Method and related apparatuses for managing identifiers of devices for the provisioning of services

The method and apparatus address the gaps in network capability descriptions by standardizing device identifier and credential management, enhancing efficiency and security in service provisioning.

WO2026086120A1PCT designated stage Publication Date: 2026-04-30HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-04-15
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

There are gaps between the requirements of future network capability descriptions and existing API specifications in communication networks, particularly in managing device identifiers and credentials for service provisioning, which affect efficiency and security.

Method used

A method and apparatus for managing device identifiers and credentials, including operations such as updating, assigning, and revoking identifiers, and generating credentials, with standardized exchanges to enhance efficiency and security in service provisioning.

Benefits of technology

The solution enables efficient and secure management of device identifiers and credentials, ensuring secure device authentication while preserving privacy and reducing errors in network configurations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025089133_30042026_PF_FP_ABST
    Figure CN2025089133_30042026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a method and related apparatuses for managing identifiers and / or credentials of devices for the provisioning of services. A first node receives, from a second node, a request related to the management of an identifier of a device for one or more services, wherein the request comprises an operation to be performed by the first node. The first node manages the identifier of the device based on the request, which may involve updating an identifier, assigning a new identifier, identifying a device, being notified of an identifier or revoking an identifier. The first node then transmits a response to the second node, wherein the response is based on the operation performed by the first node. The first node may also receive requests to generate and manage credentials of devices, based on different authentication methods and algorithms.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND RELATED APPARATUSES FOR MANAGING IDENTIFIERS OF DEVICES FOR THE PROVISIONING OF SERVICESCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to US provisional patent application No. 63 / 710,902, filed on October 23, 2024, which is hereby incorporated by reference in its entirety.TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication technologies, and in particular, to a method and related apparatuses for the management of identifiers and / or credentials of devices, for devices seeking to benefit from one or more services rendered by the network or by service providers.BACKGROUND

[0003] Many emerging trends are driving the consideration and design of wireless networks, such as 6G networks; including new network infrastructure capabilities; advances in maturing technologies, including large-scale Artificial Intelligence (AI) models, data de-privacy techniques, and blockchain; emerging applications and services, such as AI-driven solutions, data sensing services, and digital world services; and a shift toward global, open, and collaborative operations.

[0004] New expectation and stricter requirements on future networks also drive rethinking and development of new generation of wireless networks. These requirements include privacy and trustworthiness, simplified standardization and rapid deployment.

[0005] In the fifth generation (5G) era, a new core network has been introduced by 3GPP, relying on an open and modular service platform, the Service-Based Architecture (SBA) . SBA provides a cloud-native service framework, in which mobile core network functionalities (authentication, mobility management, etc. ) are supported by network functions (NFs) . Service providers can provide services to any other authorized service consumer through Application Programming Interfaces (APIs) .

[0006] In this service framework, each NF can consume the services provided by other NFs and expose services as well. There can be a centralized repository, the Network Repository Function (NRF) , in which NFs can publish new services. The service information maintained in the NRF is accessible to all the NFs to enable service discovery. The consumer NFs can also retrieve required routing information from the NRF to interact with the service producer NFs.

[0007] To expose services to consumers, a service provider may describe its services using API specifications. For example, the OpenAPI specification provides a formal standard for describing HTTP APIs. An OpenAPI description allows both people and computers to discover and understand how an API works, including available resources and authorized operations on each resource, operation parameters, input and output for each operation, etc.

[0008] However, there are gaps between the requirements of future network capability descriptions and existing API specifications.

[0009] Therefore, improvements in communication networks are desirable.

[0010] This background information is provided to reveal information believed by the applicant to be of possible relevance to the present disclosure. No admission is necessarily intended, nor should be construed, that any of the preceding information constitutes prior art against the present disclosure.SUMMARY

[0011] In a first aspect, a method applied at a first node is provided by the embodiment of the present disclosure, and the method includes: receiving, from a second node, a request related to the management of an identifier of a device for one or more services, wherein the request comprises at least one operation to be performed by the first node; managing the identifier of the device based on the request; and transmitting a response to the second node, wherein the response is based on the at least one operation performed by the first node.

[0012] The first node can therefore be configured to perform various operations in connection with identifier management of devices, and these operations make the configurations and provisioning of services for the devices more efficient, whether the services are rendered by network nodes or nodes external to the network.

[0013] In a possible implementation of the first aspect, the at least one operation performed by the first node for managing the identifier of the device includes at least one of: updating the identifier of the device, assigning a new identifier for the device, identifying the device, revoking an identifier of the device or providing notification of an identifier of the device.

[0014] In a possible implementation of the first aspect, the request may further include at least one of: a name of the device; a name of the one or more services; an identifier of the device is assigned by a service provider; and the at least one operation to be performed by the first node.

[0015] In a possible implementation of the first aspect, the name of the device may include at least one of: a first temporary identifier of the device for accessing one or more services provided by the network, a second temporary identifier of the device to access one or more services provided by a service provider; and an identifier of the device for privacy preservation of the device.

[0016] In a possible implementation of the first aspect, the name of the service may include an identifier of the service.

[0017] In a possible implementation of the first aspect, the response may include at least one of: one or more temporary identifiers of the device that are different from an initial identifier of the device provided in the request; an identifier of the device that is used for authenticating the device and an indication of whether the initial identifier of the device has been revoked.

[0018] In a possible implementation of the first aspect, the one or more temporary identifiers of the device may include at least one of the first temporary identifier of the device and the second temporary identifier of the device.

[0019] In a possible implementation of the first aspect, for executing the method, the first node may maintain a device identifier table, wherein the device identifier table includes a list of identifiers of the device and a list of names of service providers.

[0020] In a possible implementation of the first aspect, for the first node to perform the method, the second node may need to have subscribed to services of the first node. The second node may be a service provider for providing the one or more services to the device, or a network function for provisioning the services to be rendered to the device.

[0021] In a possible implementation of the first aspect, the network function comprises a service provisioning management function.

[0022] Standardizing exchanges in connection with the management of identifiers of devices that require different services, in terms of the fields (dimensions) of each message and the possible content for each of these fields, makes the configuration of network nodes and the provision of services more efficient. These implementations also limit errors and ensure secure device authentication, while preserving privacy of users of the devices.

[0023] In a possible implementation of the first aspect, when the second node is unable to identify the device, the first node receives, from the second node, the request related to the management of the identifier of the device, the request including the identifier of the device for the privacy preservation of the device and an operation to be performed by the first node, the operation being to identify the device. The first node transmits the response to the second node by performing a look-up in the device identifier table, wherein the response includes at least one of the identifiers of the device for authenticating the device, and the first temporary identifier of the device.

[0024] In a possible implementation of the first aspect, the first may receive, from the second node, a request to assign a new second temporary identifier to the device on behalf of a service provider (NC) . The request may include at least one of: the first temporary identifier of the device or the identifier of the device for privacy preservation of the device, and an identifier of the service provider. The request may further indicate an operation to be performed by the first node, the operation being to assign the new second temporary identifier to the device. The first node transmits the response to the second node, wherein the response comprises the new second temporary identifier of the device.

[0025] In a possible implementation of the first aspect, the first node may receive, from the second node, a request for updating a second temporary identifier of the device. The request may include the second temporary identifier of the device and an operation to be performed by the first node. The operation is to update the second temporary identifier of the device. The first node then transmits the response to the second node, wherein the response indicates that the second temporary identifier of the device has been updated to a new second temporary identifier of the device.

[0026] In a possible implementation of the first aspect, the first node may receive, from the second node, a request for updating a first temporary identifier of the device, wherein the request includes the first temporary identifier of the device and an operation to be performed by the first node. The operation is to update the first temporary identifier of the device. The first node transmits the response to the second node, wherein the response indicates that the first temporary identifier of the device has been updated to a new first temporary identifier of the device.

[0027] In a possible implementation of the first aspect, the first node may receive, from the second node, a request for revoking at least one of a first temporary identifier of the device, and a second temporary identifier of the device. The request includes at least one of the first temporary identifier of the device and the second temporary identifier of the device. The operation to be performed by the first node is revoke at least one of the first temporary identifier of the device and the second temporary identifier of the device. The first node transmits the response to the second node, wherein the response indicates whether at least one of the first temporary identifier of the device and the second temporary identifier of the device has been revoked.

[0028] In a possible implementation of the first aspect, the first node may receive, from the second node, a request to revoke at least one of the first temporary identifier of the device and the second temporary identifier of the device. The request includes at least one of the first temporary identifier of the device and the second temporary identifier of the device, a service provider identifier, and an operation to be performed by the first node. The operation is to revoke at least one of the first temporary identifier of the device and the second temporary identifier of the device. The first node transmits the response to the second node, wherein the response indicates whether at least one of the first temporary identifier of the device and the second temporary identifier of the device has been revoked.

[0029] In a possible implementation of the first aspect, the first node may receive, by the second node, a request to notify the first node that the second temporary identifier of the device has been assigned by a service provider. The request comprises the first temporary identifier of the device; an identifier of the service provider; the second temporary identifier of the device; and an operation to be performed by the first node. The operation is that the first node is notified that the second temporary identifier of the device has been assigned by the service provider. The first node then updates a device identifier table with the first temporary identifier of the device and the second temporary identifier of the device.

[0030] In a possible implementation of the first aspect, the first node may receive, from the second node, a request to notify the first node that the first temporary identifier of the device has been assigned by the second node, wherein the second node is a network function for provisioning the services to be rendered to the device. The request includes the identifier of the device for the privacy preservation of the device or the first temporary identifier of the device, a new first temporary identifier of the device assigned by the second node; and an operation to be performed by the first node. The operation is that the first node is notified that the first temporary identifier of the device has been assigned by the second node. The first node then updates a device identifier table with the new first temporary identifier of the device.

[0031] In a second aspect, a method performed at a first node is provided. The method includes: receiving, from a second node, a request to generate credentials for a device, the request comprising information including an identifier of the device, an authentication method and a corresponding algorithm; generating the credentials for the device based on the information in the request; and transmitting a response to the second node, the response comprising the credentials generated for the device based on at least one of: the identifier of the device, the authentication method and the corresponding algorithm.

[0032] Thus, according to this second aspect, the first node is configured to respond to requests from other nodes for device credentials to be used to authenticate devices for the provision of services by the network and / or by external service providers. The authentication methods and algorithms to be used can therefore be pre-negotiated and pre-configured, with standardized exchanges, enabling services to be rendered to devices more efficiently and securely.

[0033] In a possible implementation of the second aspect, the identifier of the device may either be a temporary identifier of the device for accessing one or more services provided by the network, or an identifier of the device for privacy preservation of the device.

[0034] In a possible implementation of the second aspect, the authentication method may include one of: an Authentication and Key Agreement (AKA) ; a Physically Unclonable Function (PUF) ; and a 6G Extensible Authentication Protocol (6G-EAP) .

[0035] In a possible implementation of the second aspect, based on the authentication method indicated in the request, an identifier of a specific authentication algorithm to be used is provided as the corresponding algorithm.

[0036] In a possible implementation of the second aspect, the request may further comprise one or more parameters associated with the credentials, the credentials depending on the authentication method selected, the credentials generated by the first node being further based on the one or more parameters.

[0037] In a possible implementation of the second aspect, the request may further comprise an identifier of the corresponding algorithm, wherein the credentials are generated based on the corresponding algorithm.

[0038] In a possible implementation of the second aspect, the authentication method may be AKA and the credentials of the device generated by the first node in this case comprise an AKA vector.

[0039] In a possible implementation of the second aspect, the authentication method may be PUF, and the credentials of the device generated by the first node in this case are PUF-based credentials.

[0040] In a possible implementation of the second aspect, the authentication method may be 6G-EAP and the credentials generated by the first node in this case comprise an EAP certificate.

[0041] In a possible implementation of the second aspect, the second node may be a service provisioning management (SPM) node.

[0042] In a possible implementation of the second aspect, the method may be performed when the second node does not have identification information on the device and the second node is required to authenticate the device.

[0043] In a possible implementation of the second aspect, the action request may be called by an automatic network capability programming (A-CAP) service or a connectivity management (CM) service, that is triggered by a device or by a service provisioning management (SPM) node.

[0044] The clear, standardized definition of the actions and information required to manage device credentials, with reliable authentication methods, enhances exchange security and assures users of the confidential and secure handling of exchanges over the network. Standardization also makes it possible to automate the configuration of the various aspects required to provide services to devices by the network and / or by external network providers.

[0045] In another aspect, an apparatus is configured to perform the method as per any one of the possible implementations described above.

[0046] In another aspect, the apparatus may include one or more processors; and one or more memories storing instructions which, when executed by the one or more processors, cause the apparatus to perform the method according to any one of the implementations described above.

[0047] In another aspect, a computer program product is provided, and comprises program code for performing the method according to any one of the implementations described above.

[0048] In another aspect, a computer program is provided, comprising computer execution instructions which, when executed by a processor, cause the processor to execute the method according to any one of the implementations described above.

[0049] In another aspect, a computer-readable medium is provided, storing computer execution instructions which, when executed by a processor, cause the processor to execute the method according to any one of the implementations described above.

[0050] In another aspect, a chip is provided, comprising an input / output (I / O) interface and a processor, wherein the processor is configured to call and run a computer program stored in a memory, to enable a device installing with the chip to perform the method according to any one of the implementations described above.BRIEF DESCRIPTION OF THE DRAWINGS

[0051] The accompanying drawings are used to provide a further understanding of the present disclosure, constitute a part of the specification, and are used to explain the present disclosure together with the following specific embodiments, but should not be construed as limiting the present disclosure.

[0052] FIG. 1 shows a simplified schematic illustration of a 6G system conceptual structure according to one or more example implementations of the present disclosure.

[0053] FIG. 2A shows a simplified schematic illustration of an example of an apparatus in a communication system according to one or more example implementations of the present disclosure.

[0054] FIG. 2B shows connections related to a wireless device in a communication system according to one or more example implementations of the present disclosure.

[0055] FIG. 3 shows a schematic flowchart of a method according to one or more embodiments of the present disclosure.

[0056] FIG. 4 shows a schematic flowchart of another method according to one or more embodiments of the present disclosure.

[0057] FIG. 5 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure.

[0058] FIG. 6 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure.

[0059] FIG. 7 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure.

[0060] FIG. 8 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure.

[0061] FIG. 9 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure.

[0062] FIG. 10 shows a block diagram of an apparatus according to one or more embodiments of the present disclosure.

[0063] FIG. 11 shows a block diagram of another apparatus according to one or more embodiments of the present disclosure.

[0064] FIG. 12 shows a schematic structural diagram of a communication apparatus according to one or more embodiments of the present disclosure.

[0065] FIG. 13 shows a schematic diagram of an architecture of a computing device cluster according to one or more embodiments of the present disclosure.

[0066] FIG. 14 shows a schematic diagram of a connection between computing devices over a network according to one or more embodiments of the present disclosure.DETAILED DESCRIPTION

[0067] In the following description, reference is made to the accompanying figures, which form part of the present disclosure, and which show, by way of illustration, specific aspects of embodiments of the present disclosure or specific aspects in which embodiments of the present disclosure may be used. It is understood that embodiments of the present disclosure may be used in other aspects and include structural or logical changes not depicted in the figures. The following detailed description, therefore, is not to be taken in a limiting sense, and the scope of the present disclosure is defined by the appended claims.

[0068] The present disclosure generally relates to wireless communications.

[0069] The solution described in the present disclosure is applicable to a next generation (e.g., sixth generation (6G) or later) network, or a legacy (e.g. 5G or 4G) network.

[0070] The proposed 6G System architecture is defined to support 6G XaaS services by using techniques such as Network Function Virtualization and Network Slicing. The 6G System architecture utilizes service-based interactions between 6G services.

[0071] The 6G System leverages service-based architecture and X as a service (XaaS) concept. XaaS services in the 6G System are categorized into three layers. The 6G System conceptual structure is shown in FIG. 1.

[0072] Infrastructure Layer includes infrastructures supporting 6G services. Among them are wireless networks (radio access network (RAN) , core network (CN) ) infrastructures, Cloud / data center infrastructures, satellite networks, storage / database infrastructures, and sensing networks, and etc. These infrastructures can be provided by a single provider or by multiple providers. As shown in FIG. 1, each of the infrastructures on the infrastructure Layer could have its control and management functions, denoted as C / M functions, for infrastructure management. Each of these infrastructures is one type of Infrastructure as a Service.

[0073] Control and Management (C / M) layer includes control and management services of the 6G System. They are developed and deployed by using slicing techniques and utilizing resource provided by infrastructure layer. 6G services in Control and Management (C / M) layer are: - Resource Management (RM) as a Service provides a capability of life-cycle management of a variety of slices and  over-the-air resource assignment to wireless devices. - A 6G mission is defined as a service provided to customers by the 6G System. A mission can be a type of services  which is provided by a single 6G XaaS service or a type of services that needs contributions from multiple XaaS services. - Mission Management (MM) as a Service provides a capability to program provisioning of XaaS services at Service  Layer to provide mission services. - Confederation Network (CONET) as a Service provides a capability to enable multiple partners jointly provide 6G  services. This capability is provided by confederation formation, mutual authentication, mutual authorization among partners and negotiation of agreement on recording and retracing of selected actions performed by partners, in order to assure a trustworthy environment of 6G System operations. - Service Provisioning Management (SPM) as a Service provides a capability of control and management of 6G  service access by customers and provisioning of requested services. The capability is provided by unified mutual authentication, authorization and policy, key management, QoS assurance and charging between any pair of XaaS service provider and customer. The customers include end-customers not only in physical world, but also digital representatives in digital world. - Connectivity Management (CM) as a Service leverages 5G connectivity management functions, but with extension  to include digital world. - Protocol as a Service provides a capability to design service customized protocol stacks for identified interfaces. - The protocol stacks could be pre-defined for on-demand selection, or could be on-demand designed. - Network Security as a Service provides a capability for owners of infrastructures to detect potential security risks  of their infrastructures. - XaaS services in C / M Layer support control and management of the 6G System itself and also provide support to  verticals if requested. One example is that RM service can serve RAN for over-the-air resource management and can also provide service to a vertical for the vertical’s over-the-air resource allocation to its end-customers. The XaaS in C / M layer can be deployed by using slicing technique.

[0074] Service Layer includes 6G services which provide services to customers. In the 6G System conceptual structure: - AI service is denoted as NET4AI as a Service. Artificial Intelligence service provides AI capability to support a  variety of AI applications. - Service of data collection, data sanitization, data analysis and data delivery are denoted as DAM as a Service, this  service provides a capability of lifecycle management of statistic data, including acquisition, de-privatization, analysis and delivery of data which are information statistic data from any types of sensors, devices, network functions, and etc. - Service of storage and sharing of data is denoted as NET4Data as a Service, this service provides a capability to  trustworthily storage and share data under the control of owners of data and following recognized authorities’ regulations on control of identified data. - Service to provide digital world is denoted as NET4DW as a Service, Digital World service provides a capability  to construct, control and manage digital world. Digital world is defined as digital realization of physical world. - 6G block chain service is denoted as NET4BC as a Service. 6G connectivity service is denoted as NET4Con as a  Service. This service provides a capability to support 6G block chain services. - Enhanced connectivity service, e.g., network for connectivity (NET4CON) as a service. This service provides a  capability to support exchange of messages and data among new 6G services.

[0075] All XaaS services at this Layer are developed and deployed by using resource provided in infrastructure and utilizing Network Function Virtualization and Slicing techniques. The capability of each of 6G services is provided by its control and management functions and service specific data process functions.

[0076] Each XaaS service mentioned above is provided by new defined 6G logical functions or by enhanced 5G logical functions or a combination of both.

[0077] In the present disclosure, the 6G customer can be of various types, including a device (e.g., electronic device ED, terminal device) , apparatus, a chip, an equipment (e.g., user equipment) etc. For example, the customer may be an individual customer, a business customer, etc. The 6G customer is used to connect persons, objects, machines, etc. The 6G customer may be widely used in various scenarios including, for example, cellular communications, device-to-device (D2D) , vehicle to everything (V2X) , peer-to-peer (P2P) , machine-to-machine (M2M) , MTC, internet of things (IoT) , virtual reality (VR) , augmented reality (AR) , mixed reality (MR) , metaverse, digital twin, industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, etc.

[0078] Each 6G customer represents any suitable end user device for wireless operation and may include such devices (or may be referred to but not limited to) as a user equipment (UE) or a user device or a terminal device, a wireless transmit / receive unit (WTRU) , a mobile station, a fixed or mobile subscriber unit, a cellular telephone, a station (STA) , a MTC device, a personal digital assistant (PDA) , a smartphone, a laptop, a computer, a tablet, a wireless sensor, a consumer electronics device, a smart book, a vehicle, a car, a truck, a bus, a train, or an IoT device, wearable devices (such as a watch, a pair of glasses, head mounted equipment, etc. ) , an industrial device, or an apparatus in (e.g. module, modem, or chip) or comprising the forgoing devices, among other possibilities. Future generation 6G customer may be referred to using other terms. When a 6G customer performs (or is configured to perform) a method described herein, it may be interpreted as the ED, one or more module (or units) in the ED, a circuit or chip, or a combination thereof, may perform the method. For example, the circuit or chip may include a modem chip, also referred to as a baseband chip, a system on chip (SoC) including a modem core, or system in package (SIP) ) , and the like, and may be responsible for one or more communication functions in the ED.

[0079] FIG. 2A shows a simplified schematic illustration of a deployment of a 6G system according to one or more example implementations of the present disclosure. In details, FIG. 2A illustrates an example of an apparatus 320 in a communication system (e.g., the 6G system) . The apparatus 320 may be a device (e.g. a device representing the customer) , a network node such as RAN, any components in RAN, CN or any Network Function in the 6G service of the present disclosure, or an apparatus includes one or more of the network functions (as mentioned above) . As shown in FIG. 2, the apparatus 320 may include at least one processor 260. Only one processor 260 is illustrated to avoid congestion in the drawing. The processor 260 may perform (or control the apparatus 320 to perform) operations (or methods) described herein as being performed by the apparatus 320.

[0080] When the apparatus is RAN, components of the RAN or the apparatus is the UE, the apparatus 320 may further include a transmitter 252 and a receiver 254 coupled to one or more antennas. One, some, or all of the antennas may alternatively be panels. The transmitter 201 and the receiver 203 may be integrated, e.g. as a transceiver. The transceiver is configured to modulate data or other content for transmission by at least one antenna or network interface controller (NIC) . The transceiver is also configured to demodulate data or other content received by the at least one antenna. Each transceiver includes any suitable structure for generating signals for wireless or wired transmission and / or processing signals received wirelessly or by wire. Each antenna includes any suitable structure for transmitting and / or receiving wireless or wired signals. In present disclosure, the transceiver (or transmitter 252 and / or receiver 254) may be viewed as an interface circuit.

[0081] The apparatus 320 may include at least one memory 258. The memory 258 stores instructions used to perform operations described herein. The memory 258 may also store data used, generated, or collected by the apparatus 320. For example, the memory 258 could store software instructions or modules configured to implement some or all of the functionality and / or embodiments described herein and that are executed by one or more processor 260.

[0082] For ease of understanding, different connections related to the device will be described in the first place. As shown in FIG. 2B, the device would be connected to its serving gateways, including a C / M gateway shown as C / M-TW-GW-1 and a data gateway shown as Data-TW-GW-1, it should be noted that although C / M-TW-GW-1 and Data-TW-GW-1 are shown as being deployed on the infrastructure of CN (e.g., CN infrastructure as shown in FIG. 1) , they could also be deployed on other infrastructures, such as RAN infrastructure, which is not limited in the embodiments of the present disclosure.

[0083] The connections related to the device may include but are not limited to following: 1) Device CN-C / M RB: an RB between a wireless device and its serving RAN (Cell, RB handler) that carries C / M  session traffic; 2) Device CN-data RB: an RB between a wireless device and its serving RAN (Cell, RB handler) that carries data  session traffic; 3) Device RAN-C / M RB: an RB between a wireless device and its serving RAN that carries RAN related C / M traffic; 4) Device RAN-data RB: an RB between a wireless device and its serving RAN that carries RAN related data traffic; 5) Device data session: a logical connection between a device and its serving Data-TW-GW, e.g., Data-TW-GW-1; 6) Device C / M session: a logical connection between a device and its serving C / M-TW-GW, e.g., C / M-TW-GW-1; 7) Device-NC connection: a logical connection between a device and a Network Capability (NC) (C / M NC or data  NC) . The connection carries data / information traffic; the connection would be a downlink connection or an uplink connection; 8) Device-ext (external) connection: a logical connection between a device and an entity, e.g., server, located in  external networks. A GW that has connection with external networks is an ext-Data-TW-GW or an ext-C / M-TW-GW, e.g., C / M-TW-GW-2 and Data-TW-GW-2 in this figure. Network needs to establish a tunnel between the device and an ext-GW to support a device-ext connection.

[0084] In 6G system, both new 6G XaaS services and network C / M XaaS services are categorized as basic XaaS services, a XaaS service (which is also referred to as service herein) is defined as a NC. The NCs at the C / M layer may be referred to as C / M NCs, and the NCs at the service layer may be referred to as data NCs.

[0085] There would be downlink and uplink RBs, downlink and uplink sessions, downlink and uplink device-NC connections, which are not shown in details.

[0086] With respect to the RBs between the device and the RAN shown in FIG. 2B, the RBs generally include device CN RB and device RAN RB. The device CN RB includes the above device CN-C / M RB and device CN-data RB, and the device RAN RB includes the above device RAN-C / M RB and device RAN-data RB. From the perspective of directions, the RB may be a downlink RB from RAN to a wireless device or an uplink RB from the wireless device to RAN, so the RB can be of a downlink type or an uplink type, the downlink and uplink RB may be referred to as a pair of RB; from the perspective of traffic types, the RB could be a C / M RB for carrying control signaling traffic on the C / M plane or a data RB for carrying data traffic on the data plane, so the RB can be of a C / M type or a data type; from the perspective of traffic destinations, the RB could be called a RAN-RB or a CN-RB, the RAN-RB is a RB that carries signaling messages or data traffic between a wireless device and RAN, the CN-RB is a RB that carries signaling messages or data traffic between a device and core network (CN) on the over-the-air interface, so in this case, the RB can be of a RAN-RB type or a CN-RB type. When combining the above different perspectives, different RBs may be downlink / uplink RAN-C / M RB (RAN-RB for carrying signaling messages on the C / M plane) , downlink / uplink RAN-data RB (RAN-RB for carrying data traffic on the data plane) , downlink / uplink CN-C / M RB (CN-RB for carrying signaling messages on the C / M plane) , downlink / uplink CN-data RB (CN-RB for carrying data traffic on the data plane) . That is, a RAN-RB may be an uplink / downlink RAN-C / M RB or RAN-data RB, a CN-RB could be an uplink / downlink CN C / M RB or CN-data RB; a C / M RB could be an uplink / downlink RAN-C / M RB or uplink / downlink CN-C / M RB, a data RB could be an uplink / downlink RAN-data RB or uplink / downlink CN-data RB.

[0087] With respect to the session related to a wireless device, from the perspective of traffic types, the session could be a C / M session which is a logical connection between a wireless device and its serving C / M-TW-GW for control signaling exchanging therebetween on the C / M plane, or a data session which is a logical connection between a device and its serving data-TW-GW for data exchanging therebetween on the data plane, so the session can be of a C / M type or a data type; from the perspective of directions, the session may be a downlink session from a serving GW (serving C / M-TW-GW or serving data-TW-GW) to a wireless device or an uplink session from the wireless device to the serving GW, so the session can be of a downlink type or an uplink type, the downlink and uplink sessions may be referred to as a pair of session. When combining the above different perspectives, different sessions may be downlink / uplink C / M session (C / M session for control signaling exchanging therebetween on the C / M plane) , or downlink / uplink data session (data session for data exchanging therebetween on the data plane) . That is, a session may be an uplink / downlink C / M session or data session.

[0088] With respect to the NC connection between a wireless device and a NC, from the perspective of traffic types, the NC connection could be a C / M NC connection which is a logical connection between a wireless device and a C / M entity of the NC, or a data NC connection which is a logical connection between the wireless device and a data entity of the NC, so the NC connection can be of a C / M type or a data type; from the perspective of directions, the NC connection may be a downlink NC connection from a entity (C / M entity or data entity) of the NC to a wireless device or an uplink NC connection from the wireless device to the entity, so the NC connection can be of a downlink type or an uplink type, the downlink and uplink NC connections may be referred to as a pair of NC connections. When combining the above different perspectives, different NC connections may be downlink / uplink C / M NC connections, or downlink / uplink data NC connections. That is, an NC connection may be an uplink / downlink C / M NC connection or a data NC connection.

[0089] As described above, both new 6G XaaS services and network C / M XaaS services are categorized as basic XaaS services, a XaaS service is defined as a NC. Each of these NCs can provide a single or a group of specific capabilities to enable 6G system control and management and 6G service provisioning, an NC can provide one or more sub-services, each sub-service being enabled by one or more basic network capabilities, i.e., actions. Each basic network capability or action could be described in a consistent format, and could be AI / LLM (large language model) friendly (for AI enabled full automation) , such a consistent format is defined as a network capability description language (NCDL) . In a possible implementation, a XaaS service can be implemented / achieved through execution of one or more actions corresponding to the XaaS service, the one or more actions are used for reflecting one or more capabilities for implementing a requirement of the service, the one or more actions may correspond to the one or more capabilities one-by-one, or a combination of multiple actions may correspond to one capability. Taking a case where the XaaS service is NET4AI service as an example, NET4AI service can provide AI related services to 6G customers or to other NCs. These AI related services can be enabled by its inference capability or sub-service, training capability or sub-service, and model management capability or sub-service. That is, the requirement for NET4AI service can include but is not limited to: a training requirement, an inference requirement, a model management requirement which can be related to storing of a model or a library related to provision of NET4AI service, enhancement / improvement of the model, or the like; for the training requirement, and there could be multiple algorithms / schemes such as algorithm / scheme A, algorithm / scheme B and algorithm / scheme C for implementing the training requirement, then the multiple algorithms / schemes can be regarded as multiple actions corresponding to NET4AI service. It should be noted that here the algorithm / scheme is just an implementation of the action, the action of a service may be characterized in other forms, which are not limited in the implementations of the present disclosure. For the purposes of this disclosure, a network capability (NC) may encompass one or more services to achieve a purpose or mission, such as providing connectivity, making predictions using AI models, or maintaining decentralized ledgers with blockchains, as examples. Accordingly, the terms "network capability" and "services" may be used interchangeably. A network capability provider, or a service provider, refers to an entity comprising both physical and logical components that deliver services to other entities, whether users or other services.

[0090] The NCDL defines a language which could be understandable by both parties, i.e., a first NC calling the action and a second NC executing the action called by the first NC. The actions may be classified into different types as follows: Type 1: In-out-action: when being called, action codes are run based on input and produce output. (Input-> action-> output) ; Type 2: In–action: when being called, action codes are run based on input and local configuration / update is then  conducted (input->action-> local update) ; Type 3: Out-action: when a local condition (triggering condition) is met, action codes are run to provide output (local  ->action->output) .

[0091] For Type 1 action and Type 2 action, the first NC calls an action to be performed by the second NC, the first NC provides an NCDL input to the second NC. The NCDL input follows a certain agreement for the second NC to correctly recognize the NCDL input and execute the action. For Type 1 action, the second NC provides an NCDL output corresponding to the NCDL input. This NCDL output may be provided to the first NC, or to other NC (s) , which is not limited in the embodiments of the present disclosure. For Type 2 action, the second NC performs a local configuration update based on the NCDL input, and no NCDL output is transmitted.

[0092] For Type 3 action, there is no NCDL input, and when a local condition (triggering condition) is met, the second NC automatically executes the operation associated with the action and provides an NCDL output to the first NC which subscribes to this action.

[0093] For an NCDL of a C / M NC, the input dimensions (NCDL input) can include one or multiple input information without defining corresponding input information format; for an NCDL of a data NC, this dimension can include one or multiple input data dimensions along with the definition of corresponding input data format.

[0094] The Service Provisioning Management (SPM) (as a service) in the C / M layer mentioned above, is a network capability (NC) or a service that is responsible for the control and management of 6G service access by users and by the provisioning of requested services. The capability may be provided by unified mutual authentication, authorization and policy, key management, quality of service (QoS) assurance and charging between any pair of XaaS service provider and customer or user. Users may include not only end users in the physical world but also their digital counterparts in the digital world.

[0095] SPM may provide security mechanisms and procedures, including authentication, key generation and agreement, C / M session security activation, C / M RB security activation, service subscription, service authorization, primary authentication and key agreement, and service access authorization and key agreement. This authentication includes mutual authentication between the 6G device and the network.

[0096] One objective of the authentication procedure is to enable mutual authentication between a 6G device, the network and / or external service providers, and to provide keying materials that can be used for generating session keys or RB keys. These keys may be used in subsequent security procedures. The keying materials generated by the authentication procedure can be derived from an anchor key provided by the SPM. Keys for more than one security context can be derived from the anchor key without the need for a new authentication run.

[0097] The 6G system may also allow the use of encryption and integrity protection algorithms for C / M session keys, C / M RB keys, data session keys, and data RB keys, which may be derived from an Extended Session Master Key (EMSK) or other similar key agreement protocol. The keys used for C / M session, C / M RB, data session, and data RB depend on the algorithms with which they are used. The keys for C / M session and data session are derived from the anchor key and then configured to a serving C / M-TW-GW or a serving Data-TW-GW. The keys for C / M RB and data RB are derived from the RB handler’s key and then configured to the RB endpoints. The SPM typically generates the encryption keys.

[0098] The present disclosure proposes SPM actions and corresponding NCDLs for the SPM, so as to enable the SPM to provide its capability to customers. To provide this capability, the SPM needs to define one or more actions (application Programming Interface (APIs) ) and provides a NCDL of each of these actions.

[0099] In some implementations, the SPM may be implemented as a logical component on a physical entity or node and may include suitable logic, circuitry, interfaces and / or code that may be operable to manage the identifiers and credentials of devices or other nodes, required to render secure services to these devices or other nodes, anonymously. The IDentifier Management (IDM) is an NC or a service that may be implemented as logical component on a physical entity or node.

[0100] The actions performed by the IDM can include, but are not limited to, generating or assigning identifiers for devices, updating and / or revoking identifiers, maintaining an identifier table for a given device, identifying devices and generating credentials for a device.

[0101] Different types of identifiers can be managed by the IDM, identifiers which are maintained in identifier tables. Examples of identifiers may include globally unique identifiers, which may be referred to as Subscriber Real IDentifiers (SRID) . Other examples of identifiers include identifiers for privacy preservation of the devices, which may be referred to as Privacy preservation Subscriber Real Identifier (PSRID) . A SRID may be encrypted using a public key, such as the IDM’s public key, and may be kept in the memory of 6G device of a registered customer. This privacy preserving identifier may correspond to an encrypted SRID. Other examples of identifiers include identifiers for authentication. These authentication identifiers can be referred to as Subscriber Authentication Identifier (SAID) . The authentication identifiers may be generated for each device of a given user and may be associated with a certificate or credentials obtained or generated by the IDM, on behalf of the device. Yet another type of identifiers includes temporary identifiers. Temporary identifiers can be used for network and / or external service providers. For example, a temporary identifier may correspond to a Subscriber Temporary Identifier (STID) , which may be generated by a SPM for each device to access a network, such as a 6G network. The STID can be sent to a device after the successful activation of a security protection on a session between a C / M gateway of the network and the device. Another type of temporary identifier includes Subscriber Service Temporary IDentifiers (SSTID) , which may be generated by a service (provided by a Network Capability) or assigned by the IDM, to allow a device to access the service after having successfully authenticated the device. According to different implementations of the present disclosure, an STID may be assigned by the IDM and may be used by a network function for accessing a network; an SSTID may be used by a service provider for accessing a service provided by the service provider; and a SAID may be used by a network function for mutual authentication.

[0102] In the following description, different actions which may be performed by the IDM (or other equivalent function) will be elaborated in detail. It should be noted that although the actions are described with reference to a first node, such as an IDM, other C / M NCs may also provide similar actions following similar NCDLs. Besides, the execution of the following actions will be described from the first node side, when interaction between the first node and other nodes are necessary, it should be understood that corresponding operations would be performed by other nodes. For example, the first node transmitting information to the other node would involve the other node receiving information from the first node, the first node receiving information from the other node would involve the other node transmitting information to the first node.

[0103] A node may comprise one or more processors; and one or more tangible, non-transitory memories. A network node may refer to any device or point within a communication network that can send, receive, process or forward data. Network nodes may include devices such as computers to more complex equipment such as routers, switches, and servers. A node can also be a virtual entity, implemented by logical functions, command blocks and / or software modules.

[0104] In a possible implementation of the present disclosure, actions are provided by a first node, such as an IDM, for the management of identifiers of devices. These actions may be combined under a single name, such as “ID Management” or each have their own names, for facilitating subscription of other NCs, such as “update ID, ” “Assign ID” or “Revoke ID. ” As one possible scenario, these actions may be called when the network or an external service provider needs to obtain information or have operations performed on identifiers of the device for the provisioning of services.

[0105] In a possible implementation, the first node can be part of a Service Provisioning Management (SPM) service or a function offered by the network. The first node can be a node or a function responsible for the management of the different identifiers a device may need to access services securely and anonymously. Identifier management operations are carried out in response to requests from other nodes, each of which can be called a “second node” . Nodes transmitting requests to the first node may include nodes of the network, including other nodes part of the SPM service, or nodes external to the network, such as service providers.

[0106] A service provider node can provide a XaaS service in the C / M layer, service layer or infrastructure layer of FIG. 1. The XaaS service in the C / M layer can be, for example, a mission management (MM) service, a connectivity management (CM) service, and the MM service can also be named as automatic network capability programming (A-CAP) service.

[0107] The present disclosure provides a method applied to a first node to implement one or more actions. FIG. 3 shows a schematic flowchart of a method according to one or more embodiments of the present disclosure, which reflects the execution of an action (including reception, managing and transmission steps) performed by the first node.

[0108] In step S301, the first node receives, from a second node, a request related to the management of an identifier (ID) of a device for one or more services. Correspondingly, the second node transmits the ID management request to the first node. A device identifier can be used to subscribe to and access services provided either by the network or by external providers. The identifier can be encrypted or anonymized to ensure that the services rendered respect the end user’s privacy. The request includes at least one operation to be performed by the first node, which is related to managing the identifier included in the request.

[0109] The request for identifier management may include the following information, provided by the second node: a name of the device; a name of one or more services to be used or provided to the device; an identifier of the device assigned by a service provider; and operation (s) to be performed by the first node on the identifier, including those defined above, such as updating, assigning, identifying, being notified or revoking the identifier. The request may be structured to include predetermined fields or dimensions.

[0110] The name of the device may include a temporary identifier of the device, assigned to the device for accessing one or more services provided by the network. The name of the device may instead correspond to a temporary identifier of the device, to access one or more services provided by a service provider, which may include a third-party service provider or a network operator. A temporary identifier is a unique identity which may be used in the network to enhance privacy and facilitate resource location without disclosing the permanent identity of end users over the radio interface. A temporary identifier may also enable the storage of a subscriber's temporary context. When the service is provided by the network, the temporary identifier may be referred to as a first temporary identifier, or as a STID, and when the temporary identifier is provided by a service provider, the temporary identifier may be referred to as a second temporary identifier, or SSTID. The name of the device may also correspond to an identifier of the device for privacy preservation of the device, or PSRID.

[0111] As for the name of a service, it can correspond to an identifier of the service. In some cases, the request addressed to the first node may not indicate the name of the service, and in this case, the “name of service” field can be empty or left to a default value, such as “non available” .

[0112] To perform the operations on the identifiers of devices, the first node may use an identifier table, in which the different field values can be stored, updated or deleted. For example, the device identifier table may include a list of identifiers of the device and a list of names of service providers. The table may include one or more sub-tables and may be part of a relational database or other type of database.

[0113] As per step S302, the operations performed by the first node upon receiving a request may include updating the identifier of the device, assigning a new identifier for the device, identifying the device, revoking an identifier of the device or providing notification of an identifier of the device.

[0114] To respond to the request from the second node, the first node transmits a response based on the operation performed, as outlined in step S303 of FIG. 3. The response may include one or more temporary identifiers of the device that are different from an initial identifier of the device provided in the request, or an identifier of the device that is used for authenticating the device. As explained previously, a temporary identifier of the device may refer to either a temporary identifier to access services provided by the network, or a temporary identifier to access services from a service provider. The response may also include an indication of whether the initial identifier of the device has been revoked.

[0115] In some implementations, for the first node to perform the method, the second node must have first subscribed to the services of the first node. As mentioned above, the second node may be a service provider (such as a provider of a network capability) for providing the one or more services to the device, or a network function, such as a Service Provisioning Management (SPM) function, for provisioning the services to be rendered to the device.

[0116] As can be appreciated, the identifier management function enables nodes within or outside the network to standardize exchanges related to identifier management, and to ensure their authenticity, privacy and anonymity. As the fields (or dimensions) and possible field values of the requests and of the responses are predefined, the action can be called up by different entities without having to agree each time on the exchange protocol or the language to be used.

[0117] The following paragraphs provide possible implementations and case scenarios for the management of device identifiers by the first node.

[0118] In a first possible scenario, a service provider may not be able to identify a device requesting its services. For example, the service provider can send a request to a second node to try to identify the device soliciting its services. Thus, when the second node is unable to identify the device, the first node may receive, from the second node, a request including the identifier of the device for the privacy preservation of the device and an indication that the operation to be performed by the first node is to identify the device. The first node may look up the requested information in the identifier table, using the privacy preserving identifier provided in the request. If the information is present, the first node transmits the response to the second node, which will include either the identifier for authenticating the device, or a temporary identifier of the device.

[0119] In a second possible scenario, a second node –such as a service provisioning management function –may request the first node –such as an identifier manager node –to assign a device identifier on behalf of a service provider. In this case, the first node receives, from the second node, a request to assign a new temporary identifier to the device on behalf of a service provider. This request may include either a (first) temporary identifier of the device, provided by the network or a privacy preservation identifier of the device. The request also includes an identifier of the service provider and an indication that the operation to be performed is to assign the new (second) temporary identifier to the device, for the service provider. The first node can thus generate the new (second) temporary identifier for the service provider and update the device identifier table with this new temporary identifier. The first node then transmits the response to the second node, which will include the new second temporary identifier of the device. FIG. 4 illustrates this possible implementation.

[0120] In a third possible scenario, a service provider may request the first node (e.g., identifier manager) to update a device identifier. In this case, the first node receives a request from the second node to update the device's second temporary identifier, which was previously assigned by or for the service provider. The request may include the initial second temporary identifier assigned to the device and an indication that the operation to be performed is to update it. The first node can generate a new (second) identifier, update the identifier table, and transmit a response to the second node, confirming that the second temporary identifier of the device has been updated to the new second temporary identifier of the device.

[0121] In a fourth possible scenario, an update request may be sent by a node of the network, rather than by a service provider. The second node may be a service provisioning management function of the network, which may call this action to request the first node to update a device identifier. In this case, the first node receives, from the second node, a request for updating the first temporary identifier of the device. The request will thus include the first temporary identifier of the device and an indication that the operation to be performed is to update the first temporary identifier of the device. Similar to the third scenario, the first node may generate a new (first) temporary identifier and update the identifier table. The first node will then transmit a response to the second node indicating that the first temporary identifier has been updated to a new first temporary identifier of the device. FIG. 5 illustrates this possible implementation.

[0122] In a fifth possible scenario, a service provider or a node of the network may need to have a device identifier revoked. In this case, the first node receives, from the second node, a request for revoking either the first temporary identifier of the device or the second temporary identifier of the device (or both) . The request thus includes a first and / or second temporary identifier of the device and an indication that the operation to be performed by the first node is to revoke said identifier. The first node may delete the entries relating to the first and / or second identifier from the identifier table. The first node may then transmit a response to the second node, indicating that the first and / or second temporary identifier of the device has been revoked.

[0123] In a sixth possible scenario, a node of the network, such as a service provisioning management function of the network, may call this action when a device identifier needs to be revoked on behalf of a service provider. The first node will thus receive a request from the second node, to revoke the first temporary identifier of the device (for use by the network) and / or the second temporary identifier of the device (for use by the service provider. ) The request may thus include at least one of the first temporary identifier of the device and the second temporary identifier of the device, a service provider identifier; and an indication that the operation to be performed is to revoke the first and / or second temporary identifier of the device. The first node may delete the entries relating to the first and / or second identifier from the identifier table. The first node may then transmit a response to the second node, indicating that the first and / or second temporary identifier of the device has been revoked.

[0124] In a seventh possible scenario, a node may call this action to notify or inform the first node that a device identifier has been assigned by a service provider, for example for allowing a device to use the services of the service provider with this identifier. In this case, the first node receives, from the second node, a request to notify the first node that the second temporary identifier of the device has been assigned by a service provider. The request comprises the first temporary identifier of the device (for use in the network) ; an identifier of the service provider, the second temporary identifier of the device (to be used to access the services of the service provider) and an indication that the operation is to notify or inform the first node of this new identifier assigned by the service provider. The first node updates the device identifier table with the first temporary identifier of the device and the newly assigned second temporary identifier of the device. A response may be sent to the second node, where the “device name” and “revoke result” may be left empty (or filled with a standard value, such as “not available” ) , since there is no new information to be provided to the second node.

[0125] In an eight possible scenario, a network node, such as a service provisioning management function, may call this action to notify or inform the first node (the identifier manager) that a device identifier has been assigned by the network. In this case, the first node receives, by the second node, a request to notify the first node that the second temporary identifier of the device has been assigned by a service provider. The request includes the first temporary identifier of the device (to identify the device in the network) ; an identifier of the service provider; a new second temporary identifier of the device (to identify the device by the service provider) ; and an indication that the operation is to inform the first node of this second temporary identifier of the device, which has been assigned by the service provider. The first node will then update a device identifier table with the first temporary identifier of the device and the second temporary identifier of the device. A response may be sent to the second node, where the “device name” and “revoke result” may be left empty (or filled with a standard value, such as “not available” ) , since there is no new information to be provided to the second node.

[0126] In a ninth possible scenario, a notification action may be sent by a (second) network node to inform the first node that an identifier has been assigned by the network node. The second node may be a network function for provisioning the services to be rendered to the device. The first node may receive, from the second node, a request to inform the first node that a first temporary identifier of the device has been assigned by the second node. The request may include the identifier of the device for the privacy preservation of the device or the first temporary identifier of the device; a new first temporary identifier of the device assigned by the second node; and an indication that the operation is to notify the first node that the first temporary identifier of the device has been assigned by the second node. The first node then updates the device identifier table with the new first temporary identifier of the device. A response may be sent to the second node, where the “device name” and “revoke result” may be left empty (or filled with a standard value, such as “not available” ) , since there is no new information to be provided to the second node.

[0127] As demonstrated, the proposed method is versatile and can be used to address a wide range of situations involving the management of identifiers which are needed to provide services to a device, whether by internal functions of the network nodes or by third-party service providers, while maintaining the device's privacy.

[0128] The following paragraphs will describe an example NCDL of the action of identifier management provided by the first node.

[0129] Name of the action: ID management.

[0130] Purpose of the action: the action is to have a device identified or to have an identifier assigned, updated or revoked by an identifier managing function, which may be referred to as an identifier manager or identifier management node (IDM) . The action may also serve to notify the identifier manager of an identifier.

[0131] Pre-condition of the action: an identifier or identification table should be ready and available for use by the IDM. The identifier table may include, as different fields, a list of device names, a list of service provider (NC) names.

[0132] Post-condition of the action: the management of identifier has been conducted. Table 1 –Capability dimensions (input and output fields) of ID management action

[0133] The parameters shown represent different capability dimensions (or fields) for the action of ID management, the capability dimensions can include input dimensions and output dimensions (NCDL output) , in which the input dimensions are used to indicate required input information in order for the execution of the action, the output dimensions are used to indicate outputs of the action.

[0134] The definitions of the capability dimensions illustrated in Table 1 are as follows: - Device name: indicates of a name of a device. A device name may include the real identifier of a subscriber; a first  temporary identifier for services provided by the network; a second temporary identifier for services provided by third-party providers; a privacy preservation identifier. These identifiers may be referred to as STID, SSTID, PSTID, as explained above. All three types of identifiers may be selected or included in an action request or response. - Service (or NC) name: indicates a name of a network capability provider (or service provider) NC, e.g., NC ID. - ID assigned by the service (NC) : this field indicates the identifier that has been assigned to a device by a service  provider (or NC) . The IDM may be notified of this identifier. For example, this ID may be a newly assigned SSTID (indicated as SSTID#) , or a newly assigned STID (indicated as STID#. ) - Operation: this filed indicates of a name or type of identifier (ID) management operation, e.g., update a device’s  identifier, assign an identifier to a device, identify an identifier of a device, revoke an identifier of a device, notification of device identifier. - Device name: indicates of one of identifiers of a device. This ID is different from the ID that is included as an  input of device name. This device name can be identified or used or assigned by a network function or a service provider. For example, the device identifier may be STID* (a STID is assigned by IDM and is used by a network function) , SSTID* (a SSTID is used by a service provider) , SAID* (a SAID is used by a network function) . - Revocation result: this field indicates whether a device identifier that was used by an NC has been revoked.

[0135] When a field value is set to “NA” , this means that the information is not available when the action is called.

[0136] Use of this NCDL: Any type of services (NCs) that has subscribed this action can call this action to obtain identifier information. - This NCDL may be subscribed by a service provider (NC) or by a function of the network, such as a SPM  function. - This NCDL is called when the identifier manager has access to an identifier table or database. - When called, items in table 1 may be populated as follows: (1) When a SPM is unable to identify a device ID, the SPM may call this action. The input may be: PSRID, NA,  NA, identification. The output may be: SAID*or STID*, NA. (2) A SPM may call this action to request the IDM to assign a device ID on behalf of a NC. In this case, the input  may be: STID or PSRID, NC ID, NA, assignment. The output may be: SSTID*, NA. (3) A NC may call this action to request the IDM to update a device ID. In this case, the input may be: SSTID, NA,  NA, update. The output may be: SSTID*, NA. (4) A SPM may call this action to request the IDM to update a device ID, the input may be: STID, NA, NA, update.  The output may be: STID*, NA. (5) A NC may call this action to request the IDM to revoke a device ID. In this case, the input may be: SSTID, NA,  NA, revoke. The output may be NA, yes. (6) A SPM may call this action to request the IDM to revoke a device ID. In this case, the input may be: STID,  NA, NA, revoke. The output may be NA, yes. (7) A SPM may call this action to request the IDM to revoke a device ID on behalf of a NC. In this case, the input  may be STID, NC ID, NA, revoke. The output may be NA, yes. (8) A SPM may call this action to notify the IDM that a device ID has been assigned by a NC. In this case, the input  may be: STID, NC ID, SSTID#, notification of device ID. The output may be NA, NA. (9) A SPM may call this action to notify the IDM that a device ID has been assigned by the SPM. In this case, the  input may be: PSRID or STID, NA, STID#, notification of device ID. The output may be NA, NA. - This action may be called by an automatic capability programming (A-CAP) function that is triggered by a device,  an NC or a SPM. - The effect of executing this action is that one or more identifiers of the device are updated, assigned, identified, or  revoked by an identification management function (IDM) , or the IDM is notified of a new identifier.

[0137] According to another aspect, the following paragraphs describe possible implementations and case scenarios for the generation and provision of device credentials by the first node.

[0138] The present disclosure provides a method applied to a first node to implement one or more actions. FIG. 6 shows a schematic flowchart of a method according to one or more embodiments, which reflects the execution of an action (including reception, credential generation and transmission steps) performed by the first node. The first node may be the same node that manages identifiers (referred to as IDM) , or a different node.

[0139] In step S601, the first node receives, from a second node, a request to generate a credential for a device. The second node may be a service provisioning management (SPM) node, which may be part of the network. The request comprises information required for the first node to generate the credential for the device, including for example an identifier of the device, an authentication method and a corresponding authentication algorithm.

[0140] The identifier of the device may either be a temporary identifier used for accessing one or more services provided by the network, or an identifier that preserves the privacy of the device (referred to as an identifier for privacy preservation. ) These types of identifiers and their functions have been described in preceding paragraphs.

[0141] The request may also specify the authentication method to be used for generating the device credential. For example, the authentication method may include Authentication and Key Agreement (AKA) ; Physically Unclonable Function (PUF) ; and 6G Extensible Authentication Protocol (6G-EAP) .

[0142] AKA is a security mechanism used in mobile and wireless networks to authenticate users and establish a secure communication channel. AKA ensures mutual authentication between a user's device and the network, while also generating session keys to encrypt and protect data exchanged over the network. AKA prevents unauthorized access and ensures the confidentiality and integrity of user data during transmission.

[0143] PUF is a hardware-based security process that leverages the inherent manufacturing variations of physical components to generate a unique and unpredictable identifier or response. As microscopic differences are nearly impossible to replicate, PUFs may be used for a secure device authentication and encryption key generation.

[0144] EAP is an authentication protocol that supports various methods for verifying user or device identities in network communications. EAP allows the use of different authentication techniques, including digital certificates.

[0145] Depending on the authentication method selected in the request, an identifier or an indication of a specific authentication algorithm to be used can be provided as the “corresponding algorithm” . Different algorithms can be used to implement authentication methods. The authentication algorithm corresponds to the algorithm to be used by the device and the second node, during the mutual authentication process. The request can include the name of the algorithm to be used, or an identifier for it.

[0146] In some cases, depending on the authentication method chosen, the request may further need to include one or more parameters associated with the credentials. The first node will use these parameters to generate the credentials.

[0147] As per step S602, the first node can then generate the credential for the device based on the information in the request. If the authentication method indicated in the request is AKA, the first node generates an AKA vector as the device credential. If the authentication method is PUF, the first node generates a PUF-based credential. If the authentication method is 6G-EAP the first node generates an EAP certificate as the device credential.

[0148] In step S603, after having generated the credentials, the first node transmits a response to the second node, which will include the credentials generated for the device based on the identifier of the device, the authentication method and corresponding algorithm, and based on device parameters, if present in the request and needed by the selected authentication method.

[0149] This action may be called when the second node (such as a service provisioning management function) does not have identification information on the device and the second node needs to authenticate the device. This action may also be called by an automatic network capability programming (A-CAP) service or a connectivity management (CM) service, that is triggered by a device or by a service provisioning management (SPM) node.

[0150] As demonstrated, the proposed method is versatile and can be used to address a wide range of situations involving the management of identifiers which are needed to provide services to a device, whether by internal functions of the network nodes or by third-party service providers, while maintaining the device's privacy.

[0151] A clear and standardized definition of the actions and information required to manage device credentials, combined with reliable authentication methods, enhances exchange security and assures users of the confidential and secure handling of network exchanges. Standardization also enables the automation of various configuration aspects needed to deliver services to devices, whether provided by the network or other service providers.

[0152] The following paragraphs will describe an example NCDL of the action of generation and provision of device credentials by the first node.

[0153] Name of the action: generation and provision of a credential for a device.

[0154] Purpose of the action: a node must provide a credential of a device. The node which generates the credential can be an identifier manager node, and the node requesting the credential may be a service provisioning management (SPM) function of a network.

[0155] Pre-condition of the action: the second node (e.g., SPM) does not have a credential for the device but the second node needs to authenticate the device, for example, to provides accesses or services to the device.

[0156] Post-condition of the action: the generation and provisioning of a credential for the device has been conducted. Table 2 -Capability dimensions (input and output) of credential generation action

[0157] The definitions of the capability dimensions illustrated in Table 2 are as follows: - Device name: this field or dimension indicates of a name of a device. A device name may include a temporary  identifier for services provided by the network (e.g. STID) or a privacy preservation identifier (PSRID) . - Authentication method: this field or dimension indicates which authentication method is to be used. Authentication  method may include for example AKA, PUF or 6G-EAP. - Algorithm ID: this field or dimension indicates the specific algorithm to be used during the mutual authentication  between a device and the SPM, e.g., ID of AKA alg. 1, ID of AKA alg. 2, ID of PUF alg. 1, ID of PUF alg. 2, NA, …. - Device parameters or information: this field indicates the type of credential information to be used for generating  the credentials, e.g., parameters for credentials (PUF) . - AKA vector: this field would include the AKA vector generated by the device when the authentication method  selected is AK. - PUF credential: this field indicates credentials for authentication on a device using a given PUF algorithm, e.g.,  credential corresponding to PUF alg. 1, NA. - EAP certificate: indicates a certificate for device, e.g., device’s certificate, NA.

[0158] When a field value is set to “NA” , this means that the information is not available for a given dimension when outputting the response. For example, if the authentication method chosen is AKA, then the 6G-EAP and PUF output fields may be set to NA.

[0159] Use of this NCDL: a node (such as a SPM node) that has subscribed to this action can call this action for obtaining credentials for a device. - This NCDL may be subscribed by a function of the network, such as a SPM function. - This NCDL may be called when a node (SPM) implements mutual authentication between device and network,  and the node does not have a credential of the device. - When called, items in table 2 may be populated as follows: (1) If a device selects a method of authentication based on AKA, the input may be: STID or PSRID, AKA, ID of  AKA alg. 1or ID of AKA alg. 2, NA. The output may be credential corresponding to AKA alg. 1or credential corresponding to AKA alg. 2, NA, NA. (2) If a device selects a method of authentication based on 6G-EAP, the input may be: STID or PSRID, 6G-EAP,  NA, NA. The output may be NA, NA, device’s certificate. (3) If a device selects a method of authentication based on PUF, the input may be: STID or PSRID, PUF, ID of  PUF alg. 1, parameters for credential (PUF) . The output may be NA, credential corresponding to PUF alg. 1, NA. - This action may be called by an automatic capability programming (A-CAP) function that is triggered by a device,  an NC or a SPM. - The effect of executing this action is that at least one credential for the device has been generated and returned to  the second node.

[0160] FIG. 7 shows an example including an action of identifier management shown in FIG. 3 and an action of credential generation of FIG. 4. In this particular example, a device selects a dynamic mutual authentication based on PUF. When the device initially accesses a network, a node, such as a SPM node, implements a mutual authentication procedure for the device.

[0161] In step 1, a device calls a request for mutual authentication. The request includes the following information : network-control credentials, an indication that the authentication method is dynamic, an identifier for preserving privacy (PSRID) of the device, the authentication method which in this case is PUF, an indication that the authentication is for an initial authentication, the identification of a specific PUF-algorithm (e.g. ID of PUF alg. 1) and parameters for credential (PUF) .

[0162] In step 2, based on the inputs provided by the device (e.g., initial authentication, PUF, device PSRID, ID of PUF alg. 1) , the SPM calls an action of ID management. The input of the action (i.e the request) includes the following information, as per the different input fields / dimensions of table 1 : device name = device PSRID, NC name = NA, ID assigned by NC =NA, Operation = identification.

[0163] In step 3, the IDM implements the action of ID management, which in this case is to identify the device.

[0164] In step 4, the IDM sends a response to the SPM (which may also be referred to as an output of the action of ID management. ) The response (or output) may include: (Device name = SAID*, Revoke result = NA)

[0165] In step 5, the SPM calls an action of generating and provisioning of credential for the device. The request may include the following field values as inputs, as per table 2: Device name = PSRID, Authentication method = PUF, Algorithm ID = ID of PUF alg. 1, Device credential parameters = parameters for credential (PUF) .

[0166] In step 6, the IDM performs the generation and provisioning of credentials for the device.

[0167] In step 7, the IDM sends the response (or output of the action) . The output may be : AKA vector = NA; PUF credential = credential corresponding to PUF alg. 1; EAP certificate = NA (as per the output structure of table 2) .

[0168] In step 8, the SPM implements the action of mutual authentication between the device and the SPM. The details of the mutual authentication implementation is beyond the scope of the present disclosure, and different mutual authentication methods may be used..

[0169] In step 9, the SPM may generate a STID for the device. The SPM calls an action of ID management. The input of the action includes : Device name = device PSRID, NC name = NA, ID assigned by NC = STID#, operation = notification of device ID (as per the input fields listed in table 1) .

[0170] In step 10, the IDM implements the action of ID management, for example, by updating the identifier table if necessary.

[0171] In step 11, the IDM sends an output of the action of ID management. The response (or output) may be Device name = NA, Revoke Result = NA.

[0172] In step 12, the SPM calls the action of generation and provisioning of credential for the device. The request may include as inputs : Device name = STID, Authentication method = PUF, Algorithm ID = ID of PUF alg. 1, Device credential parameters = parameters for credential (PUF) .

[0173] In step 13, the IDM implements the action of generation and provision of credential for device.

[0174] In step 14, the IDM sends a response (or output) of the action. The output may be : AKA vector = NA, PUF credential = credential corresponding to PUF alg. 1, EAP certificat = NA (as per the output fields indicated in table 2)

[0175] In step 15, the SPM sends a mutual authentication response, which may include an indication of successful authentication.

[0176] FIG. 8 provides another example of how an ID management may used, as part of the NCDL. In this example, a device may want to subscribe to a specific service that is provided by a service provider (or a Network Capability provider –NC) . The SPM requests an identifier (ID) from the IDM on behalf of a service provider, and the SPM calls an action of ID management.

[0177] In step 1, the SPM calls an ID management action. The input may be: Device name = STID or PSRID, NC name =NC ID, ID assigned by NC = NA, operation = assignment (as per the input stucture of table 1) .

[0178] In step 2, the IDM implements the action of ID management, in this case assigning a temporary identifier to the device.

[0179] In step 3, the IDM sends a response or an output of the action to the SPM, having successfully assigned a temporary identifier to the device, which can be used for interacting with the with service / network capability (NC) provider. The output may include : Device name = SSTID*, Revoke result = NA.

[0180] FIG. 9 provides yet another example of how ID management actions may be used, as part of the NCDL. In this example, a device may want to subscribe to a specific service from a service provider, NC. A (second) temporary identifier, SSTID#is assigned to the device by the service provider, NC. The SPM may invoke an ID management action to generate a new identifier through the IDM.

[0181] In step 1, the SPM calls an action of ID generation. The input may be NA.

[0182] In step 2, the NC implements the action of ID generation.

[0183] In step 3, the NC sends an output of the action. The output may be a SSTID#that is used by the device for accessing the NC.

[0184] In step 4, the SPM calls an action of ID management. The input may be: Device name = STID, NC name = NC ID, ID assigned by NC = SSTID#, operation = notification of device ID.

[0185] In step 5, the IDM implements the action of ID management: the IDM is informed of the temporary identified assigned by the NC, and updates the identifier table accordingly.

[0186] In step 6, the IDM sends an output (response) of the action. The output should be Device Name = NA, Revoke result = NA.

[0187] The examples given above demonstrate that standardizing action messages and their fields / dimensions make exchanges between different network nodes more efficient and predictable.

[0188] FIG. 10 shows a schematic structural diagram of an apparatus according to one or more implementations of the present disclosure. As shown in FIG. 10, the apparatus 1000 may include: a receiving module 1001, configured to receive, from a second node, a request related to the management of an  identifier of a device for one or more services, wherein the request comprises at least one operation to be performed by the first node; a processing module 1002, configured to manage the identifier of the device based on the request; a transmitting module 1003, configured to a response to the second node, wherein the response is based on the at  least one operation performed by the first node.

[0189] FIG. 11 shows a schematic structural diagram of an apparatus according to one or more implementations of the present disclosure. As shown in FIG. 11, the apparatus 1100 may include: a receiving module 1101, configured to receive, from a second node, generate credentials for a device, the request  comprising information including an identifier of the device, an authentication method and a corresponding algorithm; a processing module 1102, configured to generate the credentials for the device based on the information in the  request; and a transmitting module 1103, configured to a response to the second node, wherein the response comprises the  credentials generated for the device based on at least one of the identifiers of the device, the authentication method and the corresponding algorithm.

[0190] FIG. 12 shows a schematic structural diagram of an apparatus according to one or more implementations of the present disclosure. The apparatus may be a transmitting node or a receiving node. As shown in FIG. 12, the apparatus 1200 includes a processor 1201, an interface 1202 for communicating with other devices, a memory 1203 is coupled to the processor 1201. The memory 1203 may be stored with computer execution instructions, and the processor 1201 executes computer execution instructions stored in the memory 1203 to enable the apparatus to execute any of the above methods. In some implementations, the memory 1203 may be included or may not be included in the apparatus.

[0191] In some aspects of the present disclosure, there is provided an apparatus which includes a processor and a memory. The memory is storing instructions that cause the processor to perform any of the above methods.

[0192] It should be understood that the processor may be an integrated circuit chip and has a data processing capability. In an implementation process, steps of the foregoing method embodiments may be completed by using a hardware integrated logic circuit in the processor, or by using instructions in a form of software. The processor may be a general-purpose processor, a central processing unit (CPU) , a graphics processing unit (GPU) , a neural processing unit (NPU) , a system on chip (SoC) or another programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor may implement or perform the methods, the steps, and the logical block diagrams that are disclosed in the embodiments of the present disclosure. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor or the like. The steps of the methods disclosed with reference to the embodiments of the present disclosure may be directly performed and completed by a hardware decoding processor, or may be performed and completed by using a combination of hardware in the decoding processor and a software module. The software module may be located in a mature storage medium in the art, such as a random-access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, or a register. The storage medium is located in the memory, and the processor reads information in the memory and completes the steps of the foregoing methods in combination with hardware in the processor.

[0193] It may be understood that the memory in the embodiments of the present disclosure may be a volatile memory or a non-volatile memory, or may include both a volatile memory and a non-volatile memory. The non-volatile memory may be a read-only memory (Read-Only Memory, ROM) , a programmable read-only memory (Programmable ROM, PROM) , an erasable programmable read-only memory (Erasable PROM, EPROM) , an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) , or a flash memory. The volatile memory may be a random-access memory (Random Access Memory, RAM) and is used as an external cache. By way of example rather than limitation, many forms of RAMs may be used, and are, for example, a static random access memory (Static RAM, SRAM) , a dynamic random access memory (Dynamic RAM, DRAM) , a synchronous dynamic random access memory (Synchronous DRAM, SDRAM) , a double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDR SDRAM) , an enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM) , a synchronous link dynamic random access memory (Synchronous link DRAM, SLDRAM) , and a direct rambus random access memory (Direct Rambus RAM, DR RAM) .

[0194] It should be noted that the memory described in this specification includes but is not limited to these memories and could be a memory of any other appropriate type.

[0195] In some aspects of the present disclosure, there is provided a system, including apparatuses used to execute the steps in any of the above methods.

[0196] In some aspects of the present disclosure, there is provided a computing device cluster, including a processing circuitry for performing any of the above methods.

[0197] FIG. 13 shows a schematic diagram of an architecture of a computing device cluster according to one or more embodiments of the present disclosure. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0198] As shown in FIG. 13, the cluster of computing devices described includes at least one computing device 1300. As shown in FIG. 13, for each of the at least one computing device 1300, it includes a processor 1302, an interface 1304 and optional a memory 1306, where the processor 1302, the interface 1304 and the memory 1306 may be connected through a bus 1308. The memory 1306 in one or more of the computing devices 1300 in the cluster of computing devices can hold the same instructions, so that the processor 1302 executes the instructions to execute the method described in the above embodiments.

[0199] In some possible implementations, some of the instructions for performing the method described in the above embodiments can also be separately held in the memory 1306 of the one or more computing devices 1300 in the cluster of computing devices. In other words, a combination of the one or more computing devices 1300 can jointly execute instructions for performing the method described in the above embodiments.

[0200] It is noted that the memories 1306 in the different computing devices 1300 in the cluster of computing devices can store different instructions for performing some of the functions of the computing devices 1300, respectively.

[0201] In some possible implementations, one or more computing devices in a cluster of computing devices can be connected via a network. Among other things, the network can be a wide area network or a local area network, etc. FIG. 14 illustrates one possible implementation. FIG. 14 shows a schematic diagram of a connection between computing devices 1400A and 1400B over a network according to one or more embodiments of the present disclosure. As shown in FIG. 14, the computing device 1400A includes a processor 1402A, an interface 1404A and optional a memory 1406A, where the processor 1402A, the interface 1404A and the memory 1406A may be connected through a bus 1408A; the computing device 1400B includes a processor 1402B, an interface 1404B and optional a memory 1406B, where the processor 1402B, the interface 1404B and the memory 1406B may be connected through a bus 1408B. The memory 1406A and the memory 1406B may be stored with computer execution instructions, and the processor 1402A and the processor 1402B execute computer execution instructions stored in the memory 1406A and the memory 1406B to enable the computing devices 1400A and 1400B to execute any of the above methods. The two computing devices 1400A and 1400B are connected to each other via a network. Specifically, the connection to said network is made through a communication interface in each computing device. In this class of possible implementations, the memory 1406A in the computing device 1400A holds instructions for performing a part of the method described in the above embodiments. At the same time, the memory 1406B in the computing device 1400B holds instructions for performing other part (s) of the method described in the above embodiments.

[0202] The functions of computing device 1400A illustrated in FIG. 14 can also be accomplished by multiple computing devices. Similarly, the functions of computing device 1400B can be accomplished by multiple computing devices.

[0203] In some aspects of the present disclosure, there is provided a computer program product including computer execution instructions which, when executed by a processor, cause the processor to execute any of the above methods.

[0204] In some aspects of the present disclosure, there is provided a computer program including computer execution instructions which, when executed by a processor, cause the processor to execute any of the above methods.

[0205] In some aspects of the present disclosure, there is provided a computer-readable medium storing computer execution instructions which, when executed by a processor, cause the processor to execute any of the above methods.

[0206] In some aspects of the present disclosure, there is provided a chip, including an input / output (I / O) interface and a processor, where the processor is configured to call and run computer execution instructions stored in a memory, to enable a device installing with the chip to execute any of the above methods.

[0207] A person skilled in the art should understand that embodiments of this application may be provided as a method, an apparatus (or system) , computer-readable storage medium, or a computer program product. Therefore, this application may use a form of a hardware-only embodiment, a software-only embodiment, or an embodiment with a combination of software and hardware. Moreover, this application may use a form of a computer program product that is implemented on one or more computer-usable storage media (including but not limited to a disk memory, an optical memory, and the like) that include computer-usable program code.

[0208] Features disclosed herein in the context of any particular embodiments may also or instead be implemented in other embodiments. Method embodiments, for example, may also or instead be implemented in apparatus, system, and / or computer program product embodiments. In addition, although embodiments are described primarily in the context of methods and apparatus, other implementations are also contemplated, as instructions stored on one or more non-transitory computer-readable media, for example. Such media could store programming or instructions to perform any of various methods consistent with the present disclosure.

[0209] Although the present disclosure describes methods and processes with steps in a certain order, one or more steps of the methods and processes may be omitted or altered as appropriate. One or more steps may take place in an order other than that in which they are described, as appropriate.

[0210] Note that the expression “at least one of A or B” , as used herein, is interchangeable with the expression “A and / or B” . It refers to a list in which you may select A or B or both A and B. Similarly, “at least one of A, B, or C” , as used herein, is interchangeable with “A and / or B and / or C” or “A, B, and / or C” . It refers to a list in which you may select: A or B or C, or both A and B, or both A and C, or both B and C, or all of A, B and C. The same principle applies for longer lists having a same format.

[0211] Although the present disclosure is described, at least in part, in terms of methods, a person of ordinary skill in the art will understand that the present disclosure is also directed to the various components for performing at least some of the aspects and features of the described methods, be it by way of hardware components, software or any combination of the two. Accordingly, the technical solution of the present disclosure may be embodied in the form of a software product. A suitable software product may be stored in a pre-recorded storage device or other similar non-volatile or non-transitory computer readable medium, including DVDs, CD-ROMs, USB flash disk, a removable hard disk, or other storage media, for example. The software product includes instructions tangibly stored thereon that enable a processing device (e.g., a personal computer, a server, or a network device) to execute examples of the methods disclosed herein. The machine-executable instructions may be in the form of code sequences, configuration information, or other data, which, when executed, cause a machine (e.g., a processor or other processing device) to perform steps in a method according to examples of the present disclosure.

[0212] The present disclosure may be embodied in other specific forms without departing from the subject matter of the claims. The described example implementations are to be considered in all respects as being only illustrative and not restrictive. Selected features from one or more of the above-described implementations may be combined to create alternative implementations not explicitly described, features suitable for such combinations being understood within the scope of this disclosure.

[0213] All values and sub-ranges within disclosed ranges are also disclosed. Also, although the systems, devices and processes disclosed and shown herein may include a specific number of elements / components, the systems, devices and assemblies could be modified to include additional or fewer of such elements / components. For example, although any of the elements / components disclosed may be referenced as being singular, the implementations disclosed herein could be modified to include a plurality of such elements / components. The subject matter described herein intends to cover and embrace all suitable changes in technology.

[0214] Although implementations have been described above with reference to the accompanying drawings, those of skill in the art will appreciate that variations and modifications may be made without departing from the scope thereof as defined by the appended claims.

Claims

A method applied at a first node, the method comprising:receiving, from a second node, a request related to the management of an identifier of a device for one or more services, wherein the request comprises at least one operation to be performed by the first node;managing the identifier of the device based on the request; andtransmitting a response to the second node, wherein the response is based on the at least one operation performed by the first node.The method of claim 1, wherein the at least one operation performed by the first node for managing the identifier of the device comprises at least one of: updating the identifier of the device, assigning a new identifier for the device, identifying the device, revoking an identifier of the device or providing notification of an identifier of the device.The method of claim 1, wherein the request further comprises at least one of: a name of the device; a name of the one or more services; an identifier of the device assigned by a service provider; and the at least one operation to be performed by the first node.The method of claim 3, wherein the name of the device comprises at least one of: a first temporary identifier of the device for accessing one or more services provided by the network, a second temporary identifier of the device to access one or more services provided by a service provider; and an identifier of the device for privacy preservation of the device.The method of any one of claims 1 to 4, wherein the name of the service comprises an identifier of the service.The method of any one of claims 1 to 5, wherein the response comprises at least one of: one or more temporary identifiers of the device that are different from an initial identifier of the device provided in the request; an identifier of the device that is used for authenticating the device and an indication of whether the initial identifier of the device has been revoked.The method of claim 6, wherein the one or more temporary identifiers of the device comprises at least one of the first temporary identifier of the device and the second temporary identifier of the device.The method of claim 4, wherein, for executing the method, the first node maintains a device identifier table, wherein the device identifier table includes a list of identifiers of the device and a list of names of service providers.The method of any one of claims 1 to 8, wherein, for the first node to perform the method, the second node is subscribed to services of the first node, and wherein the second node is a service provider for providing the one or more services to the device, or a network function for provisioning the services to be rendered to the device.The method of claim 9, wherein the network function comprises a service provisioning management (SPM) function.The method of claim 8,wherein when the second node is unable to identify the device, receiving, from the second node, the request related to the management of the identifier of the device, the request comprising the identifier of the device for the privacy preservation of the device and an operation to be performed by the first node, the operation being to identify the device; andtransmitting the response to the second node by performing a look-up in the device identifier table, wherein the response comprises at least one of the identifier of the device for authenticating the device, and the first temporary identifier of the device.The method of claim 4, comprising:receiving, from the second node, the request to assign a new second temporary identifier to the device on behalf of a service provider,wherein the request comprises at least one of:the first temporary identifier of the device or the identifier of the device for privacy preservation of the device, andan identifier of the service provider, wherein the request further indicates:an operation to be performed by the first node, the operation being to assign the new second temporary identifier to the device; andtransmitting the response to the second node, wherein the response comprises the new second temporary identifier of the device.The method of claim 4, comprising:receiving, from the second node, the request for updating the second temporary identifier of the device, wherein the request comprises:the second temporary identifier of the device and an operation to be performed by the first node,the operation being to update the second temporary identifier of the device,transmitting the response to the second node, wherein the response indicates that the second temporary identifier of the device has been updated to a new second temporary identifier of the device.The method of claim 4, wherein:receiving, from the second node, the request for updating the first temporary identifier of the device, wherein the request comprises:the first temporary identifier of the device and an operation to be performed by the first node;the operation being to update the first temporary identifier of the device;transmitting the response to the second node, wherein the response indicates that the first temporary identifier of the device has been updated to a new first temporary identifier of the device.The method of claim 4, wherein:receiving, from the second node, the request for revoking at least one of the first temporary identifier of the device and the second temporary identifier of the device, whereinthe request comprises:at least one of the first temporary identifier of the device and the second temporary identifier of the device; andan operation to be performed by the first node, the operation being to revoke at least one of the first temporary identifier of the device and the second temporary identifier of the device;transmitting the response to the second node, wherein the response indicates whether at least one of the first temporary identifier of the device and the second temporary identifier of the device has been revoked.The method of claim 4, wherein:receiving, from the second node, the request to revoke at least one of the first temporary identifier of the device and the second temporary identifier of the device, whereinthe request comprises:at least one of the first temporary identifier of the device and the second temporary identifier of the device;a service provider (NC) identifier;and an operation to be performed by the first node, the operation being to revoke at least one of the first temporary identifier of the device and the second temporary identifier of the device; andtransmitting the response to the second node, wherein the response indicates whether at least one of the first temporary identifier of the device and the second temporary identifier of the device has been revoked.The method of claim 4, wherein:receiving, by the second node, the request to notify the first node that the second temporary identifier of the device has been assigned by a service provider,wherein the request comprises:the first temporary identifier of the device;an identifier of the service provider;the second temporary identifier of the device; andan operation to be performed by the first node, the first node being notified that the second temporary identifier of the device has been assigned by the service provider; andwherein the first node updates a device identifier table with the first temporary identifier of the device and the second temporary identifier of the device.The method of claim 4, wherein:receiving, from the second node, the request to notify the first node that the first temporary identifier of the device has been assigned by the second node, wherein the second node is a network function for provisioning the services to be rendered to the device,wherein the request comprises:the identifier of the device for the privacy preservation of the device or the first temporary identifier of the device;a new first temporary identifier of the device assigned by the second node; andan operation to be performed by the first node, the operation being to notify the first node that the first temporary identifier of the device has been assigned by the second node,wherein the first node updates a device identifier table with the new first temporary identifier of the device.A method performed at a first node, the method comprising:receiving, from a second node, a request to generate credentials for a device, the request comprising information including an identifier of the device, an authentication method and a corresponding algorithm;generating the credentials for the device based on the information in the request; andtransmitting a response to the second node, the response comprising the credentials generated for the device based on at least one of the identifier of the device, the authentication method and the corresponding algorithm.The method of claim 19, wherein the identifier of the device is either a temporary identifier of the device for accessing one or more services provided by the network, or an identifier of the device for privacy preservation of the device.The method of claim 19 or 20, wherein the authentication method includes one of: an Authentication and Key Agreement (AKA) ; a Physically Unclonable Function (PUF) ; and a 6G Extensible Authentication Protocol (6G-EAP) .The method of any one of claims 19 to 21, wherein based on the authentication method indicated in the request, an identifier of a specific authentication algorithm to be used is provided as the corresponding algorithm.The method of any one of claims 19 to 22, wherein the request further comprises one or more parameters associated with the credentials, the credentials depending on the authentication method selected, the credentials generated by the first node being further based on the one or more parameters.The method of claim 23, wherein the request further comprises an identifier of the corresponding algorithm, wherein the credentials are generated based on the corresponding algorithm.The method of any one of claims 20 to 24, wherein the authentication method is AKA and the credentials of the device generated by the first node comprise an AKA vector.The method of any one of claims 20 to 24, wherein the authentication method is PUF, and the credentials of the device generated by the first node are PUF-based credentials.The method of any one of claims 20 to 24, wherein the authentication method is 6G-EAP and the credentials generated by the first node comprise an EAP certificate.The method of any one of claims 20 to 27, wherein the second node is a service provisioning management (SPM) node.The method of any one of claims 19 to 28, wherein the method is performed when the second node does not have identification information on the device and the second node is required to authenticate the device.The method of any one of claims 19 to 29, wherein the action request is called by an automatic network capability programming (A-CAP) service or a connectivity management service, that is triggered by a device or by a service provisioning management (SPM) node.An apparatus configured to perform the method according to any one of claims 1 to 18 or the method according to any one of claims 19 to 30.An apparatus comprising:one or more processors; andone or more memories storing instructions which, when executed by the one or more processors, cause the apparatus to perform the method according to any one of claims 1 to 18, or the method according to any one of claims 19 to 30.A computer program product comprising program code for performing the method according to any one of claims 1 to 18, or the method according to any one of claims 19 to 30.A computer program comprising computer execution instructions which, when executed by a processor, cause the processor to execute the method according to any one of claims 1 to 18, or the method according to any one of claims 19 to 30.A computer-readable medium storing computer execution instructions which, when executed by a processor, cause the processor to execute the method according to any one of claims 1 to 18, or the method according to any one of claims 19 to 30.A chip, comprising an input / output (I / O) interface and a processor, wherein the processor is configured to call and run a computer program stored in a memory, to enable a device installing with the chip to perform the method according to any one of claims 1 to 18, or the method according to any one of claims 19 to 30.

Citation Information

Patent Citations

  • Device credential distribution method, system, user equipment and management entity

    CN109150507A

  • Service identifier distribution method in computing power aware network and communication device

    CN114844865A

  • Service providing system, service providing method, and service providing program

    JP2014179048A

  • Personal IoT network (PIN) primitive credential configuration method and apparatus, communication device, and storage medium

    WO2023231018A1