Loading doc/diagrams/interconnection/01_Creation_of_Security_Context_Same_Vault.txt 0 → 100644 +77 −0 Changes for doc/diagrams/interconnection/01_Creation_of_Security_Context_Same_Vault.txt: 77 added lines, 0 removed lines. Original line number Diff line number Diff line title Invoker Requests creation of Security Context participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded end note Invoker->OpenCAPIF-A: PUT /capif-security/v1/trustedInvokers/{api_invoker_id} note over Invoker, OpenCAPIF-A { "notificationDestination": notification_destination, "supportedFeatures": supported_features, "securityInfo": [{ "aef_id": aef_id "api_id": api_id }] } end note note over OpenCAPIF-A Check if API belongs to other CCF end note alt API belongs to this CCF note over OpenCAPIF-A Check if api_invoker is valid. Check if there are a valid security method Select security method. IF PSK selected, derive PSK and store. Create ACL (api-invoker-id, api-id, aef-id) Store Service Security at DB with PSK updated if needed. end note OpenCAPIF-A-->Invoker: 201 Created note over OpenCAPIF-A, Invoker body with service Security with selSecurityMethod end note end alt alt API belongs to other CCF note over OpenCAPIF-A Check if api_invoker is valid. Check if there are a valid security method Select security method. IF PSK selected, derive PSK and store. Create ACL (api-invoker-id, api-id, aef-id) Store Service Security at DB with PSK updated if needed. end note OpenCAPIF-A->OpenCAPIF-B: PUT /capif-security/v1/trustedInvokers/{api_invoker_id} note over OpenCAPIF-A, OpenCAPIF-B body with securityService created on first request certificate used is OpenCAPIF-A end note note over OpenCAPIF-B If OpenCAPIF-A cert is used, avoid: - check it belongs to OpenCAPIF-A. - Store all information comming from OpenCAPIF-A for this security Context. - Create Acls - Add internal mapping between invoker and ccf_id. SecurityMethod was selected by OpenCAPIF-A and psk is derived also by OpenCAPIF-A Create ACL (api-invoker-id, api-id, aef-id) Store Service Security. end note OpenCAPIF-B-->OpenCAPIF-A: 201 Created OpenCAPIF-A-->Invoker: 201 Created note over OpenCAPIF-A, Invoker body with service Security with selSecurityMethod end note end alt Invoker->Invoker: Checks selSecurityMethod value doc/diagrams/interconnection/02_OAuth.txt 0 → 100644 +64 −0 Changes for doc/diagrams/interconnection/02_OAuth.txt: 64 added lines, 0 removed lines. Original line number Diff line number Diff line title Security Method OAUTH at interconnected OpenCAPIFs participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded Security Context Created end note Invoker->Invoker: Checks selSecurityMethod is OAUTH opt OAUTH Invoker->OpenCAPIF-A: POST /capif-security/v1/securities/{INVOKER_ID}/token note over Invoker,OpenCAPIF-A { "client_id": invoker_id, "grant_type": "client_credentials", "client_secret": "string", "scope": "3gpp#{api_aef_id}:{api_name}" } end note OpenCAPIF-A->OpenCAPIF-B: POST /capif-security/v1/securities/{INVOKER_ID}/token note over OpenCAPIF-A,OpenCAPIF-B { "client_id": invoker_id, "grant_type": "client_credentials", "client_secret": "string", "scope": "3gpp#{api_aef_id}:{api_name}" } end note OpenCAPIF-B-->OpenCAPIF-A: 200 OK note over OpenCAPIF-A, OpenCAPIF-B { "access_token": "string", "token_type": "Bearer", "expires_in": 0, "scope": "string" } end note OpenCAPIF-A-->Invoker: 200 OK note over OpenCAPIF-A, Invoker { "access_token": "string", "token_type": "Bearer", "expires_in": 0, "scope": "string" } end note Invoker->AEF Provider: Send Request to ServiceAPI note over Invoker, AEF Provider header includes Bearer TOKEN with obtained token from security service end note end opt doc/diagrams/interconnection/03_PKI.txt 0 → 100644 +97 −0 Changes for doc/diagrams/interconnection/03_PKI.txt: 97 added lines, 0 removed lines. Original line number Diff line number Diff line title Security Method PKI at interconnected OpenCAPIFs participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded Security Context created end note Invoker->Invoker: Checks selSecurityMethod is PKI Invoker->AEF Provider: POST {apiRoot}/aef-security/<api_version>/check-authentication note over Invoker, AEF Provider AEF_Security_API from 3GPP { "apiInvokerId": "INV1234567890", "supportedFeatures": "0" } end note opt AEF Provider request invoker credentials if needed AEF Provider->OpenCAPIF-B: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over AEF Provider, OpenCAPIF-B: authenticationInfo true authorization true end note OpenCAPIF-B->OpenCAPIF-A: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over OpenCAPIF-A,OpenCAPIF-B OpenCAPIF-B cert used authenticationInfo true authorization true end note OpenCAPIF-A-> OpenCAPIF-A: Check this requests comes from other OpenCAPIF note over OpenCAPIF-A authenticationInfo with OpenCAPIF-A CA end note OpenCAPIF-A-->OpenCAPIF-B: 200 OK note over OpenCAPIF-A, OpenCAPIF-B ServiceSecurity body with AuthenticationInfo end note OpenCAPIF-B-->AEF Provider: 200 OK note over OpenCAPIF-B,AEF Provider ServiceSecurity body with AuthenticationInfo end note end opt AEF Provider->AEF Provider: Check Security Method AEF Provider->AEF Provider: Store credentials note over AEF Provider: Extract and store ca_root from authenticationInfo inside securityInfo attribute and store to check invoker certificate. Store aefId and apiId (maybe all ServiceSecurity) end note AEF Provider->AEF Provider: Check if Invoker has authorization note over AEF Provider: check aefId belong to it check apiId belong to one exposed api of AEF provider end note opt Invoker Authorized AEF Provider->Invoker: 200 OK note over AEF Provider,Invoker { "supportedFeatures": "0" } end note end opt opt Invoker Unauthorized AEF Provider->Invoker: 401 Unauthorized note over AEF Provider,Invoker ProblemDetailsProblemDetails end note end opt Invoker->AEF Provider: Consume Service API note over Invoker,AEF Provider: Includes Invoker Certificate. end note note over AEF Provider: Check Invoker certificate with information provided by CCF (ca_root) Authorization check if API consumed is the one present in securityInformation end note doc/diagrams/interconnection/04_PSK.txt 0 → 100644 +102 −0 Changes for doc/diagrams/interconnection/04_PSK.txt: 102 added lines, 0 removed lines. Original line number Diff line number Diff line title Security Method PSK at interconnected OpenCAPIFs participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded Security Context created end note Invoker->Invoker: Checks selSecurityMethod is PSK Invoker->AEF Provider: POST {apiRoot}/aef-security/<api_version>/check-authentication note over Invoker, AEF Provider AEF_Security_API from 3GPP { "apiInvokerId": "INV1234567890", "supportedFeatures": "0" } end note opt AEF Provider request invoker credentials if needed AEF Provider->OpenCAPIF-B: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over AEF Provider, OpenCAPIF-B: authenticationInfo true authorization true end note OpenCAPIF-B->OpenCAPIF-A: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over OpenCAPIF-A,OpenCAPIF-B OpenCAPIF-B cert used authenticationInfo true authorization true end note OpenCAPIF-A-> OpenCAPIF-A: Check this requests comes from other OpenCAPIF note over OpenCAPIF-A authenticationInfo with OpenCAPIF-A CA end note OpenCAPIF-A-->OpenCAPIF-B: 200 OK note over OpenCAPIF-A, OpenCAPIF-B ServiceSecurity body with AuthenticationInfo and AuthorizationInfo end note OpenCAPIF-B-->AEF Provider: 200 OK note over OpenCAPIF-B,AEF Provider ServiceSecurity body with AuthenticationInfo and AuthorizationInfo end note end opt AEF Provider->AEF Provider: Check Security Method AEF Provider->AEF Provider: Store credentials note over AEF Provider: Store all Security Information. Store aefId and apiId (maybe all ServiceSecurity) authenticationInfo contains ca root to check certificate if it's present. authorizationInfo contains psk that will be used by Invoker end note AEF Provider->AEF Provider: Check if Invoker has authorization note over AEF Provider: check aefId belong to it check apiId belong to one exposed api of AEF provider end note opt Invoker Authorized AEF Provider->Invoker: 200 OK note over AEF Provider,Invoker { "supportedFeatures": "0" } end note end opt opt Invoker Unauthorized AEF Provider->Invoker: 401 Unauthorized note over AEF Provider,Invoker ProblemDetailsProblemDetails end note end opt Invoker->AEF Provider: Consume Service API note over Invoker,AEF Provider: PSK at Authorization header in request end note note over AEF Provider: Check Invoker authorization header includes PSK obtained Authorization check if API consumed is the one present in securityInformation end note note over Invoker,AEF Provider TLS communication end note doc/diagrams/interconnection/CAPIF_Interconnection_Establishment.txt 0 → 100644 +40 −0 Changes for doc/diagrams/interconnection/CAPIF_Interconnection_Establishment.txt: 40 added lines, 0 removed lines. Original line number Diff line number Diff line title CAPIF Interconnection Establishment participant Administrator participant "CCF-A" as A participant "CCF-B" as B Administrator->A: POST /helper/interconnection/request\n{dstProvDom: CCF-B} alt CCF-B already interconnected A-->Administrator: 409 already interconnected else new interconnection A->B: POST /helper/interconnection/establish\nCCF-A identity (ccfId, domain, CA, publicKey) B->B: store CCF-A as interconnected B-->A: CCF-B identity (ccfId, domain, CA, publicKey) A->A: store CCF-B as interconnected == Initial sync of already published APIs == A->B: POST /helper/interconnection/sync alt CCF-A is not interconnected B-->A: 404 else interconnected B->B: find local APIs shareable with CCF-A\n(isShareable=true, CCF-A in capifProvDoms) loop each matching API B->A: POST /published-apis/v1/{CCF-B}/service-apis\ncopy with isShareable=false A->A: store copy, record CCF-B in pubApiPath A-->B: 201 end B-->A: 201 end A->A: find local APIs shareable with CCF-B loop each matching API A->B: POST /published-apis/v1/{CCF-A}/service-apis\ncopy with isShareable=false B->B: store copy, record CCF-A in pubApiPath B-->A: 201 end A-->Administrator: 201 CCF-B details end No newline at end of file Loading
doc/diagrams/interconnection/01_Creation_of_Security_Context_Same_Vault.txt 0 → 100644 +77 −0 Changes for doc/diagrams/interconnection/01_Creation_of_Security_Context_Same_Vault.txt: 77 added lines, 0 removed lines. Original line number Diff line number Diff line title Invoker Requests creation of Security Context participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded end note Invoker->OpenCAPIF-A: PUT /capif-security/v1/trustedInvokers/{api_invoker_id} note over Invoker, OpenCAPIF-A { "notificationDestination": notification_destination, "supportedFeatures": supported_features, "securityInfo": [{ "aef_id": aef_id "api_id": api_id }] } end note note over OpenCAPIF-A Check if API belongs to other CCF end note alt API belongs to this CCF note over OpenCAPIF-A Check if api_invoker is valid. Check if there are a valid security method Select security method. IF PSK selected, derive PSK and store. Create ACL (api-invoker-id, api-id, aef-id) Store Service Security at DB with PSK updated if needed. end note OpenCAPIF-A-->Invoker: 201 Created note over OpenCAPIF-A, Invoker body with service Security with selSecurityMethod end note end alt alt API belongs to other CCF note over OpenCAPIF-A Check if api_invoker is valid. Check if there are a valid security method Select security method. IF PSK selected, derive PSK and store. Create ACL (api-invoker-id, api-id, aef-id) Store Service Security at DB with PSK updated if needed. end note OpenCAPIF-A->OpenCAPIF-B: PUT /capif-security/v1/trustedInvokers/{api_invoker_id} note over OpenCAPIF-A, OpenCAPIF-B body with securityService created on first request certificate used is OpenCAPIF-A end note note over OpenCAPIF-B If OpenCAPIF-A cert is used, avoid: - check it belongs to OpenCAPIF-A. - Store all information comming from OpenCAPIF-A for this security Context. - Create Acls - Add internal mapping between invoker and ccf_id. SecurityMethod was selected by OpenCAPIF-A and psk is derived also by OpenCAPIF-A Create ACL (api-invoker-id, api-id, aef-id) Store Service Security. end note OpenCAPIF-B-->OpenCAPIF-A: 201 Created OpenCAPIF-A-->Invoker: 201 Created note over OpenCAPIF-A, Invoker body with service Security with selSecurityMethod end note end alt Invoker->Invoker: Checks selSecurityMethod value
doc/diagrams/interconnection/02_OAuth.txt 0 → 100644 +64 −0 Changes for doc/diagrams/interconnection/02_OAuth.txt: 64 added lines, 0 removed lines. Original line number Diff line number Diff line title Security Method OAUTH at interconnected OpenCAPIFs participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded Security Context Created end note Invoker->Invoker: Checks selSecurityMethod is OAUTH opt OAUTH Invoker->OpenCAPIF-A: POST /capif-security/v1/securities/{INVOKER_ID}/token note over Invoker,OpenCAPIF-A { "client_id": invoker_id, "grant_type": "client_credentials", "client_secret": "string", "scope": "3gpp#{api_aef_id}:{api_name}" } end note OpenCAPIF-A->OpenCAPIF-B: POST /capif-security/v1/securities/{INVOKER_ID}/token note over OpenCAPIF-A,OpenCAPIF-B { "client_id": invoker_id, "grant_type": "client_credentials", "client_secret": "string", "scope": "3gpp#{api_aef_id}:{api_name}" } end note OpenCAPIF-B-->OpenCAPIF-A: 200 OK note over OpenCAPIF-A, OpenCAPIF-B { "access_token": "string", "token_type": "Bearer", "expires_in": 0, "scope": "string" } end note OpenCAPIF-A-->Invoker: 200 OK note over OpenCAPIF-A, Invoker { "access_token": "string", "token_type": "Bearer", "expires_in": 0, "scope": "string" } end note Invoker->AEF Provider: Send Request to ServiceAPI note over Invoker, AEF Provider header includes Bearer TOKEN with obtained token from security service end note end opt
doc/diagrams/interconnection/03_PKI.txt 0 → 100644 +97 −0 Changes for doc/diagrams/interconnection/03_PKI.txt: 97 added lines, 0 removed lines. Original line number Diff line number Diff line title Security Method PKI at interconnected OpenCAPIFs participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded Security Context created end note Invoker->Invoker: Checks selSecurityMethod is PKI Invoker->AEF Provider: POST {apiRoot}/aef-security/<api_version>/check-authentication note over Invoker, AEF Provider AEF_Security_API from 3GPP { "apiInvokerId": "INV1234567890", "supportedFeatures": "0" } end note opt AEF Provider request invoker credentials if needed AEF Provider->OpenCAPIF-B: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over AEF Provider, OpenCAPIF-B: authenticationInfo true authorization true end note OpenCAPIF-B->OpenCAPIF-A: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over OpenCAPIF-A,OpenCAPIF-B OpenCAPIF-B cert used authenticationInfo true authorization true end note OpenCAPIF-A-> OpenCAPIF-A: Check this requests comes from other OpenCAPIF note over OpenCAPIF-A authenticationInfo with OpenCAPIF-A CA end note OpenCAPIF-A-->OpenCAPIF-B: 200 OK note over OpenCAPIF-A, OpenCAPIF-B ServiceSecurity body with AuthenticationInfo end note OpenCAPIF-B-->AEF Provider: 200 OK note over OpenCAPIF-B,AEF Provider ServiceSecurity body with AuthenticationInfo end note end opt AEF Provider->AEF Provider: Check Security Method AEF Provider->AEF Provider: Store credentials note over AEF Provider: Extract and store ca_root from authenticationInfo inside securityInfo attribute and store to check invoker certificate. Store aefId and apiId (maybe all ServiceSecurity) end note AEF Provider->AEF Provider: Check if Invoker has authorization note over AEF Provider: check aefId belong to it check apiId belong to one exposed api of AEF provider end note opt Invoker Authorized AEF Provider->Invoker: 200 OK note over AEF Provider,Invoker { "supportedFeatures": "0" } end note end opt opt Invoker Unauthorized AEF Provider->Invoker: 401 Unauthorized note over AEF Provider,Invoker ProblemDetailsProblemDetails end note end opt Invoker->AEF Provider: Consume Service API note over Invoker,AEF Provider: Includes Invoker Certificate. end note note over AEF Provider: Check Invoker certificate with information provided by CCF (ca_root) Authorization check if API consumed is the one present in securityInformation end note
doc/diagrams/interconnection/04_PSK.txt 0 → 100644 +102 −0 Changes for doc/diagrams/interconnection/04_PSK.txt: 102 added lines, 0 removed lines. Original line number Diff line number Diff line title Security Method PSK at interconnected OpenCAPIFs participant Invoker participant OpenCAPIF-A participant OpenCAPIF-B participant AEF Provider note over Invoker, OpenCAPIF-A, OpenCAPIF-B, AEF Provider CCFs interconnected Provider register waith API published Invoker onboarded Security Context created end note Invoker->Invoker: Checks selSecurityMethod is PSK Invoker->AEF Provider: POST {apiRoot}/aef-security/<api_version>/check-authentication note over Invoker, AEF Provider AEF_Security_API from 3GPP { "apiInvokerId": "INV1234567890", "supportedFeatures": "0" } end note opt AEF Provider request invoker credentials if needed AEF Provider->OpenCAPIF-B: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over AEF Provider, OpenCAPIF-B: authenticationInfo true authorization true end note OpenCAPIF-B->OpenCAPIF-A: GET {apiRoot}/capif-security/<apiVersion>/trustedInvokers/{apiInvokerId} note over OpenCAPIF-A,OpenCAPIF-B OpenCAPIF-B cert used authenticationInfo true authorization true end note OpenCAPIF-A-> OpenCAPIF-A: Check this requests comes from other OpenCAPIF note over OpenCAPIF-A authenticationInfo with OpenCAPIF-A CA end note OpenCAPIF-A-->OpenCAPIF-B: 200 OK note over OpenCAPIF-A, OpenCAPIF-B ServiceSecurity body with AuthenticationInfo and AuthorizationInfo end note OpenCAPIF-B-->AEF Provider: 200 OK note over OpenCAPIF-B,AEF Provider ServiceSecurity body with AuthenticationInfo and AuthorizationInfo end note end opt AEF Provider->AEF Provider: Check Security Method AEF Provider->AEF Provider: Store credentials note over AEF Provider: Store all Security Information. Store aefId and apiId (maybe all ServiceSecurity) authenticationInfo contains ca root to check certificate if it's present. authorizationInfo contains psk that will be used by Invoker end note AEF Provider->AEF Provider: Check if Invoker has authorization note over AEF Provider: check aefId belong to it check apiId belong to one exposed api of AEF provider end note opt Invoker Authorized AEF Provider->Invoker: 200 OK note over AEF Provider,Invoker { "supportedFeatures": "0" } end note end opt opt Invoker Unauthorized AEF Provider->Invoker: 401 Unauthorized note over AEF Provider,Invoker ProblemDetailsProblemDetails end note end opt Invoker->AEF Provider: Consume Service API note over Invoker,AEF Provider: PSK at Authorization header in request end note note over AEF Provider: Check Invoker authorization header includes PSK obtained Authorization check if API consumed is the one present in securityInformation end note note over Invoker,AEF Provider TLS communication end note
doc/diagrams/interconnection/CAPIF_Interconnection_Establishment.txt 0 → 100644 +40 −0 Changes for doc/diagrams/interconnection/CAPIF_Interconnection_Establishment.txt: 40 added lines, 0 removed lines. Original line number Diff line number Diff line title CAPIF Interconnection Establishment participant Administrator participant "CCF-A" as A participant "CCF-B" as B Administrator->A: POST /helper/interconnection/request\n{dstProvDom: CCF-B} alt CCF-B already interconnected A-->Administrator: 409 already interconnected else new interconnection A->B: POST /helper/interconnection/establish\nCCF-A identity (ccfId, domain, CA, publicKey) B->B: store CCF-A as interconnected B-->A: CCF-B identity (ccfId, domain, CA, publicKey) A->A: store CCF-B as interconnected == Initial sync of already published APIs == A->B: POST /helper/interconnection/sync alt CCF-A is not interconnected B-->A: 404 else interconnected B->B: find local APIs shareable with CCF-A\n(isShareable=true, CCF-A in capifProvDoms) loop each matching API B->A: POST /published-apis/v1/{CCF-B}/service-apis\ncopy with isShareable=false A->A: store copy, record CCF-B in pubApiPath A-->B: 201 end B-->A: 201 end A->A: find local APIs shareable with CCF-B loop each matching API A->B: POST /published-apis/v1/{CCF-A}/service-apis\ncopy with isShareable=false B->B: store copy, record CCF-A in pubApiPath B-->A: 201 end A-->Administrator: 201 CCF-B details end No newline at end of file