3GPP 23.369 v20.0.0 — the document's own text
5.6 AF authorization for AIoT Services
The information needed to support the authorization of the AF for AIoT services is stored as the authorization data for 3rd party AF in the ADM, or locally configured in the AIOTF.
Table 5.6-1 below describes items stored as AF authorization data for the AIoT.
Table 5.6-1: AF Authorization Data for AIoT
| AF Authorization Data | Description |
|---|---|
| AF ID | Identifier used to identify the AF. |
| Allowed area | Indicate the allowed area for the indicated AF to request the AIoT services. |
| Allowed service operations | Indicate the allowed service operation(s) for the indicated AF, e.g. inventory, read, write, permanent disable, subscribe to uplink application container transfer. |
| Allowed target AIoT Devices | Indicate the allowed AIoT Device(s) for the indicated AF. The information indicating the allowed target AIoT Devices is a list of the permanent AIoT Device ID (see clause 5.7) or the filtering information (see clause 5.8). |
The authorization of the AF for AIoT services includes two parts:
- NEF performs AIoT AF request authorization based on the service level agreement (SLA) between the 3rd party AF and the 5GS of the mobile network operator, the operator policy and local configuration as in TS 33.501 [8].
- AIOTF may perform authorization of AIoT service requested by the AF, using the AF authorization data retrieved from the ADM or configured locally as described in above Table 5.6-1. When an ADM is used, the AIOTF also subscribes to changes of AF authorization data in the ADM for synchronization.