IP Library Granted Patent US 11,303,676
Granted Patent B2
US 11,303,676 · App. 16/192,069 · Granted Apr 12, 2022

Method and system for authenticating application program interface (API) invokers

Inventors: Rajavelsamy Rajadurai (Bangalore, IN); Narendranath Durga Tangudu (Bangalore, IN); Nishant Gupta (Bangalore, IN)
Assignee: Samsung Electronics Co., Ltd.
H04L63/166G06F9/54H04L63/0823H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,303,676
App. No.
16/192,069
Granted
Apr 12, 2022
Kind
B2
Abstract

A method and system for authenticating application program interface (API) invokers using a common application program interface framework (CAPIF) is provided. The method includes establishing by a CAPIF core function (CCF) a secure Transport Layers Security (TLS) connection with at least one API invoker, on receiving a connection request from the at least one API invoker to access at least one service API on a CAPIF-2e interface. Further, the method includes determining by the CCF at least one security method to be used by the at least one API invoker for a CAPIF-2e interface security (C2eIS) of the at least one API invoker for accessing the at least one service API on a CAPIF-2e interface. The method further includes enabling the C2eIS by an API exposing function (AEF) the at least one API invoker based on the determined at least one security method.

Claims (36)

1. A method performed by a first entity implementing a common application program interface framework (CAPIF) core function (CCF) in a communication system, the method comprising:

establishing a session with a second entity implementing an authenticating application program interface (API) invoker using a transport layers security (TLS);

receiving, from the second entity, a security method request message including information on a security method for a third entity implementing an API exposing function (AEF);

identifying the security method for authentication between the second entity and the third entity from at least one of a TLS-pre-shared key (TLS-PSK), a TLS-public key infrastructure (TLS-PKI), or an OAuth 2.0 based on the information on the security method and an access scenario; and

transmitting, to the second entity, the security method and security information associated with the security method,

wherein the access scenario indicates whether the second entity accesses the third entity prior to service API invocation, and

wherein the security method is used to provide an interface authentication and protection of the second entity.

2. The method of claim 1 , wherein a capability of the second entity is further used to determine the security method.

3. A method performed by a second entity implementing an authenticating application program interface (API) invoker in a communication system, the method comprising:

establishing a session with a first entity implementing a common application program interface framework (CAPIF) core function (CCF) using a transport layers security (TLS);

transmitting, to the first entity, a security method request message including information on a security method for a third entity implementing an API exposing function (AEF); and

receiving, from the first entity, the security method for authentication between the second entity and the third entity, and security information associated with the security method,

wherein the security method is identified from at least one of a TLS-pre-shared key (TLS-PSK), a TLS-public key infrastructure (TLS-PKI), or an OAuth 2.0 based on the information on the security method and an access scenario,

wherein the access scenario indicates whether the second entity accesses the third entity prior to service API invocation, and

wherein the security method is used to provide an interface authentication and protection of the second entity.

4. The method of claim 3 , wherein a capability of the second entity is further used to determine the security method.

5. A first entity implementing a common application program interface framework (CAPIF) core function (CCF) in a communication system, the first entity comprising:

a transceiver; and

at least one processor configured to:

establish a session with a second entity implementing an authenticating application program interface (API) invoker using a transport layers security (TLS),

receive, via the transceiver from the second entity, a security method request message including information on a security method for a third entity implementing an API exposing function,

identify the security method for authentication between the second entity and the third entity from at least one of a TLS-pre-shared key (TLS-PSK), a TLS-public key infrastructure (TLS-PKI), or an OAuth 2.0 based on the information on the security method and an access scenario, and

transmit, via the transceiver to the second entity, the security method and security information associated with the security method,

wherein the access scenario indicates whether the second entity accesses the third entity prior to service API invocation, and

wherein the security method is used to provide an interface authentication and protection of the second entity.

6. The first entity of claim 5 , wherein a capability of the second entity is further used to determine the security method.

7. A second entity implementing an authenticating application program interface (API) invoker in a communication system, the second entity comprising:

a transceiver; and

at least one processor configured to:

establish a session with a first entity implementing a common application program interface framework (CAPIF) core function (CCF) using a transport layers security (TLS),

transmit, via the transceiver to the first entity, a security method request message including information on a security method for a third entity implementing an API exposing function (AEF), and

receive, via the transceiver from the first entity, the security method for authentication between the second entity and the third entity, and security information associated with the security method,

wherein the security method is identified from at least one of a TLS-pre-shared key (TLS-PSK), a TLS-public key infrastructure (TLS-PKI), or an OAuth 2.0 based on the information on the security method and an access scenario,

wherein the access scenario indicates whether the second entity accesses the third entity prior to service API invocation, and

wherein the security method is used to provide an interface authentication and protection of the second entity.

8. The second entity of claim 7 , wherein a capability of the second entity is further used to determine the security method.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2018
From: RAJADURAI, RAJAVELSAMY; TANGUDU, NARENDRANATH DURGA; GUPTA, NISHANT
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 047516/0010 →
Priority Claims (2)
IN 201741041088 · Nov 16, 2017 · national
IN 201741041088 · Nov 5, 2018 · national
Continuity (1)
Related Publication 20190149576A1 · May 16, 2019