CAPIF API Invoker Authentication Using AKMA and TLS Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication technologies lack a solution for the Common API Framework (CAPIF) function to authenticate API invokers during the onboarding process, which is crucial for authorizing services.

Innovation Solution

An API invoker authentication method involving sending authentication information to the CAPIF function, establishing a TLS connection, and using AKMA anchor keys and certificates to verify the identity of the API invoker.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in CAPIF, then the system structure remains simple, but the API invoker cannot be authenticated during onboarding

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an AKMA anchor key as an intermediary authentication credential between the API invoker and CAPIF function. The AKMA anchor key serves as a mediator that enables mutual authentication without requiring complex certificate management or custom authentication protocols, thus resolving the contradiction between authentication capability and system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent leverages the existing AKMA framework, which was originally designed for UE authentication, and applies it universally to API invoker authentication in CAPIF. This multi-functional use of the AKMA mechanism allows the system to achieve reliable authentication without designing a separate authentication system, thereby maintaining relative simplicity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If no authentication mechanism is implemented, then the system remains simple and easy to operate, but security of API invoker identity cannot be ensured

Engineering Contradiction:
Improveidentity securityVSAvoidonboarding complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary authentication action during the onboarding phase by establishing TLS connection and exchanging AKMA credentials before any API services are provided. This preliminary security establishment ensures identity security is built into the system from the start rather than added later, addressing the security requirement without complicating operational processes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The API invoker autonomously performs authentication by presenting its AKMA anchor key and receiving verification from the CAPIF function. This self-service authentication mechanism eliminates the need for manual security configuration or complex administrative operations, thereby maintaining ease of operation while ensuring identity security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260039644A1API invoker authentication method and apparatus, communication device, and storage medium
Publication Date: 2026.02.05 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US20260039644A1 patent drawing
  • US20260039644A1 patent drawing
  • US20260039644A1 patent drawing

AI summary

A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.