Communication method and communication device
By introducing a communication method into the communication network, allowing the device to store and publish its identity information in the communication network, the problem of data storage services being not open in the prior art is solved, and convenient management and secure authentication of the device identity information are realized.
Patent Information
- Application Number
- CN202311546179.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-17
- Publication Date
- 2025-05-20
AI Technical Summary
In communication networks, it is difficult for the prior art to provide open data storage services for users and third-party devices, resulting in inconvenient management of device identity information.
By introducing a communication method in the communication network, the first device is allowed to send a request message to the first shared device to store the device identity information, so that other devices can acquire and use the information through the network element for authentication, scheduling, deployment and other functions.
It realizes open data storage services for users and third-party devices by the communication network, simplifies the management and use of device identity information, and improves the flexibility and security of the system.
Smart Images

Figure CN120021293A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a communication method and a communication device. Background Art
[0002] Currently, in the fields of information technology and communication technologies, a large amount of device identity or attribute information needs to be maintained. In some implementations, a user can publish their public device identity information to a decentralized storage system to achieve autonomous management of user information.
[0003] However, in a communication network, a core network element is used for the storage service function of traditional authentication information, subscriptions, and runtime status data (such as: mobile status, etc.), or the operation data of internal network elements in an operator network. Each operator centrally manages its internal data and does not open its data storage service to users or third parties. Summary of the Invention
[0004] Embodiments of this application provide a communication method and a communication device, which implement an open data storage service provided by a communication network to users and third-party devices, enabling a terminal or a third-party device to store / publish its device identity information in the communication network.
[0005] To achieve the above objective, this application adopts the following technical solutions:
[0006] In a first aspect, a communication method is provided. The communication method includes: a first device obtains a first request message. The first request message is used to store device identity information. The first device sends the first request message to a first shared device. The first shared device is a network element in the communication network.
[0007] Based on the method provided in the first aspect, the first shared device can obtain the device identity information of the first device, and further implement storing the device identity information in the first shared device, enabling other devices to obtain the device identity information through network elements in the communication network, and performing authentication, scheduling, deployment, service provision, etc. according to the device identity information.
[0008] In a possible implementation, the device identity information includes the device type of the first device and / or the device type of a second device.
[0009] In this implementation, the device identity information further includes the device type, which can enable a device that obtains the device identity information to implement different functions such as authentication, scheduling, deployment, and service provision for different device types.
[0010] In a possible implementation, the device type may include: a 3rd Generation Partnership Project (3GPP) terminal, a network element of an operator, or a non-3GPP terminal.
[0011] In a possible implementation, the first device is a 3GPP terminal, and the first request message can also be used to indicate the authentication information of the first device. Among them, the authentication information of the first device can be used to verify the access of the terminal to the network, avoiding the access of unauthenticated terminals to the network, thereby making the communication more secure.
[0012] In a possible implementation, the authentication information of the first device can include the access credentials of the first device.
[0013] In a possible implementation, when the first device sends the first request message to the first shared device, it can include: the first device sends the first request message to the first shared device through an authentication network element.
[0014] In a possible implementation, the first device is a non-3GPP terminal, and the first request message is also used to indicate the information of the interface of the authentication service, which is used to authenticate the non-3GPP terminal.
[0015] In a possible implementation, if the device identity information includes the device type of the first device, the device identity information may further include one or more of the following: the first identifier of the first device, the owner of the entity corresponding to the first device, the information for verifying the ownership of the first identifier, the entity type corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, the encryption method corresponding to the first device. That is to say, the first device can upload its own device identity information, so that the complexity of the interaction process can be reduced.
[0016] In a possible implementation, if the device identity information includes the device type of the second device, the device identity information may further include one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, the information for verifying the ownership of the second identifier, the entity type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, the encryption method corresponding to the second device. That is to say, the first device can send the device identity information of other devices, and the application scenarios are more.
[0017] In a possible implementation, the first request message is also used to publish the device identity information. In this way, other devices can obtain which devices' device identity information is stored in the first shared device.
[0018] In a possible implementation, the method provided by the first aspect may further include: the first device receives a first response message from the first shared device. Among them, the first response message is used to indicate whether the first shared device has successfully stored the device identity information. In this way, the storage result of the device identity information can be timely fed back to the first device, thereby improving the user experience.
[0019] In a possible implementation, the method provided in the first aspect may further include: The first device sends a second request message to the second sharing device. The second request message is used to request the device identity information corresponding to the third device. The first device receives a second response message from the second sharing device. The second response message is used to indicate the device identity information corresponding to the third device. In this way, the first device can query the device identity information of other devices from the communication network according to requirements.
[0020] In a second aspect, a communication method is provided. The communication method includes: The first sharing device receives a first request message from the first device. The first request message is used to store device identity information. The first sharing device stores the device identity information in the first request message.
[0021] Based on the method provided in the first aspect, the first sharing device can obtain the device identity information of the first device, and then store the device identity information in the first sharing device, so that other devices can obtain the device identity information through network elements in the communication network, and perform authentication, scheduling, deployment, service provision, etc. according to the device identity information.
[0022] In a possible implementation, the device identity information includes the device type of the first device and / or the device type of the second device.
[0023] In a possible implementation, the device type may include: a 3rd Generation Partnership Project (3GPP) terminal, a network element of an operator, or a non-3GPP terminal.
[0024] In a possible implementation, the first device is a 3GPP terminal, and the first request message is further used to indicate the authentication information of the first device.
[0025] In a possible implementation, the authentication information of the first device includes the access credential of the first device.
[0026] In a possible implementation, the first sharing device receiving the first request message from the first device may include: The first sharing device receives the first request message from the first device through an authentication network element.
[0027] In a possible implementation, the first device is a 3GPP terminal, and the method provided in the second aspect may further include: The first sharing device authenticates the first device through an authentication network element. The first sharing device storing the device identity information in the first request message may include: When the first device passes the authentication, the first sharing device stores the device identity information in the first request message.
[0028] In a possible implementation, the first device is a non-3GPP terminal, and the first request message is further used to indicate information about the interface of the authentication service. The authentication service is used to authenticate the non-3GPP terminal.
[0029] In a possible implementation, if the device identity information includes the device type of the first device, the device identity information includes one or more of the following: the first identifier of the first device, the owner of the entity corresponding to the first device, information for verifying the ownership of the first identifier, the entity corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, the encryption method corresponding to the first device.
[0030] In a possible implementation, if the device identity information includes the device type of the second device, the device identity information includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information for verifying the ownership of the second identifier, the entity corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, the encryption method corresponding to the second device.
[0031] In a possible implementation, the first request message is further used to publish the device identity information, and the method provided by the second aspect may further include: the first sharing device publishes the device identity information.
[0032] In a possible implementation, the method provided by the second aspect may further include: the first sharing device sends a first response message to the first device.
[0033] In a possible implementation, the method provided by the second aspect may further include: the first sharing device sends the device identity information to the second sharing device.
[0034] In a possible implementation, the method provided by the second aspect may further include: the first sharing device receives a third request message from the fourth device. The third request message is used to request the device identity information corresponding to the fifth device. The first sharing device sends a third response message to the fourth device. The third response message is used to indicate the device identity information corresponding to the fifth device.
[0035] In a possible implementation, the method provided by the second aspect may further include: the first sharing device authenticates the fourth device through the authentication service device.
[0036] For the technical effects of the method provided by the second aspect, reference may be made to the relevant introduction in the method provided by the first aspect, which will not be elaborated here.
[0037] In a third aspect, a communication method is provided. The communication method includes: a fourth device sending a third request message to a second sharing device. The third request message is used to request device identity information corresponding to the identifier of a fifth device. The fourth device receives a third response message from the second sharing device. The third response message includes the device identity information corresponding to the identifier of the fifth device.
[0038] Based on the communication method provided in the third aspect, the fourth device can request attribute information corresponding to the identifier of the fifth device from the second sharing device, so as to obtain the device identity information.
[0039] In a possible implementation, the third request message may further include information indicating the access credential of the fourth device. The access credential of the fourth device is used to verify the identity of the fourth device.
[0040] In a possible implementation, the third request message may further include information indicating the device type of the fourth device.
[0041] In a fourth aspect, a communication method is provided. The communication method includes: the second sharing device receiving a third request message from the fourth device. The third request message is used to request device identity information corresponding to the identifier of a fifth device. The second sharing device sends a third response message to the fourth device. The third response message includes the device identity information corresponding to the identifier of the fifth device.
[0042] In a possible implementation, the method provided in the fourth aspect may further include: the second sharing device parsing the identifier of the fifth device to obtain the device identity information corresponding to the identifier of the fifth device.
[0043] In a possible implementation, the third request message is used to indicate information about the access credential of the fourth device. The access credential of the fourth device is used to verify the fourth device. The method provided in the fourth aspect may further include: the second sharing device performing identity verification with the second sharing device according to the access credential of the fourth device.
[0044] In a possible implementation, the third request message may further include information indicating the device type of the fourth device.
[0045] In addition, the technical effects of the communication method described in the fourth aspect may refer to the technical effects of the communication method described in the third aspect, which will not be elaborated here.
[0046] In a fifth aspect, a communication device is provided. The communication device is used to execute the communication method described in any one of the first aspect to the fourth aspect.
[0047] In this application, the communication device described in the fifth aspect may be the first device described in the first aspect, or the first shared device described in the second aspect, or the fourth device described in the third aspect, or the second shared device described in the fourth aspect, or a chip (system) or other component or assembly that can be disposed in the first device, the first shared device, the fourth device, or the second shared device, or a device including the first device, the first shared device, the fourth device, or the second shared device.
[0048] It should be understood that the communication device described in the fifth aspect includes corresponding modules, units, or means for implementing the communication method described in any one of the first to fourth aspects. The module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units for performing the functions involved in the above communication method.
[0049] In a sixth aspect, a communication device is provided. The communication device includes: a processor configured to execute the communication method described in any possible implementation manner of the first to fourth aspects.
[0050] In a possible implementation solution, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.
[0051] In a possible implementation solution, the communication device described in the sixth aspect may further include a memory. The memory may be integrated with the processor or may be provided separately. The memory may be used to store the computer program and / or data involved in the communication method described in any one of the first to fourth aspects. When the processor executes the computer program, the communication device is caused to execute the communication method described in any one of the implementation manners of the first to fourth aspects.
[0052] In a possible implementation solution, the processor is configured to be coupled to the memory and, after reading the computer program in the memory, execute the communication method described in any one of the implementation manners of the first to fourth aspects according to the computer program.
[0053] In this application, the communication device described in the sixth aspect may be the first device described in the first aspect, or the first shared device described in the second aspect, or the fourth device described in the third aspect, or the second shared device described in the fourth aspect, or a chip (system) or other component or assembly that can be disposed in the first device, the first shared device, the fourth device, or the second shared device, or a device including the first device, the first shared device, the fourth device, or the second shared device.
[0054] In a seventh aspect, a processor is provided. The processor is configured to execute the communication method described in any one of the possible implementations of the first aspect to the fourth aspect.
[0055] In an eighth aspect, a communication system is provided. The communication system includes one or more terminal devices and one or more network devices.
[0056] In a ninth aspect, a computer-readable storage medium is provided, including: a computer program or instructions; when the computer program or instructions are run on a computer, the computer is caused to execute the communication method described in any one of the possible implementations of the first aspect to the fourth aspect.
[0057] In a tenth aspect, a computer program product is provided, including a computer program or instructions, which, when run on a computer, cause the computer to execute the communication method described in any one of the possible implementations of the first aspect to the fourth aspect.
[0058] In addition, for the technical effects of the communication devices described in the fifth aspect to the tenth aspect above, reference may be made to the technical effects of the communication methods described in the first aspect to the fourth aspect above, which will not be elaborated here. Description of the Drawings
[0059] Figure 1 It is a schematic diagram of the architecture of the communication system provided by an embodiment of the present application;
[0060] Figure 2 It is a schematic flowchart of the communication method provided by an embodiment of the present application Figure 1 ;
[0061] Figure 3 It is a schematic flowchart of the device identity information synchronization process provided by an embodiment of the present application;
[0062] Figure 4 It is a schematic flowchart of the communication method provided by an embodiment of the present application Figure 2 ;
[0063] Figure 5 It is a schematic flowchart of the communication method provided by an embodiment of the present application Figure 3 ;
[0064] Figure 6 It is a schematic flowchart of the communication method provided by an embodiment of the present application Figure 4 ;
[0065] Figure 7 It is a schematic flowchart of the communication method provided by an embodiment of the present application Figure 5 ;
[0066] Figure 8 It is a schematic flowchart of the communication method provided by an embodiment of the present applicationFigure 6 ;
[0067] Figure 9 Structural schematic of the communication device provided by the embodiment of the present application Figure 1 ;
[0068] Figure 10 Structural schematic of the communication device provided by the embodiment of the present application Figure 2 。 Detailed implementation manners
[0069] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless fidelity (WiFi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle networking communication systems, 4th generation (4G) mobile communication systems, such as long term evolution (LTE) systems, 5th generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 6th generation (6G) mobile communication systems, etc.
[0070] The present application will present various aspects, embodiments or features around a system that may include multiple devices, components, modules, etc. It should be understood and clear that each system may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the drawings. In addition, combinations of these solutions can also be used.
[0071] In addition, in the embodiments of the present application, words such as "exemplarily", "for example", etc. are used to represent examples, illustrations or explanations. Any embodiment or implementation solution described as an "example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or implementation solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner.
[0072] In the embodiments of the present application, "information", "signal", "message", "channel", "signaling" can sometimes be used interchangeably. It should be noted that when not emphasizing their differences, the meanings they convey are the same. "Of", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when not emphasizing their differences, the meanings they convey are the same.
[0073] In the embodiments of this application, sometimes the subscript is W 1 It may be written as a non-subscript form such as W1 by mistake. When the difference is not emphasized, the meaning is the same.
[0074] The network architecture and business scenarios described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. A person skilled in the art will appreciate that, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0075] Currently, a large amount of device identity or attribute information needs to be maintained in the fields of information technology and communication technology. In some implementations, users can publish their public device identity information to a decentralized storage system to achieve autonomous management of user information.
[0076] However, in the communication network, the core network elements are used for storage service functions for traditional authentication information, subscription and runtime status data (e.g., mobile status, etc.), or the operation data of network elements within the operator network. Each operator centrally manages its internal data and does not open its data storage services to users or third parties. Therefore, how to provide data storage services to users or third parties through the operator network is a technical problem that needs to be solved urgently.
[0077] For ease of understanding, the following first introduces technical terms related to the embodiments of the present application.
[0078] Attribute information is information used to describe the characteristics of the identity corresponding to the device. The characteristics can be the identity characteristics of the device or the identity characteristics of the subject corresponding to the device.
[0079] The subject corresponding to the device can be a physical entity, such as the device itself. Alternatively, the subject corresponding to the device can be a logically composed unit, such as a person, an organization, or an enterprise. The subjects corresponding to the devices listed here are only used as examples. In actual implementation, the subjects corresponding to the device can also be used in other ways, which will not be repeated here.
[0080] Device identity information is a collection of device attribute information. One device identity information can include one or more attribute information, and the attribute information corresponds to the identity of the device. For example, one attribute information can include any of the following: the device type of the device, the identity (ID) of the device, the owner of the entity corresponding to the device, the information for verifying the ownership of the first identity, the type of entity corresponding to the device, the network domain identity corresponding to the identity of the device, the verifiable credential corresponding to the identity of the device, the service or service interface supported by the device, or the encryption method corresponding to the device.
[0081] Among them, different attribute information can be identified by attribute indexes. For example, the attribute index corresponding to the identity of the device can be "identity", the index corresponding to the owner of the entity corresponding to the device can be "entity controller", the attribute index corresponding to the information for verifying the ownership of the first identity can be "verification method", the attribute index corresponding to the type of entity corresponding to the device can be "entity type", the attribute index corresponding to the identity of the device can be "network domain identity", the attribute index corresponding to the verifiable credential corresponding to the identity of the device can be "verifiable credential", the attribute index corresponding to the service or service interface supported by the device can be "service interface", and the attribute index corresponding to the encryption method corresponding to the device can be "encryption method".
[0082] Among them, the attribute indexes, data types, whether they are mandatory, quantities, and respective interpretations corresponding to different attribute information are shown in Table 1.
[0083] Table 1
[0084]
[0085]
[0086] It can be understood that the above attribute indexes are only for example. In actual implementation, the above attribute indexes can also have other possible expressions. For example, the attribute index "identity" can also be expressed as "self - controlled identity identifier" or "scId". The attribute index "entity type" can also be expressed as "sbjType". The attribute index "entity controller" can also be expressed as "sbjController". The attribute index "network domain identity" can also be expressed as "domaninId". The attribute index "verification method" can also be expressed as "verifyMethod". The attribute index "verifiable credential" can also be expressed as "assertion method" or "assertMethod". The attribute index "supported service" can also be expressed as "service". The attribute index "encryption method" can also be expressed as "point - to - point communication encryption method" or "keyAgreeMethod".
[0087] It should be understood that the above Figure 1 Whether each piece of attribute information in the above is necessary is only for illustration. In actual implementation, for different nodes or the identifiers of different nodes, the included attribute information may be different. For example, the attribute information corresponding to the node or the identifier of the node can be determined according to the scenario where the node is located.
[0088] In some possible implementation solutions, the verifiable credential may include a verifiable credential (VC) for the subject to access the operator network. The VC may include the identity of the operator that issues the VC and proof information, and the proof information can be used to prove the legality of the device corresponding to the subject and the acquisition address of the subscription data. For example, if the device corresponding to the subject is a terminal, the proof information can be used to prove that "the terminal is legal".
[0089] In some possible implementation solutions, the device identity information may include identification information and profile information. The identification information and the profile information are generated separately and stored separately. Among them, the identification information may include the identifier of the device, and the profile information may include the attribute information other than the identifier in the device identity information. In this way, different information can be stored or read separately, which can reduce the leakage of attribute information. In addition, it can make data processing, such as publishing, more flexible.
[0090] In some possible implementation solutions, in the device identity information, the device identity information may include identification information and profile information. The identification information and the profile information are generated separately and stored separately. Among them, the identification information may include the identifier of the device and the information for verifying the device identity, such as a verifiable credential. The profile information may include other information in the device identity information except for the identifier of the device and the information for verifying the device identity. In this way, the profile information can be generated according to requirements, reducing the amount of data stored.
[0091] It should be understood that the attribute index may also be referred to as an attribute name, or other possible names.
[0092] In some possible implementation solutions, the attribute information can also be implemented through fixed fields. In this case, the attribute information corresponding to each attribute index corresponds to one field. That is to say, the attribute information corresponding to each attribute index is carried in one field.
[0093] The attribute information corresponding to the attribute index refers to the attribute information that can be identified by the attribute index. The attribute index corresponding to the attribute information refers to the attribute information that can be identified by the attribute index. The technical solutions in the present application will be described below with reference to the accompanying drawings.
[0094] To facilitate the understanding of the embodiments of the present application, first, take Figure 1Taking the communication system shown as an example, the communication system applicable to the embodiments of the present application will be described in detail. Exemplarily, Figure 1 FIG. is a schematic diagram of the architecture of a communication system applicable to the communication method provided by the embodiments of the present application.
[0095] As Figure 1 shown, the communication system includes a first type of device (such as the first type of device 101a to the first type of device 101c), a second type of device (such as the second type of device 102a and the second type of device 102b), and a first type of shared device 103.
[0096] Among them, the first type of device (such as the first type of device 101a to the first type of device 101c) and the second type of device (such as the second type of device 102a and the second type of device 102b) can both perform information interaction with the first type of shared device 103.
[0097] The first type of device (such as the first type of device 101a to the first type of device 101c) may be a 3rd generation partnership project (3GPP) terminal. The second type of device (such as the second type of device 102a and the second type of device 102b) may be a non-3GPP terminal.
[0098] A 3GPP terminal refers to a terminal whose access type when accessing the network is 3GPP access, and a non-3GPP terminal refers to a terminal whose access type when accessing the network is non-3GPP access. That is to say, for the same terminal, when using different access types, the type of the terminal is different.
[0099] The first type of shared device is a network element in the communication network. For example, a network element in the core network. For example, the first type of shared device may be a decentralized shared profile repository (dSPR). One or more first type of shared devices may be included in the communication system.
[0100] In addition, Figure 1 the communication system shown may further include an authentication network element, and the authentication network element may be used to authenticate the 3GPP terminal. For example, the authentication network element may be an authentication server function (AUSF) network element.
[0101] Figure 1Other network elements, such as network functions (NFs), may also be included in the shown communication system. Exemplarily, the NF may be a unified data management (UDM), an authentication server function (AUSF), a policy control function (PCF), or a unified data repository (UDR). In addition, Figure 1 The shown communication system may also include access network devices.
[0102] Figure 1 In the shown communication system, one or more authentication service devices ( Figure 1 not shown in the figure) may also be included. The authentication service device may be a network element or device capable of providing verification services.
[0103] In some possible implementation scenarios, the authentication service device may be used to verify devices in the network. For example, the authentication service device may be used to verify the identity of a device, such as whether the device is a device authenticated through the core network, or whether the device is a legal or valid device, etc.
[0104] In some possible implementation scenarios, the authentication service device may be used to verify non-3GPP terminals. For example, the authentication service device may be a verification server of the device provider that initiates the verification process. Taking the device that initiates the verification process as a terminal, the device provider is the terminal manufacturer, and the authentication service device may be the verification server of the terminal manufacturer. Taking the device that initiates the verification process as a card with communication functions, the device provider is the card vendor, and the authentication service device may be the verification server of the card vendor. The device provider may also be referred to as the device manufacturer or other names, and the embodiments of this application do not limit this.
[0105] Figure 1 In the shown communication system, a second type of shared device may also be included, where the second type of shared device is a device with a storage function, such as the second type of shared device may be a device in a non-3GPP network.
[0106] The above-mentioned terminal is a terminal with transceiver functions for accessing the above-mentioned communication system, or a chip or chip system that can be set in the terminal, or a unit or module with terminal functions. This terminal can also be called a terminal device, and can also be called a user equipment (UE), a mobile station (MS), a mobile terminal (MT), etc., or a device for providing voice or data connectivity to users, and can also be an Internet of Things device. For example, the terminal includes handheld devices, vehicle-mounted devices, etc. with wireless connection functions. Currently, the terminal can be: a mobile phone, a tablet computer, a laptop computer, a palm computer, a mobile internet device (MID), a wearable device (such as a smart watch, a smart bracelet, a pedometer, smart glasses, etc.), a vehicle-mounted device (such as a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed train, etc.), a satellite terminal, a virtual reality (VR) device, an augmented reality (AR) device, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a wireless terminal in industrial control, a smart home device (such as a refrigerator, a TV, an air conditioner, an electric meter, etc.), a smart robot, a robotic arm, a workshop device, a wireless terminal in driverless, a wireless terminal in remote medical treatment, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home, a flying device (such as a smart robot, a hot air balloon, a drone, an airplane), etc. The terminal can also be a vehicle device, such as a vehicle assembly, a vehicle-mounted module, a vehicle-mounted chip, an on-board unit (OBU), or a telematics box (T-BOX), etc. The terminal can also be other devices with terminal functions. For example, the terminal can also be a device that serves as a terminal function in D2D communication.
[0107] The terminal of the present application can also be a module or unit that can be used to implement terminal functions. For example, the terminal can also be a universal integrated circuit card (UICC), or a blockchain universal integrated circuit card (B-UICC).
[0108] Embodiments of the present application do not limit the device form of the terminal. The device for implementing the functions of the terminal may be the terminal; or it may be a device capable of supporting the terminal to implement the functions, such as a chip system. This device may be installed in the terminal or used in matching with the terminal. In the embodiments of the present application, the chip system may be composed of chips or may include chips and other discrete devices.
[0109] In a possible scenario, the access network device may be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next generation NodeB (gNB), a next generation base station in a 6th generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, or an access point (AP) in a WiFi system, an integrated access and backhaul (IAB) node, an access network device in a non-terrestrial network (NTN) communication system, that is, it may be deployed on a high-altitude platform or a satellite, etc. The access network device may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a radio controller in a cloud radio access network (CRAN) scenario. The access network device may also be a device that serves as a base station function in device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, drone communication, or machine communication. Optionally, the access network device may also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in vehicle-to-everything (V2X) technology may be a road side unit (RSU).
[0110] In another possible scenario, multiple access network devices cooperate to assist a terminal in achieving wireless access, and different access network devices respectively implement some functions of a base station. For example, the access network device may be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU may be separately provided, or may also be included in the same network element, such as a baseband unit (BBU). The RU may be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the access network device may be a CU node, or a DU node, or a device including a CU node and a DU node. In addition, the CU may be classified as an access network device in a radio access network (RAN), or the CU may be classified as an access network device in a core network (CN), which is not limited herein.
[0111] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open RAN (ORAN) system, the CU may also be referred to as an O-CU (open CU), the DU may also be referred to as an O-DU, the CU-CP may also be referred to as an O-CU-CP, the CU-UP may also be referred to as an O-CU-UP, and the RU may also be referred to as an O-RU. For the convenience of description, in this application, the CU, CU-CP, CU-UP, DU, and RU are used as examples for description. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0112] It should be noted that the communication method provided in the embodiments of this application can be applicable to Figure 1 any two devices shown, such as between terminal devices, between network devices, and between a terminal device and a network device. The specific implementation can refer to the following method embodiments and will not be elaborated herein.
[0113] It should be pointed out that the solution in the embodiments of this application can also be applied to other communication systems, and the corresponding names can also be replaced with the names of the corresponding functions in other communication systems.
[0114] It should be understood that Figure 1 the simplified schematic diagram shown for the convenience of understanding, and other network devices and / or other terminal devices may also be included in the communication system, Figure 1 which are not drawn in the figure.
[0115] Next, the communication method provided in the embodiments of the present application will be specifically described in conjunction with Figures 2 - 8 the following.
[0116] Exemplarily, Figure 2 the flowchart of the communication method provided in the embodiments of the present application is shown in Figure 1 . The communication method can be applicable to the communication between the nodes shown in Figure 1 .
[0117] As shown in Figure 2 , the communication method includes the following steps:
[0118] S201, the first device obtains a first request message.
[0119] Among them, the first device may be a device in a 3GPP network, a device in a non-3GPP network, or a device corresponding to an operator. That is to say, the first device may be Figure 1 the first type of device or the second type of device in the communication system provided above. In other words, the first device may be a device with a 3GPP access type. In this case, the first device can communicate through the 3GPP network. Or, the first device may be a device with a non-3GPP access type. In this case, the first device can communicate through the non-3GPP network. The first device may also be an access network device of the operator, a device in the operator's core network, or a server of the operator. In a possible implementation, the device type may include: a 3GPP terminal of the 3rd Generation Partnership Project, a network element of the operator, or a non-3GPP terminal. That is to say, for a terminal, the device type is the access type of the terminal.
[0120] The first request message is used to store device identity information, that is, to request to store device identity information. The device identity information may be carried in the first request message. For the implementation of the device identity information, reference can be made to the relevant introduction of the above technical terms, which will not be elaborated here.
[0121] In a possible implementation, the device identity information may include the device identity information corresponding to the first device and / or the device identity information corresponding to the second device. Among them, the device identity information corresponding to the first device includes the device type of the first device, and the device identity information corresponding to the second device may include the device type of the second device. In this implementation, the device identity information further includes the device type, which enables the device that obtains the device identity information to implement different functions such as authentication, scheduling, deployment, and service provision for different device types.
[0122] In a possible implementation solution, the device identity information of the first device may further include one or more of the following: the first identifier of the first device, the owner of the entity corresponding to the first device, the information for verifying the ownership of the first identifier, the entity type corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the service or service interface supported by the first device, the encryption method corresponding to the first device.
[0123] For the implementation of the attribute information corresponding to the first device, reference can be made to the relevant introduction in the technical term introduction section, which will not be elaborated here.
[0124] In a possible implementation solution, the device identity information of the second device may further include one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, the information for verifying the ownership of the second identifier, the entity type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the service or interaction interface supported by the second device, the encryption method corresponding to the second device.
[0125] For the implementation of the attribute information corresponding to the first device, reference can be made to the relevant introduction in the technical term introduction section, which will not be elaborated here.
[0126] It can be understood that in some possible implementation solutions, the first request message may further carry the subtype of the first device or the second device. For example, the subtype is used to indicate that the first device or the second device is a mobile phone, a vehicle, or an Internet of Things (IoT) device, etc.
[0127] S202. The first device sends a first request message to the first shared device. Correspondingly, the first shared device receives the first request message from the first device.
[0128] The first shared device is a network element in the communication network. This communication network may be a 3GPP network. For example, the first shared device may be the first type of shared device in the communication system provided above Figure 1 provided.
[0129] S203. The first shared device stores the device identity information in the first request message.
[0130] In a possible implementation, the first request message is also used to publish device identity information. In this case, Figure 2 The provided method may further include S204.
[0131] S204, the first shared device publishes device identity information.
[0132] Wherein, the first shared device may send a first message, and the first message is used to indicate that device identity information is stored in the first shared device.
[0133] It can be understood that the first shared device may publish device identity information in a broadcast, multicast or unicast manner.
[0134] It can be understood that the execution order in the embodiments of the present application is only for illustration. In actual implementation, different steps may be executed in other orders as long as they are logical. For example, S204 may be executed after S203, or S204 may be executed together with S203.
[0135] Based on Figure 2 the provided method, the first shared device can obtain the device identity information of the first device, and then store the device identity information in the first shared device, so that other devices can obtain the device identity information through network elements in the communication network, and perform authentication, scheduling, deployment, service provision, etc. according to the device identity information.
[0136] In a possible implementation, the method provided in the first aspect may further include S205.
[0137] S205, the first shared device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first shared device.
[0138] Wherein, the first response message is used to indicate whether the first shared device successfully stores the device identity information. For example, the first response message may be used to indicate that the first shared device successfully stores the device identity information. Another example is that the first response message may be used to indicate that the first shared device fails to store the device identity information.
[0139] It can be understood that Figure 2 in the case where the provided solution includes S204, the first response message may also be used to indicate whether the device identity information is successfully published.
[0140] In addition, Figure 2 the provided method may further include one or more of the following Designs 1 to 3. Designs 1 to 3 are described separately below.
[0141] In Design 1, the first device can also obtain the device identity information of other devices from the second sharing device. In this case, Figure 2 The provided method may further include S206 and S207.
[0142] S206, the first device sends a second request message to the second sharing device. Correspondingly, the second sharing device receives the second request message from the first device.
[0143] Wherein, the second request message is used to request the device identity information corresponding to the third device.
[0144] In the second request message, the identifier of the third device may be carried. This identifier may correspond to a device identity information of the third device.
[0145] Wherein, the implementation principle of the second sharing device may refer to the implementation principle of the first sharing device. It should be understood that the second sharing device may be the same as the first sharing device, that is, the second sharing device may be the first type of sharing device. For example, the second sharing device may be the first sharing device. Or, the second sharing device may be different from the first sharing device. For example, the second sharing device may be the second type of sharing device.
[0146] S207, the second sharing device sends a second response message to the first device. Correspondingly, the first device receives the second response message from the second sharing device.
[0147] Wherein, the second response message is used to indicate the device identity information corresponding to the third device.
[0148] It can be understood that S207 can be executed when the first device is verified successfully. In this case, Figure 2 The provided method may further include: the second sharing device verifies the first device. The principle of the second sharing device verifying the first device may refer to the relevant introduction of S209 below, which will not be elaborated here.
[0149] In Design 2, the first sharing device can provide the device identity information for the fourth device. In this case, Figure 2 The provided method may further include S208 to S210.
[0150] S208, the fourth device sends a third request message to the first sharing device. Correspondingly, the first sharing device receives the third request message from the fourth device.
[0151] Wherein, the fourth device may be the first type of device or the second type of device. The third request message is used to request the device identity information corresponding to the fifth device.
[0152] In a possible implementation, the third request message may carry information for indicating the fifth device, such as the identifier of the fifth device. The third request message also includes the identity information of the fourth device, such as a subscription concealed identifier (SUCI), a username-password pair, or a temporary verification code.
[0153] S209, the first shared device authenticates or verifies the fourth device.
[0154] The following is described in combination with different scenarios.
[0155] Scenario 1, if the fourth device is a first type of device, the first shared device accesses the authentication network element corresponding to the fourth device and sends an authentication request to the authentication network element. The authentication request contains the identity information of the fourth device carried in the third request message, for example, the identifier of the fourth device, such as SUCI. The authentication network element checks the provided identity information of the fourth device to determine whether the authentication is passed and returns an authentication result to the first shared device.
[0156] Scenario 2, if the fourth device is a second type of device, the first shared device accesses the authentication service device for the fourth device (for example, the fourth device can access the authentication server through the interface of the verification service) and sends a verification request to the authentication service device. The verification request contains the identity information provided by the fourth device in the third request message (for example, a username-password pair, or a temporary verification code, etc.). The authentication service device checks the provided identity information of the fourth device to determine whether the verification is passed and returns a verification result to the first shared device. Among them, the authentication service device may be the verification server of the fourth device provider. The authentication service device has a corresponding relationship with the verification service address of the device provider, and the authentication service device can be determined according to the verification service address of the device provider.
[0157] In some possible implementation solutions, the authentication service device may be the device corresponding to the blockchain node in the blockchain system.
[0158] In Scenario 2, the first request message is also used to indicate the information of the interface of the verification service, and the verification service is used to verify non-3GPP terminals.
[0159] S210, the first shared device sends a third response message to the fourth device. Correspondingly, the fourth device receives the third response message from the first shared device.
[0160] The third response message is used to indicate the device identity information corresponding to the fifth device.
[0161] It is understandable that in Design 2, S209 is an optional step. When S209 exists in Design 2, S210 can be executed when the verification of the fourth device is successful.
[0162] In Design 3, the first sharing device can store the device identity information on the second sharing device. In this case, the type of the second sharing device can be the same as that of the first sharing device, that is, a device in the 3GPP network, or the type of the second sharing device can also be different from that of the first sharing device. For example, it is a device in a non-3GPP network. Among them, Figure 2 The provided method may further include S211.
[0163] S211, the first sharing device shares the device identity information with the second sharing device.
[0164] In this case, the second sharing device is different from the first sharing device.
[0165] Among them, the second sharing device may be the above-mentioned first type of sharing device or the second type of sharing device.
[0166] Regarding the implementation principle of S211, reference can be made to the following Figure 3 Schematic diagram of the process of sharing device identity information shown below.
[0167] As Figure 3 shown, the process of sharing device identity information includes steps S211a to S211f.
[0168] S211a, the first sharing device negotiates the type of communication handshake protocol with the second sharing device.
[0169] The first sharing device sends the communication protocols supported by the first sharing device to the second sharing device. For example, the communication protocol can be a secure communication protocol.
[0170] The second sharing device selects a communication protocol from the communication protocols supported by the first sharing device as the target protocol.
[0171] For example, the target protocol can be a protocol in which both parties to the communication can construct a one-time session encryption symmetric key using an existing key exchange method (e.g., Diffie-Hellman Key Exchange) to communicate. Or, the target protocol can be a protocol in which both parties to the communication communicate based on the method of decentralized identifier communication (DIDComm). During the communication using this communication protocol, the two communicating parties exchange their public key certificates. After the public key certificates are verified, the encrypting party can use the public keys of both parties to encrypt the transmitted information, and the decrypting party decrypts it with the corresponding local private key.
[0172] S211b, the first sharing device sends a connection request to the second sharing device. Correspondingly, the second sharing device receives the connection request from the first sharing device.
[0173] Among them, the connection request includes the handshake credential of the first sharing device. The handshake credential of the first sharing device is used to verify the identity of the first sharing device.
[0174] In S211b, a secure channel can be established between the first sharing device and the second sharing device.
[0175] Using the established secure channel, the first sharing device sends a connection request credential to the second sharing device, and this connection request credential is used for the second sharing device to verify the identity of the first sharing device.
[0176] S211c, the second sharing device verifies the identity of the first sharing device according to the handshake credential of the first sharing device.
[0177] After the second sharing device verifies the identity of the first sharing device, it can determine whether to initiate data synchronization according to the identity verification result of the first sharing device.
[0178] Verifying the identity of the first sharing device can be performed locally on the second sharing device or with the help of a third-party verification service. For example: if the first sharing device and the second sharing device belong to different operators, then verifying the first sharing device requires the verification service of the operator where the first sharing device is located.
[0179] S211d, the second sharing device sends a connection response to the first sharing device. Correspondingly, the first sharing device receives the connection response from the second sharing device.
[0180] Among them, the connection response includes the handshake credential of the second sharing device. The handshake credential of the second sharing device can be used to verify the identity of the second sharing device.
[0181] S211e, the first sharing device negotiates a data synchronization protocol with the second sharing device.
[0182] In a possible implementation, S211e may include: the first sharing device sends the supported data synchronization protocols to the second sharing device, and the second sharing device selects a target data synchronization protocol from the data synchronization protocols supported by the first device and returns the selection result to the first sharing device. The data synchronization protocols supported by the first device may be a distributed database synchronization method or a decentralized synchronization method based on a distributed ledger database, etc.
[0183] In a possible implementation, the first sharing device verifies the identity of the second sharing device based on the handshake credential of the second sharing device. For the implementation principle, reference can be made to the relevant introduction of S211c. In this case, when the identity verification of the second sharing device passes, S211e is executed.
[0184] S211f, the first sharing device sends device identity information to the second sharing device. Correspondingly, the second sharing device receives the device identity information from the first sharing device.
[0185] The first sharing device preprocesses the device identity information according to the data synchronization protocol replied by the second sharing device and sends the preprocessed device identity information to the second sharing device. The preprocessing of the device identity information may include: packing (compressing) the whole device identity information data or chunking the device identity information.
[0186] Figure 3 In the provided method, S211a to S211e are optional steps and can be executed when the types of the first sharing device and the second sharing device are different, such as when the second sharing device is a device in a non-3GPP network.
[0187] It should be understood that the identity credentials submitted by the first sharing device and the second sharing device may be of different credential types. The method for verifying the identity of the first sharing device and the method for verifying the identity of the second sharing device may also be different.
[0188] For ease of understanding the above Figure 2 provided method, the following describes the above Figure 2 provided communication method in combination with different scenarios.
[0189] In some possible scenarios, the first device is a 3GPP terminal (hereinafter referred to as the terminal), and this first device directly verifies with the authentication network element and directly sends device identity information to the first sharing device. In this case, Figure 2 the provided method can be referred to as follows Figure 4 the provided communication method. AsFigure 4 As shown in the figure, the communication method includes:
[0190] S401, the first device performs authentication through an authentication network element.
[0191] For example, the first device may send an authentication request to the authentication network element. Among them, the authentication request is used to request authentication of the identity of the first device. The authentication request may include an identifier of the first device, such as SUCI. It is understandable that SUCI is only for illustration. In actual implementation, the identifier of the first device may also be other information that can be used to identify the first device.
[0192] After receiving the authentication request, the authentication network element authenticates the first device. For example, the authentication network element may call an authentication service interface (such as the Nausf_auth service interface) to implement the authentication of the first device. After the first device passes the authentication, the authentication network element may send an authentication response to the first device. Among them, the authentication response may carry an access credential (such as a token) of the first device. For the detailed steps, reference can be made to Section 6.1 of 3GPP Technical Specification (TS) 33.501.
[0193] Among them, for the implementation principle of the authentication network element, reference can be made to Figure 1 the relevant introduction in the provided communication system, which will not be elaborated here.
[0194] S402, the first device sends a first request message to the first shared device. Correspondingly, the first shared device receives the first request message from the first device.
[0195] For the first request message, reference can be made to the relevant introduction in S201.
[0196] Optionally, the authentication information of the first device may include an access credential of the first device. Among them, the authentication information of the first device can be used to perform network access verification on the terminal, avoiding unauthenticated terminals from accessing the network, thereby making the communication more secure.
[0197] In a possible implementation, the first request message can be implemented by invoking a publishing service interface (such as the Publish() service interface). Exemplarily, the publishing service interface can be a representational state transfer application program interface (RESTful API). This API complies with the uniform resource identifier (URI) standard. The interface address of this API includes: the host name (host) of the first shared device, the host identifier (id), and the parameters of the publishing method (method), which are used to indicate the storage method of the device identity information. The first device can access or invoke this API through this interface address. The parameters (i.e., input parameters) required when invoking this API include: information for authenticating the identity of the first device (e.g., oAuth2ClientCredential), and the device identity information to be carried in the first request message (e.g., ProfileDataResource). The response information of this API includes: the first response message. For example, when the identity information is successfully published, the response information includes "OK"; when the identity information publishing fails, the response information includes "Error message", etc.
[0198] S403. The first shared device stores the device identity information in the first request message.
[0199] For the implementation principle of S403, reference can be made to Figure 2 the relevant introduction of S203 in the provided method, which will not be elaborated here.
[0200] S404. The first shared device publishes the device identity information.
[0201] For the process of S404, reference can be made to Figure 2 the relevant introduction of S204 in the provided method, which will not be elaborated here.
[0202] S405. The first shared device sends the first response message to the first device. Correspondingly, the first device receives the first response message from the first shared device.
[0203] For the implementation principle of the first response message, reference can be made to the above Figure 2 relevant introduction in the provided method, which will not be elaborated here.
[0204] Regarding Figure 4 the technical effects of the provided method, reference can be made to the above Figure 2The technical effects of the provided method. In addition, the first device directly authenticates with the authentication network element. In this way, the storage process of the device identity information and the authentication process of the first device are executed separately, and the timing of storing the device identity information is more flexible.
[0205] In some possible scenarios, the first device is a 3GPP terminal (hereinafter referred to as the terminal), and the first device sends the device identity information to the first shared device through the authentication network element. In this case, Figure 2 The provided method can be referred to as follows Figure 5 The provided communication method. As Figure 5 shown, the communication method includes:
[0206] S501, the first device sends a first message to the authentication network element. Correspondingly, the authentication network element receives the first message from the first device.
[0207] Among them, the first message includes a first request message and an authentication request of the first device.
[0208] Regarding the implementation principle of the first request message, reference can be made to the relevant introduction in the above Figure 4 provided method. The authentication request of the first device can be used to authenticate the identity of the first device, or to authenticate the first device.
[0209] It should be understood that in S501, the first device can send the first message to the authentication network element through a non-access stratum (NAS) message. Correspondingly, the authentication network element can receive the first message from the first device through the NAS message.
[0210] S502, the first device is authenticated through the authentication network element.
[0211] Regarding the implementation principle of S502, reference can be made to the relevant introduction of S401. The difference is that the step of the first device sending an authentication request to the authentication network element is completed in S501.
[0212] S503, the authentication network element sends the first request message to the first shared device. Correspondingly, the first shared device receives the first request message from the authentication network element.
[0213] In a possible implementation, the first request message can be implemented by invoking a publishing service interface (such as the Publish() service interface). Exemplarily, the publishing service interface can be: a RESTful API. This API complies with the URI rule standard. The interface address of this API includes: the host name host identifier of the first shared device and the parameters of the publishing method. The first device can access or invoke this API through this interface address. The parameters (i.e., input parameters) required when invoking this API include: the identity information for authenticating the first device (e.g., oAuth2ClientCredential), the publishing valid domain (e.g., validDomain), and the data of the device identity information to be carried in the first request message (e.g., ProfileDataResource). The response information of this API includes: the first response message.
[0214] S504. The first shared device stores the device identity information in the first request message.
[0215] For the implementation principle of S504, reference can be made to Figure 2 the relevant introduction of S203 in the provided method, which will not be elaborated here.
[0216] S505. The first shared device publishes the device identity information.
[0217] In the embodiment of this application, the first shared device can publish the device identity information after receiving the first request message.
[0218] For the implementation principle of S505, reference can be made to Figure 2 the relevant introduction of S204 in the provided method, which will not be elaborated here.
[0219] S506. The first shared device sends the first response message to the authentication network element. Correspondingly, the authentication network element receives the first response message from the first shared device.
[0220] For the implementation principle of the first response message, reference can be made to the above Figure 2 the relevant introduction of S205 in the provided method, which will not be elaborated here.
[0221] S507. The authentication network element sends the first response message to the first device. Correspondingly, the first device receives the first response message from the authentication network element.
[0222] Regarding Figure 5 the technical effects of the provided method, reference can be made to the above Figure 2The technical effects of the provided method. In addition, by sending the first request message through the authentication network element and carrying the first request message and the authentication request of the first device in the same message, the signaling interaction process can be reduced, the resource overhead can be lowered, the communication efficiency can be improved, and the overhead of the terminal can be reduced.
[0223] In this case, Figure 5 in S501 to S503, that is, the first device sends a first request message to the first shared device through the authentication network element. The first shared device receives the first request message from the first device through the authentication network element. That is to say, Figure 2 In the provided method, for the first device to send a first request message to the first shared device, it may include: the first device sends a first request message to the first shared device through the authentication network element. Figure 2 In the provided method, for the first shared device to receive the first request message from the first device, it may include: the first shared device receives the first request message from the first device through the authentication network element.
[0224] In some possible scenarios, the first device is a 3GPP terminal (hereinafter referred to as the terminal), and the first device directly sends device identity information to the first shared device. The first shared device realizes the authentication of the first device through the authentication network element. In this case, Figure 2 The provided method can be referred to as follows Figure 6 The provided communication method. As Figure 6 shown, this communication method includes:
[0225] S601, the first device sends a first request message to the first shared device. Correspondingly, the first shared device receives the first request message from the first device.
[0226] Regarding the implementation principle of the first request message, reference can be made to the relevant introduction in S401.
[0227] S602, the first shared device authenticates the first device through the authentication network element.
[0228] Regarding the implementation principle of S602, reference can be made to the relevant introduction in Scenario 2, which will not be elaborated here.
[0229] S603, the first shared device stores the device identity information in the first request message.
[0230] Optionally, S603 may include: when the first device passes the authentication, the first shared device stores the device identity information in the first request message.
[0231] Regarding the implementation principle of the first shared device storing the device identity information in the first request message, reference can be made to the relevant introduction in S203, which will not be elaborated here.
[0232] S604, the first sharing device publishes the device identity information in the first request message.
[0233] Optionally, S604 may include: when the first device is authenticated, the first sharing device publishes the device identity information in the first request message.
[0234] For the implementation principle of the first sharing device publishing the device identity information in the first request message, reference can be made to the relevant introduction in S204, which will not be elaborated here.
[0235] S605, the first sharing device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first sharing device.
[0236] For the implementation principle of S605, reference can be made to Figure 4 the relevant introduction in S405 in, which will not be elaborated here.
[0237] Regarding Figure 6 the technical effects of the provided method, reference can be made to the above Figure 2 technical effects of the provided method. In addition, after receiving the first request message, the first sharing device authenticates the first device through the authentication network element, which can reduce the amount of data exchanged between the first device and the first sharing device, thereby reducing resource overhead and the power consumption of the terminal.
[0238] In some possible scenarios, the first device is a non-3GPP terminal (hereinafter referred to as the terminal), and the first device directly sends the device identity information to the first sharing device. And the first sharing device verifies the first device through the authentication service device. In this case, Figure 2 the provided method can refer to the following Figure 7 provided communication method. As Figure 7 shown, the communication method includes:
[0239] S701, the first device sends a first request message to the first sharing device. Correspondingly, the first sharing device receives the first request message from the first device.
[0240] The first request message is also used to indicate the information of the interface of the verification service. The verification service is used to verify the non-3GPP first device. Based on the interface information of the verification service, the first device can access the authentication service device.
[0241] In addition, for the implementation principle of the first request message, reference can be made to the relevant introduction in S201.
[0242] S702, the first sharing device verifies the first device through the authentication service device.
[0243] The authentication service device can be a function node controlled by a third party. Based on the identity information proprietary to the third party, it is used to provide identity confirmation for the first device authorized by the third party, and to confirm the legitimacy, validity, etc. of the first device.
[0244] For the implementation principle of S702, reference can be made to the relevant introduction in S209. The difference is that the fourth device is the authentication service device, which will not be elaborated here.
[0245] S703, the first shared device stores the device identity information in the first request message.
[0246] Optionally, in S703, when the first device passes the verification, the first shared device stores the device identity information in the first request message.
[0247] For the implementation principle of the first shared device storing the device identity information in the first request message, reference can be made to the relevant introduction in S203, which will not be elaborated here.
[0248] S704, when the first device passes the verification, the first shared device publishes the device identity information in the first request message.
[0249] Optionally, S704 may include: when the first device passes the verification, the first shared device publishes the device identity information in the first request message.
[0250] For the implementation principle of the first shared device publishing the device identity information in the first request message, reference can be made to the relevant introduction in S204, which will not be elaborated here.
[0251] S705, the first shared device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first shared device.
[0252] For the implementation principle of S705, reference can be made to Figure 4 the relevant introduction of S405 therein, which will not be elaborated here.
[0253] Regarding Figure 7 the technical effects of the provided method, reference can be made to the above Figure 2 the technical effects of the provided method, which will not be elaborated here.
[0254] In some possible embodiments, a device can obtain the device identity information of other devices from a shared device. As Figure 8 shown:
[0255] S801, the fourth device sends a third request message to the second shared device. Correspondingly, the second shared device receives the third request message from the fourth device.
[0256] Among them, the third request message is used to request the device identity information corresponding to the fifth device. For the implementation principle of the third request, reference can be made to Figure 2 the relevant introduction in the provided method, which will not be elaborated here.
[0257] The fourth device can be a device corresponding to an individual, organization or institution, such as the first type of device or the second type of device in the above-mentioned Figure 1 provided communication system. In some possible implementation scenarios, the device type of the fourth device can be a 3GPP device, and in some possible implementation manners, the device type of the fourth device can be a non-3GPP device.
[0258] In Figure 8 the provided method, the second shared device is a device with data storage function, and the second shared device can interact with other devices. The second shared device can be the first type of shared device. At this time, in one possible implementation scenario, the second shared device can also be the first shared device in the above-mentioned Figure 2 provided method. Or, the second shared device can also be the second type of shared device. The fourth device can be a device in a 3GPP network or a non-3GPP network. At least one device identity information is pre-stored in the second shared device. Each device identity information corresponds to an identifier. For the implementation principle of the device identity information, reference can be made to the relevant introduction in the above-mentioned Figure 2 which will not be elaborated here.
[0259] The second shared device will be described below in combination with different scenarios.
[0260] Scenario 3, the second shared device can be a device in a 3GPP network. For example, the second shared device can be a network element in the core network. Among them, the network element of the core network can also be a node in the blockchain. In this case, the implementation principle of the second shared device can reference the above-mentioned first shared device.
[0261] Scenario 4, the second shared device can be a device in a non-3GPP network. For example, the implementation of the second shared device can reference the first shared device, the difference is that the ownership of the second shared device is different from that of the first shared device, or rather, the owner of the second shared device is different from the owner of the first shared device. Another example is that the second shared device can be a device corresponding to a distributed node in a distributed storage system, or a device corresponding to a blockchain node in a blockchain system, or other devices with storage functions.
[0262] Optionally, the third request message can further include information for indicating the device type of the fourth device.
[0263] Optionally, the third request message can include information for indicating the identifier of the fifth device.
[0264] S802. The second shared device authenticates according to the access credential of the fourth device.
[0265] If the fourth device is a 3GPP device, the second shared device authenticates according to the access credential of the fourth device, including: the second shared device authenticates with the authentication network element according to the access credential of the fourth device. For the principle of the second shared device authenticating with the authentication network element according to the access credential of the fourth device, reference can be made to the relevant introduction in S602.
[0266] If the fourth device is a non-3GPP device, the second shared device authenticates according to the access credential of the fourth device, including: the second shared device authenticates with the authentication service device according to the access credential of the fourth device. For the principle of the second shared device authenticating with the authentication service device according to the access credential of the fourth device, reference can be made to the relevant introduction in S702, which will not be elaborated here.
[0267] In this case, the third request message may further include information for indicating the access credential of the fourth device. The access credential of the fourth device is used to verify the identity of the fourth device. If the fourth device is a 3GPP device, then the access credential of the fourth device may be information for authentication in the 3GPP network, such as a username, a user password, or the ID information already registered by the fourth device. If the fourth device is a non-3GPP device, then the access credential of the fourth device may be the VC corresponding to the fourth device.
[0268] S803. The second shared device resolves the identifier of the fifth device to obtain the device identity information corresponding to the identifier of the fifth device.
[0269] Optionally, the second shared device resolves the identifier of the fifth device to obtain the device identity information corresponding to the identifier of the fifth device, which may include: when the authentication of the fourth device is successful, the second shared device resolves the identifier of the fifth device to obtain the device identity information corresponding to the identifier of the fifth device.
[0270] In a possible implementation, the third request message may be implemented by invoking a resolution service interface, such as the "Resolve() service interface". Exemplarily, the resolution service interface may be represented as a RESTful API. This API conforms to the URI rule standard. The interface address of this API includes: the host name of the second shared device. The first device can access or invoke this API through this interface address. The parameters (i.e., input parameters) required to be provided when invoking this API include: access verification information (such as an access credential) and the identifier of the fifth device. The response information of this API includes: the third response message.
[0271] S804, the second shared device sends a third response message to the fourth device. Correspondingly, the fourth device receives the third response message from the second shared device.
[0272] The third response message includes device identity information corresponding to the identifier of the fifth device.
[0273] Optionally, the third response message may further include information indicating that the fourth device has successfully requested device identity information. For example, the third response message may be used to indicate that the first shared device has successfully stored the device identity information. Alternatively, the third response message may be used to indicate that the first shared device has failed to store the device identity information.
[0274] Based on Figure 8 the provided method, the fourth device may request attribute information corresponding to the identifier of the fifth device from the second shared device, thereby obtaining device identity information.
[0275] The above Figures 2 - 8 has described in detail the communication method provided by the embodiments of the present application. The following Figures 9 - 10 will describe in detail the communication device for executing the communication method provided by the embodiments of the present application.
[0276] Exemplarily, Figure 9 is a schematic structural diagram of the communication device provided by the embodiments of the present application Figure 1 . As Figure 9 shown, the communication device 900 includes: a processing module 901 and a transceiver module 902. For ease of description, Figure 9 only the main components of the communication device 900 are shown.
[0277] In some embodiments, the communication device 900 may be applicable to Figure 1 the communication system shown in Figure 2 , Figures 4 - 7 and perform the functions of the first device in the communication method shown in
[0278] The processing module 901 is configured to obtain a first request message. The first request message is used to store device identity information. The device identity information includes the device type of the communication device 900 and / or the device type of the second device. The transceiver module 902 is configured to send the first request message to the first shared device. The first shared device is a network element in the communication network.
[0279] In a possible implementation, the device type may include: a 3rd Generation Partnership Project (3GPP) terminal, a network element of an operator, or a non-3GPP terminal.
[0280] In a possible implementation, the communication device 900 is a 3GPP terminal, and the first request message can also be used to indicate the authentication information of the communication device 900. The authentication information of the communication device 900 can be used to verify the access of the terminal to the network, avoiding the access of unauthenticated terminals to the network, thus making the communication more secure.
[0281] In a possible implementation, the authentication information of the communication device 900 can include the access credentials of the communication device 900.
[0282] In a possible implementation, the transceiver module 902 is further configured to send the first request message to the first shared device through an authentication network element.
[0283] In a possible implementation, the communication device 900 is a non-3GPP terminal, and the first request message is also used to indicate the information of the interface of the authentication service. The authentication service is used to authenticate the non-3GPP terminal.
[0284] In a possible implementation, if the device identity information includes the device type of the communication device 900, the device identity information further includes one or more of the following: the first identifier of the communication device 900, the owner of the entity corresponding to the communication device 900, the information for verifying the ownership of the first identifier, the entity type corresponding to the communication device 900, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the communication device 900, and the encryption method corresponding to the communication device 900.
[0285] In a possible implementation, if the device identity information includes the device type of the second device, the device identity information can further include one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, the information for verifying the ownership of the second identifier, the entity type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, and the encryption method corresponding to the second device.
[0286] In a possible implementation, the first request message is also used to publish the device identity information.
[0287] In a possible implementation, the transceiver module 902 is further configured to receive a first response message from the first shared device. The first response message is used to indicate whether the first shared device has successfully stored the device identity information.
[0288] In a possible implementation, the transceiver module 902 is further configured to send a second request message to a second sharing device. The second request message is used to request the device identity information corresponding to a third device. The communication device 900 receives a second response message from the second sharing device. The second response message is used to indicate the device identity information corresponding to the third device.
[0289] Optionally, the transceiver module 902 may include a receiving module and a sending module ( Figure 9 not shown in the figure). The transceiver module 902 is configured to implement the sending function and the receiving function of the communication device 900.
[0290] Optionally, the communication device 900 may further include a storage module ( Figure 9 not shown in the figure), and the storage module stores programs or instructions. When the processing module 901 executes the programs or instructions, the communication device 900 can execute Figure 2 、 Figures 4 - 7 the functions of the first device in any of the communication methods shown.
[0291] It should be understood that the processing module 901 involved in the communication device 900 may be implemented by a processor or processor-related circuit components, and may be a processor or a processing unit; the transceiver module 902 may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or a transceiver unit.
[0292] It should be noted that the communication device 900 may be a terminal device, or a chip (system) or other components or assemblies that can be set in the terminal device, or a device including the terminal device. The present application does not make any limitations in this regard.
[0293] In addition, the technical effects of the communication device 900 can refer to Figure 2 、 Figures 4 - 7 the technical effects of any of the communication methods shown, and will not be elaborated here.
[0294] In some other embodiments, the communication device 900 may be applicable to Figure 1 the communication system shown, and execute Figure 2 、 Figures 4 - 7 the functions of the first sharing device in the communication methods shown.
[0295] Among them, the transceiver module 902 is configured to receive a first request message from a first device. The first request message is used to store device identity information. The device identity information includes the device type of the first device and / or the device type of the second device. The processing module 901 is configured to store the device identity information in the first request message.
[0296] In a possible implementation, the device type may include: a 3rd Generation Partnership Project (3GPP) terminal, a network element of an operator, or a non-3GPP terminal.
[0297] In a possible implementation, the first device is a 3GPP terminal, and the first request message is further used to indicate the authentication information of the first device.
[0298] In a possible implementation, the authentication information of the first device includes the access credentials of the first device.
[0299] In a possible implementation, the transceiver module 902 is further configured to receive, via an authentication network element, a first request message from the first device.
[0300] In a possible implementation, the first device is a 3GPP terminal, and the processing module 901 is further configured to verify the first device via an authentication network element. The processing module 901 is further configured to store the device identity information in the first request message when the first device passes the verification.
[0301] In a possible implementation, the first device is a non-3GPP terminal, and the first request message is further used to indicate information about the interface of a verification service. The verification service is used to verify the non-3GPP terminal.
[0302] In a possible implementation, if the device identity information includes the device type of the first device, the device identity information includes one or more of the following: the first identifier of the first device, the owner of the entity corresponding to the first device, information for verifying the ownership of the first identifier, the entity corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, the encryption method corresponding to the first device.
[0303] In a possible implementation, if the device identity information includes the device type of the second device, the device identity information includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information for verifying the ownership of the second identifier, the entity corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, the encryption method corresponding to the second device.
[0304] In a possible implementation, the first request message is further used to publish the device identity information, and the processing module 901 is further configured to publish the device identity information.
[0305] In a possible implementation, the transceiver module 902 is further configured to send a first response message to the first device.
[0306] In a possible implementation, the transceiver module 902 is further configured to send device identity information to a second sharing device.
[0307] In a possible implementation, the transceiver module 902 is further configured to receive a third request message from a fourth device. The third request message is used to request the device identity information corresponding to a fifth device. The transceiver module 902 is further configured to send a third response message. The third response message is used to indicate the device identity information corresponding to the fifth device.
[0308] In a possible implementation, the processing module 901 is further configured to verify the fourth device through an authentication service device.
[0309] Optionally, the transceiver module 902 may include a receiving module and a sending module ( Figure 9 not shown in the figure). Wherein, the transceiver module 902 is used to implement the sending function and the receiving function of the communication device 900.
[0310] Optionally, the communication device 900 may further include a storage module ( Figure 9 not shown in the figure), and the storage module stores programs or instructions. When the processing module 901 executes the programs or instructions, the communication device 900 can execute Figure 2 、 Figures 4 - 7 the functions of the first device in the communication methods shown in any one of
[0311] It should be understood that the processing module 901 involved in the communication device 900 may be implemented by a processor or processor-related circuit components, and may be a processor or a processing unit; the transceiver module 902 may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or a transceiver unit.
[0312] It should be noted that the communication device 900 may be a network device, or a chip (system) or other components or assemblies that can be disposed in a network device, or a device including a network device. The present application does not make any limitations in this regard.
[0313] In addition, the technical effects of the communication device 900 can be referred to Figure 2 、 Figures 4 - 7 the technical effects of the communication methods shown in any one of
[0314] In some other embodiments, the communication device 900 may be applicable to Figure 1 the communication system shown in Figure 2 、 Figures 4 - 7 and execute the functions of the first device in the communication methods shown in
[0315] The processing module 901 is configured to send a third request message to the second sharing device via the transceiver module 902. The third request message is used to request the device identity information corresponding to the identifier of the fifth device. The processing module 901 is further configured to receive a third response message from the second sharing device via the transceiver module 902. The third response message includes the device identity information corresponding to the identifier of the fifth device.
[0316] In a possible implementation, the third request message may further include information indicating the access credential of the communication device 900. The access credential of the communication device 900 is used to verify the identity of the communication device 900.
[0317] In a possible implementation, the third request message may further include information indicating the device type of the communication device 900.
[0318] Optionally, the transceiver module 902 may include a receiving module and a sending module ( Figure 9 not shown in the figure). The transceiver module 902 is configured to implement the sending function and the receiving function of the communication device 900.
[0319] Optionally, the communication device 900 may further include a storage module ( Figure 9 not shown in the figure), and the storage module stores programs or instructions. When the processing module 901 executes the programs or instructions, the communication device 900 can perform Figure 8 the functions of the first device in the communication method shown in the figure.
[0320] It should be understood that the processing module 901 involved in the communication device 900 may be implemented by a processor or processor-related circuit components, and may be a processor or a processing unit; the transceiver module 902 may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or a transceiver unit.
[0321] It should be noted that the communication device 900 may be a terminal device, or a chip (system) or other components or assemblies that can be set in a terminal device, or a device including a terminal device. The present application does not make any limitations in this regard.
[0322] In addition, the technical effects of the communication device 900 may refer to Figure 8 the technical effects of the communication method shown in the figure, which will not be elaborated here.
[0323] In some other embodiments, the communication device 900 may be applicable to Figure 1 the communication system shown in the figure, and perform Figure 8 the functions of the second sharing device in the communication method shown in the figure.
[0324] Among them, the processing module 901 is configured to receive, via the transceiver module 902, a third request message from a fourth device. The third request message is used to request device identity information corresponding to the identity of a fifth device. The processing module 901 is further configured to send, via the transceiver module 902, a third response message to the fourth device. The third response message includes the device identity information corresponding to the identity of the fifth device.
[0325] In a possible implementation, the processing module 901 is further configured to parse the identity of the fifth device to obtain the device identity information corresponding to the identity of the fifth device.
[0326] In a possible implementation, the third request message is used to indicate information about the access credential of the fourth device. The access credential of the fourth device is used to authenticate the fourth device. The processing module 901 is further configured to perform identity authentication with a second shared device according to the access credential of the fourth device.
[0327] In a possible implementation, the third request message may further include information for indicating the device type of the fourth device.
[0328] Optionally, the transceiver module 902 may include a receiving module and a sending module ( Figure 9 not shown in the figure). The transceiver module 902 is configured to implement the sending function and the receiving function of the communication device 900.
[0329] Optionally, the communication device 900 may further include a storage module ( Figure 9 not shown in the figure), and the storage module stores programs or instructions. When the processing module 901 executes the programs or instructions, the communication device 900 can perform Figure 9 the functions of the second shared device in the communication method shown in the figure.
[0330] It should be understood that the processing module 901 involved in the communication device 900 may be implemented by a processor or processor-related circuit components, and may be a processor or a processing unit; the transceiver module 902 may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or a transceiver unit.
[0331] It should be noted that the communication device 900 may be a network device, or a chip (system) or other components or assemblies that can be disposed in a network device, or a device including a network device. The present application does not make any limitations in this regard.
[0332] In addition, the technical effects of the communication device 900 may refer to Figure 8 the technical effects of the communication method shown in the figure, which will not be elaborated here.
[0333] Exemplarily, Figure 10 is a schematic structural diagram of the communication device provided by an embodiment of the present applicationFigure 2 The communication device can be a terminal or a network device, or can be a chip (system) or other components or assemblies that can be disposed in a terminal device or a network device. For example Figure 10 As shown, the communication device 1000 may include a processor 1001. Optionally, the communication device 1000 may further include a memory 1002 and / or a transceiver 1003. Among them, the processor 1001 is coupled to the memory 1002 and the transceiver 1003, and can be connected through a communication bus, for example
[0334] Next, a specific introduction to each component of the communication device 1000 will be given in conjunction with Figure 10 :
[0335] Among them, the processor 1001 is the control center of the communication device 1000, and can be a single processor or a collective term for multiple processing elements. For example, the processor 1001 is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or is one or more integrated circuits configured to implement the embodiments of the present application. For example: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0336] Optionally, the processor 1001 can execute various functions of the communication device 1000 by running or executing software programs stored in the memory 1002 and calling data stored in the memory 1002
[0337] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as Figure 10 the CPU0 and CPU1 shown in
[0338] In a specific implementation, as an embodiment, the communication device 1000 may also include multiple processors, such as Figure 10 the processor 1001 and the processor 1004 shown in. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0339] Among them, the memory 1002 is used to store the software program for executing the solution of this application, and is controlled by the processor 1001 to execute. The specific implementation method can refer to the above method embodiment and will not be elaborated here.
[0340] Optionally, the memory 1002 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1002 can be integrated with the processor 1001 or exist independently, and is coupled to the processor 1001 through the interface circuit of the communication device 1000 ( Figure 10 not shown in the figure), and the embodiments of this application do not make specific limitations on this.
[0341] The transceiver 1003 is used for communication with other communication devices. For example, when the communication device 1000 is a terminal device, the transceiver 1003 can be used for communication with a network device or with another terminal device. Another example is that when the communication device 1000 is a network device, the transceiver 1003 can be used for communication with a terminal device or with another network device.
[0342] Optionally, the transceiver 1003 can include a receiver and a transmitter ( Figure 10 not shown separately in the figure). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.
[0343] Optionally, the transceiver 1003 can be integrated with the processor 1001 or exist independently, and is coupled to the processor 1001 through the interface circuit of the communication device 1000 ( Figure 10 not shown in the figure), and the embodiments of this application do not make specific limitations on this.
[0344] It should be noted that Figure 10The structure of the communication device 1000 shown does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than those shown, or combine certain components, or have a different component arrangement.
[0345] In addition, for the technical effects of the communication device 1000, reference may be made to the technical effects of the communication method described in the foregoing method embodiments, which will not be elaborated herein.
[0346] An embodiment of this application provides a communication system. The communication system includes one or more of the foregoing terminal devices and one or more network devices.
[0347] It should be understood that the processor in the embodiments of this application may be a CPU, and the processor may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc.
[0348] It should also be understood that the memory in the embodiments of this application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory may be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0349] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0350] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context.
[0351] In this application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0352] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0353] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and implementation constraints of the technical solution. Skilled artisans may use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0354] Those skilled in the art can clearly understand that for the sake of convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0355] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0356] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0357] In addition, the functional units in each embodiment of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0358] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0359] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A communication method, characterized in that: The method comprises: The first device obtains a first request message; the first request message is used to store device identity information; The first device sends the first request message to a first shared device; the first shared device is a network element in a communication network.
2. The method according to claim 1, characterized in that The device identity information includes a device type of the first device and / or a device type of the second device.
3. The method according to claim 2, characterized in that The device type includes: a 3rd Generation Partnership Project 3GPP terminal, a network element of an operator, or a non-3GPP terminal.
4. The method according to claim 3, characterized in that The first device is a 3GPP terminal, and the first request message is also used to indicate authentication information of the first device.
5. The method according to claim 4, characterized in that The authentication information of the first device includes access credentials of the first device.
6. The method according to claim 4 or 5, characterized in that: The first device sending the first request message to the first sharing device includes: The first device sends the first request message to the first shared device through an authentication network element.
7. The method according to claim 3, characterized in that The first device is a non-3GPP terminal, and the first request message is further used to indicate information of an interface of a verification service; the verification service is used to verify the non-3GPP terminal.
8. The method according to any one of claims 1 to 7, characterized in that If the device identity information includes the device type of the first device, the device identity information also includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject type corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.
9. The method according to any one of claims 1 to 8, characterized in that If the device identity information includes the device type of the second device, the device identity information also includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, and the encryption method corresponding to the second device.
10. The method according to any one of claims 1 to 9, characterized in that The first request message is also used to publish the device identity information.
11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: The first device receives a first response message from the first sharing device; wherein the first response message is used to indicate whether the first sharing device successfully stores the device identity information.
12. The method according to any one of claims 1 to 11, characterized in that The method further comprises: The first device sends a second request message to the second shared device; wherein the second request message is used to request device identity information corresponding to the third device; The first device receives a second response message from the second sharing device; wherein the second response message is used to indicate device identity information corresponding to the third device.
13. A communication method, characterized in that: The method further comprises: The first sharing device receives a first request message from the first device; the first request message is used to store device identity information; The first shared device stores the first request message.
14. The method according to claim 13, characterized in that The device identity information includes a device type of the first device and / or a device type of the second device.
15. The method according to claim 14, characterized in that The device type includes: a 3rd Generation Partnership Project 3GPP terminal, a network element of an operator, or a non-3GPP terminal.
16. The method according to claim 15, characterized in that The first device is a 3GPP terminal, and the first request message is also used to indicate authentication information of the first device.
17. The method according to claim 16, characterized in that The authentication information of the first device includes access credentials of the first device.
18. The method according to claim 15 or 16, characterized in that The first sharing device receives a first request message from a first device, including: The first shared device receives a first request message from the first device through the authentication network element.
19. The method according to claim 15, characterized in that The first device is a 3GPP terminal, and the method further includes: The first shared device authenticates the first device through an authentication network element; The first sharing device storing the first request message includes: When the first device passes authentication, the first sharing device stores the first request message.
20. The method according to claim 15, characterized in that The first device is a non-3GPP terminal, and the first request message is further used to indicate information of an interface of a verification service; the verification service is used to verify the non-3GPP terminal.
21. The method according to any one of claims 13 to 20, characterized in that If the device identity information includes the device type of the first device, the device identity information includes one or more of the following: the device identity information includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credentials corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.
22. The method according to any one of claims 13 to 20, characterized in that If the device identity information includes the device type of the second device, the device identity information includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, and the encryption method corresponding to the second device.
23. The method according to any one of claims 13 to 22, characterized in that The first request message is also used to publish the device identity information. The method further includes: The first sharing device publishes the device identity information.
24. The method according to any one of claims 13 to 23, characterized in that The method further comprises: The first sharing device sends a first response message to the first device.
25. The method according to any one of claims 13 to 24, characterized in that The method further comprises: The first sharing device sends the device identity information to the second sharing device.
26. The method according to any one of claims 13 to 25, characterized in that The method further comprises: The first sharing device receives a third request message from a fourth device; the third request message is used to request device identity information corresponding to the fifth device; The first sharing device sends a third response message to the fourth device; the third response message is used to indicate device identity information corresponding to the fifth device.
27. The method according to claim 26, characterized in that The method further comprises: The shared device verifies the fourth device through an authentication service device.
28. A communication device, characterized in that: The communication device is used to execute the communication method according to any one of claims 1 to 27.
29. A communication device, characterized in that: include: a processor coupled to the memory; The processor is configured to execute a computer program stored in the memory so that the communication device executes the communication method according to any one of claims 1 to 27.
30. A communication device, characterized in that: include: processor and interface circuit; wherein, The interface circuit is used to receive code instructions and transmit them to the processor; The processor is configured to execute the code instructions to perform the method according to any one of claims 1-27.
31. A communication device, characterized in that: The communication device includes a processor and a transceiver, the transceiver is used for information exchange between the communication device and other communication devices, and the processor executes program instructions to perform the communication method according to any one of claims 1-27.
32. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a computer program or an instruction. When the computer program or the instruction is executed on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 27.
33. A computer program product, characterized in that The computer program product comprises: a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 27.
Citation Information
Cited By
Communication method and communication apparatus
EP4797752A1
Communication method and communication apparatus
WO2025103482A1