IP Library Granted Patent US 12706897
Granted Patent B2
US 12706897 · App. 18/688,578 · Granted Aug 11, 2026

Method, apparatus, and computer program

Inventors: Jing Ping (Chengdu, CN); Anatoly Andrianov (Naperville, IL)
Assignee: Nokia Technologies Oy
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706897
App. No.
18/688,578
Granted
Aug 11, 2026
Kind
B2
Abstract

An apparatus comprises means configured to: receive an authentication request from a management service consumer, the request comprising at least an identifier associated with an identity of the management service consumer and a credential used by the identity; and authenticate the management service consumer in dependence on the request, said authentication being dependent on one or more authentication policies associated with the management service consumer, different types of management service consumers being associated with one or more different authentication policies.

Claims (38)

1 . An apparatus comprising:

one or more processors, and memory storing instructions that, when executed by the one or more processors, cause the apparatus to:

receive an authentication request from a management service consumer, the request comprising at least an identifier associated with an identity of the management service consumer and a credential used by the identity, wherein the request further comprises context information and information identifying a client;

receive a second request, the second request comprising at least one of:

authentication information about an authentication policy, the second request being one of a request to read the authentication policy, a request to create the authentication policy, a request to delete the authentication policy, and a request to update the authentication policy,

group information about a group of one or more management service entities, the second request being one of a request to read the group information, a request to create the group, a request to delete the group, and a request to update the group, or

identity information about the management service consumer or a management service producer, the second request being one of a request to read the identity information, a request to create an identity, a request to delete the identity, and a request to update the identity;

authenticate the management service consumer in dependence on the request, said authentication being dependent on the one or more authentication policies associated with the management service consumer, different types of management service consumers being associated with one or more different authentication policies; and

provide an authentication assertion in response to a successful authentication comprising providing a response to the management service consumer indicating a successful authentication with the authentication assertion.

2 . The apparatus as claimed in claim 1 , wherein the request further comprises information identifying an application associated with the management service consumer.

3 . The apparatus as claimed in claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to obtain from a data store information associated with the identifier of the management service consumer and use the obtained information to authenticate the management service consumer.

4 . The apparatus as claimed in in claim 3 , wherein the instructions, when executed by the one or more processors, cause the apparatus to cause an update of an authentication status of the management service consumer in response to a successful authentication.

5 . The apparatus as claimed in in claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to receive an authentication policy request, the authentication policy request comprising information about an authentication policy.

6 . The apparatus as claimed in claim 5 , wherein the information about the authentication policy comprises at least one or more of: one or more authentication factors, or one or more authentication protocols.

7 . The apparatus as claimed in claim 1 , wherein one or more authentication policies associated with the management service consumer are provided in the request and/or are stored in a data store.

8 . The apparatus as claimed in claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to:

one of read, update, create, and delete the authentication policy in dependence on the second request.

9 . The apparatus as claimed in claim 8 , wherein the information about the authentication policy comprises at least one or more of: one or more authentication factor, authentication protocol, credential policy, and one or more authentication context parameters.

10 . The apparatus as claimed in claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to:

one of read, update, create, and delete information about the group in dependence on the second request.

11 . The apparatus as claimed in claim 10 , wherein the management service entities comprise management service consumers or management service producers.

12 . The apparatus as claimed in claim 10 , wherein the instructions, when executed by the one or more processors, cause the apparatus to cause an update when the group is updated, created, or deleted.

13 . The apparatus as claimed in claim 10 , wherein the instructions, when executed by the one or more processors, cause the apparatus to provide a group response comprising information about the group.

14 . The apparatus as claimed in claim 13 , wherein the group response comprises at least one or more identities and/or number of identities associated with the group.

15 . The apparatus as claimed in claim 10 , wherein the group information comprises at least one or more of: a state of the group, a type of the group, an owner of the group, a domain of the group, one or more authentication policies of the group, and a role of the group.

16 . The apparatus as claimed in claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to:

one of read, update, create, and delete information about the identity in dependence on the second request.

17 . The apparatus as claimed in claim 16 , wherein the identity information comprises at least one or more of: an identifier of the identity, a type of the identifier, a type of the identity, a state of the identity, a status of the identity, an owner of the identity, a domain of the identity, and a group of the identity.

18 . The apparatus as claimed in claim 16 , wherein the instructions, when executed by the one or more processors, cause the apparatus to associate the identity to one or more default group in response to a create request if no group information is provided in the create request.

19 . The apparatus as claimed in claim 16 , wherein the instructions, when executed by the one or more processors, cause the apparatus to cause updating of one or more groups in data store to add the identity to or delete the identity from an identity list of a respective group in dependence on the request.

20 . An apparatus comprising:

one or more processors, and memory storing instructions that, when executed by the one or more processors, cause the apparatus to:

cause an authentication request to be sent to authentication service producer, the request comprising at least an identifier associated with an identity of a management service consumer and a credential used by the identity, wherein the request further comprises context information and information identifying a client;

send a second request, the second request comprising at least one of:

authentication information about an authentication policy, the second request being one of a request to read the authentication policy, a request to create the authentication policy, a request to delete the authentication policy, and a request to update the authentication policy,

group information about a group of one or more management service entities, the second request being one of a request to read the group information, a request to create the group, a request to delete the group, and a request to update the group, or

identity information about the management service consumer or a management service producer, the second request being one of a request to read the identity information, a request to create an identity, a request to delete the identity, and a request to update the identity; and

receive a response to the authentication request from the authentication service producer, said authentication being dependent on the one or more authentication policies associated with the management service consumer, different types of management service consumers being associated with one or more different authentication policies, further comprising receiving an authentication assertion in response to a successful authentication comprising receiving a response from the authentication service producer indicating a successful authentication with the authentication assertion.