruct the CCF to create at least one of the context related to authorization of a plurality of API invokers and the first information.
[0128] The first information is used to indicate at least one of an identifier of an RO, a login state of the RO, and an authentication state of the RO.
[0129] In the above embodiments, the CCF receives a first request sent by an API invoker or an ROF, and when the ROF or the API invoker does not acquire the first information, the first request is used to instruct the CCF to create at least one of the context related to authorization of a plurality of API invokers and the first information; and the first information is used to indicate at least one of an identifier of an RO, a login state of the RO, and an authentication state of the RO, so that the CAPIF supports the RO to perform a one-time identity verification and authorization process for a plurality of token requests from different application programs running on the same UE. This means that the RO only needs to perform a login and authorization operation once to generate and authorize tokens for all related application programs, without the need to perform identity verification and authorization for each application program separately. This improves the user experience and reduces the number of repeated identity verification and authorization processes.
[0130] In combination with some embodiments of the third aspect, in some embodiments, the method further comprises:
[0131] creating the first information.
[0132] In combination with some embodiments of the third aspect, in some embodiments, the method further comprises:
[0133] sending a first response to the API invoker or the ROF;
[0134] The first response includes an authorization code and the first information.
[0135] In some embodiments of the third aspect, in some embodiments, the first request includes at least one of:
[0136] a first indication, indicating that the CCF creates at least one of a context related to a plurality of API invoker authorizations and the first information;
[0137] an identity of the API invoker;
[0138] an identity of the RO;
[0139] a scope of a request call;
[0140] authorization information, indicating a calling right that the API invoker has;
[0141] a first list, including an identity of at least one API invoker.
[0142] In some embodiments of the third aspect, in some embodiments, further including:
[0143] establishing a mapping relationship between at least two of the first information, the authorization information, and the first list.
[0144] In some embodiments of the third aspect, in some embodiments, when the ROF or the API invoker does not obtain the first information, any one of the following is used:
[0145] the ROF does not search for the first information locally in the ROF;
[0146] the API invoker does not search for the first information in a secure environment of the UE or the ROF.
[0147] In some embodiments of the third aspect, in some embodiments, when the ROF or the API invoker obtains the first information, the first request is used to indicate that the CCF performs authorization of the API invoker according to the context, or to indicate that the CCF judges whether the RO needs to be authenticated according to the first information.
[0148] In some embodiments of the third aspect, in some embodiments, when the first request is used to indicate that the CCF performs authorization of the API invoker according to the context, the first request includes at least one of:
[0149] a second indication, indicating that the CCF performs authorization of the API invoker according to the context;
[0150] an identity of the API invoker;
[0151] a scope of the request call;
[0152] an identity of the RO.
[0153] In the above embodiment, since the ROF obtains the first information, the ROF does not need to send the first list and the authorization information.
[0154] In combination with some embodiments of the third aspect, in some embodiments, further comprising:
[0155] sending a second response to the API invoker or the ROF;
[0156] wherein the second response comprises the authorization code or a message indicating authorization failure.
[0157] In combination with some embodiments of the third aspect, in some embodiments, the message indicating authorization failure is determined by the CCF according to at least one of:
[0158] an identity of the RO having a mapping relationship with the first list is inconsistent with the identity of the RO provided by the API invoker;
[0159] the first information indicates that a login state of the RO corresponding to the identity of the RO provided by the API invoker is not a login-in state;
[0160] the first information indicates that the CCF does not authenticate the RO corresponding to the identity of the RO provided by the API invoker;
[0161] the identity of the API invoker is not in the first list;
[0162] the authorization information indicates that the API invoker is not authorized;
[0163] wherein the first list and the authorization information are sent by the ROF when the ROF or the API invoker does not obtain the first information.
[0164] In the above embodiment, the CCF can determine whether authorization fails according to the first list, the login state of the RO, the authentication state and the authorization information, thereby improving flexibility and accuracy of determining authorization failure.
[0165] In combination with some embodiments of the third aspect, in some embodiments, the ROF or the API invoker obtains the first information in any of the following ways:
[0166] the ROF locally retrieves the first information in the ROF;
[0167] The API caller searches for the first information in a security environment of the UE or the ROF.
[0168] In a fourth aspect, an embodiment of the present disclosure provides a first communication device, including:
[0169] a transceiver configured to send a first request to a resource owner function (ROF) or a common API framework core function (CCF);
[0170] When the API caller does not obtain the first information, the first request is configured to instruct the CCF to create at least one of a context related to authorization of a plurality of API callers and the first information.
[0171] The first information is configured to indicate at least one of an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0172] In a fifth aspect, an embodiment of the present disclosure provides a second communication device, including:
[0173] a transceiver configured to receive an authorization request sent by an API caller, and send a first request to a CCF;
[0174] When the ROF or the API caller does not obtain the first information, the first request is configured to instruct the CCF to create at least one of a context related to authorization of a plurality of API callers and the first information.
[0175] The first information is configured to indicate at least one of an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0176] In a sixth aspect, an embodiment of the present disclosure provides a third communication device, including:
[0177] a transceiver configured to receive a first request sent by an API caller or an ROF,
[0178] When the ROF or the API caller does not obtain the first information, the first request is configured to instruct the CCF to create at least one of a context related to authorization of a plurality of API callers and the first information.
[0179] The first information is configured to indicate at least one of an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0180] In a seventh aspect, an embodiment of the present disclosure provides a communication device, including one or more processors.
[0181] The processor is configured to invoke instructions to enable the communication device to perform the method of the first aspect, the second aspect, or the third aspect.
[0182] In an eighth aspect, a storage medium is provided, which, when instructions are executed on a communication device, causes the communication device to perform the method of any of the embodiments of the present disclosure.
[0183] In a ninth aspect, a program product is provided, which, when executed by a communication device, causes the communication device to perform the method of any of the embodiments of the present disclosure.
[0184] It can be understood that the API invoker, the ROF, the CCF, the communication system, the storage medium, the program product, the computer program, the chip, or the chip system are all configured to perform the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved by the above-mentioned API invoker, the ROF, the CCF, the communication system, the storage medium, the program product, the computer program, the chip, or the chip system can refer to the beneficial effects in the corresponding method, which will not be described here again.
[0185] The embodiments of the present disclosure provide a communication method, an API invoker, a ROF, a CCF, a communication system, and a storage medium. In some embodiments, the terms of the communication method, the signal sending method, the wireless frame sending method, and the authorization method can be replaced with each other, and the terms of the information processing system and the communication system can be replaced with each other.
[0186] The embodiments of the present disclosure are not exhaustive, but are only a part of the embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or part or all of the steps of different embodiments can be combined arbitrarily, and an embodiment can be combined with the optional implementation manners of other embodiments.
[0187] In the embodiments of the present disclosure, the terms and / or descriptions of the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form a new embodiment according to the logical relationship thereof.
[0188] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0189] In the embodiments of the present disclosure, “a plurality of” refers to two or more.
[0190] In some embodiments, the terms "at least one of," "one or more of," "a plurality of," "multiple," and the like can be used interchangeably.
[0191] In some embodiments, the recitations "at least one of A, B," "A and / or B," "in one case A, in another case B," "in response to a case A, in response to a case B," and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B (A and B are executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0192] In some embodiments, the recitations "A or B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0193] In the embodiments of the present disclosure, the prefix words "first", "second", and the like are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an unnecessary limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor do they limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.
[0194] In some embodiments, "include A", "contain A", "for indicating A", "carry A" can be interpreted as directly carrying A, or indirectly indicating A.
[0195] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0196] In some embodiments, the terms "greater than", "less than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.
[0197] In some embodiments, the apparatus and device can be interpreted as physical or virtual, and the name thereof is not limited to the name described in the embodiments, and in some cases can also be understood as "equipment", "device", "circuit", "device", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like.
[0198] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.
[0199] In some embodiments, the terms "terminal," "terminal device," "user equipment," "user terminal," "mobile station," "mobile terminal," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and the like can be used interchangeably.
[0200] In some embodiments, an access network device, or a network device can be replaced with a terminal. For example, for a structure in which communication between an access network device, or a network device and a terminal is replaced with communication between a plurality of terminals (for example, also referred to as device-to-device (D2D), vehicle-to-everything (V2X), and the like), embodiments of the present disclosure can also be applied. In this case, a structure in which a terminal has all or part of the functions of an access network device can also be provided. Furthermore, the language of "uplink," "downlink," and the like can also be replaced with language corresponding to communication between terminals (for example, "side"). For example, an uplink channel, a downlink channel, and the like can be replaced with a side channel, and an uplink, a downlink, and the like can be replaced with a sidelink.
[0201] In some embodiments, a terminal can be replaced with an access network device, or a network device. In this case, a structure in which an access network device, or a network device has all or part of the functions of a terminal can also be provided.
[0202] In some embodiments, the terms “uplink”, “uplink”, “physical uplink” and the like can be replaced with each other, the terms “downlink”, “downlink”, “physical downlink” and the like can be replaced with each other, and the terms “side”, “sidelink”, “sidelink communication”, “sidelink communication”, “direct connection”, “direct connection link”, “direct connection communication”, “direct connection link communication” and the like can be replaced with each other.
[0203] In some embodiments, the terms “downlink control information (DCI)”, “downlink (DL) assignment”, “DL DCI”, “uplink (UL) grant”, “UL DCI” and the like can be replaced with each other.
[0204] In some embodiments, the terms “physical downlink shared channel (PDSCH)”, “DL data” and the like can be replaced with each other, and the terms “physical uplink shared channel (PUSCH)”, “UL data” and the like can be replaced with each other.
[0205] In some embodiments, “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” and the like can be replaced with each other, and can be interpreted as receiving from other subjects, obtaining from protocols, obtaining by oneself, implementing autonomously and the like.
[0206] In some embodiments, the terms “send”, “transmit”, “report”, “issue”, “transmit”, “bidirectional transmission”, “send and / or receive” and the like can be replaced with each other.
[0207] In some embodiments, “predetermined” and “preset” can be interpreted as being previously specified in protocols and the like, or can be interpreted as being previously set by devices and the like.
[0208] In some embodiments, the acquisition of data, information and the like can comply with the laws and regulations of the country where the device is located.
[0209] In some embodiments, data, information and the like can be acquired after obtaining the consent of the user.
[0210] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of elements, rows, and columns can also be implemented as an independent embodiment.
[0211] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1, the communication system 100 includes a terminal 101 and a network device 102.
[0212] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like, but is not limited thereto. The terminal 101 can run the ROF and one or more API callers.
[0213] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.
[0214] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, but is not limited thereto.
[0215] In some embodiments, the core network device can be one device, or a plurality of devices or device groups. The core network device can include one or more network elements, which can be virtual or physical. The core network includes, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0216] The CCF of the embodiments of the present disclosure is a function in CAPIF, which can be deployed by an operator, and the CCF can be regarded as part of the core network. In some embodiments, CAPIF can also be deployed by a third party (for example, a third party enterprise), at this time, the CCF is not part of the core network.
[0217] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed in the embodiments of the present disclosure are also applicable to similar technical problems.
[0218] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1, or part of the main bodies, but are not limited thereto. The main bodies shown in FIG. 1 are illustrative, and the communication system can include all or part of the main bodies in FIG. 1, or other main bodies other than those in FIG. 1. The number and form of each main body is arbitrary, and the connection relationship between the main bodies is illustrative. The main bodies can be connected or not connected, and the connection can be in any manner, can be direct or indirect, and can be wired or wireless.
[0219] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), 5G-Advanced (5G-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, or the like. Further, a plurality of systems can be combined (for example, combination of LTE or LTE-A and 5G, or the like).
[0220] In the context of Common API Framework (CAPIF) Resource Owner Aware Northbound API Access (RNAA), a Resource Owner (RO) participates in authorizing API invokers (e.g., application servers, applications on user equipment) requests for resources related to the owner (e.g., location information). The RO is a user / 3GPP subscriber. The user can be a natural person. The 3GPP subscriber can be a corporate entity or a natural person.
[0221] Currently, if a game application (i.e., API invoker) wants to access location information, the RO needs to be authenticated first and then participate in the authorization process. If another API invoker on the same user equipment, for example, a weather application, also wants to access location information, the RO needs to be authenticated and authorized again.
[0222] If the RO can perform a one-time authentication and authorization procedure to authorize multiple token requests from different applications running on the same UE, the commercialization process of RNAA will be much smoother.
[0223] FIG. 2A is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2A, the present embodiment relates to a communication method for a communication system 100, the method comprising:
[0224] S2101, the API invoker sends a first request.
[0225] In some embodiments, the API invoker searches for first information before sending the first request. Illustratively, the API invoker can search for the first information in a secure environment of the UE or in a ROF.
[0226] In some embodiments, the first information is used to indicate at least one of an identity of the RO, a login status of the RO, and an authentication status of the RO. The authentication status is that the RO has been authenticated or the RO has not been authenticated. In some embodiments, the login status of the RO can be a login status of the RO at a CCF. The authentication status of the RO can be an authentication status of the RO at a CCF.
[0227] In some embodiments, the login status of the RO indicates that the RO proves his / her identity by providing credentials, passwords, etc. to the CCF, thereby achieving login and presenting a logged-in status. After login, the RO can log out from the CCF, thereby presenting a logged-out status. The login status of the RO is used to indicate the logged-in status of the RO or the logged-out status of the RO.
[0228] In some embodiments, the authentication of the RO refers to the RO proving its identity to the CCF by providing credentials, passwords, etc., so that the CCF authenticates the RO and presents an authenticated state. After authenticating the RO, the CCF can change the RO from the authenticated state to the unauthenticated state due to the security policy setting for a period of time, the RO choosing to log out, or the RO failing to communicate with the CCF for a long time. The authentication state of the RO is used to indicate the authenticated state of the RO or the unauthenticated state of the RO.
[0229] In some embodiments, the first information is used to indicate at least one of the identity of the RO, the login state of the RO, and the authentication state of the RO. The authentication state refers to whether the RO has been authenticated or not.
[0230] If the first information indicates that the RO has logged in or has been authenticated by the CCF, the CCF will no longer authenticate the RO. If the first information indicates that the RO has not logged in or has not been authenticated by the CCF, the CCF will authenticate the RO.
[0231] If the ROF obtains the first information, the RO does not need to send the first list and the authorization information to the CCF through the ROF.
[0232] In some embodiments, the first information can include a hash value of at least one of the identity of the RO, the login state of the RO, and the authentication state of the RO. Such a design can ensure the uniqueness and security of the first information, because it combines the identity of the resource owner and their state. In this way, the CCF can verify whether the first request of the API caller is based on a valid resource owner identity and the current state. At the same time, using the hash value also helps to protect privacy, because it does not directly expose sensitive information of the resource owner.
[0233] In some embodiments, the first information can include at least one of the identity of the RO, the login state of the RO, and the authentication state of the RO. Such a design directly includes the identity information and the state of the resource owner, making the verification process more intuitive. In actual applications, the security and ease of use need to be balanced, and the most suitable design scheme for the current scenario is selected.
[0234] The information indicated by the first request of the embodiment of the disclosure is related to whether the API invoker obtains the first information. It should be understood that the API invoker does not obtain the first information means that the API invoker does not obtain the first information in the security environment of the UE and the ROF locally; the API invoker obtains the first information means that the API invoker obtains the first information in the security environment of the UE or the ROF.
[0235] In some embodiments, when the API invoker does not obtain the first information, the first request is used to indicate that the CCF creates at least one of the context related to the multiple API invoker authorizations and the first information. Exemplarily, the first request includes at least one of the following:
[0236] The first indication is used to indicate that the CCF creates at least one of the context related to the multiple API invoker authorizations and the first information;
[0237] The identity of the API invoker;
[0238] The scope of the request call;
[0239] The identity of the RO;
[0240] The authorization information is used to indicate the calling authority that the API invoker has;
[0241] The first list includes the identity of at least one API invoker.
[0242] In some embodiments, the context includes at least one of the following: the first information, the authorization information, and the first list.
[0243] The CCF of the embodiment of the disclosure can authorize the API invoker in the first list by using the multiple API invoker authorization mechanism. In some embodiments, the multiple API invoker authorization mechanism means that the CCF can authorize the API invoker in the first list according to the authorization information sent by the ROF to the CCF on the condition that the first information indicates that the RO has logged in or has been authenticated.
[0244] In some embodiments, if the API invoker is not in the first list, the CCF of the embodiment of the disclosure cannot authorize the API invoker by using the multiple API invoker authorization mechanism. In some embodiments, the multiple API invoker authorization mechanism means that the CCF can authorize the API invoker in the first list according to the authorization information sent by the ROF to the CCF on the condition that the first information indicates that the RO has logged in or has been authenticated.
[0245] In some embodiments, when the API invoker obtains the first information, the first request is used to instruct the CCF to authorize the API invoker according to the context, or to instruct the CCF to determine whether the RO needs to be authenticated according to the first information.
[0246] In some embodiments, under the condition that the first information indicates that the RO has logged in or has been authenticated, the CCF can not authenticate the RO or can bypass the authentication of the RO.
[0247] In some embodiments, when the first request is used to instruct the CCF to authorize the API invoker according to the context, the first request includes at least one of the following:
[0248] a second indication, the second indication being used to instruct the CCF to authorize the API invoker according to the context;
[0249] an identity of the API invoker;
[0250] an identity of the RO;
[0251] a scope of the request call.
[0252] There are two ways for the API invoker to send the first request in the embodiments of the present disclosure:
[0253] In the first way, the API invoker sends the first request to the ROF;
[0254] In the second way, the API invoker sends the first request to the CCF.
[0255] For the first way, it means that the ROF receives the first request, and the ROF further sends the first request to the CCF according to the indication of the API invoker. In some embodiments, the request name when the ROF sends the first request to the CCF can be different from the name of the first request sent by the API invoker to the ROF.
[0256] For the second way, it means that the CCF directly receives the first request sent by the API invoker.
[0257] S2102, the CCF sends a first response or a second response.
[0258] Before step S2102, the CCF receives the first request sent by the API invoker, or the first request sent by the ROF.
[0259] In some embodiments, when the first request is used to instruct the CCF to create at least one of the context related to the authorization of multiple API invokers and the first information, the CCF creates the first information, and sends the first response to the API invoker or the ROF, the first response including an authorization code and the first information.
[0260] In some embodiments, the first information created by the CCF can be used for single sign-on of the RO. Specifically, API invoker 1 needs to use an authorization flow involving the RO because it needs to access resources related to the RO. API invoker 1 sends a first request to the ROF, and the RO authenticates and / or authorizes with the CCF through the ROF. During the authentication process, the CCF can obtain the identity information of the RO. During the authorization process, the RO agrees or disagrees with the first request of API invoker 1 with the authenticated identity. In order to facilitate API invoker 2 to use the same RO to participate in authorization, the login or authentication process of the RO can be omitted. After the first authentication of the RO, the CCF can record the record of the RO having been authenticated or logged in, and generate a first information. The first information can be an index of the record of the authentication or login state of the RO. Specifically, the index can be a hash value of the record. The CCF sends the first information to API invoker 1 or the terminal where API invoker 1 is located or the ROF of the terminal where API invoker 1 is located. At this time, API invoker 2 or the ROF can use the first information. Then, API invoker 2 can directly carry the first information in the first request, or the ROF carries the first information in the request to the CCF after receiving the first request of API invoker 2, so that the CCF queries the RO having been authenticated or logged in through the first information, and does not need to authenticate the RO. After obtaining the first information and confirming that the RO has authenticated or logged in the CCF, the authorization information or agreement information sent by the ROF is considered as the authorization information or agreement information sent by the RO.
[0261] In some embodiments, if the first information indicates that the state of the RO corresponding to the RO identifier provided by the API invoker is an authenticated state, the CCF considers that the RO agrees with the authorization request related to the RO sent by the API invoker. For example, if the first information indicates that the state of the RO corresponding to the RO identifier provided by the API invoker is an authenticated state, and the authorization request initiated by the RO is a request to access the location information of the RO, then the CCF considers that the request of API invoker to access the location information of the RO has been agreed by the RO.
[0262] In some embodiments, if the first information indicates that the state in the RO corresponding to the RO's identity provided by the API invoker is a log in state, the CCF considers that the RO agrees to the authorization request related to the RO sent by the API invoker. For example, if the first information indicates that the state in the RO corresponding to the RO's identity provided by the API invoker is a log in state, and the authorization request initiated by the RO is a request for accessing the location information of the RO, the CCF considers that the request of the API invoker for accessing the location information of the RO has been agreed by the RO.
[0263] In some embodiments, the CCF further establishes a mapping relationship between at least two of the first information, the authorization information and the first list, for example, a mapping relationship between the first information and the authorization information, a mapping relationship between the first information and the first list, a mapping relationship between the authorization information and the first list, and a mapping relationship between the first information, the authorization information and the first list.
[0264] In some embodiments, when the first request is used to indicate that the CCF authorizes the API invoker according to the context, or to indicate that the CCF judges whether the RO needs to be authenticated according to the first information, the CCF sends a second response to the API invoker or the ROF; wherein the second response includes the authorization code or a message indicating that the authorization fails.
[0265] In some embodiments, the CCF determines that the authorization fails according to at least one of the following:
[0266] 1) The identity of the RO having a mapping relationship with the first list is inconsistent with the identity of the RO provided by the API invoker
[0267] After obtaining the first request containing the authorization information and the first list, the CCF establishes a mapping relationship between the first information, the authorization information and the first list. If it is found that the identity of the RO having a mapping relationship with the first list is inconsistent with the identity of the RO provided by the API invoker, it means that the RO does not authorize the API invoker's permission, and therefore the CCF determines that the authorization fails;
[0268] 2) The first information indicates that the login state in the RO corresponding to the RO's identity provided by the API invoker is not a log in state
[0269] In some embodiments, the API invoker provides the identity of the RO to the CCF through the ROF;
[0270] In some embodiments, the API invoker directly provides the identity of the RO to the CCF;
[0271] In some embodiments, if the first information indicates that the login state of the RO corresponding to the RO identification provided by the API invoker is not in the login state, it generally means that the RO is in the offline state, and the RO does not have the objective condition to provide the permission to the API invoker, and thus it is determined that the authorization fails.
[0272] In some embodiments, if the first information indicates that the login state of the RO corresponding to the RO identification provided by the API invoker is not in the login state, it generally means that the RO is in the offline state, and the RO does not have the objective condition to provide the permission to the API invoker, and thus it is determined that the authorization fails.
[0273] In some embodiments, the RO provides the authorization information to the CCF only when the RO is in the login state, the CCF saves the authorization information when the RO is in the login state, and the CCF does not save the authorization information when the RO is in the offline state, and thus it is determined that the authorization fails when the RO is in the offline state.
[0274] In some embodiments, if the first information indicates that the state of the RO corresponding to the RO identification provided by the API invoker is not in the login state, it is determined that the authorization fails.
[0275] In some embodiments, if the first information indicates that the state of the RO corresponding to the RO identification provided by the API invoker is not in the login state and the authorization requested by the API invoker is related to the RO, it is determined that the authorization fails, wherein the authorization requested by the API invoker is related to the RO means that the API invoker directly sends the RO identification to the CCF, or the API invoker sends the RO identification to the CCF through the ROF, or if the API invoker is authorized, the token sent by the CCF to the API invoker needs to include the RO identification.
[0276] 3) The authentication state indicated by the first information indicates that the CCF does not authenticate the RO corresponding to the RO identification provided by the API invoker.
[0277] In some embodiments, the API invoker provides the RO identification to the CCF through the ROF.
[0278] In some embodiments, the API invoker directly provides the RO identification to the CCF.
[0279] In some embodiments, if the authentication state indicated by the first information indicates that the CCF does not authenticate the RO corresponding to the RO identification provided by the API invoker, it generally means that the RO does not support the multi-API invoker authorization mechanism for CAPIF, and thus it is determined that the authorization fails.
[0280] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API caller is not the authentication state, it generally means that the RO is in the unauthenticated state. Since the RO is in the unauthenticated state, the CCF does not have the authorization policy provided by the RO locally, and therefore determines that the authorization fails;
[0281] In some embodiments, the RO provides the authorization information to the CCF only when the RO is in the authentication state, and the CCF saves the authorization information when the RO is in the authentication state, while the CCF does not save the authorization information when the RO is in the unauthenticated state. If the RO is in the unauthenticated state, the CCF determines that the authorization fails;
[0282] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API caller is not the authentication state, the CCF determines that the authorization fails;
[0283] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API caller is not the authentication state, and the authorization requested by the API caller is related to the RO, the CCF determines that the authorization fails. The authorization requested by the API caller being related to the RO means that the API caller directly sends the identification of the RO to the CCF, or the API caller sends the identification of the RO to the CCF through the ROF, or if the API caller is authorized, the identification of the RO needs to be included in the token sent by the CCF to the API caller;
[0284] 4) The identification of the API caller is not in the first list;
[0285] 5) The authorization information indicates that the API caller is not authorized.
[0286] In some embodiments, the CCF can directly send the first response or the second response to the API caller, or send the first response or the second response to the ROF, and then the ROF sends the first response or the second response to the API caller.
[0287] In some embodiments, the API caller can receive the first response sent by the CCF or the ROF, or receive the second response sent by the CCF or the ROF.
[0288] In some embodiments, after receiving the first information, the API caller stores the first information in the security environment of the UE.
[0289] To enable CAPIF to support a resource owner (RO) to perform a single sign-on and authorization procedure for multiple token requests from different applications running on the same UE. This means that the RO only needs to perform a login and authorization operation once, and CAPIF can generate and authorize tokens for all related applications without the RO having to perform individual authentication and authorization for each application. This improves the user experience and reduces the number of repeated authentication and authorization procedures.
[0290] FIG. 2B is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2B, the embodiment of the present disclosure relates to a communication method for the communication system 100, and the method comprises:
[0291] S2201, the ROF sends a first request.
[0292] In some embodiments, the API invoker sends an authorization request to the ROF.
[0293] In some embodiments, the authorization request includes an API invoker ID, a resource owner ID, and a requested scope.
[0294] The ROF searches for first information in a secure environment of the UE or the ROF, and the first information is used to indicate at least one of an identity of the RO, a login state of the RO, and an authentication state of the RO. The authentication state is that the RO has been authenticated or the RO has not been authenticated. In some embodiments, the login state of the RO can be a login state of the RO at the CCF. The authentication state of the RO can be an authentication state of the RO at the CCF.
[0295] In some embodiments, the login state of the RO indicates that the RO proves its identity by providing credentials, passwords, etc. to the CCF, thereby achieving login and presenting a logged-in state. After login, the RO can log out of the CCF, thereby presenting a logged-out state. The login state of the RO is used to indicate the logged-in state of the RO or the logged-out state of the RO.
[0296] In some embodiments, the authentication of the RO refers to the RO proving its identity to the CCF by providing credentials, passwords, etc., so as to realize the authentication of the RO by the CCF and present an authenticated state. After authenticating the RO, the CCF can change the RO from the authenticated state to an unauthenticated state due to a security policy setting to expire after a certain time, or the RO choosing to log out, or the RO being unable to communicate with the CCF for a long time. The authentication state of the RO is used to indicate the authenticated state of the RO or the unauthenticated state of the RO.
[0297] In some embodiments, the first information is used to indicate at least one of the identity of the RO, the login state of the RO, and the authentication state of the RO. The authentication state refers to whether the RO has been authenticated or not.
[0298] If the first information indicates that the RO has logged in or has been authenticated by the CCF, the CCF will no longer authenticate the RO. If the first information indicates that the RO has not logged in or has not been authenticated by the CCF, the CCF will authenticate the RO.
[0299] If the ROF obtains the first information, the RO does not need to send the first list and the authorization information to the CCF through the ROF.
[0300] In some embodiments, the first information can include a hash value of at least one of the identity of the RO, the login state of the RO, and the authentication state of the RO. Such a design can ensure the uniqueness and security of the first information, because it combines the identity of the resource owner and their state. In this way, the CCF can verify whether the first request of the API caller is based on a valid resource owner identity and the current state. At the same time, using a hash value also helps to protect privacy, because it does not directly expose sensitive information of the resource owner.
[0301] In some embodiments, the first information can include at least one of the identity of the RO, the login state of the RO, and the authentication state of the RO. Such a design directly includes the identity information and state of the resource owner, making the verification process more intuitive. In actual applications, the security and ease of use need to be balanced, and the design scheme that is most suitable for the current scenario is selected.
[0302] The information indicated by the first request of the present embodiment is related to whether the API caller obtains the first information. It should be understood that the API caller not obtaining the first information means that the API caller does not obtain the first information in the secure environment of the UE and locally in the ROF; and the API caller obtaining the first information means that the API caller obtains the first information in the secure environment of the UE or in the ROF.
[0303] In some embodiments, when the ROF does not obtain the first information, the first request is configured to instruct the CCF to create at least one of the context related to the multiple API invoker authorizations and the first information. Exemplarily, the first request comprises at least one of the following:
[0304] a first instruction, configured to instruct the CCF to create at least one of the context related to the multiple API invoker authorizations and the first information;
[0305] an identification of the API invoker;
[0306] an identification of the RO;
[0307] a scope of the request invocation;
[0308] authorization information, configured to indicate a calling right that the API invoker has;
[0309] a first list, comprising an identification of at least one API invoker.
[0310] In some embodiments, the context comprises at least one of the following: the first information, the authorization information, and the first list.
[0311] In some embodiments, when the ROF does not obtain the first information, the authorization request is configured to instruct the CCF to create at least one of the context related to the multiple API invoker authorizations and the first information, or the authorization request comprises a first instruction, configured to instruct the CCF to create at least one of the context related to the multiple API invoker authorizations and the first information.
[0312] The CCF of the embodiments of the present disclosure can authorize the API invokers in the first list by using a multiple API invoker authorization mechanism. In some embodiments, the multiple API invoker authorization mechanism refers to that the CCF can authorize the API invokers in the first list according to the authorization information sent by the ROF to the CCF, on the condition that the first information indicates that the RO has logged in or has been authenticated.
[0313] In some embodiments, if an API invoker is not in the first list, the CCF of the embodiments of the present disclosure can not authorize the API invoker by using the multiple API invoker authorization mechanism. In some embodiments, the multiple API invoker authorization mechanism refers to that the CCF can authorize the API invokers in the first list according to the authorization information sent by the ROF to the CCF, on the condition that the first information indicates that the RO has logged in or has been authenticated.
[0314] In some embodiments, when the ROF obtains the first information, the first request is used to instruct the CCF to authorize the API invoker according to the context, or to instruct the CCF to determine whether the RO needs to be authenticated according to the first information.
[0315] In some embodiments, under the condition that the first information indicates that the RO has logged in or has been authenticated, the CCF can not authenticate the RO or can bypass the authentication of the RO.
[0316] In some embodiments, when the ROF obtains the first information, the authorization request is used to instruct the CCF to authorize the API invoker according to the context, or the authorization request includes a second indication, which is used to instruct the CCF to authorize the API invoker according to the context.
[0317] In some embodiments, when the first request is used to instruct the CCF to authorize the API invoker according to the context, the first request includes at least one of the following:
[0318] a second indication, which is used to instruct the CCF to authorize the API invoker according to the context;
[0319] the identity of the API invoker;
[0320] the identity of the RO;
[0321] the scope of the request call.
[0322] In some embodiments, under the condition that the first information indicates that the RO has logged in or has been authenticated, the CCF can not authenticate the RO or can bypass the authentication of the RO.
[0323] S2202, the CCF sends a first response or a second response.
[0324] In some embodiments, when the first request is used to instruct the CCF to create at least one of the context related to the authorization of multiple API invokers and the first information, the CCF creates the first information and sends a first response to the API invoker or the ROF, and the first response includes an authorization code and the first information.
[0325] In some embodiments, the first information created by the CCF can be used for single sign-on of the RO. Specifically, API invoker 1 needs to use an authorization flow involving the RO because it needs to access resources related to the RO. API invoker 1 sends a first request to the ROF, and the RO authenticates and / or authorizes with the CCF through the ROF. During the authentication process, the CCF can obtain the identity information of the RO. During the authorization process, the RO agrees or disagrees with the first request of API invoker 1 with the authenticated identity. In order to facilitate API invoker 2 to use the same RO to participate in authorization, the login or authentication process of the RO can be omitted. After the first authentication of the RO, the CCF can record the record that the RO has been authenticated or logged in, and generate a first information. The first information can be an index of the record of the RO authentication state or login state. Specifically, the index can be a hash value of the record. The CCF sends the first information to API invoker 1 or the terminal where API invoker 1 is located or the ROF of the terminal where API invoker 1 is located. At this time, API invoker 2 or the ROF can use the first information. Then, API invoker 2 can directly carry the first information in the first request, or the ROF carries the first information in the request to the CCF after receiving the first request of API invoker 2. In this way, the CCF queries the RO has been authenticated or logged in through the first information, and does not need to authenticate the RO. After obtaining the first information and confirming that the RO has been authenticated or logged in with the CCF, the authorization information or agreement information sent by the ROF is considered as the authorization information or agreement information sent by the RO.
[0326] In some embodiments, if the first information indicates that the state of the RO corresponding to the RO identifier provided by the API invoker is an authenticated state, the CCF considers that the RO agrees with the authorization request related to the RO sent by the API invoker. For example, if the first information indicates that the state of the RO corresponding to the RO identifier provided by the API invoker is an authenticated state, and the authorization request initiated by the RO is a request to access the location information of the RO, then the CCF considers that the request of API invoker to access the location information of the RO has been agreed by the RO.
[0327] In some embodiments, if the first information indicates that the state of the RO corresponding to the RO's identity provided by the API invoker is a log in state, the CCF considers that the RO agrees to the authorization request related to the RO sent by the API invoker. For example, if the first information indicates that the state of the RO corresponding to the RO's identity provided by the API invoker is a log in state, and the authorization request initiated by the RO is a request for accessing the location information of the RO, the CCF considers that the request of the API invoker for accessing the location information of the RO has been agreed by the RO.
[0328] In some embodiments, the CCF further establishes a mapping relationship between at least two of the first information, the authorization information and the first list, for example, a mapping relationship between the first information and the authorization information, a mapping relationship between the first information and the first list, a mapping relationship between the authorization information and the first list, and a mapping relationship between the first information, the authorization information and the first list.
[0329] In some embodiments, when the first request is used to indicate that the CCF authorizes the API invoker according to the context, or to indicate that the CCF judges whether the RO needs to be authenticated according to the first information, the CCF sends a second response to the API invoker or the ROF; wherein the second response includes the authorization code or a message indicating that the authorization fails.
[0330] In some embodiments, the CCF determines that the authorization fails according to at least one of the following:
[0331] 1) The identity of the RO having a mapping relationship with the first list is inconsistent with the identity of the RO provided by the API invoker
[0332] After obtaining the first request containing the authorization information and the first list, the CCF establishes a mapping relationship between the first information, the authorization information and the first list. If it is found that the identity of the RO having a mapping relationship with the first list is inconsistent with the identity of the RO provided by the API invoker, it means that the RO does not authorize the API invoker's permission, and therefore the CCF determines that the authorization fails;
[0333] 2) The first information indicates that the login state of the RO corresponding to the identity of the RO provided by the API invoker is not a log in state
[0334] In some embodiments, the API invoker provides the identity of the RO to the CCF through the ROF;
[0335] In some embodiments, the API invoker directly provides the identity of the RO to the CCF;
[0336] In some embodiments, if the first information indicates that the login state of the RO corresponding to the identification of the RO provided by the API invoker is not in the login state, it generally means that the RO is in the offline state, and the RO does not have the objective condition to provide the authority to the API invoker, and thus it is determined that the authorization fails.
[0337] In some embodiments, if the first information indicates that the login state of the RO corresponding to the identification of the RO provided by the API invoker is not in the login state, it generally means that the RO is in the offline state, and the RO does not have the objective condition to provide the authority to the API invoker, and thus it is determined that the authorization fails.
[0338] In some embodiments, the RO provides the authorization information to the CCF only when the RO is in the login state, the CCF saves the authorization information when the RO is in the login state, and the CCF does not save the authorization information when the RO is in the offline state, and thus it is determined that the authorization fails when the RO is in the offline state.
[0339] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API invoker is not in the login state, it is determined that the authorization fails.
[0340] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API invoker is not in the login state and the authorization requested by the API invoker is related to the RO, it is determined that the authorization fails, wherein the authorization requested by the API invoker is related to the RO means that the API invoker directly sends the identification of the RO to the CCF, or the API invoker sends the identification of the RO to the CCF through the ROF, or if the API invoker is authorized, the token sent by the CCF to the API invoker needs to include the identification of the RO.
[0341] 3) The authentication state indicated by the first information indicates that the CCF has not authenticated the RO;
[0342] In some embodiments, the API invoker provides the identification of the RO to the CCF through the ROF.
[0343] In some embodiments, the API invoker directly provides the identification of the RO to the CCF.
[0344] In some embodiments, if the authentication state indicated by the first information indicates that the CCF has not authenticated the RO corresponding to the identification of the RO provided by the API invoker, it generally means that the RO does not support the multi-API invoker authorization mechanism for CAPIF, and thus it is determined that the authorization fails.
[0345] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API caller is not the authentication state, it generally means that the RO is in the unauthenticated state. Since the RO is in the unauthenticated state, the CCF does not have the authorization policy provided by the RO locally, and therefore determines that the authorization fails;
[0346] In some embodiments, the RO provides the authorization information to the CCF only when the RO is in the authentication state, and the CCF saves the authorization information when the RO is in the authentication state, while the CCF does not save the authorization information when the RO is in the unauthenticated state. If the RO is in the unauthenticated state, the CCF determines that the authorization fails;
[0347] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API caller is not the authentication state, the CCF determines that the authorization fails;
[0348] In some embodiments, if the first information indicates that the state of the RO corresponding to the identification of the RO provided by the API caller is not the authentication state, and the authorization requested by the API caller is related to the RO, the CCF determines that the authorization fails. The authorization requested by the API caller being related to the RO means that the API caller directly sends the identification of the RO to the CCF, or the API caller sends the identification of the RO to the CCF through the ROF, or if the API caller is authorized, the identification of the RO needs to be included in the token sent by the CCF to the API caller;
[0349] 4) The identification of the API caller is not in the first list;
[0350] 5) The authorization information indicates that the API caller is not authorized.
[0351] In some embodiments, the CCF can directly send the first response or the second response to the API caller, or send the first response or the second response to the ROF, and then the ROF sends the first response or the second response to the API caller.
[0352] In some embodiments, the API caller can receive the first response sent by the CCF or the ROF, or receive the second response sent by the CCF or the ROF.
[0353] In some embodiments, after receiving the first information, the API caller stores the first information in the security environment of the UE.
[0354] The CAPIF supports a resource owner (RO) to perform a one-time authentication and authorization procedure for multiple token requests from different applications running on the same UE. This means that the RO only needs to perform a login and authorization operation once, and the CAPIF can generate and authorize tokens for all related applications without the RO performing authentication and authorization for each application individually. This improves the user experience and reduces the number of repeated authentication and authorization procedures.
[0355] FIG. 3A is a flowchart of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiment of the present disclosure is performed by an API invoker, and the above method comprises:
[0356] S3101, searching for first information in a security environment of the UE or an ROF.
[0357] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.
[0358] S3102, sending a first request to the ROF or CCF.
[0359] The optional implementation of step S3102 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here
[0360] S3103, receiving a first response or a second response.
[0361] The optional implementation of step S3103 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.
[0362] The communication method involved in the embodiments of the present disclosure can comprise at least one of steps S3101-S3103. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, and step S3103 can be implemented as an independent embodiment, but is not limited thereto.
[0363] It should be noted that S3101, S3102 and S3103 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.
[0364] FIG. 3B is a flowchart of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiment of the present disclosure is performed by an ROF, and the above method comprises:
[0365] S3201, receiving an authorization request sent by an API invoker.
[0366] The optional implementation of step S3201 can refer to the optional implementation of step S2201D in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which are not described here again.
[0367] S3202, sending the first request to the CCF.
[0368] The optional implementation of step S3202 can refer to the optional implementation of step S2201 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which are not described here again.
[0369] S3203, receiving the first response or the second response sent by the CCF.
[0370] The optional implementation of step S3203 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which are not described here again.
[0371] S3204, sending the first response or the second response to the API invoker.
[0372] The optional implementation of step S3204 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which are not described here again.
[0373] The communication method involved in the embodiments of the present disclosure can include at least one of steps S3201 to S3204. For example, step S3201 can be implemented as an independent embodiment, step S3202 can be implemented as an independent embodiment, step S3203 can be implemented as an independent embodiment, and step S3204 can be implemented as an independent embodiment, but is not limited thereto.
[0374] It should be noted that S3201, S3202, S3203 and S3204 of the embodiments of the present disclosure can be exchanged in any order without contradiction and can be freely combined and implemented.
[0375] FIG. 3C is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure are performed by the ROF, and the method includes:
[0376] S3301, receiving the first request.
[0377] The optional implementation of step S3301 can refer to the optional implementation of steps S2101 in FIG. 2A, S2201 in FIG. 2B, S3101 in FIG. 3A and S3201 in FIG. 3B, and other associated parts in the embodiments involved in FIG. 2A, FIG. 2B, FIG. 3A and FIG. 3B, which are not described here again.
[0378] S3302, sending the first response or the second response.
[0379] The optional implementation of step S3302 can refer to the optional implementation of step S2102 in FIG. 2A, step S2202 in FIG. 2B, step S3103 in FIG. 3A, and step S3203 in FIG. 3B, and other associated parts in the embodiments related to FIGS. 2A, 2B, 3A, and 3B, which are not described here again.
[0380] The communication method related to the embodiments of the present disclosure can include at least one of steps S3301-S3302. For example, step S3301 can be implemented as an independent embodiment, and step S3302 can be implemented as an independent embodiment, but is not limited thereto.
[0381] It should be noted that S3201, S3202, S3203, and S3204 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.
[0382] FIG. 4A is a flow diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method includes:
[0383] S4101, the API invoker locally searches the first information in a secure environment of the UE or the ROF.
[0384] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in FIG. 2A, step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIGS. 2 and 3A, which are not described here again.
[0385] S4102, the API invoker sends the first request to the ROF.
[0386] The optional implementation of step S4102 can refer to the optional implementation of step S2101 in FIG. 2A, step S3102 in FIG. 3A, and other associated parts in the embodiments related to FIGS. 2 and 3A, which are not described here again.
[0387] S4103, the ROF sends the first request to the CCF.
[0388] The optional implementation of step S4103 can refer to the optional implementation of step S2101 in FIG. 2A, step S3202 in FIG. 3B, and other associated parts in the embodiments related to FIGS. 2A and 3B, which are not described here again.
[0389] S4104, the CCF sends the first response or the second response to the ROF.
[0390] The optional implementation of step S4104 can refer to step S2102 of FIG. 2A, the optional implementation of step S3203 of FIG. 3B, step S3302 of FIG. 3C, and other associated parts in the embodiments related to FIG. 2, FIG. 3B and FIG. 3C, which are not described here.
[0391] S4105, the ROF sends the first response or the second response to the API invoker.
[0392] The optional implementation of step S4105 can refer to step S2103 of FIG. 2A, the optional implementation of step S3103 of FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 3A, FIG. 3B and FIG. 3C, which are not described here.
[0393] The communication method related to the embodiments of the present disclosure can include at least one of steps S4101-S4105. For example, step S4101 can be implemented as an independent embodiment, step S4102 can be implemented as an independent embodiment, step S4103 can be implemented as an independent embodiment, step S4104 can be implemented as an independent embodiment, and step S4105 can be implemented as an independent embodiment, but is not limited thereto.
[0394] In some embodiments, step S4101 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0395] In some embodiments, step S4102 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0396] In some embodiments, step S4103 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0397] In some embodiments, step S4104 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0398] In some embodiments, step S4105 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0399] It should be noted that S4101-S4105 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.
[0400] FIG. 4B is a flow diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method comprises:
[0401] S4201、The API invoker sends a first request to the CCF in a secure environment of the UE or locally with the ROF.
[0402] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in FIG. 2, step S3101 in FIG. 3A, and other associated parts in the embodiments involved in FIG. 2 and FIG. 3A, which are not described here again.
[0403] S4202、The API invoker sends a first request to the CCF.
[0404] The optional implementation of step S4202 can refer to the optional implementation of step S2101 in FIG. 2, step S3102 in FIG. 3A, and other associated parts in the embodiments involved in FIG. 2 and FIG. 3A, which are not described here again.
[0405] S4203、The CCF sends a first response or a second response to the API invoker.
[0406] The optional implementation of step S4203 can refer to the optional implementation of step S2102 in FIG. 2, step S3302 in FIG. 3C, and other associated parts in the embodiments involved in FIG. 2 and FIG. 3C, which are not described here again.
[0407] The communication method involved in the embodiments of the present disclosure can include at least one of steps S4201-S4203. For example, step S4201 can be implemented as an independent embodiment, step S4202 can be implemented as an independent embodiment, step S4203 can be implemented as an independent embodiment, step S4204 can be implemented as an independent embodiment, step S4205 can be implemented as an independent embodiment, but is not limited thereto.
[0408] In some embodiments, step S4201 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0409] In some embodiments, step S4202 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0410] In some embodiments, step S4203 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0411] It should be noted that S4201-S4203 of the embodiments of the present disclosure can be arbitrarily exchanged in order and freely combined for implementation without contradiction.
[0412] FIG. 5A is an interaction diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method comprises:
[0413] S5101, the API invoker sends an authorization request to the ROF.
[0414] The authorization request can include at least one of an API invoker ID, a resource owner ID, and a requested scope.
[0415] S5102, the API invoker sends a first request to the ROF.
[0416] The ROF does not obtain the first information in the ROF local or the security environment of the UE, and the first request is used to instruct the CCF to create at least one of a context related to multiple API invoker authorizations and the first information.
[0417] The first request of the embodiment of the present disclosure includes at least one of:
[0418] A first instruction, used to instruct the CCF to create at least one of a context related to multiple API invoker authorizations and the first information;
[0419] An identification of the API invoker;
[0420] An identification of the RO;
[0421] A requested scope of a call;
[0422] Authorization information, used to indicate a calling permission that the API invoker has;
[0423] A first list, including at least one identification of an API invoker.
[0424] S5103, the CCF and the RO perform mutual identity authentication through the ROF.
[0425] If the CCF receives the first instruction, the CCF generates the first information.
[0426] The CCF constructs and maintains a mapping relationship between at least two of the first information, the identification of the RO, a login state (for example, login, logout) of the RO, and the first list.
[0427] S5104, the CCF sends an authorization-related response to the ROF.
[0428] The authorization-related response can be a first response, and the first response includes an authorization code and the first information.
[0429] S5105a, the ROF sends the authorization-related response to the API invoker.
[0430] S5105b, the ROF stores the first information in the security environment of the UE (optional).
[0431] S5106, the API invoker sends the authorization code to the CCF.
[0432] S5107, the CCF sends the token and the first information (optional) to the API invoker.
[0433] S5108, the API invoker stores the first information in the secure environment of the UE (optional).
[0434] FIG. 5B is an interaction diagram of a communication method according to an embodiment of the present disclosure, the method being performed by a communication system, the method comprising:
[0435] S5201, the API invoker sends an authorization request to the ROF.
[0436] The API invoker of the embodiment of the present disclosure sends the authorization request to the ROF.
[0437] S5202, the ROF sends a first request to the CCF.
[0438] The ROF obtains the first information in the secure environment of the UE or locally in the ROF, and sends the first request to the CCF, the first request being used to instruct the CCF to authorize the API invoker according to the context, or instruct the CCF to determine whether the RO needs to be authenticated according to the first information.
[0439] The first request comprises at least one of the following:
[0440] A second indication, the second indication being used to instruct the CCF to authorize the API invoker according to the context;
[0441] The identity of the API invoker;
[0442] The identity of the RO;
[0443] The range of the requested call.
[0444] S5203, checking the identity of the resource owner
[0445] The CCF decides to skip the identity verification and authorization process of the resource owner according to the second indication, and searches the maintained mapping relationship according to the first information to obtain the identity of the resource owner.
[0446] If the identity of the resource owner is different from the identity provided by the ROF, the CCF will send a failure message to the ROF. The failure message indicates that the identity of the resource owner requested by the API invoker is different from the identity related to the first information.
[0447] S5204, the CCF searches the maintained mapping table using the retrieved identity of the resource owner to obtain the login state of the corresponding resource owner.
[0448] If the login status indicates that the RO is logged on, the flow continues. Otherwise, the CCF sends a failure message to the API invoker. The failure message indicates that the resource owner is not logged on.
[0449] S5205, the CCF checks whether the identity of the API invoker is in the first list.
[0450] The CCF checks whether the API invoker is allowed to use the multi-API invoker authorization mechanism. Specifically, if the identity of the API invoker of the invoker is in the first list provided by the resource owner, the API invoker can use the multi-API invoker authorization mechanism, and the flow continues. Otherwise, the CCF terminates the flow. The CCF sends a failure message to the API invoker through the ROF. The failure message indicates that the API invoker cannot use the multi-API invoker authorization.
[0451] S5206, the CCF checks whether the requested scope is authorized.
[0452] The CCF checks whether the requested scope can be authorized by checking the authorization information provided by the resource owner through the authorization-related request. If the requested scope is not authorized, the CCF terminates the flow. The CCF sends a failure message to the API invoker through the ROF. The failure message indicates that the requested scope is not authorized.
[0453] S5207, if the API invoker is authorized, the CCF sends the authorization-related response to the ROF.
[0454] S5208, the ROF sends the authorization-related response to the API invoker.
[0455] S5209, the API invoker sends a token-related request to the CCF.
[0456] S5210, the CCF and the API invoker authenticate each other.
[0457] S5211, after the authentication is passed, the CCF sends a token-related response to the API invoker, and the response includes a token.
[0458] FIG. 5C is an interaction diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method includes:
[0459] S5300, the API invoker searches for first information in a secure environment of the UE.
[0460] S5301, the API invoker sends a first request to the ROF.
[0461] The API caller cannot obtain the first information from the security environment of the UE, sends a first request to the ROF, the first request being used to instruct the CCF to create at least one of a context related to authorization of multiple API callers and the first information.
[0462] The first request comprises at least one of:
[0463] a first instruction used to instruct the CCF to create at least one of a context related to authorization of multiple API callers and the first information;
[0464] an identity of the API caller;
[0465] an identity of the RO;
[0466] a scope of a request call;
[0467] authorization information used to indicate a calling right that the API caller has;
[0468] a first list comprising at least one identity of an API caller.
[0469] S5302, the ROF sends a first request to the CCF.
[0470] S5203, the CCF and the RO perform mutual identity authentication through the ROF.
[0471] If the CCF receives the first instruction, the CCF generates the first information.
[0472] The CCF constructs and maintains a mapping relationship between at least two of the first information, the identity of the RO, a login state (for example, login on the RO, logout) of the RO, and the first list.
[0473] S5204, the CCF sends an authorization-related response to the ROF.
[0474] The authorization-related response can be a first response, the first response comprising an authorization code and the first information.
[0475] S5205a, the ROF sends the authorization-related response to the API caller.
[0476] S5205b, the ROF stores the first information in the security environment of the UE (optional).
[0477] S5206, the API caller sends the authorization code to the CCF.
[0478] S5207, the CCF sends a token and the first information to the API caller (optional).
[0479] S5208, the API caller stores the first information in the security environment of the UE.
[0480] FIG. 5D is an interaction diagram of a communication method according to an embodiment of the present disclosure, the method being performed by a communication system, the method comprising:
[0481] S5400, the API invoker searches for the first information in the secure environment of the UE.
[0482] S5401, the API invoker sends a first request to the ROF.
[0483] The API invoker obtains the first information from the secure environment of the UE, sends the first request to the ROF, and the first request is used to instruct the CCF to perform authorization of the API invoker according to the context or instruct the CCF to determine whether the RO needs to be authenticated according to the first information.
[0484] The first request comprises at least one of:
[0485] A second indication, the second indication being used to instruct the CCF to perform authorization of the API invoker according to the context;
[0486] The identity of the API invoker;
[0487] The identity of the RO;
[0488] The scope of the request call.
[0489] S5402, the ROF sends the first request to the CCF.
[0490] S5403, the CCF checks the identity of the resource owner.
[0491] The CCF decides to skip the identity verification and authorization process with the resource owner according to the second indication, and obtains the identity of the resource owner by searching a maintained mapping relationship according to the first information.
[0492] If the identity of the resource owner is different from the identity provided by the ROF, the CCF will send a failure message to the ROF. The failure message indicates that the identity of the resource owner requested by the API invoker is different from the identity related to the first information.
[0493] S5404, the CCF uses the retrieved identity of the resource owner to search a maintained mapping table to obtain a login state of the corresponding resource owner.
[0494] If the login state indicates that the RO is logged in, the process continues. Otherwise, the CCF sends a failure message to the API invoker. The failure message indicates that the resource owner is not logged in.
[0495] S5405, the CCF checks whether the API invoker is in the first list.
[0496] The CCF checks whether the API invoker is allowed to use the multi-API invoker authorization. Specifically, if the identity of the API invoker of the invoker is in the first list provided by the resource owner, the API invoker can use the multi-API invoker authorization, and the process continues. Otherwise, the CCF terminates the process. The CCF sends a failure message to the API invoker through the ROF. The failure message indicates that the API invoker cannot use the multi-API invoker authorization.
[0497] S5406, the CCF checks whether the requested scope is authorized.
[0498] The CCF checks whether the requested scope is authorized by checking the authorization information provided by the resource owner through the authorization-related request. If the requested scope is not authorized, the CCF terminates the process. The CCF sends a failure message to the API invoker through the ROF. The failure message indicates that the requested scope is not authorized.
[0499] S5407, if the API invoker is authorized, the CCF sends the authorization-related response to the ROF.
[0500] S5408, the ROF sends the authorization-related response to the API invoker.
[0501] S5409, the API invoker sends a token-related request to the CCF.
[0502] S5410, the CCF and the API invoker authenticate each other.
[0503] S5411, after the authentication is passed, the CCF sends a token-related response to the API invoker, and the response includes a token.
[0504] FIG. 5E is an interaction diagram of a communication method according to an embodiment of the present disclosure, which is performed by a communication system, and the method includes:
[0505] S5501a, the API invoker searches for first information in the ROF.
[0506] S5501b, the API invoker searches for first information in the secure environment of the UE.
[0507] S5402, the API invoker sends a first request to the CCF.
[0508] The API invoker obtains the first information from the secure environment of the UE, and sends a first request to the ROF, where the first request is used to instruct the CCF to perform authorization of the API invoker according to the context, or to instruct the CCF to determine whether the RO needs to be authenticated according to the first information.
[0509] The first request includes at least one of the following:
[0510] a second indication, the second indication indicating that the CCF authorizes the API caller according to the context;
[0511] an identity of the API caller;
[0512] an identity of the RO;
[0513] a scope of the request.
[0514] S5403, the CCF checks the identity of the resource owner.
[0515] The CCF decides to skip the authentication and authorization procedure with the resource owner according to the second indication. The CCF searches the maintained mapping relationship according to the first information to obtain the identity of the resource owner.
[0516] If the identity of the resource owner is different from the identity provided by the ROF, the CCF sends a failure message to the ROF. The failure message indicates that the identity of the resource owner requested by the API caller is different from the identity related to the first information.
[0517] S5504, the CCF searches the maintained mapping table using the retrieved identity of the resource owner to obtain the login state of the corresponding resource owner.
[0518] If the login state indicates that the RO is logged in, the procedure continues. Otherwise, the CCF sends a failure message to the API caller. The failure message indicates that the resource owner is not logged in.
[0519] S5505, the CCF checks whether the API caller is in the first list.
[0520] The CCF checks whether the API caller is allowed to use the multi-API caller authorization. Specifically, if the identity of the API caller of the caller is in the first list provided by the resource owner, the API caller can use the multi-API caller authorization, and the procedure continues. Otherwise, the CCF terminates the procedure. The CCF sends a failure message to the API caller through the ROF. The failure message indicates that the API caller cannot use the multi-API caller authorization.
[0521] S5506, the CCF checks whether the scope of the request is authorized.
[0522] The CCF checks whether the scope of the request is authorized by checking the authorization information provided by the resource owner through authorization of the related request. If the scope of the request is not authorized, the CCF terminates the procedure. The CCF sends a failure message to the API caller through the ROF. The failure message indicates that the scope of the request is not authorized.
[0523] S5507、If the API caller has been authorized, the CCF sends a response related to the authorization to the ROF.
[0524] S5508、The ROF sends a response related to the token to the API caller.
[0525] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device comprising units or modules for implementing the steps performed by the API caller in any of the above methods. For another example, another device is also proposed, comprising units or modules for implementing the steps performed by the ROF in any of the above methods. For another example, another device is also proposed, comprising units or modules for implementing the steps performed by the CCF in any of the above methods.
[0526] It should be understood that the division of units or modules in the above device is only a logical function division, and all or part of them can be integrated into one physical entity, or can be physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device comprises a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is, for example, a general processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules can be implemented in the form of processor calling software, and the remaining part can be implemented in the form of hardware circuit.
[0527] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0528] FIG. 6A is a structural schematic diagram of a first communication apparatus according to an embodiment of the present disclosure. As shown in the figure, the first communication apparatus can include a transceiver module 6011.
[0529] In some embodiments, the transceiver module 6011 is configured to send a first request to a resource owner function (ROF) or a common API framework core function (CCF).
[0530] When the API invoker does not obtain the first information, the first request is configured to instruct the CCF to create at least one of a context related to multiple API invoker authorizations and the first information.
[0531] The first information is configured to indicate at least one of an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0532] FIG. 6B is a structural schematic diagram of a second communication apparatus according to an embodiment of the present disclosure. As shown in the figure, the second communication apparatus can include a transceiver module 6021.
[0533] In some embodiments, the transceiver 6021 is configured to receive an authorization request sent by an API invoker, and send a first request to the CCF;
[0534] The first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information when the ROF or the API invoker does not obtain the first information.
[0535] The first information is used to indicate at least one of an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0536] FIG. 6C is a structural schematic diagram of a second communication device according to the embodiments of the present disclosure. As shown in the figure, the second communication device can include a transceiver 6031.
[0537] In some embodiments, the transceiver 6031 is configured to receive a first request sent by an API invoker or an ROF,
[0538] The first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information when the ROF or the API invoker does not obtain the first information.
[0539] The first information is used to indicate at least one of an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO.
[0540] FIG. 7A is a structural schematic diagram of a communication device 7100 according to the embodiments of the present disclosure. The communication device 7100 can be a network device (for example, an access network device, etc.), can be an Internet of Things device, can be a chip, a chip system, or a processor supporting the network device to implement any of the above methods, and can also be a chip, a chip system, or a processor supporting the Internet of Things device to implement any of the above methods. The communication device 7100 can be used to implement the methods described in the above method embodiments, and specific reference can be made to the descriptions in the above method embodiments.
[0541] As shown in FIG. 7A, the communication device 7100 includes one or more processors 7101. The processor 7101 can be a general-purpose processor or a special-purpose processor, etc., for example, can be a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of programs. Optionally, the communication device 7100 is configured to execute any of the above methods. Optionally, the one or more processors 7101 are configured to invoke instructions to cause the communication device 7100 to execute any of the above methods.
[0542] In some embodiments, the communication device 7100 further includes one or more transceivers 7102. When the communication device 7100 includes one or more transceivers 7102, the transceiver 7102 performs at least one of the communication steps (for example, step S2101, but not limited to) in the above-described method, and the processor 7101 performs at least one of the other steps (for example, step S2102, but not limited to). In alternative embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Alternatively, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced with each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.
[0543] In some embodiments, the communication device 7100 further includes one or more memories 7103 for storing data. Alternatively, all or part of the memory 7103 can also be outside the communication device 7100. In alternative embodiments, the communication device 7100 can include one or more interface circuits 7104. Alternatively, the interface circuit 7104 is connected with the memory 7103, and the interface circuit 7104 can be used to receive data from the memory 7103 or other devices, and can be used to send data to the memory 7103 or other devices. For example, the interface circuit 7104 can read the data stored in the memory 7103 and send the data to the processor 7101.
[0544] The communication device 7100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 7100 described in the present disclosure is not limited thereto, and the structure of the communication device 7100 can not be limited by Figure 7A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally include a storage component for storing data, programs; (3) an ASIC, such as a Modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0545] Figure 7B is a structural schematic diagram of a chip 7200 according to an embodiment of the present disclosure. For the case where the communication device 7100 is a chip or a chip system, the structural schematic diagram of the chip 7200 shown in Figure 7B can be referred to, but is not limited thereto.
[0546] The chip 7200 comprises one or more processors 7201. The chip 7200 is configured to perform any of the above methods.
[0547] In some embodiments, the chip 7200 further comprises one or more interface circuits 7202. Optionally, the terms interface circuit, interface, transceiver pin, etc. can replace each other. In some embodiments, the chip 7200 further comprises one or more memories 7203 for storing data. Optionally, all or part of the memory 7203 can be outside the chip 7200. Optionally, the interface circuit 7202 is connected with the memory 7203, the interface circuit 7202 can be configured to receive data from the memory 7203 or other devices, and the interface circuit 7202 can be configured to send data to the memory 7203 or other devices. For example, the interface circuit 7202 can read the data stored in the memory 7203 and send the data to the processor 7201.
[0548] In some embodiments, the interface circuit 7202 performs at least one of the communication steps (for example, step S2101, but not limited to) such as sending and / or receiving in the above methods. The interface circuit 7202 performing the communication steps such as sending and / or receiving in the above methods means that the interface circuit 7202 performs data interaction between the processor 7201, the chip 7200, the memory 7203 or the transceiver device. In some embodiments, the processor 7201 performs at least one of the other steps (for example, step S2102, but not limited to).
[0549] The disclosure also proposes a storage medium, and the above storage medium stores instructions, when the instructions run on the communication device 7100, the communication device 7100 performs any of the above methods. Optionally, the above storage medium is an electronic storage medium. Optionally, the above storage medium is a computer readable storage medium, but not limited to, it can also be a storage medium readable by other devices. Optionally, the above storage medium can be a non-transitory storage medium, but not limited to, it can also be a transitory storage medium.
[0550] The disclosure also proposes a program product, and the above program product is executed by the communication device 7100, so that the communication device 7100 performs any of the above methods. Optionally, the above program product is a computer program product.
[0551] The disclosure also proposes a computer program, when it runs on a computer, so that the computer performs any of the above methods.
Claims
A communication method characterized by comprising: The method is executed by an application program interface (API) invoker, and the method comprises: sending a first request to a resource owner function (ROF) or a common API framework core function (CCF); wherein, when the API invoker does not obtain first information, the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information; the first information is used to indicate at least one of an identifier of a resource owner (RO), a login state of the RO and an authentication state of the RO. The method of claim 1, wherein The first request comprises at least one of: a first instruction, used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information; an identifier of the API invoker; an identifier of the RO; a range of a request call; authorization information, used to indicate a calling right possessed by the API invoker; a first list comprising at least one identifier of an API invoker. The method according to claim 1 or 2, characterized in that The API invoker does not obtain the first information, and the first information is not searched for by the API invoker in a secure environment of a UE or the ROF. The method according to any one of claims 1 to 3, characterized in that Further comprising: receiving a first response sent by the ROF or the CCF; wherein, the first response comprises an authorization code and the first information. The method according to claim 4, characterized in that Further comprising: storing the first information in the secure environment of the UE. The method of claim 1, wherein When the API invoker obtains the first information, the first request is used to instruct the CCF to perform authorization of the API invoker according to the context, or to instruct the CCF to judge whether the RO needs to be authenticated according to the first information. The method according to claim 6, characterized in that When the first request is used to instruct the CCF to perform authorization of the API invoker according to the context, the first request comprises at least one of: a second instruction, used to instruct the CCF to perform authorization of the API invoker according to the context; an identifier of the API invoker; a range of a request call; an identifier of the RO. The method according to claim 6 or 7, characterized in that The API invoker obtains the first information, and the first information is searched for by the API invoker in the secure environment of the UE or the ROF. The method according to any one of claims 6-8, characterized in that Further comprising: receiving a second response sent by the ROF or the CCF; wherein, the second response comprises the authorization code or a message indicating authorization failure. A communication method characterized by comprising: The method is executed by the ROF, and the method comprises: receiving an authorization request sent by an API invoker; sending a first request to a CCF; wherein, when the ROF or the API invoker does not obtain first information, the first request is used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information; the first information is used to indicate at least one of an identifier of a resource owner (RO), a login state of the RO and an authentication state of the RO. The first request comprises at least one of: The method of claim 10, wherein a first instruction, used to instruct the CCF to create at least one of a context related to authorization of multiple API invokers and the first information; an identifier of the API invoker; an identifier of the RO; a range of a request call; authorization information, used to indicate a calling right possessed by the API invoker; a first list comprising at least one identifier of an API invoker. The method according to claim 10 or 11, characterized in that Further comprising: receiving a first response sent by the CCF; wherein the first response comprises an authorization code and the first information. The method according to any one of claims 10-12, characterized in that When the ROF or the API invoker fails to obtain the first information, the method comprises any of the following: The ROF fails to retrieve the first information locally in the ROF. The API invoker fails to search for the first information in a secure environment of the UE or the ROF. The method of claim 13, wherein The ROF or the API invoker fails to obtain the first information, and the API invoker fails to search for the first information in a secure environment of the UE or the ROF. The authorization request is used to instruct the CCF to create at least one of a context related to multiple API invoker authorizations and the first information, or the authorization request comprises a first instruction, which is used to instruct the CCF to create at least one of a context related to multiple API invoker authorizations and the first information. The method according to any one of claims 12-14, characterized in that Further comprising: storing the first information locally in the ROF or in a secure environment of the UE. The method of claim 10, wherein When the ROF or the API invoker obtains the first information, the first request is used to instruct the CCF to perform API invoker authorization according to the context, or to instruct the CCF to determine whether authentication of the RO is required according to the first information. The method of claim 16, wherein The first request is used to instruct the CCF to perform API invoker authorization according to the context, and the first request comprises at least one of the following: A second instruction, which is used to instruct the CCF to perform API invoker authorization according to the context. An identifier of the API invoker. A range of a request call. An identifier of the RO. The method according to claim 16 or 17, characterized in that Further comprising: receiving a second response sent by the CCF; wherein the second response comprises the authorization code or a message indicating that authorization fails. The method according to any one of claims 16-18, characterized in that When the ROF or the API invoker obtains the first information, the method comprises any of the following: The ROF retrieves the first information locally in the ROF. The API invoker searches for the first information in a secure environment of the UE or the ROF. The method of claim 19, wherein The ROF or the API invoker obtains the first information, and the API invoker searches for the first information in a secure environment of the UE or the ROF. The authorization request is used to instruct the CCF to perform API invoker authorization according to the context, or the authorization request comprises a second instruction, which is used to instruct the CCF to perform API invoker authorization according to the context. A communication method characterized by comprising: The method is performed by the CCF, and the method comprises: receiving a first request sent by an API invoker or an ROF; When the ROF or the API invoker fails to obtain the first information, the first request is used to instruct the CCF to create at least one of a context related to multiple API invoker authorizations and the first information. The first information is used to instruct at least one of an identifier of the RO, a login state of the RO, and an authentication state of the RO. The method of claim 21, wherein Further comprising: creating the first information. The method according to claim 21 or 22, characterized in that Further comprising: sending a first response to the API invoker or the ROF; wherein the first response comprises an authorization code and the first information. The method according to any one of claims 21-23, characterized in that The first request comprises at least one of the following: A first indication, used to indicate that the CCF creates at least one of the following: a context related to multiple API caller authorizations and the first information; An identification of the API caller; An identification of the RO; A range of a requested call; Authorization information, used to indicate a calling authority possessed by the API caller; A first list comprising at least one identification of the API caller. The method of claim 24, wherein Further comprising: Establishing a mapping relationship between at least two of the following: the first information, the authorization information, and the first list. The method according to any one of claims 21-25, characterized in that When the ROF or the API caller fails to obtain the first information, the following any one mode is used: The ROF fails to search for the first information in the ROF locally; The API caller fails to search for the first information in a secure environment of a UE or the ROF. The method of claim 21, wherein When the ROF or the API caller obtains the first information, the first request is used to indicate that the CCF performs authorization of the API caller according to the context, or that the CCF judges whether to perform authentication on the RO according to the first information. The method of claim 27, wherein When the first request is used to indicate that the CCF performs authorization of the API caller according to the context, the first request comprises at least one of the following: A second indication, used to indicate that the CCF performs authorization of the API caller according to the context; An identification of the API caller; A range of a requested call; An identification of the RO. The method according to claim 27 or 28, characterized in that Further comprising: Sending a second response to the API caller or the ROF; The second response comprises the authorization code or a message indicating authorization failure. The method of claim 29, wherein The message indicating authorization failure is determined by the CCF according to at least one of the following: An identification of the RO having a mapping relationship with the first list is inconsistent with an identification of the RO provided by the API caller; The first information indicates that a login state of the RO corresponding to the identification of the RO provided by the API caller is not a login state; The first information indicates that an authentication state indicates that the CCF has not authenticated the RO corresponding to the identification of the RO provided by the API caller; The identification of the API caller is not in the first list; The authorization information indicates that the API caller is not authorized; The first list and the authorization information are sent by the ROF when the ROF or the API caller fails to obtain the first information. The method according to any one of claims 27-30, characterized in that When the ROF or the API caller obtains the first information, the following any one mode is used: The ROF searches for the first information in the ROF locally; The API caller searches for the first information in a secure environment of a UE or the ROF. A first communication device, characterized in that Comprise: A transceiver module, configured to send a first request to a resource owner function (ROF) or a common API framework core function (CCF); When the API caller fails to obtain the first information, the first request is used to indicate that the CCF creates at least one of the following: a context related to multiple API caller authorizations and the first information; The first information is used to indicate at least one of the following: an identification of a resource owner (RO), a login state of the RO, and an authentication state of the RO. A second communication device, characterized in that Comprise: The transceiver module is configured to receive an authorization request sent by an API invoker, and send a first request to the CCF; When the ROF or the API invoker fails to obtain the first information, the first request is configured to instruct the CCF to create at least one of the following: a context related to authorization of multiple API invokers and the first information. The first information is configured to indicate at least one of the following: an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO. A third communication device, characterized in that The transceiver module is configured to receive a first request sent by an API invoker or an ROF, When the ROF or the API invoker fails to obtain the first information, the first request is configured to instruct the CCF to create at least one of the following: a context related to authorization of multiple API invokers and the first information. The first information is configured to indicate at least one of the following: an identifier of a resource owner (RO), a login state of the RO, and an authentication state of the RO. The one or more processors are configured to invoke instructions to cause the communication device to perform the communication method of any one of claims 1-9, 10-20, and 21-31. A communication device characterized by comprising: The API invoker is configured to implement the method of any one of claims 1-9. The ROF is configured to implement the method of any one of claims 10-20. The CCF is configured to implement the method of any one of claims 21-31. A communication system characterized by The instructions, when executed on the communication device, cause the communication device to perform the method of any one of claims 1-31. The program product, when executed by the communication device, implements the method of any one of claims 1-31. A storage medium storing instructions, characterized in that, A program product, characterized in that
Citation Information
Patent Citations
Authorization method, device and system and storage medium
CN117546163A
Communication method and communication device
CN117641358A
API calling method and device, equipment and storage medium
CN118120176A
Resource calling method and device
CN118120199A
Resource owner agreement information management
CN118614097A