oneM2M标准实现疑问:向MN-CSE注册AE时ACPI如何获取
Great question—this is one of those "hidden setup details" that’s easy to overlook when diving into oneM2M’s application registration flow! Let’s walk through the most practical ways an ADN-AE-1 would get the required ACPI (Access Control Policy ID):
Pre-Configuration (Most Common)
In nearly all production oneM2M deployments, the ACPI is pre-set in the AE before it ever connects to the CSE. For yourlight_ae1example:- The smart light’s manufacturer would hardcode the MN-CSE’s default or device-specific ACPI into the AE’s firmware.
- Enterprise devices might get the ACPI via an onboarding tool (e.g., a local web UI or out-of-band provisioning) during setup.
This is the standard approach because the AE needs to know its access rules upfront to interact with the CSE securely.
Query the MN-CSE’s Default ACP
If pre-configuration isn’t feasible, the AE can first send a GET request to fetch the MN-CSE’s default Access Control Policy (ACP) resource. Here’s a stripped-down example:GET /home_gateway/ACP-default?rcn=0 HTTP/1.1 Host: mn.provider.com:8080 X-M2M-Origin: C X-M2M-RI: mncse-78901The CSE’s response will include the
acpivalue of the default ACP, which the AE can then plug into its registration POST request.Dynamic Resource Discovery
For flexible deployments, the AE can use oneM2M’s built-in resource discovery to find suitable ACP resources. It sends a discovery request targeting ACP resources (ty=1) that allow registration access, then extracts the ACPI from the matching resource in the response.
A Quick Side Note
If your registration request omitted the ACPI entirely, the MN-CSE would automatically assign its default ACP to the new AE. But including an explicit ACPI lets you enforce custom access policies right from the moment the AE is registered.
内容的提问来源于stack exchange,提问作者Barış Velioğlu

