Methods, intermediary device, identifier server, and node

An intermediary device uses obfuscating identifiers to protect network associations, enabling secure third-party aggregation and value-added services by resolving network-specific information without exposing it to external parties.

WO2026084627A1PCT designated stage Publication Date: 2026-04-23TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2024-10-18
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing communication networks face challenges in integrating seamless API integration while protecting sensitive information about network associations from external invokers, risking exposure of competitive data.

Method used

An intermediary device uses an obfuscating communication device identifier to obscure network associations, allowing the intermediary to resolve the identifier while keeping network information hidden from invokers, enabling secure third-party aggregation.

Benefits of technology

Enables secure third-party aggregation and value-added services by safeguarding sensitive network information, allowing scalable and confidential operations without revealing network-specific details to external parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050887_23042026_PF_FP_ABST
    Figure SE2024050887_23042026_PF_FP_ABST
Patent Text Reader

Abstract

An intermediary device (16) is configured to serve as an intermediary for one or more communication networks (10-1…10-N) The intermediary device receives a first request (20R) from an invoker device (18) through a first application programming interface, API, (20) exposed by the intermediary device. The first request requests a service or resource for a communication device (12T) identified by a communication device identifier (22) included in or referenced by the first request. The communication device identifier (22) obfuscates with which communication network (10-1…10-N) the communication device is associated. The intermediary device resolves the communication device identifier (22) to identify the communication network (10-n) associated with the communication device. The intermediary device transmits a second request (14R) to the identified communication network (10-n) through a second API (14) exposed by the identified communication network (10-n). The second request (14R) requests the service or resource for the communication device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHODS, INTERMEDIARY DEVICE, IDENTIFIER SERVER, AND NODE

[0002] TECHNICAL FIELD

[0003] The application relates to an intermediary device, an identifier server, and a node, as well as to corresponding methods, computer programs, carriers of those computer programs and corresponding non-transitory computer-readable storage media.

[0004] BACKGROUND

[0005] In order to enable seamless integration of a communication network’s capabilities into third-party applications, platforms, and systems, a communication network may provide external parties with access to some of the network’s services and / or resources. One way for the communication network to do this is to expose an application programming interface (API) to those services and / or resources. An exposed API provides a set of endpoints and protocols that allow an external party to programmatically request network services and / or resources. Through this, the API may for example offer a range of functionalities such as sending text messages, making voice calls, managing user accounts, and accessing network data.

[0006] Different communication networks may however cover different geographical areas, countries, states, or regions and / or may expose APIs that differ in form and / or function, such that the APIs directly exposed by communication networks may be network-specific in nature. To address this, a trusted third-party aggregator may aggregate (e.g., combine or harmonize) service offerings provided by multiple respective communication networks, e.g., as part of providing value-added services tailored to the specific needs of business or organizations. An aggregator may for example expose a single, generic API that is generic across multiple communication networks, e.g., in terms of API parameters and / or API functionality, so as to insulate an application service provider (ASP) or other API invoker from the network-specific nature of the APIs directly exposed by the networks.

[0007] An invoker of such a generic API may however still need to identify to which communication network its API call relates, e.g., as part of identifying for which communication device its API call requests a service or resource and identifying which communication network serves that communication device. This way, the aggregator will know which network-specific API to invoke in order to carry out the invoker’s call to the generic API. Problematically, though, this risks undesirably exposing information to the invoker of the generic API, including for instance competitive information about the communication networks. For example, this risks exposing to the invoker statistical information about a given communication network, such as the number of subscribers to the communication network. Challenges therefore exist with how to enable an aggregator or other device to serve as an intermediary to communication networks that expose respective APIs, while at the same time protecting against undesirably exposing information about the communication networks to those invoking the APIs via the intermediary.

[0008] PCT / CN2024 / 081362 discloses an identifier server deployed in a communication network. The identifier server receives a request for an identifier that is to identify a communication device to an external invoker device of an API exposed by the communication network.

[0009] SUMMARY

[0010] An object of the invention is to enable a device to serve as an intermediary (e.g., aggregator) for communication networks that expose respective application programming interfaces (APIs) to those networks, but to mitigate exposing information about the communication networks to other devices invoking the APIs via the intermediary.

[0011] Towards this end, some embodiments herein exploit an identifier for a communication device that obfuscates with which communication network the communication device is associated. The obfuscating nature of the communication device identifier means that the identifier renders information about with which communication network the communication device is associated obscure, unclear, hidden, or otherwise unintelligible.

[0012] An identifier server herein provides such a communication device identifier to an invoker device. This equips the invoker device to identify a particular communication device, without revealing to the invoker device with which communication network the communication device is associated. The invoker device uses this communication device identifier in a request to invoke an API exposed by an intermediary device, with the communication device identifier identifying for which communication device the request requests a service or resource. Unlike the invoker device, the intermediary device is configured to resolve the communication device identifier and can therefore determine from the communication device identifier with which communication network the communication device is associated. After identifying with which communication network the communication device is associated, the intermediary device correspondingly invokes the API exposed by that communication network, by requesting the resource or service for the communication device from the identified communication network.

[0013] By way of the communication device identifier, then, some embodiments enable an intermediary device to serve as an intermediary to communication networks that expose respective APIs, while at the same time protecting against undesirably exposing information about the communication networks to the invoker device or an application executed thereon. Some embodiments thus advantageously enable third-party aggregation or other value- added services while safeguarding sensitive or confidential information about the networks’ respective operations or subscriber bases, e.g., how many subscribers a given communication network operator has.

[0014] More particularly, embodiments herein include a method performed by an intermediary device configured to serve as an intermediary for one or more communication networks in accordance with particular embodiments. The method includes receiving a first request from an invoker device through a first application programming interface, API, exposed by the intermediary device. In some embodiments, the first request requests a service or resource for a communication device identified by a communication device identifier included in or referenced by the first request. In some embodiments, the communication device identifier obfuscates with which communication network the communication device is associated. The method also includes resolving the communication device identifier to identify the communication network associated with the communication device. The method also includes transmitting a second request to the identified communication network through a second API exposed by the identified communication network. In some embodiments, the second request requests the service or resource for the communication device.

[0015] Other embodiments herein include a method performed by an identifier server of a communication network in accordance with other particular embodiments. The method includes generating a communication device identifier for a communication device. In some embodiments, the communication device identifier is generated to include a network-specific device identifier that identifies the communication device within whatever communication network the communication device is associated. In some embodiments, the communication device identifier is generated to include an obfuscated network identifier that is associated with, but that obfuscates, the communication network with which the communication device is associated. The method also includes transmitting the communication device identifier to one or more other devices.

[0016] Other embodiments herein include a method performed by a node that is a communication device or a server in accordance with other particular embodiments. The method includes transmitting, to an identifier server in a communication network, a request for a communication device identifier that is to identify a communication device to an invoker device of a first application programming interface, API, exposed by an intermediary device which serves as an intermediary for the communication network. The method also includes receiving a response that includes the communication device identifier. In some embodiments, the communication device identifier obfuscates with which communication network the communication device is associated. Embodiments herein also include corresponding apparatus, computer programs, and carriers of those computer programs.

[0017] BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a block diagram of an intermediary device configured to serve as an intermediary for communication networks according to some embodiments.

[0019] Figure 2 is a block diagram of an intermediary device configured to serve as an intermediary for communication networks and an identifier server configured to provide a communication device identifier according to some embodiments.

[0020] Figure 3 is a block diagram of a Generic Mobile Subscription Architecture (GMSA) Open Gateway according to some embodiments.

[0021] Figures 4A-4B are a call flow diagram of communication device identifier allocation and use according to some embodiments.

[0022] Figure 5 is a call flow diagram of communication device identifier allocation and use according to other embodiments.

[0023] Figure 6 is a logic flow diagram of a method performed by an intermediary device according to some embodiments.

[0024] Figure 7 is a logic flow diagram of a method performed by an identifier server of a communication network according to some embodiments.

[0025] Figure 8 is a logic flow diagram of a method performed by a node that is a communication device or a server according to some embodiments.

[0026] Figure 9 is a block diagram of an intermediary device according to some embodiments.

[0027] Figure 10 is a block diagram of an identifier server according to some embodiments.

[0028] Figure 11 is a block diagram of a node according to some embodiments.

[0029] DETAILED DESCRIPTION

[0030] Figure 1 shows multiple different communication networks 10-1...10-N according to some embodiments, e.g., in the form of 3rd Generation Partnership Project (3GPP) 4G, 5G and / or the future 6G networks. Each communication network 10-n provides communication service to one or more communication devices 12, e.g., that are authorized to receive such communication service on the basis of a subscription to that communication network 10-n.

[0031] In this context, the communication networks 10-1...10-N as shown expose respective application programming interfaces (API) 14-1... 14-N, e.g., via respective Network Exposure Functions (NEFs) or respective Services Capability Exposure Functions (SCEFs). The API 14-n exposed by a communication network 10-n provides access to service(s) and / or resource(s) of the communication network 10-n, e.g., by providing a set of endpoints and protocols for requesting such service(s) and / or resource(s). Different communication networks 10-1...10-N may however expose APIs 14-1...14-N that cover different geographical areas and / or that differ in form and / or function, such that the APIs 14-1 ... 14-N directly exposed by communication networks 10-1...10-N may be network-specific in nature. Different APIs 14-1 ... 14-N may for example have different endpoints, parameters, and / or functionality.

[0032] In these and other embodiments, Figure 1 shows that an intermediary device 16 serves as an intermediary for the communication networks 10-1...10-N. The intermediary device 16 in doing so functions as an intermediary between the communication networks 10- 1 ... 10-N and another device (referred to as an invoker device 18) that seeks access to service(s) and / or resource(s) of at least one of the communication networks 10-1... 10-N. The invoker device 18 may for instance be an application backend server that provides a service to an application executed on a communication device 12 or may even be a communication device 12 itself which executes an application. Regardless, the intermediary device 16 in its role mediates access by the invoker device 18 (or an application executed thereon) to the service(s) and / or resource(s) of one or more of the communication networks 10-1...10-N, e.g., where the service(s) and / or resource(s) may be application-level service(s) and / or resource(s). In some embodiments, the intermediary device 16 may be a third-party device and / or may be external to all of the communication networks 10-1... 10-N, e.g., in the sense that the intermediary device 16 is not under the management or control of any of the respective operators of the communication networks 10-1...10-N. The intermediary device 16 may nevertheless be a trusted device and / or be managed and controlled by a trusted third-party that is trusted by the operators of the communication networks 10-1 ... 10-N, e.g., at least in the sense that the intermediary device 16 is allowed to invoke APIs respectively exposed by the communication networks 10-1... 10-N (even if the intermediary device 16 is not allowed to communicate with internal network nodes / functions).

[0033] In its role as intermediary, the intermediary device 16 exposes an API 20 towards the invoker device 18. This API 20 may also be referred to herein as a first API 20. Rather than the invoker device 18 requesting service(s) or resource(s) of a communication network 10-n directly through the API 14-n exposed by that network 10-n, the invoker device 18 sends a request 20R for the service(s) or resource(s) to the intermediary device 16, through the API 20 exposed by the intermediary device 16. The intermediary device 16 then in turn requests the service(s) or resource(s) through the API 14-n exposed by the communication network 10-n on the invoker device’s behalf and / or otherwise for the benefit of the invoker device 18.

[0034] In some embodiments, the API 20 exposed by the intermediary device 16 is a generic API that is generic across multiple communication networks 10-1... 10-N, e.g., in terms of API endpoints, parameters, and / or functionality. The invoker device 18 may for example access the intermediary device’s API 20 without concern for the network-specific nature of the APIs 14-1...14-N directly exposed by the communication networks 10-1...10-N. The intermediary device 16 in these and other embodiments may be said to aggregate (e.g., combine or harmonize) the service and / or resource offerings provided by the multiple communication networks 10-1...10-N, e.g., as part of providing value-added services.

[0035] Nonetheless, at least some of the services or resources accessible via the APIs 14- 1 ... 14-N may be communication device specific, e.g., for sending a text message to a specific communication device or for retrieving data associated with a specific communication device. A request for a service or resource for a specific communication device 12T must thereby identify for which communication device 12 the service or resource is requested, i.e., which communication device 12 the request targets. The intermediary device 16 however is configurable to serve as an intermediary for multiple communication networks 10-1 ... 10-N. This means that the specific communication device 12T must be identified in such a way that informs the intermediary device 16 about which communication network 10-1... 10-N the specific communication device 12T is associated, e.g., in the sense that the intermediary device 16 is informed about which communication network serves the specific communication device 12T and / or which communication network is the device’s home network to which the specific communication device 12T has a subscription. Indeed, only by identifying the targeted communication device 12T in this way will the intermediary device 16 be able to send an API request to the correct communication network, i.e., the one that can actually provide the requested service or resource for the targeted communication device 12T.

[0036] Some embodiments herein recognize, though, that the information about which communication devices 12 are associated with which communication networks 10-1...10-N is sensitive information. Indeed, operators of the communication networks 10-1...10-N may desire to keep this information from being disclosed to untrusted parties, as it may reveal confidential information about the networks’ respective operations or subscriber bases, e.g., how many subscribers a given communication network operator has. Without a way to keep this information from being exposed to an invoker device 18 (or an application executed thereon), a communication network operator would have to require that any invoker device (or application executed thereon) be trusted by the operator. Requiring any invoker device 18 (or application executed thereon) to be trusted by the communication networks 10-1 ... 10- N, however, would threaten to limit which types of devices and / or which types of applications could request service(s) or resource(s) of the communication networks, such that it would jeopardize the scalability and / or the use cases otherwise realizable by having an intermediary for the communication networks 10-1... 10-N.

[0037] Embodiments herein address these and other problems by exploiting an identifier 22 for a communication device 12T that obfuscates with which communication network the communication device 12T is associated. The obfuscating nature of the communication device identifier 22 means that the identifier 22 renders information about with which communication network the communication device 12T is associated obscure, unclear, hidden, or otherwise unintelligible, at least to the invoker device 18, an application executed thereon, or any other untrusted party. The intermediary device 16 is nonetheless configured to resolve the communication device identifier 22 and can therefore determine from the communication device identifier 22 with which communication network the communication device 12T is associated. As such, the identifier 22 effectively obfuscates with which communication network the communication device 12T is associated from the invoker device 18 or an application executed thereon, but not from the intermediary device 16. Indeed, embodiments herein may equip the intermediary device 16, but not the invoker device 18 or an application executed thereon, with information needed to resolve the communication device identifier 22.

[0038] By way of the communication device identifier 22, then, some embodiments enable the intermediary device 16 to serve as an intermediary to communication networks 10- 1 ... 10-N that expose respective APIs 14-1 ... 14-N, while at the same time protecting against undesirably exposing information about the communication networks 10-1... 10-N to the invoker device 18 or an application executed thereon. Some embodiments thus advantageously enable third-party aggregation or other value-added services while safeguarding sensitive or confidential information about the networks’ respective operations or subscriber bases, e.g., how many subscribers a given communication network operator has.

[0039] Figure 2 illustrates additional details according to some embodiments. As shown, a communication network 10-n exposes an API 14-n to service(s) and / or resource(s) of the communication network 10-n, e.g., for invocation by devices that are external to the communication network 10-n such that they are not under the management or control of the communication network 10-n. To facilitate identification of a specific communication device 12T in requests made to the exposed API 14-n, without undesirably revealing that the communication device 12T is associated with the communication network 10-n, the communication network 10-n includes an identifier server 24. The identifier server 24 is a server in the communication network 10-n itself that facilitates identification of the communication device 12T, rather than some server external to the communication network 10-n. The deployment of the identifier server 24 in the communication network 10-n puts the identifier server 24 in an advantageous position for facilitating identification of the communication device 12T.

[0040] The identifier server 24 in this regard is configured to generate a communication device identifier 22 for the communication device 12T. The communication device identifier 22 as generated identifies the communication device 12T to the communication network 10- n; that is, the identifier server 24 generates the communication device identifier 22 in such a way that the communication network 10-n can pinpoint the identified communication device 12T when presented with that identifier 22. But the communication device identifier 22 obfuscates with which communication network the communication device 12T is associated, at least to the invoker device 18, an application executed thereon, or any other untrusted party that is not configured to resolve the communication device identifier 22.

[0041] In some embodiments as shown in Figure 2, for example, the identifier server 24 generates the communication device identifier 22 to include a network-specific device identifier 22D and an obfuscated network identifier 22N. The network-specific device identifier 22D may take the form of a JavaScript Object Notation (JSON) Web Token (JWT), be in the form of a Network Access Identifier (NAI), or even be an opaque string. The communication device identifier 22 in these and other embodiments may correspond to the identifier 12-ID described in International Patent Application No. PCT / CN 2024 / 081362 but without obfuscation of the network identifier part. No matter its form, though, the networkspecific device identifier 22D identifies the communication device 12T within whatever communication network the communication device 12T is associated, which in this example is communication network 10-n. The network-specific device identifier 22D may for example be a local identifier that is local to, or unique within, the communication network 10-n associated with the communication device 12T. In such a case, then, the network-specific device identifier 22D is not unique across the communication networks 10, such that the identifier 22D alone does not itself specifically identify the communication device 12T without knowledge of which communication network 12 the network-specific device identifier 22D is specific to.

[0042] The identifier server 24 in this regard generates the obfuscated network identifier 22N to be associated with the communication network 10-n, i.e. , the communication network with which the communication device 12T is associated and for which the network-specific device identifier 22D is specific. Together, the network-specific device identifier 22D and the obfuscated network identifier 22N may in combination form a global identifier that is globally unique, e.g., in the sense that only one communication service provider is able to make use of the global identifier. In fact, the network-specific identifier 22D and the obfuscated network identifier 22N may be combined to form the communication device identifier 22 as a Network Access Identifier (NAI), e.g., with the network-specific device identifier 22D being included in or represented by the username part of the NAI and the obfuscated network identifier 22N being included in the realm part of the NAI. However, in these and other embodiments, the identifier server 24 generates the obfuscated network identifier 22 N to obfuscate the communication network 10-n with which the communication device 12T is associated, i.e., such that the association between the obfuscated network identifier 22N and the communication network 10-n is obscure, unclear, hidden, or otherwise unintelligible, at least to an untrusted party that is not configured with information 24 based on which to resolve the obfuscated network identifier 22N. Such information may be referred to for convenience as obfuscation resolution information 26.

[0043] In some embodiments, for example, the identifier server 24 generates the obfuscated network identifier 22N by encrypting a communication network identifier (not shown) that identifies the communication network 10-n (or a domain controlled by the communication network 10-n). The resulting obfuscated network identifier 22N thereby is in fact associated with the communication network identifier, but that association is obfuscated to any device, application, or party that is not configured with a decryption key usable to decrypt the obfuscated network identifier 22N. In another embodiment, by contrast, the identifier server 24 may generate the obfuscated network identifier 22N by hashing the communication network identifier, e.g., with a random value according to a hashing algorithm. Similarly, then, the resulting obfuscated network identifier 22N is in fact associated with the communication network identifier, but that association is obfuscated to any device, application, or party that is not configured with the random value and / or the hashing algorithm usable to validate the obfuscated network identifier 22N as being the hash of a certain communication network identifier. In these examples, then, the obfuscation resolution information 26 may include the encryption key and / or the decryption key, or may include the random value and / or the hashing algorithm.

[0044] Generally, though, the obfuscation resolution information 26 may include any information based on which the associated communication network 10-n is determinable. Indeed, in a general sense, the obfuscation resolution information 26 may include some sort of mapping between the obfuscated network identifier 22N and a resolved network identifier that identifies the associated communication network 10-n (or a domain controlled by that communication network 10-n). The mapping may for instance map different possible obfuscated network identifiers to different respective resolved network identifiers. Any given obfuscated network identifier 22N in this case may be resolved by mapping the obfuscated network identifier 22N to the resolved network identifier according to the mapping.

[0045] In any event, the communication device identifier 22 in some embodiments is dedicated for identifying the communication device 12T in API requests to the intermediary device 16 and / or to the communication network 10-n. Alternatively, the communication device identifier 22 may be more broadly dedicated for identifying the communication device 12T to any device or entity external to the communication network 10-n, i.e., outside of the control and / or management of the communication network’s operator. In one or more such embodiments, the communication device identifier 22 may be, correspond to, or have the same function or purpose as an External Identifier described in Section 4.6 of 3GPP TS 23.682 V18.0.0. In still other embodiments, though, the communication device identifier 22 may be usable for identifying the communication device 12T to any entity and / or for any purpose, but embodiments herein exploit that identifier 22 for the purposes described herein.

[0046] No matter the particular way that the identifier server 24 generates the communication device identifier 22, though, the identifier server 24 may provide that identifier 22 to one or more other devices, either directly or indirectly, e.g., upon request. The identifier server 24 may for instance transmit the communication device identifier 22 to the communication device 12T, the intermediary device 16, and / or the invoker device 18, e.g., responsive to receiving a request for such an identifier 22. Either way, though, in embodiments where the obfuscation is specific to a certain intermediary device, a request for a communication device identifier 22 may indicate for which intermediary device the communication device identifier 22 is to be generated.

[0047] The identifier server 24 may however selectively equip the intermediary device 16 to resolve the communication device identifier 22, but not the invoker device 18 or an application executed thereon. The identifier server 24 may for instance provide the obfuscation resolution information 26 to the intermediary device 16 so that the intermediary device 16 can resolve the communication device identifier 22. Yet the identifier server 24 may refrain from providing the obfuscation resolution information 26 to the invoker device 18 or an application executed thereon, to avoid revealing the device-network association that is obfuscated by the communication device identifier 22.

[0048] Without the obfuscation resolution information 26, the invoker device 18 or an application executed thereon simply associates the communication device identifier 22 as identifying a desired target of an API call to the API 20 exposed by the intermediary device 16. The invoker device 18 or the application executed thereon makes this association without knowledge or concern for which communication network the targeted communication device 12T is associated. In fact, in some sense, the invoker device 18 or the application executed thereon need simply rely on the intermediary device 16 to discern for which communication network the communication device 12T is associated. The communication device identifier 22 may accordingly appear arbitrary to the invoker device 18, usable as a mere reference to the communication device 12T, with the invoker device 18 being ill- equipped to discern or interpret any meaning conveyed by the communication device identifier 22 beyond the fact that it identifies the communication device 12T targeted by its request 20R.

[0049] More particularly in this regard, the invoker device 18 as shown in Figure 2 transmits a request 20R to the intermediary device 16 through the API 20 exposed by the intermediary device 16. The request 20R request includes the communication device identifier 22, as the identity of the communication device 12T targeted by the request 20R. The request 20R as such requests a service or resource for the communication device 12T that is identified by the communication device identifier 22 included in the request 20R. Without the obfuscation resolution information 26, the invoker device 18 or the application executed thereon identifies the communication device 12T as the target of the request 20R using the communication device identifier 22 without knowledge of for which communication network the communication device 12T is associated.

[0050] The intermediary device 16 correspondingly receives the request 20R with the communication device identifier 22. The intermediary device 16 notably resolves the communication device identifier 22 to identify the communication network 10-n associated with the communication device 12T for which the service or resource is requested. The intermediary device 16 may do so for instance using the obfuscation resolution information 26. Where the obfuscation resolution information includes a decryption key, for instance, the intermediary device 16 may decrypt the communication device identifier 22 using the decryption key. Or, where the obfuscation resolution information includes one or more random values and a (non-obfuscated) network device identifier known to be associated with the communication network 10-n, the intermediary device 16 may hash the (non-obfuscated) network identifier using one or more of the random values and compare the hashed value(s) to the obfuscated network identifier 22N.

[0051] Having identified the communication network 10-n associated with the communication device 12T for which the service or resource is requested, the intermediary device 16 as shown transmits a request 14R to the identified communication network 10-n through the API 14-n exposed by that network 10-n. This request 14R may be derived from or otherwise based on the request 20R received from the invoker device 18. The intermediary device 16 may for example address the request 14R to the communication network 10-n identified from the communication device identifier 22 included in the request 20R, e.g., by addressing the request 14R to a known Internet Protocol (IP) address of a gateway or server in the identified communication network 10-n. In some embodiments, for instance, preconfigured information may be used by the intermediary device 16 for each communication network 10-1 ... 10-N, or other standard ways of resolving a domain name to an IP address by means of Domain Name Service (DNS) may be used. Regardless, this request 14R correspondingly requests the service or resource for the communication device 12T identified by the communication device identifier 22 included in the request 20R from the invoker device 18. The request 14R may for instance be directed to a defined endpoint and / or include certain parameter(s) that inform the communication network 10-n about which service(s) and / or which resource(s) are requested. Moreover, in order to identify the communication device 12T to the communication network 10-n, the request 14R may include some sort of identifier that informs the communication network 10-n of the identity of the communication device 12T.

[0052] Towards this end, the request 14R in some embodiments may also include the communication device identifier 22, so that the intermediary device 16 propagates the communication device identifier 22 from request 20R to request 14R. Where the communication device identifier 22 includes the network-specific device identifier 22D and the obfuscated network identifier 22N, for example, the communication network 10-n may then read the network-specific device identifier 22D from the communication network identifier 22 in order to identify the communication device 12T that the request 14R targets. In some of these embodiments, though, the obfuscated network identifier 22N included in the communication device identifier 22 may no longer serve a purpose for the communication network 10-n, since the communication network’s reception of the request 14R already indicates that the identified communication device 12T is associated with that communication network 10-n.

[0053] According to other embodiments shown in Figure 2, then, the intermediary device 16 may selectively include the network-specific device identifier 22D in its request 14R to the communication network 10-n, to the exclusion of the obfuscated network identifier 22N. Indeed, with the request 14R already properly addressed or directed to the communication network 10-n, the communication network 10-n may assume that the network-specific device identifier 20D is specific to that communication network 10-n and interpret it accordingly on that basis.

[0054] In still other embodiments as shown, though, the intermediary device 16 may resolve the obfuscated network identifier 22N into a communication network identifier 22R and then may also include that resolved communication network identifier 22R in its request 14R to the communication network 10-n. In fact, in one or more such embodiments, the intermediary device 16 generates a new communication device identifier as a combination of the network-specific device identifier 22D (from the request 20R) and the resolved communication network identifier 22R, e.g., as the received communication device identifier 22 but with the obfuscated network identifier 22N replaced by the resolved communication network identifier 22R. The intermediary device 16 in this case generates its request 14R to include the new communication device identifier. Either way, in receipt of this communication network identifier, the communication network 10-n may confirm that the request 14R is properly directed to it and / or use and process the communication network identifier as it would have without obfuscation.

[0055] Irrespective of these details, the resulting effect is that the intermediary device 16 and the communication network 10-n are able to determine for which communication device 12T a service or resource is requested, while keeping the communication device’s association with the communication network 10-n obfuscated from the invoker device 18 (or an application executed thereon).

[0056] Note that, in some embodiments, the obfuscation resolution information 26 as described herein may be time limited in nature. This may prove to better obfuscate the communication device’s association with the communication network 10-n, e.g., by mitigating the potential for tracking repeated use of the obfuscated network identifier 22N with the communication device 12T. According to some embodiments, then, the obfuscated resolution information 24 may have an expiration time after which it becomes invalid. The intermediary device 16 in such a case may attempt to resolve the obfuscated network identifier 22N included in the communication device identifier 22 using obfuscation resolution information 26 that has been received from one or more of the one or more communication networks 10-1 ... 10-N and that is still valid.

[0057] Note too that although some embodiments are shown as including the communication device identifier 22 in the request 20R to the intermediary device 16, in other embodiments the communication device identifier 22 is transmitted to the intermediary device 16 separately from, but in association with, the request 20R. For example, the communication device identifier 22 may be transmitted in a separate message to the intermediary device 16, in advance of the request 20R. The request 20R may then reference the previously sent message as a way to indicate that the request 20R targets whatever communication device 12T is identified by the communication device identifier 22 which was included in that message.

[0058] Consider now specific examples of some embodiments herein in a context where the communication network 10 is a 5G network or another network specified by the 3GPP. As such, a communication device 12 is exemplified as a user equipment (UE) and the communication device identifier 22 is exemplified as a UE identifier (ID). In these examples, the following terms are used, e.g., consistent with 3GPP TS 23.222 V19.0.0.

[0059] API: The means by which an API invoker can access a service.

[0060] API invoker: The entity which invokes a Common API Framework (CAPIF) or service APIs. The API invoker in the examples below may exemplify the invoker device 18 and / or the intermediary device 16 in Figure 1.

[0061] API exposing function: The entity which provides the service communication entry point for the service APIs.

[0062] Common API framework (CAPIF): A framework comprising common API aspects that are required to support service APIs.

[0063] Northbound API: A service API exposed to higher-layer API invokers.

[0064] Resource: The object or component of the API on which the operations are acted upon, e.g., as requested by the request 20R or 14R in Figure 2.

[0065] Resource owner: An entity (either a UE user or a mobile network operator subscriber) capable of granting access to a protected resource related to the invoked API.

[0066] Service API: The interface through which a component of the system exposes its services to API invokers by abstracting the services from the underlying mechanisms.

[0067] Some embodiments herein enable communication service providers (CSPs) to expose network capabilities to external consumers. This for example enables different external entities like aggregators to get access to network capabilities. Some embodiments in particular address a common issue across multiple APIs (Network Exposure Function), namely, the identification of the targeted user or device.

[0068] 3GPP UE identifiers at exposure layer

[0069] Some embodiments herein are applicable in a context where the 3GPP Exposure layer supports different types of UE / target resource identifiers. Beside the UE IP Address (Non-NATed 5G Core (5GC) assigned IP address), also the General Public Subscription Identifier (GPSI) can be used as UE I target resource identifier.

[0070] GPSI as UE identifier at exposure layer

[0071] Some embodiments herein are also applicable where a Generic Public Subscription Identifier (GPSI) is defined as having two variants: (i) Mobile Station International Subscriber Directory Number (MSISDN); and (ii) External Id.

[0072] The value of an “GPSI in form of an MSISDN” is not equal to an MSISDN (in 3GPP stage 3, TS 29.571 V18.6.0). The GPSI is constructed by using “msisdn-" as prefix, so that the resulting identifier is “msisdn-<msisdn>”. The part <msisdn> contains the value of the MSISDN, as used within earlier 3GPP network releases (see Cl. 3.3 of TS 23.003 V18.6.0).

[0073] The “GPSI in form of an External Identifier” is constructed as “extid-<extid>”. The part <extid> is formatted according to TS 23.003 V18.6.0, Cl 19.7.2, which defines the <extid> to be formatted as username@realm as specified in clause 2.1 of IETF RFC 4282 (Network Access Identifier). TS 23.003 V18.6.0, Cl 19.7.2 introduces the for “<Local ldentifier>@<Domain Identifier^’ as format of the external identifier.

[0074] As specified in clause 4 of IETF RFC 4282, the Domain Identifier shall be a duly registered Internet domain name. There are no restrictions on the Local Identifier.

[0075] UE IP as UE identifier at exposure layer

[0076] The UE IP address can be either an IPv4 address or an IPv6 prefix. The IP address is assigned by the 5G System at time of Protocol Data Unit (PDU) Session establishment for a single PDU Session. When the UE establishes multiple PDU Sessions, the 5G System assigns one IP address for each PDU session to the UE.

[0077] GSMA PPG Telco Finder

[0078] Some embodiments herein are applicable in a context where the Generic Mobile Subscription Architecture (GMSA) Open Gateway Platform (OPG) activity focuses on multiple interfaces to enable aggregator setups. An aggregator offers the Network Capability services of typically multiple communication service providers (CSPs) and harmonizes the API offerings. The harmonization may be just on API parameters or potentially even on functionality. The intention is that consumers of the Aggregator API, like Application Service Providers (ASP), do not implement CSP-specific API flavors. Another intention of the aggregator is to enable a single entry for different CSPs. The aggregator offers the functionality for discovering the CSPs and its API exposure platform. For this purpose, the aggregator may contain a so called “Telco Finder” function. Figure 3 illustrates one example. Here, the aggregator or operator as aggregator corresponds to the intermediary device 16, and the telco-router corresponds to the logic to determine the communication network of the target device in API request 20R.

[0079] Some embodiments herein are exemplified in these and other contexts, where an aggregator corresponds to the intermediary device 16 in Figures 1-2, where an Application executed on a UE or an Application Backend (BE) corresponds to the invoker device 18 in Figures 1-2, a CSP corresponds to a communication network 10-1... 10-N in Figures 1-2, a global UE identifier corresponds to the communication device identifier 22 in Figures 1-2, an obfuscated CSP identifier (or simply CSPO identifier) corresponds to the obfuscated network identifier 22N in Figure 2, and a local UE identifier corresponds to the network-specific device identifier 22D in Figure 2, with corresponding elements being represented with the same reference number.

[0080] Some embodiments introduce a global UE identifier as an example implementation of the communication device identifier 22 in Figure 1. The global UE identifier may be subdivided into an obfuscated CSP identifier and a local UE identifier. A CSP here may correspond to a communication network provided by that CSP. The obfuscated CSP identifier exemplifies the obfuscated network identifier 22N in Figure 2 and the local UE identifier exemplifies the network-specified device identifier 22D in Figure 2. The local UE identifier may be a signed or encrypted blob (called token), as in International Patent Application No. PCT / CN2024 / 081362, filed March 13, 2024.

[0081] In some embodiments, the global UE Identifier is in NAI format and / or is obtained from the CSP, e.g. via a PDU Session, based on GSM Association (GSMA) TS.43 Service Entitlement Configuration specification procedures (e.g. Version 11.0 of TS.43), or through a self-service portal. Thus, the service CSP may be responsible for handing out the global UE Id and for also resolving that UE Id, e.g. into a Subscription Permanent Identifier (SUPI) or a 5GC assigned IP address.

[0082] In embodiments where the global UE identifier is in the form of a NAI, the domain part may be used as the obfuscated CSP identifier. Obfuscated in this case may mean that the serving CSP cannot be directly obtained from the domain name string, e.g. it is NOT a duly registered domain name. For an aggregator, by contrast, it is possible to lookup or derive the CSP info from the domain string. Consider two alternatives in this regard.

[0083] In a first alternative, the CSP creates an obfuscated string and shares the string as obfuscated CSP identifier with its registered Aggregator(s), where an Aggregator exemplifies an intermediary device 16 in Figure 1. In addition, the CSP may notify each aggregator with its CSP identifier. The CSP may add an expiration time to the CSP identifier. The expiration time is related to the expiration of the UE ids. Each UE id in this case is only valid for a duration. The aggregator keeps the CSP identifier in cache until its expiration. The association here is between CSP Identifier and Backend API endpoints (i.e. URLs) of this CSP.

[0084] In a second alternative, the Aggregator creates the obfuscation and it shares its Public Key or the URL of the location of the Public Key (via AppBE and UE) with the UE ID Server (CSP). The UE ID server then uses the Public Aggregator Key for creating an encrypted CSP identifier string.

[0085] Some embodiments abide by a requirement that an External Id I NAI format have a Domain Identifier which is a duly registered Internet domain name. Such embodiments may implement some identifier conversion for this purpose. For example, the API invoker may be provided an identifier which is not compliant to RFC 4282, e.g. the domain identifier is not registered or the identifier has a completely different format (e.g. no “@” character). The aggregator however may create a valid External Id, based on input from the API invoker.

[0086] The CSP identifier in some embodiments is time-limited, e.g., short-lived CSP, yet can still be used by aggregators to find the service CSP and to route an API request to the correct endpoint. Some embodiments in doing so create anonymity, that Application Service Providers (customers of aggregators) cannot easily determine, and / or capture statistics about, which CSP is serving which subscribers and / or how many API requests are handled by a certain CSP.

[0087] In order to enable-time limited CSP identifiers, some embodiments introduce new procedures between Aggregators and CSPs. Aggregators may request updated information at expiration or a CSP may notify all aggregators upon changes.

[0088] In some embodiments, a CSP provides a CSP identifier together with an expiration time and the CSP Service Exposure Platform URLs (or API gateway URL) to the aggregator. After time of expiration, the aggregator updates the information element, e.g. gets a new CSP identifier or some new Service Exposure Platform URLs. An alternative realization may be based on a Publish / Subscribe architecture (e.g., even with a broker like Message Queuing Telemetry Transport or similar), where the CSP is allowed to notify the aggregators about changes at any time. The usage of the CSP Identifier may be connected with the UE ID described in International Patent Application No. PCT / CN2024 / 081362. In this case, the CSP may offer a dedicated UE Id service to its subscribers, allowing a UE to request its UE id via an established PDU Session (e.g., 5G Connection).

[0089] Certain embodiments may provide one or more of the following technical advantage(s). Some embodiments simplify the operations of aggregators or enterprises to identify which CSP needs to be contacted, when activating a specific network service. Some embodiments alternatively or additionally simplify the management of different CSP exposure Gateway URLs (landing pages). Alternatively or additionally, some embodiments prevent ASPs from gathering statistics about CSPs and their subscribers. Alternatively or additionally, some embodiments allow a CSP to dynamically select a new CSP route identifier in order to protect its privacy towards Application Service Providers.

[0090] Figures 4A-4B and 5 depict two possible call flows according to different embodiments herein. In both cases, one Aggregator onboards itself with two CSPs. A single CSP may offer network services to multiple aggregators and a single aggregator may connect to more than just two CSPs. According to the first call flow in Figures 4A-4B, the CSP manages the obfuscation of the CSP identifier. By contrast, according to the second call flow, the Aggregator 16 controls the process of obfuscation by using Public I Private key security.

[0091] More particularly with regard to Figures 4A-4B, the CSP manages route identifier obfuscation as follows.

[0092] 1. The Aggregator 16 registers with CSP1 10-1 and provides general information, like payment information, Aggregator’s legal address, etc.

[0093] 2. The Aggregator 16 registers with a second CSP (CSP2) 10-2 and provides general information, like payment information, Aggregator address, etc.

[0094] In the following, CSP1 10-1 exemplfiies the provider of communication network 10-n in Figure 2. The Aggregator 16 may register with more CSPs, e.g. in different countries.

[0095] 3. The CSP1 10-1 provides its Route identifier, so that the Aggregator 16 can route received API access requests 20R to the correct CSP 10-1. Two alternatives are identified. In one alternative (Alternative A), the CSP1 10-1 provides an Obfuscated CSP identifier 22N together with an expiration time to the Aggregator 16. After the expiration timer has expired, the CSP1 10-1 will use a different Obfuscated CSP identifier 22N within the global UE Id. In another alternative (Alternative B), the CSP1 10-1 provides a CSP Identifier 22 (in clear text) together with an indexed list of salts and an expiration time to the Aggregator 16. The Aggregator 16 creates a list of obfuscated CSP identifiers 22N by using a hash function like sha256 on the CSP id 22 and each salt. The hash function (e.g. sha256) is agreed between the CSP and the Aggregator. When an application desires to invoke a network service, the application instructs the UE 12T to obtain a global UE Id 22 from the CSP1 10-1 , e.g. using the PDU Session. The CSP1 10-1 creates a local UE Id 22D, e.g. by encrypting the SUPI into a token format. The local UE Id is unique within the CSP network. It is the local identifier part of an External Identifier (GPSI) as defined in TS 23.003, clause 19.7.2 (in, e.g., Version 19.0.0) When determining the domain part of the global UE Id 22, the CSP1 10-1 follows one of two alternatives. In case of Alternative 1 , the CSP1 10-1 uses the obfuscated CSP Id 22N, which has been earlier registered with all registered aggregators, as domain part (<string> value). In case of Alternative 2, the CSP1 10-1 randomly selects one salt from the list of salts (which have been earlier registered with all the aggregators). The CSP1 10-1 hashes (e.g. using sha256) the CSP identifier 22N (clear text identifier) with the randomly selected salt. The domain part (<string>) is created by combining the hashed CSP Identifier 22N with the Salt Id. Note, the Salt Id remains in clear, i.e. readable. The CSP1 10-1 creates the global UE Id 22 by combining the local UE Id 22D (<token>) with the domain part (<string>). This global UE Id 22 is then sent with a response message to the UE 12T and provided to the AppBE 18. The AppBE 18 can now invoke the network service for this UE 12T by invoking the according service API 20 at the Aggregator 16, passing in the obtained global UE ID 22. The aggregator determines the CSP identifier

[0096] Alternative 1 : The Aggregator simply looks up the domain identifier in its data base. In Alternative 1 , the domain identifier is an obfuscated CSP identifier, which has been generated by the CSP and registered in Step 3 with the aggregator.

[0097] Alternative 2: The aggregator separates the Salt Id from the hashed CSP Id. The Aggregator had received a CSP Identifier (clear text) and an indexed list of salts in step 3. The Salt Id identifies the index of the salt value in the indexed list. The Aggregator can have prepared and stored the result of hashing the CSP Identifier text and each salt value prior to step 8 or can do the hashing when needed. The aggregator matches the hashed CSP Identifier of the Salt Index with the received domain part (string). When there is a match (i.e. the aggregator can find an entry for a CSP), the Aggregator creates a new UE ID for the subsequent interactions with the CSP by either (A) replace the domain part of the receive UE ID with a valid (dully registered) domain Identifier of the CSP, or

[0098] (B) remove the domain part and only use the local UE Id (local identifier part), or

[0099] (C) use the original UE Id with the obfuscated domain part

[0100] NOTE: Only Option (A) represents a valid GPSI per 3GPP TS 23.003 Cl. 19.7.2. However, the two other cases also work for the given usage since the domain part of the UE ID is not needed anymore during subsequent interactions.

[0101] In some embodiments, the format of the token part 22D of the UE Id 22 is as described in International Patent Application No. PCT / CN2024 / 081362. In short, the token part 22D may use JWT either with signing or with encrypting the token payload. When the token is following the encrypted format, the token contains an encrypted portion (beside the readable parts), which embeds CSP sensitive information like a SUPI or Data Network Name (DNN), IP Address or similar.

[0102] Figure 5 by contrast shows a call flow where the Aggregator controls the process of obfuscation by using Public / Private key security (in combination with signing the Public Key), i.e. , Aggregator managed route identifier obfuscation.

[0103] 1. Onboarding CSP1 : During these steps, an Aggregator 16 registers and authenticates itself with CSP1 10-1. The registration transactions will contain sharing of legal information (like taxation id, postal address, etc), terms of use, payment information, responsibilities, etc (Service Level Agreement details / information).

[0104] 2. Onboarding CSP2: The Aggregator 16 registers to a second CSP2 10-2. When the registration is completed, the Aggregator 16 gets API Access credentials (e.g. API key) for the CSPs API gateway (GW). Also, the CSP1 10-1 gets some API access credentials to an Aggregator API Platform to send notifications or other information. As a next step, the CSPs 10-1, 10-2 register their respective CSP identifier 22N (e.g. <PLMN ld>) information with the Aggregator 16, so that the Aggregator 16 can reliably identify one of the CSPs 10-1, 10-2, which “serves” the subscriber 12T. Conceptually, a CSP1 10-1 serving the device 12 encrypts its CSP Identifier 22N using the Aggregator’s public key, together with a random number (salt) if needed by the nature of the encryption algorithm (note that in case of Rivest-Shamir-Adlenan (RSA) encryption used by public key infrastructure (PKI), each encryption produces a different string). The Aggregator 16 decrypts the information to find the CSP identifier 22N. Note, the random number is only used to increase the randomness of the resulting encrypted string. It ensures that each generated obfuscated CSP identifier is different from earlier generated ones. The CSP 10-1 provides its CSP identifier string 22N (<PLMN ID>) together with the CSP API GW URL, expiration time, and other information to the Aggregator 16. In response, the Aggregator 16 provides a means for verification of the Aggregator’s Public Key (e.g. a digital fingerprint of the Aggregator’s Public Key). The CSP identifier string 22N (<PLMN ID>) is used for the CSP matching function to determine that the decryption of the <encrypted CSP identifier (<(enc) CSP identifier) was successful. Usage of the <(enc) CSP identifier in some embodiments is based on the UE ID retrieval solution described in International Patent Application No. PCT / CN2024 / 081362, where a UE obtains a UE Id from the CSP, leveraging an established PDU Session. The intention is to hide information about the CSP to the ASP. The digital fingerprint, or the fingerprint for short (sometimes also called thumbprint), is in one embodiment a sequence of bytes used to identify the public key of the aggregator and is typically shorter than the public key. The fingerprint is / was created using a cryptographic hash function with the public key of the Aggregator as input, optionally with other data as additional input. The sequence starts with the need from the UE Application to access a network service. The UE Application first interacts with the Application Backend 18 and obtains the Public Key of the Aggregator 18 (AggPubKey) or the URL location of the Public Key (AggPubKeyURL). Note that this interaction may not be needed at every service invocation. App BE 18 could get this key or URL of the key earlier, e.g. as part of onboarding with the Aggregator 16, and the app client could also get it earlier (e.g. from the App BE 18) and store it. Note that the Public Key is verified either by means of a signature of the message containing the key and / or by validating the fingerprint of the public key. Once the UE application gets the AggPubKey or AggPubKeyURL, it will discover the UE ID server 24 (e.g. using a Domain Name Server, DNS) and send a request to obtain a UE Id 22. The request contains the (signed) AggPubKey or AggPubKeyURL. The UE ID Server 24 first verifies the AggPubKey signature, ensuring that the AggPubKey is truly provided by a registered Aggregator. The intention here is to prevent that the UE ID Server 24 is using the Public Key from any source, e.g. a selfcreated Public Key. In case of the AggPubKeyURL, the UE ID Server 24 will fetch the Public Key from the given URL and will ensure that the key is provided by a registered Aggregator. The UE ID Server 24 can use the information from the HTTPS Certificate (X.508) to confirm that the AggPubKey is provided by a registered Aggregator.

[0105] The UE ID Server 24 creates the < token> part.

[0106] The UE ID Server 24 creates the domain part by using the AggPubKey for encrypting the CSP Identifier (e.g. in form of <PLMN ID>). Additionally, a random number, e.g. a timestamp, may be inserted so that the value of the encrypted CSP Id is certainly changing. If multiple encryption keys are available, the UE ID server will add to the ‘domain’ part information about the key used for the encryption, which can be e.g. in the form of a key identifier, the key’s fingerprint, etc. This information will be delimited in such a way that it cannot be mistaken as part of the encrypted CSP Identifier.

[0107] The UE ID server 24 provides the UE ID 22 back to the client. Note that the UE ID 22 is formally NOT in form of a NAI, since the domain identifier is NOT registered anywhere, e.g., according to TS 23.003 Cl 19.7.2 or IETF RFC 4282.

[0108] 6. In order to invoke the network service, the UE Application shares the UE Id 22 with the Application Backend (AppBE) 18.

[0109] 7. The App BE 18 then passes the UE ID 22 with the API request 20R to the Aggregator 16.

[0110] 8. The Aggregator 16 uses its private key (AggPrivKey) for decrypting the token part 22D. It obtains the contained CSP Identifier 22N (in form of <PLMN ID>) and uses this to construct a UE Id, by replacing the domain part. It becomes a valid identifier in NAI format.

[0111] 9. The Aggregator 16 uses this newly created UE ID to access the network service at the CSPs exposure layer.

[0112] The Application BE 18 thereby contacts its Aggregator 16 to invoke the needed network service. It is assumed that the Application BE 18 is leveraging only a single Aggregator 16. The Aggregator 16 extracts the <(enc) CSP Identifier 22N as a first step from the UE Id 22 and decrypts it using its private Aggregator key.

[0113] In view of the modifications and variations herein, Figure 6 depicts a method performed by an intermediary device 16 configured to serve as an intermediary for one or more communication networks 10-1...10-N in accordance with particular embodiments. The method includes receiving a first request 20R from an invoker device 18 through a first application programming interface, API, 20 exposed by the intermediary device 16 (Block 600). In some embodiments, the first request 20R requests a service or resource for a communication device 12T identified by a communication device identifier 22 included in or referenced by the first request 20R. In some embodiments, the communication device identifier 22 obfuscates with which communication network 10-1... 10-N the communication device 12T is associated. The method also includes resolving the communication device identifier 22 to identify the communication network 10-n associated with the communication device 12T (Block 610). The method also includes transmitting a second request 14R to the identified communication network 10-n through a second API 14 exposed by the identified communication network 10-n (Block 620). In some embodiments, the second request 14R requests the service or resource for the communication device 12T.

[0114] In some embodiments, the communication device identifier 22 includes a networkspecific device identifier 22D that identifies the communication device 12T within whatever communication network 10-n the communication device 12T is associated. In some embodiments, the communication device identifier 22 includes an obfuscated network identifier that is associated with, but that obfuscates, the communication network 10-n with which the communication device 12T is associated.

[0115] In some embodiments, the network-specific device identifier 22D is a local identifier that is local to, or unique within, the communication network 10-n associated with the communication device 12T, and the local identifier and the obfuscated network identifier in combination form a global identifier that is globally unique.

[0116] In some embodiments, the communication device identifier 22 is a network access identifier comprising a username part and a realm part. In some embodiments, the networkspecific device identifier 22D is included in or represented by the username part and the obfuscated network identifier is included in the realm part.

[0117] In some embodiments, said resolving comprises resolving the obfuscated network identifier to identify the communication network 10-n associated with the communication device 12T in terms of a resolved network identifier.

[0118] In some embodiments, the resolved network identifier includes a communication network identifier that identifies the communication network 10-n associated with the communication device 12T. In other embodiments, the resolved network identifier includes a communication network domain identifier that identifies a domain controlled by the communication network 10-n associated with the communication device 12T.

[0119] In some embodiments, the method further comprises generating a second identifier as a combination of the network-specific device identifier 22D and the resolved network identifier. In some embodiments, the method further comprises generating the second request 14R to include or reference the second identifier.

[0120] In some embodiments, the obfuscated network identifier is formed from encryption of the network identifier, and resolving the obfuscated network identifier comprises decrypting the obfuscated network identifier to obtain the resolved network identifier. In some embodiments, resolving the obfuscated network identifier further comprises transmitting, to another device, signaling indicating an encryption key based on which the obfuscated network identifier is to be or has been encrypted. The encryption key may be indicated by including the encryption key itself in the signaling, or by including an identifier of a location or resource from which the encryption key can be obtained. In some embodiments, decrypting the obfuscated network identifier comprises decrypting the obfuscated network identifier using a decryption key that is paired with the encryption key.

[0121] In some embodiments, the method further comprises, before receiving the first request 20R, receiving, from each of the one or more communication networks 10-1...10-N, obfuscation resolution information. In some embodiments, the information includes a resolved network identifier that identifies the communication network 10-n or a domain controlled by the communication network 10-n. In some embodiments, the information includes an obfuscated network identifier that is associated with, but that obfuscates, the resolved network identifier, or information based on which the obfuscated network identifier is determinable. In some embodiments, said resolving comprises attempting to resolve the obfuscated network identifier included in the communication device identifier 22 using the obfuscation resolution information received from one or more of the one or more communication networks 10-1...10-N.

[0122] In some embodiments, for each of the one or more communication networks 10- 1 ... 10-N, the information based on which the obfuscated network identifier is determinable includes a random value. In some embodiments, the obfuscated network identifier is determinable by hashing the resolved network identifier with the random value.

[0123] In some embodiments, the obfuscation resolution information received from each of the one or more communication networks 10-1... 10-N further includes an expiration time after which the obfuscation resolution information becomes invalid. In some embodiments, said resolving comprises attempting to resolve the obfuscated network identifier included in the communication device identifier 22 using obfuscation resolution information that has been received from one or more of the one or more communication networks 10-1... 10-N and that is still valid.

[0124] In some embodiments, the invoker device 18 is the communication device 12T, with the first request 20R being received from an application executed on the communication device 12T. In other embodiments, the invoker device 18 is an application backend server that provides a service to an application executed on the communication device 12T.

[0125] Figure 7 depicts a method performed by an identifier server 24 of a communication network 10-n in accordance with other particular embodiments. The method includes generating a communication device identifier 22 for a communication device 12T (Block 700). In some embodiments, the communication device identifier 22 is generated to include a network-specific device identifier 22D that identifies the communication device 12T within whatever communication network 10-1... 10-N the communication device 12T is associated. In some embodiments, the communication device identifier 22 is generated to include an obfuscated network identifier 22N that is associated with, but that obfuscates, the communication network 10-n with which the communication device 12T is associated. The method also includes transmitting the communication device identifier 22 to one or more other devices 12T, 16, 18 (Block 730).

[0126] In some embodiments, the one or more other devices include at least the communication device 12T. In other embodiments, the one or more other devices include at least an intermediary device 16 configured to serve as an intermediary for the communication network 10-n and to expose a first application programming interface, API, 20. In yet other embodiments, the one or more other devices include at least an invoker device 18 configured to invoke the first API 20 for requesting a service or resource for the communication device 12T.

[0127] In some embodiments, the invoker device 18 is the communication device 12T or an application backend server that provides a service to an application executed on the communication device 12T.

[0128] In some embodiments, the method further comprises transmitting, to the intermediary device 16, obfuscation resolution information. In some embodiments, the obfuscation resolution information includes a resolved network identifier that identifies the communication network 10-n or a domain controlled by the communication network 10-n. In some embodiments, the obfuscation resolution information includes the obfuscated network identifier 22N or information based on which the obfuscated network identifier 22N is determinable.

[0129] In some embodiments, the information based on which the obfuscated network identifier 22N is determinable includes a random value, wherein the obfuscated network identifier 22N is determinable by hashing the communication network domain identifier with the random value. In some embodiments, the obfuscation resolution information further includes an expiration time after which the obfuscation resolution information becomes invalid.

[0130] In some embodiments, the network-specific device identifier 22D is a local identifier that is local to, or unique within, the communication network 10-n associated with the communication device 12T, and the local identifier and the obfuscated network identifier 22N in combination form a global identifier that is globally unique.

[0131] In some embodiments, the communication device identifier 22 is a network access identifier comprising a username part and a realm part. In some embodiments, the networkspecific device identifier 22D is included in or represented by the username part and the obfuscated network identifier 22N is included in the realm part.

[0132] In some embodiments, the method further comprises generating the obfuscated network identifier 22N by encrypting or hashing a communication network identifier that identifies the communication network 10-n or a domain controlled by the communication network 10-n (Block 740). Figure 8 depicts a method performed by a node 12T, 18 that is a communication device 12T or a server 18 in accordance with other particular embodiments. The method includes transmitting, to an identifier server 24 in a communication network 10-n, a request for a communication device identifier 22 that is to identify a communication device 12T to an invoker device 18 of a first application programming interface, API, 20 exposed by an intermediary device 16 which serves as an intermediary for the communication network 10-n (Block 800). The method also includes receiving a response that includes the communication device identifier 22 (Block 810). In some embodiments, the communication device identifier 22 obfuscates with which communication network 10-n the communication device 12T is associated.

[0133] In some embodiments, the communication device identifier 22 includes a networkspecific device identifier 22D that identifies the communication device 12T within whatever communication network 10-n the communication device 12T is associated. In some embodiments, the communication device identifier 22 includes an obfuscated network identifier 22N that is associated with, but that obfuscates, the communication network 10-n with which the communication device 12T is associated. In some embodiments, the communication network 10-n or a domain controlled by the communication network 10-n is identified by a communication network identifier. In some embodiments, the obfuscated network identifier 22N is the communication network identifier as encrypted with an encryption key. In some embodiments, the request includes the encryption key or the location of the encryption key with which the communication network identifier is to be encrypted.

[0134] In some embodiments, the node 12T, 18 is the invoker device 18. In some embodiments, the method further comprises transmitting a first request 20R to the intermediary device 16. In some embodiments, the first request 20R includes the communication device identifier 22 and requests a service or resource for the communication device 12T identified by the communication device identifier 22.

[0135] Embodiments herein also include corresponding apparatuses. Embodiments herein for instance include an intermediary device 16 configured to perform any of the steps of any of the embodiments described above for the intermediary device 16.

[0136] Embodiments also include an intermediary device 16 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the intermediary device 16. The power supply circuitry is configured to supply power to the intermediary device 16.

[0137] Embodiments further include an intermediary device 16 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the intermediary device 16. In some embodiments, the intermediary device 16 further comprises communication circuitry.

[0138] Embodiments further include an intermediary device 16 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the intermediary device 16 is configured to perform any of the steps of any of the embodiments described above for the intermediary device 16.

[0139] Embodiments herein also include an identifier server 24 configured to perform any of the steps of any of the embodiments described above for the identifier server 24.

[0140] Embodiments also include an identifier server 24 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the identifier server 24. The power supply circuitry is configured to supply power to the identifier server 24.

[0141] Embodiments further include an identifier server 24 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the identifier server 24. In some embodiments, the identifier server 24 further comprises communication circuitry.

[0142] Embodiments further include an identifier server 24 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the identifier server 24 is configured to perform any of the steps of any of the embodiments described above for the identifier server 24.

[0143] Embodiments herein also include a node configured to perform any of the steps of any of the embodiments described above for a communication device 12T or a server (e.g., which may be the invoker device 18).

[0144] Embodiments also include a node comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for a communication device 12T or a server (e.g., which may be the invoker device 18). The power supply circuitry is configured to supply power to the node.

[0145] Embodiments further include a node comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for a communication device 12T or a server (e.g., which may be the invoker device 18). In some embodiments, the node further comprises communication circuitry.

[0146] Embodiments further include a node comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the node is configured to perform any of the steps of any of the embodiments described above for a communication device 12T or a server (e.g., which may be the invoker device 18). More particularly, the apparatuses described above may perform the methods herein and any other processing by implementing any functional means, modules, units, or circuitry. In one embodiment, for example, the apparatuses comprise respective circuits or circuitry configured to perform the steps shown in the method figures. The circuits or circuitry in this regard may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. For instance, the circuitry may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein, in several embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the one or more processors, carries out the techniques described herein.

[0147] Figure 9 for example illustrates an intermediary device 16 as implemented in accordance with one or more embodiments. As shown, the intermediary device 16 includes processing circuitry 910 and communication circuitry 920. The communication circuitry 920 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 910 is configured to perform processing described above, e.g., in Figure 6, such as by executing instructions stored in memory 930. The processing circuitry 910 in this regard may implement certain functional means, units, or modules.

[0148] Figure 10 illustrates an identifier server 24 as implemented in accordance with one or more embodiments. As shown, the identifier server 24 includes processing circuitry 1010 and communication circuitry 1020. The communication circuitry 1020 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 1010 is configured to perform processing described above, e.g., in Figure 7, such as by executing instructions stored in memory 1030. The processing circuitry 1010 in this regard may implement certain functional means, units, or modules.

[0149] Figure 11 illustrates a node 1100 as implemented in accordance with one or more embodiments. The node 1100 may for example be the communication device 12T. Or, the node 1100 may be a server, such as the application backend server described herein or another server that functions as the invoker device 18 herein. As shown, the node 1100 includes processing circuitry 1110 and communication circuitry 1120. The communication circuitry 1120 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 1110 is configured to perform processing described above, e.g., in Figure 7, such as by executing instructions stored in memory 1130. The processing circuitry 1110 in this regard may implement certain functional means, units, or modules.

[0150] Those skilled in the art will also appreciate that embodiments herein further include corresponding computer programs.

[0151] A computer program comprises instructions which, when executed on at least one processor of an apparatus, cause the apparatus to carry out any of the respective processing described above. A computer program in this regard may comprise one or more code modules corresponding to the means or units described above.

[0152] Embodiments further include a carrier containing such a computer program. This carrier may comprise one of an electronic signal, optical signal, radio signal, or computer readable storage medium.

[0153] In this regard, embodiments herein also include a computer program product stored on a non-transitory computer readable (storage or recording) medium and comprising instructions that, when executed by a processor of an apparatus, cause the apparatus to perform as described above.

[0154] Embodiments further include a computer program product comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device. This computer program product may be stored on a computer readable recording medium.

[0155] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0156] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally. Notably, modifications and other embodiments of the present disclosure will come to mind to one skilled in the art having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the present disclosure is not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of this disclosure. Although specific terms may be employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

CLAIMS1 . A method performed by an intermediary device (16) configured to serve as an intermediary for one or more communication networks (10-1 ... 10-N), the method comprising: receiving (600) a first request (20R) from an invoker device (18) through a first application programming interface, API, (20) exposed by the intermediary device (16), wherein the first request (20R) requests a service or resource for a communication device (12T) identified by a communication device identifier (22) included in or referenced by the first request (20R), wherein the communication device identifier (22) obfuscates with which communication network (10-1 ... 10-N) the communication device (12T) is associated; resolving (610) the communication device identifier (22) to identify the communication network (10-n) associated with the communication device (12T); and transmitting (620) a second request (14R) to the identified communication network (10-n) through a second API (14) exposed by the identified communication network (10-n), wherein the second request (14R) requests the service or resource for the communication device (12T).

2. The method of claim 1 , wherein the communication device identifier (22) includes: a network-specific device identifier (22D) that identifies the communication device (12T) within whatever communication network (10-n) the communication device (12T) is associated; and an obfuscated network identifier (22N) that is associated with, but that obfuscates, the communication network (10-n) with which the communication device (12T) is associated.

3. The method of claim 2, wherein the network-specific device identifier (22D) is a local identifier that is local to, or unique within, the communication network (10-n) associated with the communication device (12T), and wherein the local identifier and the obfuscated network identifier (22N) in combination form a global identifier that is globally unique.

4. The method of any one of claims 2-3, wherein the communication device identifier (22) is a network access identifier comprising a username part and a realm part, wherein the network-specific device identifier (22D) is included in or represented by the username part and the obfuscated network identifier (22N) is included in the realm part.

5. The method of any one of claims 2-4, wherein said resolving comprises resolving the obfuscated network identifier (22N) to identify the communication network (10-n) associated with the communication device (12T) in terms of a resolved network identifier, wherein the resolved network identifier includes: a communication network identifier that identifies the communication network (10-n) associated with the communication device (12T); or a communication network domain identifier that identifies a domain controlled by the communication network (10-n) associated with the communication device (12T).

6. The method of claim 5, wherein the method further comprises: generating a second identifier as a combination of the network-specific device identifier (22D) and the resolved network identifier; and generating the second request (14R) to include or reference the second identifier.

7. The method of any one of claims 5-6, wherein the obfuscated network identifier (22N) is formed from encryption of the resolved network identifier, and wherein resolving the obfuscated network identifier (22N) comprises decrypting the obfuscated network identifier (22N) to obtain the resolved network identifier.

8. The method of claim 7, further comprising transmitting, to another device, signaling indicating an encryption key based on which the obfuscated network identifier (22N) is to be or has been encrypted, wherein decrypting the obfuscated network identifier (22N) comprises decrypting the obfuscated network identifier (22N) using a decryption key that is paired with the encryption key.

9. The method of any one of claims 2-8, further comprising, before receiving the first request (20R), receiving, from each of the one or more communication networks (10-1 ... 10- N), obfuscation resolution information that includes: a resolved network identifier that identifies the communication network (10-n) or a domain controlled by the communication network (10-n); and an obfuscated network identifier (22N) that is associated with, but that obfuscates, the resolved network identifier, or information based on which the obfuscated network identifier (22N) is determinable; and wherein said resolving comprises attempting to resolve the obfuscated network identifier (22N) included in the communication device identifier (22) using the obfuscation resolutioninformation received from one or more of the one or more communication networks (10- 1...10-N).

10. The method of claim 9, wherein, for each of the one or more communication networks (10-1 ... 10-N), the information based on which the obfuscated network identifier (22N) is determinable includes a random value, wherein the obfuscated network identifier (22N) is determinable by hashing the resolved network identifier with the random value.

11. The method of any one of claims 9-10, wherein the obfuscation resolution information received from each of the one or more communication networks (10-1 ... 10-N) further includes an expiration time after which the obfuscation resolution information becomes invalid, wherein said resolving comprises attempting to resolve the obfuscated network identifier (22N) included in the communication device identifier (22) using obfuscation resolution information that has been received from one or more of the one or more communication networks (10-1 ... 10-N) and that is still valid.

12. The method of any one of claims 1-11 , wherein the invoker device (18) is either: the communication device (12T), with the first request (20R) being received from an application executed on the communication device (12T); or an application backend server that provides a service to an application executed on the communication device (12T).

13. A method performed by an identifier server (24) of a communication network (10-n), the method comprising: generating (700) a communication device identifier (22) for a communication device (12T) to include: a network-specific device identifier (22D) that identifies the communication device (12T) within whatever communication network (10-1 ... 10-N) the communication device (12T) is associated; and an obfuscated network identifier (22 N) that is associated with, but that obfuscates, the communication network (10-n) with which the communication device (12T) is associated; and transmitting (730) the communication device identifier (22) to one or more other devices (12T, 16, 18).

14. The method of claim 1 , wherein the one or more other devices include one or more of: the communication device (12T);an intermediary device (16) configured to serve as an intermediary for the communication network (10-n) and to expose a first application programming interface, API, (20); or an invoker device (18) configured to invoke the first API (20) for requesting a service or resource for the communication device (12T), wherein the invoker device (18) is the communication device (12T) or an application backend server that provides a service to an application executed on the communication device (12T).

15. The method of claim 14, further comprising transmitting, to the intermediary device (16), obfuscation resolution information that includes: a resolved network identifier that identifies the communication network (10-n) or a domain controlled by the communication network (10-n); and the obfuscated network identifier (22N) or information based on which the obfuscated network identifier (22N) is determinable16. The method of claim 15, wherein the information based on which the obfuscated network identifier (22N) is determinable includes a random value, wherein the obfuscated network identifier (22N) is determinable by hashing the communication network domain identifier with the random value.

17. The method of any one of claims 15-16, wherein the obfuscation resolution information further includes an expiration time after which the obfuscation resolution information becomes invalid.

18. The method of any one of claims 13-17, wherein the network-specific device identifier (22D) is a local identifier that is local to, or unique within, the communication network (10-n) associated with the communication device (12T), and wherein the local identifier and the obfuscated network identifier (22N) in combination form a global identifier that is globally unique.

19. The method of any one of claims 13-18, wherein the communication device identifier (22) is a network access identifier comprising a username part and a realm part, wherein the network-specific device identifier (22D) is included in or represented by the username part and the obfuscated network identifier (22N) is included in the realm part.

20. The method of any one of claims 13-19, further comprising generating the obfuscated network identifier (22N) by encrypting or hashing a communication network identifier that identifies the communication network (10-n) or a domain controlled by the communication network (10-n).

21. The method of claim 20, further comprising: receiving a request for the communication device identifier (22); retrieving an encryption key from the request or from a location indicated by the request; verifying a signature or fingerprint of the encryption key to confirm that the encryption key is provided by a registered intermediary device; wherein generating the obfuscated network identifier (22N) comprises, based on said verifying, generating the obfuscated network identifier (22N) by encrypting the communication network identifier using the encryption key.

22. The method of any of claims 20-21 , wherein generating the obfuscated network identifier (22N) comprises generating the obfuscated network identifier (22N) by encrypting the communication network identifier using an encryption key, wherein generating the communication device identifier (22) comprises generating the communication device identifier (22) to include an indication of the encryption key used to encrypt the communication network identifier.

23. A method performed by a node (12T, 18) that is a communication device (12T) or a server (18), the method comprising: transmitting (800), to an identifier server (24) in a communication network (10-n), a request for a communication device identifier (22) that is to identify a communication device (12T) to an invoker device (18) of a first application programming interface, API, (20) exposed by an intermediary device (16) which serves as an intermediary for the communication network (10-n); and receiving (810) a response that includes the communication device identifier (22), wherein the communication device identifier (22) obfuscates with which communication network (10-n) the communication device (12T) is associated.

24. The method of claim 23, wherein the communication device identifier (22) includes: a network-specific device identifier (22D) that identifies the communication device (12T) within whatever communication network (10-n) the communication device (12T) is associated; andan obfuscated network identifier (22N) that is associated with, but that obfuscates, the communication network (10-n) with which the communication device (12T) is associated.

25. The method of claim 24, wherein the communication network (10-n) or a domain controlled by the communication network (10-n) is identified by a communication network identifier, wherein the obfuscated network identifier (22N) is the communication network identifier as encrypted with an encryption key, wherein the request includes the encryption key with which the communication network identifier is to be encrypted.

26. The method of any one of claims 23-25, wherein the node (12T, 18) is the invoker device (18), wherein the method further comprises transmitting a first request (20R) to the intermediary device (16), wherein the first request (20R) includes the communication device identifier (22) and requests a service or resource for the communication device (12T) identified by the communication device identifier (22).

27. An intermediary device (16) configured to serve as an intermediary for one or more communication networks (10-1 ... 10-N), the intermediary device (16) configured to: receive a first request (20R) from an invoker device (18) through a first application programming interface, API, (20) exposed by the intermediary device (16), wherein the first request (20R) requests a service or resource for a communication device (12T) identified by a communication device identifier (22) included in or referenced by the first request (20R), wherein the communication device identifier (22) obfuscates with which communication network (10-n) the communication device (12T) is associated; resolve the communication device identifier (22) to identify the communication network (10-n) associated with the communication device (12T); and transmit a second request (14R) to the identified communication network (10-n) through a second API (14) exposed by the identified communication network (10-n), wherein the second request (14R) requests the service or resource for the communication device (12T).

28. The intermediary device (16) of claim 27, configured to perform the method of any of claims 2-12.

29. An identifier server (24) of a communication network (10-n), the identifier server (24) configured to:generate a communication device identifier (22) for a communication device (12T) to include: a network-specific device identifier (22D) that identifies the communication device (12T) within whatever communication network (10-n) the communication device (12T) is associated; and an obfuscated network identifier (22 N) that is associated with, but that obfuscates, the communication network (10-n) with which the communication device (12T) is associated; and transmit the communication device identifier (22) to one or more other devices.

30. The intermediary device (16) of claim 29, configured to perform the method of any of claims 14-22.

31. A node (12T, 18) that is a communication device (12T) or a server, the node (12T, 18) configured to: transmit, to an identifier server (24) in a communication network (10-n), a request for a communication device identifier (22) that is to identify a communication device (12T) to an invoker device (18) of a first application programming interface, API, (20) exposed by an intermediary device (16) which serves as an intermediary for the communication network (10-n); and receive a response that includes the communication device identifier (22), wherein the communication device identifier (22) obfuscates with which communication network (10-n) the communication device (12T) is associated.

32. The node (12T, 18) of claim 31 , configured to perform the method of any of claims 24- 26.

33. A computer program comprising instructions which, when executed by at least one processor of an intermediary device (16), causes the external intermediary device (16) to perform the method of any one of claims 1-12.

34. A computer program comprising instructions which, when executed by at least one processor of an identifier server (24), causes the identifier server (24) to perform the method of any one of claims 13-22.

35. A computer program comprising instructions which, when executed by at least one processor of a node (12T, 18), causes the node (12T, 18) to perform the method of any oneof claims 23-26.

36. A carrier containing the computer program of any one of claims 33-35, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.

37. An intermediary device (16) configured to serve as an intermediary for one or more communication networks (10-1 ... 10-N), the external intermediary device (16) comprising: communication circuitry (920); and processing circuitry (910) configured to: receive a first request (20R) from an invoker device (18) through a first application programming interface, API, (20) exposed by the intermediary device (16), wherein the first request (20R) requests a service or resource for a communication device (12T) identified by a communication device identifier (22) included in or referenced by the first request (20R), wherein the communication device identifier (22) obfuscates with which communication network (10-n) the communication device (12T) is associated; resolve the communication device identifier (22) to identify the communication network (10-n) associated with the communication device (12T); and transmit a second request (14R) to the identified communication network (10-n) through a second API (14) exposed by the identified communication network (10-n), wherein the second request (14R) requests the service or resource for the communication device (12T).

38. The intermediary device (16) of claim 37, the processing circuitry (910) configured to perform the method of any of claims 2-12.

39. An identifier server (24) of a communication network (10-n), the identifier server (24) comprising: communication circuitry (1020); and processing circuitry (1010) configured to: generate a communication device identifier (22) for a communication device (12T) to include: a network-specific device identifier (22D) that identifies the communication device (12T) within whatever communication network (10-n) the communication device (12T) is associated; andan obfuscated network identifier (22 N) that is associated with, but that obfuscates, the communication network (10-n) with which the communication device (12T) is associated; and transmit the communication device identifier (22) to one or more other devices.

40. The identifier server (24) of claim 39, the processing circuitry (1010) configured to perform the method of any of claims 14-22.

41. A node (1100, 12T, 18) that is a communication device (12T) or a server, the node (1100, 12T, 18) comprising: communication circuitry (1120); and processing circuitry (1110) configured to: transmit, to an identifier server (24) in a communication network (10-n), a request for a communication device identifier (22) that is to identify a communication device (12T) to an invoker device (18) of a first application programming interface, API, (20) exposed by an intermediary device (16) which serves as an intermediary for the communication network (10-n); and receive a response that includes the communication device identifier (22), wherein the communication device (12T) identifier obfuscates with which communication network (10-n) the communication device (12T) is associated.

42. The node (12T, 18) of claim 41, the processing circuitry (1110) configured to perform the method of any of claims 24-26.

43. A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an intermediary device (16), cause the intermediary device (16) to: receive a first request (20R) from an invoker device (18) through a first application programming interface, API, (20) exposed by the intermediary device (16), wherein the first request (20R) requests a service or resource for a communication device (12T) identified by a communication device identifier (22) included in or referenced by the first request (20R), wherein the communication device identifier (22) obfuscates with which communication network (10-n) the communication device (12T) is associated;resolve the communication device identifier (22) to identify the communication network (10-n) associated with the communication device (12T); and transmit a second request (14R) to the identified communication network (10-n) through a second API (14) exposed by the identified communication network (10-n), wherein the second request (14R) requests the service or resource for the communication device (12T).

44. A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of an identifier serve of a communication network (10-n), cause the identifier server (24) to: generate a communication device identifier (22) for a communication device (12T) to include: a network-specific device identifier (22D) that identifies the communication device (12T) within whatever communication network (10-n) the communication device (12T) is associated; and an obfuscated network identifier (22 N) that is associated with, but that obfuscates, the communication network (10-n) with which the communication device (12T) is associated; and transmit the communication device identifier (22) to one or more other devices.

45. A non-transitory computer-readable storage medium on which is stored instructions that, when executed by a processor of a node (12T, 18) that is a communication device (12T) or a server, cause the node (12T, 18) to: transmit, to an identifier server (24) in a communication network (10-n), a request for a communication device identifier (22) that is to identify a communication device (12T) to an invoker device (18) of a first application programming interface, API, (20) exposed by an intermediary device (16) which serves as an intermediary for the communication network (10-n); and receive a response that includes the communication device identifier (22), wherein the communication device (12T) identifier obfuscates with which communication network (10-n) the communication device (12T) is associated.

Citation Information

Patent Citations

  • Methods and apparatus for an identifier server, communication device, server, authorization server, external invoker device, and application programming interface provider server

    WO2025189380A1

  • Web cookie virtualization

    US10747787B2

  • Network service architecture

    US20040193677A1

  • Obfuscation and de-obfuscation of identifiers

    US9596263B1