Commit 5786f545 authored by Jorge Moratinos's avatar Jorge Moratinos
Browse files

Adding texts files with diagrams related with Security Context at Interconnection

parent 6a36ad31
Loading
Loading
Loading
Loading
+77 −0
Changes for doc/diagrams/interconnection/01_Creation_of_Security_Context_Same_Vault.txt: 77 added lines, 0 removed lines.
Original line number Diff line number Diff line
title Invoker Requests creation of Security Context

participant Invoker
participant OpenCAPIF-A
participant OpenCAPIF-B
participant AEF Provider

note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider
CCFs interconnected
Provider register waith API published
Invoker onboarded
end note

Invoker->OpenCAPIF-A: PUT /capif-security/v1/trustedInvokers/{api_invoker_id}
note over Invoker, OpenCAPIF-A
{
"notificationDestination": notification_destination,
"supportedFeatures": supported_features,
"securityInfo": [{
"aef_id": aef_id
"api_id": api_id
}]
}
end note

note over OpenCAPIF-A
Check if API belongs to other CCF
end note

alt API belongs to this CCF
note over OpenCAPIF-A
Check if api_invoker is valid.
Check if there are a valid security method
Select security method. IF PSK selected, derive PSK and store.
Create ACL (api-invoker-id, api-id, aef-id)
Store Service Security at DB with PSK updated if needed.
end note
OpenCAPIF-A-->Invoker: 201 Created
note over OpenCAPIF-A, Invoker
body with service Security with selSecurityMethod
end note
end alt

alt API belongs to other CCF
note over OpenCAPIF-A
Check if api_invoker is valid.
Check if there are a valid security method
Select security method. IF PSK selected, derive PSK and store.
Create ACL (api-invoker-id, api-id, aef-id)
Store Service Security at DB with PSK updated if needed.
end note

OpenCAPIF-A->OpenCAPIF-B: PUT /capif-security/v1/trustedInvokers/{api_invoker_id}
note over OpenCAPIF-A, OpenCAPIF-B
body with securityService created on first request
certificate used is OpenCAPIF-A
end note

note over OpenCAPIF-B
If OpenCAPIF-A cert is used, avoid:
- check it belongs to OpenCAPIF-A.
- Store all information comming from OpenCAPIF-A for this security Context.
- Create Acls
- Add internal mapping between invoker and ccf_id.
SecurityMethod was selected by OpenCAPIF-A and psk is derived also by OpenCAPIF-A

Create ACL (api-invoker-id, api-id, aef-id)
Store Service Security.
end note
OpenCAPIF-B-->OpenCAPIF-A: 201 Created
OpenCAPIF-A-->Invoker: 201 Created
note over OpenCAPIF-A, Invoker
body with service Security with selSecurityMethod
end note
end alt

Invoker->Invoker: Checks selSecurityMethod value
+64 −0
Changes for doc/diagrams/interconnection/02_OAuth.txt: 64 added lines, 0 removed lines.
Original line number Diff line number Diff line
title Security Method OAUTH at interconnected OpenCAPIFs

participant Invoker
participant OpenCAPIF-A
participant OpenCAPIF-B
participant AEF Provider

note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider
CCFs interconnected
Provider register waith API published
Invoker onboarded
Security Context Created
end note

Invoker->Invoker: Checks selSecurityMethod is OAUTH

opt OAUTH
Invoker->OpenCAPIF-A: POST /capif-security/v1/securities/{INVOKER_ID}/token
note over Invoker,OpenCAPIF-A
{
"client_id": invoker_id,
"grant_type": "client_credentials",
"client_secret": "string",
"scope": "3gpp#{api_aef_id}:{api_name}"
}
end note

OpenCAPIF-A->OpenCAPIF-B: POST /capif-security/v1/securities/{INVOKER_ID}/token
note over OpenCAPIF-A,OpenCAPIF-B
{
"client_id": invoker_id,
"grant_type": "client_credentials",
"client_secret": "string",
"scope": "3gpp#{api_aef_id}:{api_name}"
}
end note
OpenCAPIF-B-->OpenCAPIF-A: 200 OK
note over OpenCAPIF-A, OpenCAPIF-B
{
  "access_token": "string",
  "token_type": "Bearer",
  "expires_in": 0,
  "scope": "string"
}
end note

OpenCAPIF-A-->Invoker: 200 OK
note over OpenCAPIF-A, Invoker
{
  "access_token": "string",
  "token_type": "Bearer",
  "expires_in": 0,
  "scope": "string"
}
end note


Invoker->AEF Provider: Send Request to ServiceAPI
note over Invoker, AEF Provider
header includes Bearer TOKEN with obtained token from security service
end note

end opt
+97 −0
Changes for doc/diagrams/interconnection/03_PKI.txt: 97 added lines, 0 removed lines.
Original line number Diff line number Diff line
title Security Method PKI at interconnected OpenCAPIFs

participant Invoker
participant OpenCAPIF-A
participant OpenCAPIF-B
participant AEF Provider

note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider
CCFs interconnected
Provider register waith API published
Invoker onboarded
Security Context created
end note

Invoker->Invoker: Checks selSecurityMethod is PKI

Invoker->AEF Provider: POST {apiRoot}/aef-security/<api_version>/check-authentication
note over Invoker, AEF Provider
AEF_Security_API from 3GPP
{
"apiInvokerId": "INV1234567890",
"supportedFeatures": "0"
}
end note

opt AEF Provider request invoker credentials if needed
AEF Provider->OpenCAPIF-B: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId}
note over AEF Provider, OpenCAPIF-B:
authenticationInfo true
authorization true
end note

OpenCAPIF-B->OpenCAPIF-A: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId}
note over OpenCAPIF-A,OpenCAPIF-B
OpenCAPIF-B cert used
authenticationInfo true
authorization true
end note

OpenCAPIF-A-> OpenCAPIF-A: Check this requests comes from other OpenCAPIF
note over OpenCAPIF-A
authenticationInfo with OpenCAPIF-A CA 
end note

OpenCAPIF-A-->OpenCAPIF-B: 200 OK
note over OpenCAPIF-A, OpenCAPIF-B
ServiceSecurity body with AuthenticationInfo
end note

OpenCAPIF-B-->AEF Provider: 200 OK
note over OpenCAPIF-B,AEF Provider
ServiceSecurity body with AuthenticationInfo
end note
end opt

AEF Provider->AEF Provider: Check Security Method
AEF Provider->AEF Provider: Store credentials

note over AEF Provider:
Extract and store ca_root from authenticationInfo inside securityInfo attribute 
and store to check invoker certificate.
Store aefId and apiId (maybe all ServiceSecurity)
end note

AEF Provider->AEF Provider: Check if Invoker has authorization
note over AEF Provider:
check aefId belong to it 
check apiId belong to one exposed api of AEF provider
end note

opt Invoker Authorized
AEF Provider->Invoker: 200 OK
note over AEF Provider,Invoker
{
"supportedFeatures": "0"
}
end note
end opt

opt Invoker Unauthorized
AEF Provider->Invoker: 401 Unauthorized
note over AEF Provider,Invoker
ProblemDetailsProblemDetails
end note
end opt

Invoker->AEF Provider: Consume Service API
note over Invoker,AEF Provider:
Includes Invoker Certificate.

end note
note over AEF Provider:
Check Invoker certificate with information provided by CCF (ca_root)
Authorization check if API consumed is the one present in securityInformation
end note

+102 −0
Changes for doc/diagrams/interconnection/04_PSK.txt: 102 added lines, 0 removed lines.
Original line number Diff line number Diff line
title Security Method PSK at interconnected OpenCAPIFs

participant Invoker
participant OpenCAPIF-A
participant OpenCAPIF-B
participant AEF Provider

note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider
CCFs interconnected
Provider register waith API published
Invoker onboarded
Security Context created
end note

Invoker->Invoker: Checks selSecurityMethod is PSK

Invoker->AEF Provider: POST {apiRoot}/aef-security/<api_version>/check-authentication
note over Invoker, AEF Provider
AEF_Security_API from 3GPP
{
"apiInvokerId": "INV1234567890",
"supportedFeatures": "0"
}
end note

opt AEF Provider request invoker credentials if needed
AEF Provider->OpenCAPIF-B: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId}
note over AEF Provider, OpenCAPIF-B:
authenticationInfo true
authorization true
end note

OpenCAPIF-B->OpenCAPIF-A: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId}
note over OpenCAPIF-A,OpenCAPIF-B
OpenCAPIF-B cert used
authenticationInfo true
authorization true
end note

OpenCAPIF-A-> OpenCAPIF-A: Check this requests comes from other OpenCAPIF
note over OpenCAPIF-A
authenticationInfo with OpenCAPIF-A CA 
end note

OpenCAPIF-A-->OpenCAPIF-B: 200 OK
note over OpenCAPIF-A, OpenCAPIF-B
ServiceSecurity body with AuthenticationInfo and AuthorizationInfo
end note

OpenCAPIF-B-->AEF Provider: 200 OK
note over OpenCAPIF-B,AEF Provider
ServiceSecurity body with AuthenticationInfo and AuthorizationInfo
end note
end opt

AEF Provider->AEF Provider: Check Security Method
AEF Provider->AEF Provider: Store credentials

note over AEF Provider:
Store all Security Information.
Store aefId and apiId (maybe all ServiceSecurity)
authenticationInfo contains ca root to check certificate if it's present.
authorizationInfo contains psk that will be used by Invoker
end note


AEF Provider->AEF Provider: Check if Invoker has authorization
note over AEF Provider:
check aefId belong to it 
check apiId belong to one exposed api of AEF provider
end note

opt Invoker Authorized
AEF Provider->Invoker: 200 OK
note over AEF Provider,Invoker
{
"supportedFeatures": "0"
}
end note
end opt

opt Invoker Unauthorized
AEF Provider->Invoker: 401 Unauthorized
note over AEF Provider,Invoker
ProblemDetailsProblemDetails
end note
end opt

Invoker->AEF Provider: Consume Service API
note over Invoker,AEF Provider:
PSK at Authorization header in request

end note
note over AEF Provider:
Check Invoker authorization header includes PSK obtained
Authorization check if API consumed is the one present in securityInformation
end note
note over Invoker,AEF Provider
TLS communication
end note