CAPIF API Invoker Authentication Using AKMA and TLS Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication technologies lack a solution for the Common API Framework (CAPIF) function to authenticate API invokers during the onboarding process, which is crucial for authorizing services.
Innovation Solution
An API invoker authentication method involving sending authentication information to the CAPIF function, establishing a TLS connection, and using AKMA anchor keys and certificates to verify the identity of the API invoker.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in CAPIF, then the system structure remains simple, but the API invoker cannot be authenticated during onboarding
Solution Approach 1:
The patent introduces an AKMA anchor key as an intermediary authentication credential between the API invoker and CAPIF function. The AKMA anchor key serves as a mediator that enables mutual authentication without requiring complex certificate management or custom authentication protocols, thus resolving the contradiction between authentication capability and system complexity
Solution Approach 2:
The patent leverages the existing AKMA framework, which was originally designed for UE authentication, and applies it universally to API invoker authentication in CAPIF. This multi-functional use of the AKMA mechanism allows the system to achieve reliable authentication without designing a separate authentication system, thereby maintaining relative simplicity
2Reliability
If no authentication mechanism is implemented, then the system remains simple and easy to operate, but security of API invoker identity cannot be ensured
Solution Approach 1:
The patent implements preliminary authentication action during the onboarding phase by establishing TLS connection and exchanging AKMA credentials before any API services are provided. This preliminary security establishment ensures identity security is built into the system from the start rather than added later, addressing the security requirement without complicating operational processes
Solution Approach 2:
The API invoker autonomously performs authentication by presenting its AKMA anchor key and receiving verification from the CAPIF function. This self-service authentication mechanism eliminates the need for manual security configuration or complex administrative operations, thereby maintaining ease of operation while ensuring identity security
Data Source
AI summary
A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.


