Webauthn for authentication in capif

WO2026188472A1PCT designated stage Publication Date: 2026-09-17NOKIA SOLUTIONS (SHANGHAI) CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/082275
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2026-09-17

Smart Images

  • Figure CN2025082275_17092026_PF_FP_ABST
    Figure CN2025082275_17092026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are web authentication, WebAuthn, for authentication in common application programming interface framework, CAPIF. An example apparatus for a user equipment, UE, may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to:receive at a resource owner, RO, entity of the UE, an authentication request comprising a first challenge for authentication; transmit from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a CAPIF core function, CCF, information on an application programming interface, API, exposing function, AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; and receive at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.
Need to check novelty before this filing date? Find Prior Art

Description

WEBAUTHN FOR AUTHENTICATION IN CAPIFTECHNICAL FIELD

[0001] Various example embodiments relate to web authentication (WebAuthn) for authentication in common application programming interface framework (CAPIF) .BACKGROUND

[0002] Fast Identity Online (FIDO) alliance is an open industry associated with a focused mission of reducing the world’s reliance on passwords. Version 2.0 of FIDO (FIDO2) comprise World Wide Web Consortium (W3C) WebAuthn specification and FIDO alliance’s corresponding client-to-authenticator protocol (CTAP) . WebAuthn defines a standard web application programming interface (API) which is built into browsers and platforms to enable support for FIDO authentication. By using WebAuthn APIs, developer partners and developer community can use FIDO2 security keys to implement passwordless multi-factor authentication for the applications on various devices. Users of the applications or sites can use browser which supports WebAuthn APIs for passwordless authentication.SUMMARY

[0003] A brief summary of exemplary embodiments is provided below to provide basic understanding of some aspects of various embodiments. It should be noted that this summary is not intended to identify key features of essential elements or define scopes of the embodiments, and its sole purpose is to introduce some concepts in a simplified form as a preamble for a more detailed description provided below.

[0004] In a first aspect, disclosed is an apparatus for a UE. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to: receive at a RO entity of the UE, an authentication request comprising a first challenge for authentication; transmit from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a CCF, information on an AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; and receive at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.

[0005] In a second aspect, disclosed is an apparatus for a CCF. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to: generate a first challenge for authentication; transmit to a UE, an authentication request comprising the first challenge; receive from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on the CCF, information on an AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and verify the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0006] In a third aspect, disclosed is an apparatus for an AEF. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to: generate a first challenge for authentication; transmit to a UE, an authentication request comprising the first challenge; receive from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on a CCF, information on the AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and verify the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0007] Other aspects provide methods, apparatuses, and computer-readable media for authentication in CAPIF, which generally correspond to the above aspects and a repetitive description thereof is omitted here for convenience.

[0008] Other features and advantages of the example embodiments of the present disclosure will also be apparent from the following description of specific embodiments when read in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of example embodiments of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Some example embodiments will now be described, by way of non-limiting examples, with reference to the accompanying drawings.

[0010] FIG. 1 shows an example diagram according to the example embodiments of the present disclosure.

[0011] FIG. 2A shows an example diagram according to the example embodiments of the present disclosure.

[0012] FIG. 2B shows an example diagram according to the example embodiments of the present disclosure.

[0013] FIG. 3A shows an example diagram according to the example embodiments of the present disclosure.

[0014] FIG. 3B shows an example diagram according to the example embodiments of the present disclosure.

[0015] FIG. 4 shows a flow chart illustrating an example method 400 according to the example embodiments of the present disclosure.

[0016] FIG. 5 shows a flow chart illustrating an example method 500 according to the example embodiments of the present disclosure.

[0017] FIG. 6 shows a flow chart illustrating an example method 600 according to the example embodiments of the present disclosure.

[0018] FIG. 7 shows a block diagram illustrating an example apparatus according to the example embodiments of the present disclosure.

[0019] FIG. 8 shows a block diagram illustrating an example apparatus 800 according to the example embodiments of the present disclosure.

[0020] FIG. 9 shows a block diagram illustrating an example apparatus 900 according to the example embodiments of the present disclosure.

[0021] FIG. 10 shows a block diagram illustrating an example apparatus 1000 according to the example embodiments of the present disclosure.

[0022] Throughout the drawings, same or similar reference numbers indicate same or similar elements. A repetitive description on the same elements would be omitted.DETAILED DESCRIPTION

[0023] Herein below, some example embodiments are described in detail with reference to the accompanying drawings. The following description includes specific details for the purpose of providing a thorough understanding of various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well known circuits, techniques and components are shown in block diagram form to avoid obscuring the described concepts and features.

[0024] The following embodiments are exemplary. Although the specification may refer to “an” , “one” , or “some” embodiment (s) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment (s) , or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it is within the knowledge of one skilled in the art to apply such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described. It shall be understood that although the terms “first, ” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.

[0025] For the purposes of the present disclosure, the phrases “at least one of A or B” , “at least one of A and B” , and “Aand / or B” means (A) , (B) , or (Aand B) . For the purposes of the present disclosure, the phrase “A, B, and / or C” means (A) , (B) , (C) , (Aand B) , (Aand C) , (B and C) , or (A, B, and C) .

[0026] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , or a Mobile Station (MS) . The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, USB dongles, an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like.

[0027] Exposure of mobile network service / resource to a third party user, either individual or organizational customer, is an important feature in sixth generation of mobile communication system (6G) and CAPIF is main framework to support this purpose. Security, for example, authentication and authorization of an end user to access the exposed service / function, is critical to deploy the framework.

[0028] CAPIF security mechanisms defined in current 3rd Generation Partnership Project (3GPP) specifications are focused on machine to machine communication without considering the end user at the beginning of design. Resource owner-aware Northbound API access (RNAA) was added to allow CAPIF core function (CCF) to get permission from the resource owner (RO) during authorization procedure. However, in current CAPIF solutions, there are following gaps, e.g. to support consumer use cases such as metaverse, extended reality (XR) , etc. (1) How to authenticate the user behind user equipment (UE) device towards CCF?  (2) How to authenticate the user behind UE device towards API exposing function (AEF) ?  (3) How to assert the permission / authorization really come from the resource owner / user without  authenticating the user?

[0029] Example embodiments of the present disclosure provide solutions for addressing the gaps by means of CAPIF authentication on end user. For example, the example embodiments of the present disclosure may perform user authentication in the context of RNAA based on CAPIF. In some embodiments, an authenticator can be used to verify the end-user as a RO in the RNAA procedure. In some embodiments, the CCF is allowed to authenticate the RO through a resource owner client (ROC) or resource owner function (ROF) .

[0030] RNAA is introduced in 3GPP Technical Specification (TS) 33.122, in which the CCF retrieves authorization from a RO before granting access permission to an API invoker. According to 3GPP TS 33.700-22, the authentication of the RO can be realized via application layer mechanisms, e.g., the RO can be authenticated via a password. The example embodiments of the present disclosure can authenticate a resource owner / an end user before the resource owner / end user creates a resource, or before the CCF retrieves the authorization from the resource owner when other API invoker access the resource. The example embodiments of the present disclosure provide solutions which can be used for authentication and authorization of digital asset, e.g. avatar, management.

[0031] FIG. 1 shows an example diagram according to the example embodiments of the present disclosure. Referring to FIG. 1, a RO 210 may represent any end user of a network, and a UE 212 may represent any terminal device of the RO 210. The UE 212 comprises a RO entity 216, which may be a ROC or a ROF. In the network, there are also an authenticator 214, a CCF 218, an AEF 220, and an API invoker 202. The authenticator 214 may be located in the UE 212 or may be outside the UE 212. The operations in FIG. 1 may be performed for the registration of the UE 212 / RO entity 216 with the CCF 218.

[0032] The CCF 218 may receive a registration request 224 for the registration. The registration may be an initial registration or an update of an existing registration. In some embodiments, the registration request 224 may be from the RO entity 216 and based on a registration request 222 from the RO 210, as is shown in FIG. 1. In some embodiments, the registration request 224 may be from other entity in the network. In some embodiments, the registration request 224 does not need a registration request from the RO 210 as prerequisite. In other words, for registration in the CCF 218, a registration request from the RO 210 may be unnecessary.

[0033] In some embodiments, the registration request 224 may comprise at least one of the following: information on the RO 210, information on the authentication, information on the AEF 220, or information on the RO entity 216. In some embodiments, the registration request 224 may comprise the information on the RO 210 and the information on the RO entity 216 and optionally comprise at least one of the information on the authentication or the information on the AEF 220.

[0034] The information on the RO 210 may also be referred to as RO information or user information. The information on the RO 210 may comprise, for example, name, phone number, email, address, payment related information, interested application, etc.

[0035] The information on the authentication may also be referred to as authentication information and may comprise the information on the type of authenticator 214 and / or the information on mechanism of the authentication. The information on the type of authenticator 214 may comprise for example, internal (embedded) authenticator or external (roaming) authenticator, etc. The mechanism of the authentication may also be referred to as authentication mechanism and may comprise, for example, swiping a finger, looking at the camera, speaking into the mic, entering a personal identity number (PIN) , etc.

[0036] The information on the AEF 220 may also be referred to as AEF information and may comprise, for example, AEF identity, AEF address, etc.

[0037] The information on the RO entity 216 may also be referred to as ROC information or ROF information and may comprise, for example, uniform resource identifier (URI) , uniform resource locator (URL) , etc. of the RO entity 216.

[0038] In some embodiments, the registration may be initiated by the RO 210. For example, the RO entity 216 may receive the registration request 222 from an interface for the RO 210, and the registration request 222 may comprise at least one of the following: the information on the RO 210, the information on the authentication, or the information on the AEF 220. In some embodiments, the registration request 222 may comprise the information on the RO 210 and optionally comprise at least one of the information on the authentication or the information on the AEF 220. In response to the registration request 222, the RO entity 216 may transmit the registration request 224 to the CCF 218.

[0039] Receiving the registration request 224, in an operation 226, the CCF 218 may create or update for the RO 210, an account associated with at least one of the following: the RO 210, the RO entity 216, the authenticator 214, or the AEF 220. For example, the CCF 218 may create a new account or update the existing account for the RO 210 and associate the RO entity 216 with the account. For example, the CCF 218 may also associate the account with AEFs, e.g. the AEF 220 based on the registration request 224 and / or a contract with the RO 210. In some embodiments, the account created or updated may be associated with the party the information on which is in the registration request 224.

[0040] In addition, in an operation 228, the CCF 218 may generate one or more challenges for registration. In case a single key pair will be used for user authentication by the CCF 218 and suitable AEF (s) , the CCF 218 may generate a single challenge for registration. In case different key pairs will be used for user authentication by the CCF 218 and different AEFs, the CCF 218 may generate multiple challenges for registration, and one key pair may be used to respond one challenge for registration. It may be assumed that the AEF 220 may represent any of the relevant AEF (s) .

[0041] Then, the CCF 218 may transmit to the UE 212, a credential creation request 230 for a credential creation. The UE 212 may receive the credential creation request 230 at the RO entity 216. In some embodiments, the credential creation request 230 may comprise the one or more challenges for registration and additional information. The additional information may comprise at least one of the following: the information on the RO 210, the information on the RO entity 216, the information on the CCF 218, the information on the AEF 220, the information on type of the authenticator 214, or the information on the mechanism of the authentication. In some embodiments, the additional information may comprise the information on the RO 210, the information on the RO entity 216 and optionally comprise at least one of the following: the information on the AEF 220, the information on the type of the authenticator 214, or the information on the mechanism of the authentication. In some embodiments, the additional information may be the information in the registration request 224.

[0042] In some embodiments, the credential creation request 230 may request a WebAuthn based credential creation. For example, the credential creation may conform to WebAuthn protocols and / or leverage WebAuthn technologies. In this case the credential creation request 230 may be referred to as WebAuthn credential creation request.

[0043] Then, the UE 212 may transmit from the RO entity 216 to the authenticator 214, an authenticator credential creation request 232 comprising at least a part of the credential creation request 230, and the part of the credential creation request 230 may be with respect to a challenge of the one or more challenges for registration.

[0044] For example, the authenticator credential creation request 232 may comprise at least one challenge of the one or more challenges for registration in the credential creation request 230, as well as the following related to the at least one challenge in the credential creation request 230: the information on the RO 210, the information on the RO entity 216, the information on the CCF 218, the information on the AEF 220, the information on the type of the authenticator 214, or the information on the mechanism of the authentication.

[0045] For example, if a single challenge is included in the credential creation request 230 from the CCF 218, the RO entity 216 may send one authenticator credential creation request 232 to the authenticator 214. If multiple challenges are included in the credential creation request 230 from the CCF 218, and each challenge is corresponding to a CCF / AEF, the RO entity 216 may send multiple authenticator credential creation requests 232 to the authenticator 214, and each authenticator credential creation request 232 may include a challenge and corresponding CCF / AEF information. Or alternatively, the RO entity 216 may include the multiple challenges and CCF / AEF information in a single authenticator credential creation request 232 to the authenticator 214.

[0046] Receiving the authenticator credential creation request 232, in an operation 234, the authenticator 214 may perform user verification with the RO 210. For example, the authenticator 214 may pop up a prompt to ask the RO 210 to verify and authorize the operation. In some embodiments, the authenticator 214 may authenticate the RO 210 thorough, for example, biometrics solutions.

[0047] Then, in an operation 236, the authenticator 214 may generate a key pair comprising a public key and a private key. The key pair generated in the operation 236, i.e. during the registration may be denoted as a first key pair comprising a first public key and a first private key, to distinguish a key pair of the authenticator 214 before the registration, which may be denoted as a second key pair comprising a second public key and a second private key. The second key pair may be generated by the authenticator 214 or other network entity and be of the authenticator 214 before the registration. The second public key has been transmitted to and stored in the CCF 218, and the second private key is stored in the authenticator 214.

[0048] Then, in an operation 238, the authenticator 214 may perform an attestation for the authenticator credential creation request 232. For example, the authenticator 214 may sign the first public key and the additional information with the second private key. The authenticator 214 may also sign the challenge in the authenticator credential creation request 232 with the second private key.

[0049] Then, the authenticator 214 may transmit an authenticator credential creation response 240 to the UE 212. The UE 212 may receive the authenticator credential creation response 240 at the RO entity 216. In some embodiments, the authenticator credential creation response 240 may comprise the first public key and the additional information signed with the second private key. In some embodiments, the authenticator credential creation response 240 may also comprise the challenge signed with the second private key.

[0050] Receiving the authenticator credential creation response 240, the RO entity 216 may construct a credential creation response 242 based on the authenticator credential creation response 240 and transmit the credential creation response 242 to the CCF 218. The credential creation response 242 may comprise the first public key and the additional information signed with the second private key.

[0051] Receiving the credential creation response 242, in an operation 244, the CCF 218 may verify the credential creation response 242 using the second public key paired with the second private key. In an operation 246, the CCF 218 may store the first public key in case of successful verification.

[0052] In some embodiments, the CCF 218 may add information of the account created or updated in the operation 226, e.g. an identifier (ID) of the account of the RO 210, into the information of the RO 210, and the CCF 218 may transmit to the UE 212, a registration response 248. The UE 212 may receive the registration response 248 at the RO entity 216. The registration response 248 may comprise the information on the RO 210 into which the ID of the account of the RO 210 is added.

[0053] Receiving the registration response 248, the RO entity 216 may construct a registration response 250 based on the registration response 248 and transmit the registration response 250 to an interface for the RO 210.

[0054] In some embodiments, in case of successful verification in the operation 244, the CCF 218 may transmit the first public key to the relevant AEF 220. Thus, during a service request, for example, if the RO 210 would create a digital asset through the AEF 220 for asset management, the first public key may be used by the AEF 220 for authenticating the user / RO 210.

[0055] FIG. 2A shows an example diagram according to the example embodiments of the present disclosure. The operations in FIG. 2A may be performed for the authentication for resource creation after the registration phase described with respect to FIG. 1. The authentication operations shown in FIG. 2A may be initiated by the AEF 220.

[0056] The user / RO 210 logins to an interested AEF 220 to create a resource, and the AEF may receive a login request 254 from an interface for the RO 210. In some embodiments, the login request 254 may comprise at least one of the following: the information on the RO 210, or the information on the RO entity 216. In some embodiments, the login request 254 may comprise the information on the RO 210 and optionally comprise the information on the RO entity 216. The login request 254 may be transmitted through the RO entity 216 with which the RO 210 register to the CCF 218 and / or the AEF 220.

[0057] If the RO 210 logins to the AEF 220 through other browser / application client without the information on the RO entity 216, the AEF 220 may get the information on the RO entity 216 locally or from the CCF 218 in which the information on the RO entity 216 was stored during registration. If there are multiple RO entities associated to the RO 210, the AEF 220 or the CCF 218 may promote the user to select a RO entity.

[0058] Receiving the login request 254, in an operation 256, the AEF 220 may generate a challenge for authentication. The challenge for authentication may be denoted as first challenge, and the challenge mentioned above for registration may be denoted as second challenge.

[0059] Then, the AEF 220 may transmit to the UE 212 an authentication request 258 comprising the first challenge. The UE 212 may receive the authentication request 258 at the RO entity 216.

[0060] In some embodiments, the authentication request 258 may request a WebAuthn based authentication. For example, the authentication may conform to WebAuthn protocols and / or leverage WebAuthn technologies. In this case the authentication request 258 may be referred to as WebAuthn authentication request.

[0061] Receiving the authentication request 258, the RO entity 216 may transmit to the authenticator 214 a get assertion request 260. In some embodiments, get assertion request 260 may comprise the first challenge and the additional information. In some embodiments, the additional information may comprise at least one of the following: the information on the CCF 218, the information on the AEF 220, the information on the RO 210, the information on the RO entity 216, the information on the type of the authenticator 214, or the information on the mechanism of the authentication. In some embodiments, the additional information may comprise the information on the RO 210, the information on the RO entity 216, the information on the CCF 218, and the information on the AEF 220, and optionally comprise at least one of the information on the type of the authenticator 214, or the information on the mechanism of the authentication. In some embodiments, the additional information during the authentication may be the same as the additional information during the registration.

[0062] Receiving the get assertion request 260, in an operation 262, the authenticator 214 may perform user verification with the RO 210, and after the user verification, in an operation 264, the authenticator 214 may generate an assertion 266. In some embodiments, in the operation 264, the authenticator 214 may sign the first challenge and the additional information in the get assertion request 260 with the first private key which is paired with the first public key and was generated during the registration of the UE 212 with the CCF 218.

[0063] Then, the authenticator 214 may transmit the assertion 266 as an authenticator assertion response to the UE 212, and the UE 212 may receive the assertion 266 at the RO entity 216. The assertion 266 may comprise the first challenge and the additional information signed with the first private key. The RO entity 216 may transmit the assertion 266 to the AEF 220.

[0064] Receiving the assertion 266, in an operation 268, the AEF 220 may verify the assertion 266 using the first public key, which is paired with the first private key and corresponds to a combination of the RO 210 and the UE 212. For example, the AEF 220 may verify the signature of the assertion 266 using the first public key of the corresponding combination of the RO 210 and RO entity 216 / UE 212, which is determined during the registration phase. If the AEF 220 does not have the first public key of the RO 210 associated with the AEF 220 / CCF 218, the AEF 220 may ask the CCF 218 for the first public key of the RO 210 linked to the RO entity 216 and the AEF 220.

[0065] In case of successful verification, the AEF 220 may transmit to the interface for the RO 210, a notification 270 of login. The RO 210 receives the successful login notification 270, and the authentication session is established.

[0066] Then, in an operation 272, the resource creation may be performed. For example, the user / RO 210 may call the AEF 220 to create a resource managed by the AEF 220, e.g. digital asset. The AEF 220 may create the resource for the user / RO 210 and attach the information on the RO 210 and the information on the RO entity 216 in the authentication session with the resource.

[0067] FIG. 2B shows an example diagram according to the example embodiments of the present disclosure. The operations in FIG. 2B may be performed for the authentication during RNAA after the registration phase described with respect to FIG. 1. The authentication operations shown in FIG. 2B may be initiated by the CCF 218.

[0068] In an operation 204, an API invoker 202 may retrieve access token from the CCF 218 to access resource from an AEF, e.g., the AEF 220. Then, the CCF 274 may get RO information, e.g., the information on the RO 210, from the AEF 220. For example, the CCF 218 may transmit a request to the AEF 220 for the RO information, and the AEF 220 may return the information on the RO 210 and the RO entity 216 of the resource.

[0069] Receiving the information on the RO 210 and the information on the RO entity 216 from the AEF 220, in an operation 276, the CCF 218 may generate a first challenge for authentication, which may be similar to the operation 256. Then, the CCF 218 may transmit to the UE 212 an authentication request 278 comprising the first challenge. The UE 212 may receive the authentication request 278 at the RO entity 216.

[0070] In some embodiments, the authentication request 278 may be similar to the authentication request 258. In some embodiments, the authentication request 278 may further comprise information on the API invoker 202. The information on the API invoker 202 may comprise, for example, API invoker identity, address, etc.

[0071] In some embodiments, the authentication request 278 may request a WebAuthn based authentication. For example, the authentication may conform to WebAuthn protocols and / or leverage WebAuthn technologies. In this case the authentication request 278 may be referred to as WebAuthn authentication request.

[0072] Receiving the authentication request 278, the RO entity 216 may transmit to the authenticator 214 a get assertion request 280. In some embodiments, the get assertion request 280 may be similar to the get assertion request 260. In some embodiments, the get assertion request 280 may further comprise the information on the API invoker 202.

[0073] Receiving the get assertion request 280, in an operation 282, the authenticator 214 may perform user verification with the RO 210, which may be similar to the operation 262. After the user verification, in an operation 284, the authenticator 214 may generate an assertion 286.

[0074] In some embodiments, the operation 284 may be similar to the operation 264. In some embodiments, if the get assertion request 280 further comprises the information on the API invoker 202, the authenticator 214 may sign the information on the API invoker 202 with the first private key. In some embodiments, even if the get assertion request 280 further comprises the information on the API invoker 202, the authenticator 214 does not need to sign the information on the API invoker 202 with the first private key.

[0075] Then, the authenticator 214 may transmit the assertion 286 as an authenticator assertion response to the UE 212, and the UE 212 may receive the assertion 286 at the RO entity 216.

[0076] In some embodiments, the assertion 286 may be similar to the assertion 266. In some embodiments, the assertion 286 may further comprise the information on the API invoker 202 signed or not signed with the first private key. The RO entity 216 may transmit the assertion 286 to the CCF 218.

[0077] Receiving the assertion 286, in an operation 288, the CCF 218 may verify the assertion 286 using the first public key, which is paired with the first private key and corresponds to a combination of the RO 210 and the UE 212. The operation 288 may be similar to the operation 268.

[0078] If the CCF 218 successfully verifies the assertion 286, in an operation 290 the CCF 218 may retrieve authorization from the RO entity 215 following RNAA procedures, and in an operation 206 the CCF 218 may return the access token to the API invoker 202.

[0079] Alternatively, in some embodiments, the CCF 218 may include authorization information together with the first challenge when transmitting the authentication request 278 to the RO entity 216, and the authorization information may be forwarded to the authenticator 214, verified by the end user / RO 210, and asserted by the authenticator 214. Therefore, successful verification of assertion in the operation 288 may imply authorization from the RO 210, and the operation 290 on the RNAA procedures can be omitted.

[0080] FIG. 3A shows an example diagram according to the example embodiments of the present disclosure. The operations in FIG. 3A may be performed for the registration of the UE 212 / RO entity 216 with the CCF 218. The registration may also be referred to as onboarding. Compared to the example embodiments with respect to FIG. 1, in the example embodiments with respect to FIG. 3A, the user authentication has been done in advance.

[0081] The user / RO 210 has previously interacted with the CCF 218 to create an initial secret. The RO 210 and the CCF 218 are aware of the initial secret, but other parties are not aware the initial secret. The initial secret may be for example, user name and password, and in the CCF 218 may link to the information on the RO 210.

[0082] The RO 210 may transmit via an interface for the RO 210 a registration request 312 to the RO entity 216 to initiate the registration of the UE 212 / RO entity 216. The registration request 312 may comprise the information in the registration request 222, and compared to the registration request 222, the registration request 312 may further comprise the initial secret.

[0083] Receiving the registration request 312, the RO entity 216 may transmit a registration request 314 to the CCF 218. The registration request 314 may comprise the information in the registration request 224, and compared to the registration request 224, the registration request 314 may further comprise the initial secret.

[0084] Receiving the registration request 314, the CCF 218 may perform an operation similar to the operation 226 to create or update an account. In an operation 316, the CCF 218 may retrieve the information on the RO 210 based on the initial secret.

[0085] Then, in an operation 318, the the CCF 218 may generate one or more second challenges for registration, which may be similar to the operation 228, and may transmit to the UE 212 a credential creation request 320, which may be similar to the credential creation request 230.

[0086] The UE 212 may receive the credential creation request 230 at the RO entity 216, and the RO entity 216 may transmit to the authenticator 214 an authenticator credential creation request 322, which may be similar to the authenticator credential creation request 232.

[0087] Receiving the authenticator credential creation request 322, in an operation 324, the authenticator 214 may perform user verification with the RO 210, which may be similar to the operation 234. After the user verification, in an operation 326, the authenticator 214 may generate a first key pair comprising a first public key and a first private key, which may be similar to the operation 236.

[0088] Then, in an operation 328, the authenticator 214 may perform an attestation for the authenticator credential creation request 322, which may be similar to the operation 238. And then, the authenticator 214 may transmit to the UE 212 an authenticator credential creation response 330, which may be similar to the authenticator credential creation response 240.

[0089] The UE 212 may receive the authenticator credential creation response 330 at the RO entity 216, and the RO entity 216 may construct a credential creation response 332 based on the authenticator credential creation response 330 and transmit to the CCF 218 the credential creation response 332, which may be similar to the credential creation response 242.

[0090] Receiving the credential creation response 332, in an operation 334, the CCF 218 may verify the credential creation response 332 using the second public key of the authenticator 214 before the registration phase, which may be similar to the operation 244. Then, in an operation 336, the CCF 218 may store the first public key in case of successful verification, which may be similar to the operation 246.

[0091] Then, optionally, the CCF 218 may transmit to UE 212 a registration response 338, which may be similar to the registration response 248. The UE 212 may receive the registration response 338 at the RO entity 216.

[0092] Receiving the registration response 338, based on the registration response 338 the RO entity 216 may construct a registration response 340, which may be similar to the registration response 250, and transmit the registration response 340 to an interface for the RO 210.

[0093] FIG. 3B shows an example diagram according to the example embodiments of the present disclosure. The operations in FIG. 3B may be performed for the authentication of an end user after the registration phase described with respect to FIG. 3A. The authentication operations shown in FIG. 3B may be initiated by the CCF 218.

[0094] The RO 210 may transmit a login request 342 via an interface for the RO 210 to the UE 212, and the UE 212 may receive at the RO entity 216 the login request 342 from the interface for the RO 210. In some embodiments, the login request 342 may comprise the information of the RO 210, for example, an ID of the RO 210 as user ID.

[0095] Then, the RO entity 216 may transmit to the CCF 218, a login request 344. In some embodiments, the login request 344 may comprise at least one of the following: the ID of the RO 210, or the information on the RO entity 216. In some embodiments, the login request 344 may comprise the login request 342 and the information on the RO entity 216.

[0096] Receiving the login request 344, in an operation 346, the CCF 218 may identify the ID of the RO 210 and the first public key. The first public key is stored in the operation 336 and corresponds to a combination of the RO 210 and the UE 212. After identifying the correct user ID and the first public key, in an operation 348, the CCF 218 may generate a first challenge for authentication, which may be similar to the operation 276. Then, the CCF 218 may transmit to the UE 212 an authentication request 350 comprising the first challenge. The authentication request 350 may be similar to the authentication request 258. The UE 212 may receive the authentication request 350 at the RO entity 216.

[0097] Receiving the authentication request 350, the RO entity 216 may transmit to the authenticator 214 a get assertion request 352, which may be similar to the get assertion request 260. Receiving the get assertion request 352, in an operation 354, the authenticator 214 may perform user verification with the RO 210, which may be similar to the operation 262. After the user verification, in an operation 356, the authenticator 214 may generate an assertion 358. The operation 356 may be similar to the operation 264, and the assertion 358 may be similar to the assertion 266.

[0098] Then, the authenticator 214 may transmit the assertion 358 as an authenticator assertion response to the UE 212, and the UE 212 may receive the assertion 358 at the RO entity 216. The RO entity 216 may transmit the assertion 358 to the CCF 218.

[0099] Receiving the assertion 358, in an operation 360, the CCF 218 may verify the assertion 358 using the first public key, which is paired with the first private key and corresponds to a combination of the RO 210 and the UE 212. The operation 360 may be similar to the operation 268. Thus, the CCF 218 can verify the signature and authenticate the end user.

[0100] Thus, according to the example embodiments of the present disclosure, user authentication function can be added in CAPIF, and further CAPIF architecture can be enhanced with WebAuthn function.

[0101] Moreover, WebAuthn based credential creation and WebAuthn based authentication can be performed in the example embodiments of the present disclosure. WebAuthn protocols can be used to authenticate the user behind the device. The example embodiments of the present disclosure may leverage the WebAuthn protocols in support of RNAA use-cases in CAPIF. The WebAuthn protocols can be adapted to CAPIF use-case to create the initial authentication required by RNAA.

[0102] FIG. 4 shows a flow chart illustrating an example method 400 according to the example embodiments of the present disclosure. The example method 400 may be performed, for example, by an apparatus for a UE, such as the UE 212 above mentioned.

[0103] Referring to FIG. 4, the example method 400 may comprise: an operation 410 of receiving at a RO entity of the UE, an authentication request comprising a first challenge for authentication; an operation 420 of transmitting from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a CCF, information on an AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; and an operation 430 of receiving at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.

[0104] In some embodiments, the example method 400 may comprise: in case the authentication request is received from the AEF, transmitting the assertion from the RO entity to the AEF.

[0105] In some embodiments, the example method 400 may comprise: in case the authentication request is received from the CCF, transmitting the assertion from the RO entity to the CCF.

[0106] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0107] In some embodiments, the authentication request may further comprise information on an API invoker.

[0108] In some embodiments, the get assertion request may further comprise the information on the API invoker, and the assertion may further comprise the information on the API invoker signed with the first private key.

[0109] In some embodiments, the example method 400 may comprise: receiving at the RO entity from an interface for the RO, a first login request comprising an identifier of the RO; and transmitting from the RO entity to the CCF, a second login request comprising the first login request and the information on the RO entity.

[0110] In some embodiments, the example method 400 may comprise: receiving at the RO entity from the CCF, a credential creation request comprising one or more second challenges for registration and the additional information; and transmitting from the RO entity to the authenticator, an authenticator credential creation request comprising at least a part of the credential creation request, wherein the part of the credential creation request may be with respect to a second challenge of the one or more second challenges.

[0111] In some embodiments, the example method 400 may comprise: receiving at the RO entity from the authenticator, an authenticator credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair of the authenticator before the registration; constructing at the RO entity, a credential creation response based on the authenticator credential creation response; and transmitting from the RO entity to the CCF, the credential creation response.

[0112] In some embodiments, the credential creation request may request a WebAuthn based credential creation.

[0113] In some embodiments, the first key pair may be generated by the authenticator.

[0114] In some embodiments, the example method 400 may comprise: receiving at the RO entity, from an interface for the RO, a first registration request comprising at least one of the following: the information on the RO, information on authentication, or the information on the AEF; and transmitting from the RO entity to the CCF, a second registration request comprising at least one of the following: the information on the RO, the information on the authentication, the information on the AEF, or the information on the RO entity.

[0115] In some embodiments, the example method 400 may comprise: receiving at the RO entity from the CCF, a registration response comprising the information on the RO into which an identifier of an account of the RO in the CCF is added; and transmitting from the RO entity to an interface for the RO, the registration response.

[0116] In some embodiments, the first registration request may further comprise an initial secret, the second registration request further comprises the initial secret, and the initial secret may be previously created between the RO and the CCF.

[0117] FIG. 5 shows a flow chart illustrating an example method 500 according to the example embodiments of the present disclosure. The example method 500 may be performed, for example, by an apparatus for a CCF, such as the CCF 218 above mentioned.

[0118] Referring to FIG. 5, the example method 500 may comprise: an operation 510 of generating a first challenge for authentication; an operation 520 of transmitting to a UE, an authentication request comprising the first challenge; an operation 530 of receiving from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on the CCF, information on an AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and an operation 540 of verifying the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0119] In some embodiments, the example method 500 may comprise: transmitting to the AEF, a request for the information on the RO; and receiving from the AEF, the information on the RO and the information on the RO entity.

[0120] In some embodiments, the example method 500 may comprise: receiving from the UE, a login request comprising at least one of the following: an identifier of the RO, or the information on the RO entity; and identifying the identifier of the RO and the first public key.

[0121] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0122] In some embodiments, the authentication request may further comprise information on an API invoker.

[0123] In some embodiments, the assertion may further comprise the information on the API invoker signed with the first private key.

[0124] In some embodiments, the example method 500 may comprise: receiving a registration request comprising at least one of the following: the information on the RO, information on authentication, the information on the AEF, or information on the RO entity; creating or updating for the RO, an account associated with at least one of the following: the RO, the RO entity, an authenticator, or the AEF; generating one or more second challenges; transmitting to the UE, a credential creation request comprising the one or more second challenges and the additional information; and receiving from the UE, a credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair comprising the second private key and a second public key of the authenticator before the registration.

[0125] In some embodiments, the example method 500 may comprise: verifying the credential creation response using the second public key paired with the second private key; and storing the first public key in case of successful verification.

[0126] In some embodiments, the example method 500 may comprise: transmitting to the AEF, the first public key in case of successful verification.

[0127] In some embodiments, the example method 500 may comprise: transmitting to the UE, a registration response comprising the information on the RO into which an identifier of the account of the RO is added.

[0128] In some embodiments, the registration request may further comprise an initial secret previously created between the RO and the CCF, and the example method 500 may comprise: retrieving the information on the RO based on the initial secret.

[0129] In some embodiments, the credential creation request may request a WebAuthn based credential creation.

[0130] FIG. 6 shows a flow chart illustrating an example method 600 according to the example embodiments of the present disclosure. The example method 600 may be performed, for example, by an apparatus for an AEF, such as the AEF 220 above mentioned.

[0131] Referring to FIG. 6, the example method 600 may comprise: an operation 610 of generating a first challenge for authentication; an operation 620 of transmitting to a UE, an authentication request comprising the first challenge; an operation 630 of receiving from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on a CCF, information on the AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and an operation 640 of verifying the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0132] In some embodiments, the example method 600 may comprise: receiving from an interface for the RO, a login request comprising at least one of the following: the information on the RO, or the information on the RO entity; and transmitting to the interface for the RO, a notification of login in case of successful verification.

[0133] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0134] FIG. 7 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods as disclosed herein, and any of the embodiments thereof. In an example, the at least one memory and the instructions (e.g. a computer program code, software) , are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods as disclosed herein, and any of the embodiments thereof.

[0135] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with example embodiments described herein. As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0136] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may be at least in part external to apparatus 10 but accessible to apparatus 10.

[0137] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM) .

[0138] For example, the apparatus 10 is a terminal device, such as the UE 212. As another example, the apparatus is comprised in such a terminal device, e.g. as a chipset configured to control the terminal device. The apparatus 10 may be caused or configured to perform at least the method 400 and / or any one or more of the embodiments described.

[0139] As another example, the apparatus 10 is a CCF, e.g. the CCF 218. In another embodiment, the apparatus is comprised in such a CCF, e.g. as a chipset configured to control the CCF. The apparatus 10 may be caused or configured to perform at least the method 500 and / or any one or more of the embodiments described.

[0140] As another example, the apparatus 10 is an AEF, e.g. the AEF 220. In another embodiment, the apparatus is comprised in such an AEF, e.g. as a chipset configured to control the AEF. The apparatus 10 may be caused or configured to perform at least the method 600 and / or any one or more of the embodiments described.

[0141] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity. In some embodiments, the entity is configured to perform at least the method 400, the method 500 or the method 600, and / or any one or more of the embodiments described.

[0142] The apparatus 10 comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.

[0143] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10.For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.

[0144] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods as disclosed herein, and any of the embodiments thereof. As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C] ” , is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.

[0145] FIG. 8 shows a block diagram illustrating an example apparatus 800 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a UE, such as the UE 212 in the above examples.

[0146] As shown in FIG. 8, the example apparatus 800 may comprise: means 810 for receiving at a RO entity of the UE, an authentication request comprising a first challenge for authentication; means 820 for transmitting from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a CCF, information on an AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; and means 830 for receiving at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.

[0147] In some embodiments, the example apparatus 800 may comprise: means for in case the authentication request is received from the AEF, transmitting the assertion from the RO entity to the AEF.

[0148] In some embodiments, the example apparatus 800 may comprise: means for in case the authentication request is received from the CCF, transmitting the assertion from the RO entity to the CCF.

[0149] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0150] In some embodiments, the authentication request may further comprise information on an API invoker.

[0151] In some embodiments, the get assertion request may further comprise the information on the API invoker, and the assertion may further comprise the information on the API invoker signed with the first private key.

[0152] In some embodiments, the example apparatus 800 may comprise: means for receiving at the RO entity from an interface for the RO, a first login request comprising an identifier of the RO; and means for transmitting from the RO entity to the CCF, a second login request comprising the first login request and the information on the RO entity.

[0153] In some embodiments, the example apparatus 800 may comprise: means for receiving at the RO entity from the CCF, a credential creation request comprising one or more second challenges for registration and the additional information; and means for transmitting from the RO entity to the authenticator, an authenticator credential creation request comprising at least a part of the credential creation request, wherein the part of the credential creation request may be with respect to a second challenge of the one or more second challenges.

[0154] In some embodiments, the example apparatus 800 may comprise: means for receiving at the RO entity from the authenticator, an authenticator credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair of the authenticator before the registration; means for constructing at the RO entity, a credential creation response based on the authenticator credential creation response; and means for transmitting from the RO entity to the CCF, the credential creation response.

[0155] In some embodiments, the credential creation request may request a WebAuthn based credential creation.

[0156] In some embodiments, the first key pair may be generated by the authenticator.

[0157] In some embodiments, the example apparatus 800 may comprise: means for receiving at the RO entity, from an interface for the RO, a first registration request comprising at least one of the following: the information on the RO, information on authentication, or the information on the AEF; and means for transmitting from the RO entity to the CCF, a second registration request comprising at least one of the following: the information on the RO, the information on the authentication, the information on the AEF, or the information on the RO entity.

[0158] In some embodiments, the example apparatus 800 may comprise: means for receiving at the RO entity from the CCF, a registration response comprising the information on the RO into which an identifier of an account of the RO in the CCF is added; and means for transmitting from the RO entity to an interface for the RO, the registration response.

[0159] In some embodiments, the first registration request may further comprise an initial secret, the second registration request further comprises the initial secret, and the initial secret may be previously created between the RO and the CCF.

[0160] In some example embodiments, examples of means in the example apparatus 800 may include circuitries. For example, an example of means 810 may include a circuitry configured to perform the operation 410 of the example method 400, an example of means 820 may include a circuitry configured to perform the operation 420 of the example method 400, and an example of means 830 may include a circuitry configured to perform the operation 430 of the example method 400.

[0161] The example apparatus 800 may further include means comprising circuitry configured to perform the example method 400. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0162] FIG. 9 shows a block diagram illustrating an example apparatus 900 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a CCF, such as the CCF 218 in the above examples.

[0163] As shown in FIG. 9, the example apparatus 900 may comprise: means 910 for generating a first challenge for authentication; means 920 for transmitting to a UE, an authentication request comprising the first challenge; means 930 for receiving from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on the CCF, information on an AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and means 940 for verifying the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0164] In some embodiments, the example apparatus 900 may comprise: means for transmitting to the AEF, a request for the information on the RO; and means for receiving from the AEF, the information on the RO and the information on the RO entity.

[0165] In some embodiments, the example apparatus 900 may comprise: means for receiving from the UE, a login request comprising at least one of the following: an identifier of the RO, or the information on the RO entity; and means for identifying the identifier of the RO and the first public key.

[0166] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0167] In some embodiments, the authentication request may further comprise information on an API invoker.

[0168] In some embodiments, the assertion may further comprise the information on the API invoker signed with the first private key.

[0169] In some embodiments, the example apparatus 900 may comprise: means for receiving a registration request comprising at least one of the following: the information on the RO, information on authentication, the information on the AEF, or information on the RO entity; means for creating or updating for the RO, an account associated with at least one of the following: the RO, the RO entity, an authenticator, or the AEF; means for generating one or more second challenges; means for transmitting to the UE, a credential creation request comprising the one or more second challenges and the additional information; and means for receiving from the UE, a credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair comprising the second private key and a second public key of the authenticator before the registration.

[0170] In some embodiments, the example apparatus 900 may comprise: means for verifying the credential creation response using the second public key paired with the second private key; and means for storing the first public key in case of successful verification.

[0171] In some embodiments, the example apparatus 900 may comprise: means for transmitting to the AEF, the first public key in case of successful verification.

[0172] In some embodiments, the example apparatus 900 may comprise: means for transmitting to the UE, a registration response comprising the information on the RO into which an identifier of the account of the RO is added.

[0173] In some embodiments, the registration request may further comprise an initial secret previously created between the RO and the CCF, and the example apparatus 900 may comprise: means for retrieving the information on the RO based on the initial secret.

[0174] In some embodiments, the credential creation request may request a WebAuthn based credential creation.

[0175] In some example embodiments, examples of means in the example apparatus 900 may include circuitries. For example, an example of means 910 may include a circuitry configured to perform the operation 510 of the example method 500, an example of means 920 may include a circuitry configured to perform the operation 520 of the example method 500, an example of means 930 may include a circuitry configured to perform the operation 530 of the example method 500, and an example of means 940 may include a circuitry configured to perform the operation 540 of the example method 500.

[0176] The example apparatus 900 may further include means comprising circuitry configured to perform the example method 500. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0177] FIG. 10 shows a block diagram illustrating an example apparatus 1000 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of an AEF, such as the AEF 220 in the above examples.

[0178] As shown in FIG. 10, the example apparatus 1000 may comprise: means 1010 for generating a first challenge for authentication; means 1020 for transmitting to a UE, an authentication request comprising the first challenge; means 1030 for receiving from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on a CCF, information on the AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and means 1040 for verifying the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0179] In some embodiments, the example apparatus 1000 may comprise: means for receiving from an interface for the RO, a login request comprising at least one of the following: the information on the RO, or the information on the RO entity; and means for transmitting to the interface for the RO, a notification of login in case of successful verification.

[0180] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0181] In some example embodiments, examples of means in the example apparatus 1000 may include circuitries. For example, an example of means 1010 may include a circuitry configured to perform the operation 610 of the example method 600, an example of means 1020 may include a circuitry configured to perform the operation 620 of the example method 600, an example of means 1030 may include a circuitry configured to perform the operation 630 of the example method 600, and an example of means 1040 may include a circuitry configured to perform the operation 640 of the example method 600

[0182] The example apparatus 1000 may further include means comprising circuitry configured to perform the example method 600. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0183] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a UE, such as the UE 212 in the above examples, may cause the apparatus at least to: receive at a RO entity of the UE, an authentication request comprising a first challenge for authentication; transmit from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a CCF, information on an AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; and receive at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.

[0184] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: in case the authentication request is received from the AEF, transmit the assertion from the RO entity to the AEF.

[0185] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: in case the authentication request is received from the CCF, transmit the assertion from the RO entity to the CCF.

[0186] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0187] In some embodiments, the authentication request may further comprise information on an API invoker.

[0188] In some embodiments, the get assertion request may further comprise the information on the API invoker, and the assertion may further comprise the information on the API invoker signed with the first private key.

[0189] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive at the RO entity from an interface for the RO, a first login request comprising an identifier of the RO; and transmit from the RO entity to the CCF, a second login request comprising the first login request and the information on the RO entity.

[0190] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive at the RO entity from the CCF, a credential creation request comprising one or more second challenges for registration and the additional information; and transmit from the RO entity to the authenticator, an authenticator credential creation request comprising at least a part of the credential creation request, wherein the part of the credential creation request may be with respect to a second challenge of the one or more second challenges.

[0191] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive at the RO entity from the authenticator, an authenticator credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair of the authenticator before the registration; construct at the RO entity, a credential creation response based on the authenticator credential creation response; and transmit from the RO entity to the CCF, the credential creation response.

[0192] In some embodiments, the credential creation request may request a WebAuthn based credential creation.

[0193] In some embodiments, the first key pair may be generated by the authenticator.

[0194] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive at the RO entity, from an interface for the RO, a first registration request comprising at least one of the following: the information on the RO, information on authentication, or the information on the AEF; and transmit from the RO entity to the CCF, a second registration request comprising at least one of the following: the information on the RO, the information on the authentication, the information on the AEF, or the information on the RO entity.

[0195] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive at the RO entity from the CCF, a registration response comprising the information on the RO into which an identifier of an account of the RO in the CCF is added; and transmit from the RO entity to an interface for the RO, the registration response.

[0196] In some embodiments, the first registration request may further comprise an initial secret, the second registration request further comprises the initial secret, and the initial secret may be previously created between the RO and the CCF.

[0197] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a CCF, such as the CCF 218 in the above examples, may cause the apparatus at least to: generate a first challenge for authentication; transmit to a UE, an authentication request comprising the first challenge; receive from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on the CCF, information on an AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and verify the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0198] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to the AEF, a request for the information on the RO; and receive from the AEF, the information on the RO and the information on the RO entity.

[0199] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive from the UE, a login request comprising at least one of the following: an identifier of the RO, or the information on the RO entity; and identify the identifier of the RO and the first public key.

[0200] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0201] In some embodiments, the authentication request may further comprise information on an API invoker.

[0202] In some embodiments, the assertion may further comprise the information on the API invoker signed with the first private key.

[0203] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive a registration request comprising at least one of the following: the information on the RO, information on authentication, the information on the AEF, or information on the RO entity; create or update for the RO, an account associated with at least one of the following: the RO, the RO entity, an authenticator, or the AEF; generate one or more second challenges; transmit to the UE, a credential creation request comprising the one or more second challenges and the additional information; and receive from the UE, a credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair comprising the second private key and a second public key of the authenticator before the registration.

[0204] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: verify the credential creation response using the second public key paired with the second private key; and store the first public key in case of successful verification.

[0205] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to the AEF, the first public key in case of successful verification.

[0206] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to the UE, a registration response comprising the information on the RO into which an identifier of the account of the RO is added.

[0207] In some embodiments, the registration request may further comprise an initial secret previously created between the RO and the CCF, and the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: retrieve the information on the RO based on the initial secret.

[0208] In some embodiments, the credential creation request may request a WebAuthn based credential creation.

[0209] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for an AEF, such as the AEF 220 in the above examples, may cause the apparatus at least to: generate a first challenge for authentication; transmit to a UE, an authentication request comprising the first challenge; receive from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on a CCF, information on the AEF, information on a RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; and verify the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.

[0210] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: receive from an interface for the RO, a login request comprising at least one of the following: the information on the RO, or the information on the RO entity; and transmit to the interface for the RO, a notification of login in case of successful verification.

[0211] In some embodiments, the authentication request may request a WebAuthn based authentication.

[0212] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0213] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node) . In the above description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.

[0214] The term “circuitry” throughout this disclosure may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) ; (b) combinations of hardware circuits and software, such as (as applicable) (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) ; and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to one or all uses of this term in this disclosure, including in any claims. As a further example, as used in this disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0215] Another example embodiment may relate to computer program codes or instructions which may cause an apparatus to perform at least the respective methods described above. Another example embodiment may be related to a computer-readable medium having such computer program codes or instructions stored thereon. In some embodiments, such a computer-readable medium may include at least one storage medium in various forms such as a volatile memory and / or a non-volatile memory. The volatile memory may include, but is not limited to, for example, a RAM, a cache, and so on. The non-volatile memory may include, but is not limited to, a ROM, a hard disk, a flash memory, and so on. The non-volatile memory may also include, but is not limited to, an electric, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, apparatus, or device or any combination of the above. The volatile memory and the non-volatile memory may be non-transitory memory.

[0216] Unless the context clearly requires otherwise, throughout the description and the claims, the words “comprise, ” “comprising, ” and the like are to be construed in an inclusive sense, as opposed to an exclusive or exhaustive sense; that is to say, in the sense of “including, but is not limited to. ” The word “coupled” , as generally used herein, refers to two or more elements that may be either directly connected, or connected by way of one or more intermediate elements. Likewise, the word “connected” , as generally used herein, refers to two or more elements that may be either directly connected, or connected by way of one or more intermediate elements. Additionally, the words “herein, ” “above, ” “below, ” and words of similar import, when used in this application, shall refer to this application as a whole and not to any particular portions of this application. Where the context permits, words in the description using the singular or plural number may also include the plural or singular number respectively. The word “or” in reference to a list of two or more items, that word covers all of the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list.

[0217] Moreover, conditional language used herein, such as, among others, “can, ” “could, ” “might, ” “may, ” “e.g., ” “for example, ” “such as” and the like, unless specifically stated otherwise, or otherwise understood within the context as used, is generally intended to convey that certain embodiments include, while other embodiments do not include, certain features, elements and / or states. Thus, such conditional language is not generally intended to imply that features, elements and / or states are in any way required for one or more embodiments or that one or more embodiments necessarily include logic for deciding, with or without author input or prompting, whether these features, elements and / or states are included or are to be performed in any particular embodiment.

[0218] As used herein, the term "determine / determining" (and grammatical variants thereof) can include, not least: calculating, computing, processing, deriving, measuring, investigating, looking up (for example, looking up in a table, a database or another data structure) , ascertaining and the like. Also, "determining" can include receiving (for example, receiving information) , accessing (for example, accessing data in a memory) , obtaining and the like. Also, "determine / determining" can include resolving, selecting, choosing, establishing, and the like.

[0219] While some embodiments have been described, these embodiments have been presented by way of example, and are not intended to limit the scope of the disclosure. Indeed, the apparatus, methods, and systems described herein may be embodied in a variety of other forms; furthermore, various omissions, substitutions, and changes in the form of the methods and systems described herein may be made without departing from the spirit of the disclosure. For example, while blocks are presented in a given arrangement, alternative embodiments may perform similar functionalities with different components and / or circuit topologies, and some blocks may be deleted, moved, added, subdivided, combined, and / or modified. At least one of these blocks may be implemented in a variety of different ways. The order of these blocks may also be changed. Any suitable combination of the elements and actions of the some embodiments described above can be combined to provide further embodiments. The accompanying claims and their equivalents are intended to cover such forms or modifications as would fall within the scope and spirit of the disclosure.

[0220] Abbreviations used in the description and / or in the figures are defined as follows: 3GPP            3rd Generation Partnership Project TS                Technical Specification 6G               sixth generation of mobile communication system API               application programming interface AEF              API exposing function CAPIF           common application programming interface framework CCF              CAPIF core function CTAP            client-to-authenticator protocol FIDO             Fast Identity Online FIDO2           Version 2.0 of FIDO ID                identifier PIN              personal identity number RNAA           resource owner-aware Northbound API access RO              resource owner ROC             resource owner client ROF             resource owner function UE             user equipment URI             uniform resource identifier URL             uniform resource locator W3C             World Wide Web Consortium WebAuthn  web authentication XR      extended reality

Claims

1.An apparatus for a user equipment, UE, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive at a resource owner, RO, entity of the UE, an authentication request comprising a first challenge for authentication;transmit from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a common application programming interface framework, CAPIF, core function, CCF, information on an application programming interface, API, exposing function, AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; andreceive at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.2.The apparatus of claim 1, wherein the apparatus is configured to:in case the authentication request is received from the AEF, transmit the assertion from the RO entity to the AEF.3.The apparatus of claim 1, wherein the apparatus is configured to:in case the authentication request is received from the CCF, transmit the assertion from the RO entity to the CCF.4.The apparatus of any of claims 1 to 3, wherein the authentication request requests a web authentication, WebAuthn, based authentication.5.The apparatus of any of claims 1 to 4, wherein the authentication request further comprises information on an API invoker.6.The apparatus of claim 5, wherein the get assertion request further comprises the information on the API invoker, and the assertion further comprises the information on the API invoker signed with the first private key.7.The apparatus of any of claims 1 to 6, wherein the apparatus is configured to:receive at the RO entity from an interface for the RO, a first login request comprising an identifier of the RO; andtransmit from the RO entity to the CCF, a second login request comprising the first login request and the information on the RO entity.8.The apparatus of any of claims 1 to 7, wherein the apparatus is configured to:receive at the RO entity from the CCF, a credential creation request comprising one or more second challenges for registration and the additional information; andtransmit from the RO entity to the authenticator, an authenticator credential creation request comprising at least a part of the credential creation request, wherein the part of the credential creation request is with respect to a second challenge of the one or more second challenges.9.The apparatus of claim 8, wherein the apparatus is configured to:receive at the RO entity from the authenticator, an authenticator credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair of the authenticator before the registration;construct at the RO entity, a credential creation response based on the authenticator credential creation response; andtransmit from the RO entity to the CCF, the credential creation response.10.The apparatus of claim 8 or 9, wherein the credential creation request requests a WebAuthn based credential creation.11.The apparatus of any of claims 1 to 10, wherein the first key pair is generated by the authenticator.12.The apparatus of any of claims 1 to 11, wherein the apparatus is configured to:receive at the RO entity, from an interface for the RO, a first registration request comprising at least one of the following: the information on the RO, information on authentication, or the information on the AEF; andtransmit from the RO entity to the CCF, a second registration request comprising at least one of the following: the information on the RO, the information on the authentication, the information on the AEF, or the information on the RO entity.13.The apparatus of claim 12, wherein the apparatus is configured to:receive at the RO entity from the CCF, a registration response comprising the information on the RO into which an identifier of an account of the RO in the CCF is added; andtransmit from the RO entity to an interface for the RO, the registration response.14.The apparatus of claim 12 or 13, wherein the first registration request further comprises an initial secret, the second registration request further comprises the initial secret, and the initial secret is previously created between the RO and the CCF.15.An apparatus for a common application programming interface framework, CAPIF, core function, CCF, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:generate a first challenge for authentication;transmit to a user equipment, UE, an authentication request comprising the first challenge;receive from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on the CCF, information on an application programming interface, API, exposing function, AEF, information on a resource owner, RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; andverify the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.16.The apparatus of claim 15, wherein the apparatus is configured to:transmit to the AEF, a request for the information on the RO; andreceive from the AEF, the information on the RO and the information on the RO entity.17.The apparatus of claim 15, wherein the apparatus is configured to:receive from the UE, a login request comprising at least one of the following: an identifier of the RO, or the information on the RO entity; andidentify the identifier of the RO and the first public key.18.The apparatus of any of claims 15 to 17, wherein the authentication request requests a web authentication, WebAuthn, based authentication.19.The apparatus of any of claims 15 to 18, wherein the authentication request further comprises information on an API invoker.20.The apparatus of claim 19, wherein the assertion further comprises the information on the API invoker signed with the first private key.21.The apparatus of any of claims 15 to 20, wherein the apparatus is configured to:receive a registration request comprising at least one of the following: the information on the RO, information on authentication, the information on the AEF, or information on the RO entity;create or update for the RO, an account associated with at least one of the following: the RO, the RO entity, an authenticator, or the AEF;generate one or more second challenges;transmit to the UE, a credential creation request comprising the one or more second challenges and the additional information; andreceive from the UE, a credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair comprising the second private key and a second public key of the authenticator before the registration.22.The apparatus of claim 21, wherein the apparatus is configured to:verify the credential creation response using the second public key paired with the second private key; andstore the first public key in case of successful verification.23.The apparatus of claim 22, wherein the apparatus is configured to:transmit to the AEF, the first public key in case of successful verification.24.The apparatus of any of claims 21 to 23, wherein the apparatus is configured to:transmit to the UE, a registration response comprising the information on the RO into which an identifier of the account of the RO is added.25.The apparatus of any of claims 21 to 24, wherein the registration request further comprises an initial secret previously created between the RO and the CCF, and the apparatus is configured to:retrieve the information on the RO based on the initial secret.26.The apparatus of any of claims 21 to 25, wherein the credential creation request requests a WebAuthn based credential creation.27.An apparatus for an application programming interface, API, exposing function, AEF, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:generate a first challenge for authentication;transmit to a user equipment, UE, an authentication request comprising the first challenge;receive from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on a common application programming interface framework, CAPIF, core function, CCF, information on the AEF, information on a resource owner, RO, information on a RO entity of the UE, information on the type of authenticator, or information on mechanism of authentication; andverify the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.28.The apparatus of claim 27, wherein the apparatus is configured to:receive from an interface for the RO, a login request comprising at least one of the following: the information on the RO, or the information on the RO entity; andtransmit to the interface for the RO, a notification of login in case of successful verification.29.The apparatus of claim 27 or 28, wherein the authentication request requests a web authentication, WebAuthn, based authentication.30.A method performed by an apparatus for a user equipment, UE, comprising:receiving at a resource owner, RO, entity of the UE, an authentication request comprising a first challenge for authentication;transmitting from the RO entity to an authenticator, a get assertion request comprising the first challenge and additional information comprising at least one of the following: information on a common application programming interface framework, CAPIF, core function, CCF, information on an application programming interface, API, exposing function, AEF, information on a RO, information on the RO entity, information on type of the authenticator, or information on mechanism of authentication; andreceiving at the RO entity from the authenticator, an assertion comprising the first challenge and the additional information signed with a first private key in a first key pair comprising the first private kay and a first public key generated during a registration of the UE with the CCF.31.The method of claim 30, comprising:in case the authentication request is received from the AEF, transmitting the assertion from the RO entity to the AEF.32.The method of claim 30, comprising:in case the authentication request is received from the CCF, transmitting the assertion from the RO entity to the CCF.33.The method of any of claims 30 to 32, wherein the authentication request requests a web authentication, WebAuthn, based authentication.34.The method of any of claims 30 to 33, wherein the authentication request further comprises information on an API invoker.35.The method of claim 34, wherein the get assertion request further comprises the information on the API invoker, and the assertion further comprises the information on the API invoker signed with the first private key.36.The method of any of claims 30 to 35, comprising:receiving at the RO entity from an interface for the RO, a first login request comprising an identifier of the RO; andtransmitting from the RO entity to the CCF, a second login request comprising the first login request and the information on the RO entity.37.The method of any of claims 30 to 36, comprising:receiving at the RO entity from the CCF, a credential creation request comprising one or more second challenges for registration and the additional information; andtransmitting from the RO entity to the authenticator, an authenticator credential creation request comprising at least a part of the credential creation request, wherein the part of the credential creation request is with respect to a second challenge of the one or more second challenges.38.The method of claim 37, comprising:receiving at the RO entity from the authenticator, an authenticator credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair of the authenticator before the registration;constructing at the RO entity, a credential creation response based on the authenticator credential creation response; andtransmitting from the RO entity to the CCF, the credential creation response.39.The method of claim 37 or 38, wherein the credential creation request requests a WebAuthn based credential creation.40.The method of any of claims 30 to 39, wherein the first key pair is generated by the authenticator.41.The method of any of claims 30 to 40, comprising:receiving at the RO entity, from an interface for the RO, a first registration request comprising at least one of the following: the information on the RO, information on authentication, or the information on the AEF; andtransmitting from the RO entity to the CCF, a second registration request comprising at least one of the following: the information on the RO, the information on the authentication, the information on the AEF, or the information on the RO entity.42.The method of claim 41, comprising:receiving at the RO entity from the CCF, a registration response comprising the information on the RO into which an identifier of an account of the RO in the CCF is added; andtransmitting from the RO entity to an interface for the RO, the registration response.43.The method of claim 41 or 42, wherein the first registration request further comprises an initial secret, the second registration request further comprises the initial secret, and the initial secret is previously created between the RO and the CCF.44.A method performed by an apparatus for a common application programming interface framework, CAPIF, core function, CCF, comprising:generating a first challenge for authentication;transmitting to a user equipment, UE, an authentication request comprising the first challenge;receiving from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on the CCF, information on an application programming interface, API, exposing function, AEF, information on a resource owner, RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; andverifying the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.45.The method of claim 44, comprising:transmitting to the AEF, a request for the information on the RO; andreceiving from the AEF, the information on the RO and the information on the RO entity.46.The method of claim 44, comprising:receiving from the UE, a login request comprising at least one of the following: an identifier of the RO, or the information on the RO entity; andidentifying the identifier of the RO and the first public key.47.The method of any of claims 44 to 46, wherein the authentication request requests a web authentication, WebAuthn, based authentication.48.The method of any of claims 44 to 47, wherein the authentication request further comprises information on an API invoker.49.The method of claim 48, wherein the assertion further comprises the information on the API invoker signed with the first private key.50.The method of any of claims 44 to 49, comprising:receiving a registration request comprising at least one of the following: the information on the RO, information on authentication, the information on the AEF, or information on the RO entity;creating or updating for the RO, an account associated with at least one of the following: the RO, the RO entity, an authenticator, or the AEF;generating one or more second challenges;transmitting to the UE, a credential creation request comprising the one or more second challenges and the additional information; andreceiving from the UE, a credential creation response comprising the first public key and the additional information signed with a second private key of a second key pair comprising the second private key pair and a second public key of the authenticator before the registration.51.The method of claim 50, comprising:verifying the credential creation response using the second public key paired with the second private key; andstoring the first public key in case of successful verification.52.The method of claim 51, comprising:transmitting to the AEF, the first public key in case of successful verification.53.The method of any of claims 50 to 52, comprising:transmitting to the UE, a registration response comprising the information on the RO into which an identifier of the account of the RO is added.54.The method of any of claims 50 to 53, wherein the registration request further comprises an initial secret previously created between the RO and the CCF, and the method comprises:retrieve the information on the RO based on the initial secret.55.The method of any of claims 50 to 54, wherein the credential creation request requests a WebAuthn based credential creation.56.A method performed by an apparatus for an application programming interface, API, exposing function, AEF, comprising:generating a first challenge for authentication;transmitting to a user equipment, UE, an authentication request comprising the first challenge;receiving from the UE, an assertion comprising the first challenge and additional information signed with a first private key in a first key pair generated by an authenticator, the additional information comprising at least one of the following: information on a common application programming interface framework, CAPIF, core function, CCF, information on the AEF, information on a resource owner, RO, information on a RO entity of the UE, information on type of the authenticator, or information on mechanism of authentication; andverifying the assertion using a first public key paired with the first private key corresponding to a combination of the RO and the UE.57.The method of claim 56, comprising:receiving from an interface for the RO, a login request comprising at least one of the following: the information on the RO, or the information on the RO entity; andtransmitting to the interface for the RO, a notification of login in case of successful verification.58.The method of claim 56 or 57, wherein the authentication request requests a web authentication, WebAuthn, based authentication.59.An apparatus for a user equipment, UE, comprising means for performing the method of any of claims 30 to 43.60.An apparatus for a common application programming interface framework, CAPIF, core function, CCF, comprising means for performing the method of any of claims 44 to 55.61.An apparatus for an application programming interface, API, exposing function, AEF, comprising means for performing the method of any of claims 56 to 58.62.A computer-readable medium comprising program instructions that, when executed by an apparatus for a user equipment, UE, cause the apparatus to at least perform the method of any of claims 30 to 43.63.A computer-readable medium comprising program instructions that, when executed by an apparatus for a common application programming interface framework, CAPIF, core function, CCF, cause the apparatus to at least perform the method of any of claims 44 to 55.64.A computer-readable medium comprising program instructions that, when executed by an apparatus for an application programming interface, API, exposing function, AEF, cause the apparatus to at least perform the method of any of claims 56 to 58.