A communication method and a communication device
The authentication between devices is realized through the core network, which solves the problem of distance limitation in the existing technology, realizes the flexibility of remote control between devices, and meets the needs of the Internet of Things.
Patent Information
- Application Number
- CN202010605441.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-29
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-06-29
AI Technical Summary
In the prior art, authentication between devices is limited by distance, and the flexibility of remote control between devices cannot be achieved, and the needs of the Internet of Things cannot be met.
The authentication of the device is realized through the core network, and the authentication network element is used to receive the identification information of the device, determine the permissions of the device, and transmit the permission information through the core network equipment to complete the authentication and remote control between devices.
It realizes authentication between devices without being restricted by distance, greatly improving the flexibility of remote control between devices, and meeting the needs of the Internet of Things.
Smart Images

Figure CN113938879B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communications, and in particular, to a communication method and a communication device. Background Art
[0002] The Internet of Things (IoT) is an extended and expanded network based on the Internet. It combines various information sensing devices with the Internet to form a huge network. Based on the network, it can realize the interconnection and communication of people, machines and things.
[0003] In the prior art, when two devices are in the same local area network, the devices can authenticate each other through the local area network; or, the two devices can be paired via Bluetooth and authenticated based on the Bluetooth connection. After authentication, the two devices can communicate through the core network to achieve remote control of one device over another. In this mode, device authentication is limited by the distance between the devices. Two devices at a long distance must first be authenticated through short-range communication (WiFi or Bluetooth) before one device can remotely control another device. Management is not flexible enough and cannot meet the needs of the Internet of Things. Summary of the invention
[0004] The embodiments of the present application provide a communication method and a communication device, which can improve the flexibility of remote control between devices and meet the current needs of the Internet of Things.
[0005] In the first aspect, a communication method is provided, which can be applied to control authentication network elements. The authentication network element can be a network element in the core network that has the function of querying smart contracts and can identify the identity and authority of the owner. The name of the authentication network element is not limited to the control anchor function network element, but can also be named with other names as long as it can meet the above functions. The method includes: receiving a first message sent by a first device, the first message is used to request a second device to perform a first operation, and the first message may include identification information of the second device. It is also possible to determine that the first device has the authority to request the second device to perform the first operation based on the identification information of the second device, and then a second message can be sent to the second device through the core network device, the second message is used to request the second device to perform the first operation, and the second message includes the permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation.
[0006] In the method provided in the embodiment of the present application, the first device initiates a control request to the second device, requesting the second device to perform a first operation. During this process, the service network of the second device can also authenticate the first device to determine that the first device has the authority to request the second device to perform the first operation, and the service network of the second device transmits the control request of the first device to the second device so that the second device performs the first operation. It can be seen that the authentication between devices is not limited by distance. After the authentication of the device is completed through the service network of the second device, the devices can transmit instructions through the user plane connection to achieve control of other devices. The flexibility of remote control between devices is greatly improved, meeting the current needs of the Internet of Things.
[0007] In combination with the first aspect, in a first possible implementation manner of the first aspect, the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device.
[0008] In the method provided in the embodiment of the present application, the authentication network element shares a key with the second device, and the authentication network element can also send a random number to the second device, so that the second device determines the communication key according to the random number and the shared key. When the second device subsequently communicates with the first device, the communication key is used to protect the integrity of the message.
[0009] In combination with the first aspect or the first possible implementation manner of the first aspect, in a second possible implementation manner of the first aspect, the method further includes: sending a key used by the first device and the second device for communication to the first device.
[0010] In the method provided in the embodiment of the present application, the authentication network element can also generate a communication key based on the random number and the authentication network element, and send the communication key to the first device, so that when the first device subsequently communicates with the second device, the communication key is used to protect the integrity of the message.
[0011] In combination with the first aspect or the first or second possible implementation of the first aspect, in a third possible implementation of the first aspect, determining whether the first device has permission to request the second device to perform a first operation based on the identification information of the second device includes: determining a target device group based on the identification information of the second device, the target device group including one or more target devices, and the target device having permission to request the second device to perform the first operation; determining that the first device has permission to request the second device to perform the first operation based on one or more target devices including the first device.
[0012] The embodiment of the present application provides a method for authenticating a first device, and a large number of devices can be managed in batches through a group. Specifically, the permissions of each device in the group can also be recorded, and each device in the group can have the same permissions, for example, the permission to request a second device to perform a first operation. If the group to which the first device belongs has control authority over the second device, it is considered that the first device has control authority over the second device.
[0013] In combination with the first aspect or the first or second possible implementation of the first aspect, in a third possible implementation of the first aspect, determining that the first device has the authority to request the second device to perform the first operation based on the identification information of the second device includes: sending the identification information of the second device to the blockchain device; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has the authority to request the second device to perform the first operation, and the one or more target devices include the first device; receiving the permission information of the first device from the blockchain device, and determining that the first device has the authority to request the second device to perform the first operation based on the permission information.
[0014] The embodiment of the present application also provides a method for authenticating a first device, which can manage a large number of devices in batches through groups. The blockchain device stores the information of the device group, and can send the identification information of the second device to the blockchain device. The blockchain device combines the identification information of the first device and the information of the device group to determine whether the first device has the authority to request the second device to perform the first operation. The permission information of the first device can also be returned, and the authentication network element can determine whether the first device has the authority to request the second device to perform the first operation based on the permission information of the first device.
[0015] In combination with the first aspect or the first or second possible implementation of the first aspect, in the fifth possible implementation of the first aspect, the executor of the method is a control anchor function network element; the control anchor function network element belongs to the service network of the second device, and the control anchor function network element is a network element trusted by the home network of the second device.
[0016] In the embodiment of the present application, the network element that performs device authentication is a network element in the service network of the second device and is trusted by the home network of the second device. The device information can be protected during the authentication process to improve communication security.
[0017] In combination with the first aspect or the first to fifth possible implementations of the first aspect, in the sixth possible implementation of the first aspect, determining that the first device has the authority to request the second device to perform the first operation based on the identification information of the second device includes: determining that the first device has the authority to request the second device to perform the first operation based on the identification information of the first device and the identification information of the second device.
[0018] An embodiment of the present application also provides a method for authenticating a first device, which can determine a target device group based on identification information of a second device, and determine whether the first device belongs to the target device group based on the identification information of the first device, thereby determining whether the first device has the authority to request the first device to perform a first operation.
[0019] In combination with the first aspect or the first to sixth possible implementations of the first aspect, in a seventh possible implementation of the first aspect, the method further includes: receiving identification information of the first device from the first device.
[0020] In the method provided in the embodiment of the present application, the authentication network element can also perform two-way authentication with the first device, and the authentication network element can also obtain identification information of the first device from the first device, so as to determine whether the first device has the authority to request the second device to perform the first operation in combination with the identification information of the first device.
[0021] In a second aspect, a communication method is disclosed, including: a second device receives a second message sent by a core network device; the second message is used by a first device to request the second device to perform a first operation, the second message includes permission information of the first device, and the permission information indicates that the first device has permission to request the second device to perform the first operation; the second device performs the first operation according to the permission information.
[0022] In the method provided in the embodiment of the present application, the first device can be authenticated through the service network of the second device. After the authentication is passed, the second device can receive the control request of the first device through the core network device and perform the first operation according to the request of the first device. It can be seen that the authentication between devices is not limited by distance. After the authentication of the device is completed through the service network of the second device, the devices can transmit instructions through the user plane connection to realize the control of other devices. The flexibility of remote control between devices is greatly improved, meeting the current needs of the Internet of Things.
[0023] In combination with the second aspect, in a first possible implementation manner of the second aspect, the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device.
[0024] In combination with the second aspect or the first possible implementation of the second aspect, in the second possible implementation of the second aspect, the method also includes: the second device receives service network information sent by the access network device, the service network information includes the name of the service network accessed by the second device and the first information; the first information is used to indicate whether the service network includes a control anchor point function network element trusted by the home network of the second device; the control anchor point function network element is used to determine whether the first device has the authority to request the second device to perform the first operation.
[0025] In the method provided in the embodiment of the present application, when the second device accesses the network, network trusted information can be sent to inform the second device whether the service network includes a trusted network that can be used for device authentication, so that when other devices (for example, the first device) subsequently initiate a control request for the second device, the device's permissions can be authenticated.
[0026] In combination with the second possible implementation manner of the second aspect, in a third possible implementation manner of the second aspect, the service network information further includes a trust level of the control anchor function network element.
[0027] According to a third aspect, a communication method is provided, comprising: a second device sends a first message to a core network device, the first message being used to verify whether the first device has the authority to request the second device to perform a first operation, the first message including identification information of the first device; the second device receives a second message sent by the core network device, the second message including permission information of the first device, the permission information indicating that the first device has the authority to request the second device to perform the first operation; and the second device performs the first operation according to the permission information.
[0028] In the method provided in the embodiment of the present application, the controlled device (for example, the second device) can also initiate authentication of the owner (for example, the first device) through the first message. In this process, the service network of the second device can authenticate the first device and determine that the first device has the authority to request the second device to perform the first operation. The service network of the second device transmits the control request of the first device to the second device so that the second device performs the first operation. It can be seen that the authentication between devices is not limited by distance. After the authentication of the device is completed through the service network of the second device, the devices can transmit instructions through the user plane connection to achieve control of other devices. The flexibility of remote control between devices is greatly improved, meeting the current needs of the Internet of Things.
[0029] In combination with the third aspect, in a first possible implementation manner of the third aspect, the method also includes: the second device receives a third message from the first device; the third message is used to request the first device to perform the first operation, and the third message includes information about the first operation.
[0030] In the method provided in the embodiment of the present application, after the first device initiates a control request to the second device and requests the second device to perform a first operation, the second device initiates authentication of the first device through the service network.
[0031] In combination with the third aspect or the first possible implementation of the third aspect, in the second possible implementation of the third aspect, the method also includes: the second device receives service network information from the access network device, the service network information includes the name of the service network accessed by the second device and the first information; the first information is used to indicate whether the service network of the second device includes a control anchor function network element trusted by the home network of the second device; the control anchor function network element is used to determine whether the first device has the authority to request the second device to perform the first operation.
[0032] In combination with the third aspect or the first possible implementation manner of the third aspect, in a third possible implementation manner of the third aspect, the service network information also includes a trust level of a control anchor function network element.
[0033] In combination with the third aspect or the first to third possible implementation manners of the third aspect, the first message further includes: information of a first session; the first session is a session for communication between the first device and the second device.
[0034] In a fourth aspect, a communication method is provided, which can be applied to control authentication network elements. The authentication network element can be a network element in the core network that has the function of querying smart contracts and can identify the identity and authority of the owner. The name of the authentication network element is not limited to the control anchor function network element, but can also be named with other names as long as it can meet the above functions. The method includes: receiving a first message from a second device through a core network device, the first message is used to verify whether the first device has the authority to request the second device to perform a first operation, and the first message includes identification information of the first device; determining that the first device has the authority to request the second device to perform the first operation based on the identification information of the first device; sending a second message to the second device through the core network device; the second message includes the permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation.
[0035] In the method provided in the embodiment of the present application, the controlled device (for example, the second device) can also initiate authentication of the owner (for example, the first device) through the first message. In this process, the service network of the second device can authenticate the first device and determine that the first device has the authority to request the second device to perform the first operation. The service network of the second device transmits the control request of the first device to the second device so that the second device performs the first operation. It can be seen that the authentication between devices is not limited by distance. After the authentication of the device is completed through the service network of the second device, the devices can transmit instructions through the user plane connection to achieve control of other devices. The flexibility of remote control between devices is greatly improved, meeting the current needs of the Internet of Things.
[0036] In combination with the fourth aspect, in a first possible implementation manner of the fourth aspect, the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device.
[0037] In combination with the fourth aspect or the first possible implementation manner of the fourth aspect, in a second possible implementation manner of the fourth aspect, the method further includes: sending a key used by the first device and the second device for communication to the first device.
[0038] In combination with the fourth aspect or the first or second possible implementation of the fourth aspect, in a third possible implementation of the fourth aspect, determining that the first device has permission to request the second device to perform a first operation based on the identification information of the first device includes: determining a target device group based on the identification information of the second device, the target device group including one or more target devices, and the target device having permission to request the second device to perform the first operation; determining that the first device has permission to request the second device to perform the first operation based on the identification information of the one or more target devices including the identification information of the first device.
[0039] In combination with the fourth aspect or the first to third possible implementations of the fourth aspect, in a fourth possible implementation of the fourth aspect, determining that the first device has permission to request the second device to perform a first operation based on identification information of the first device includes: sending identification information of the second device and identification information of the first device to the blockchain device; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has permission to request the second device to perform the first operation, and the identification information of the one or more target devices includes the identification information of the first device; receiving permission information of the first device from the blockchain device, and determining that the first device has permission to request the second device to perform the first operation based on the permission information.
[0040] In combination with the fourth aspect or the first to fourth possible implementation methods of the fourth aspect, in the fifth possible implementation method of the fourth aspect, the executor of the method is a control anchor function network element; the control anchor function network element belongs to the service network of the second device, and the control anchor function network element is a network element trusted by the home network of the second device.
[0041] In combination with the fourth aspect or the first to fifth possible implementations of the fourth aspect, in a sixth possible implementation of the fourth aspect, determining that the first device has authority to request the second device to perform the first operation based on the identification information of the first device includes: determining that the first device has authority to request the second device to perform the first operation based on the identification information of the first device and the identification information of the second device.
[0042] In combination with the fourth aspect or the first to sixth possible implementations of the fourth aspect, in a seventh possible implementation of the fourth aspect, the method further includes: receiving identification information of the second device sent by the second device.
[0043] In a fifth aspect, a communication device is provided, which may be the control anchor function network element described in the embodiment of the present application, or a component in the control anchor function network element. The device includes: a communication unit, which is used to receive a first message sent by a first device, the first message is used to request a second device to perform a first operation, and the first message includes identification information of the second device; a processing unit, which is used to determine, based on the identification information of the second device, that the first device has the authority to request the second device to perform the first operation; the communication unit is also used to send a second message to the second device through a core network device, the second message is used to request the second device to perform the first operation, the second message includes permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation.
[0044] In combination with the fifth aspect, in a first possible implementation manner of the fifth aspect, the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device.
[0045] In combination with the fifth aspect or the first possible implementation manner of the fifth aspect, in a second possible implementation manner of the fifth aspect, the communication unit is further used to send a key used by the first device and the second device for communication to the first device.
[0046] In combination with the fifth aspect or the first or second possible implementation of the fifth aspect, in the third possible implementation of the fifth aspect, the processing unit is specifically used to determine a target device group based on the identification information of the second device, the target device group including one or more target devices, and the target device has the authority to request the second device to perform the first operation; based on the one or more target devices including the first device, determine that the first device has the authority to request the second device to perform the first operation.
[0047] In combination with the fifth aspect or any one of the first to third possible implementations of the fifth aspect, in a fourth possible implementation of the fifth aspect, the processing unit is specifically used to send identification information of the second device to the blockchain device through the communication unit; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has the authority to request the second device to perform a first operation, and the one or more target devices include the first device; the permission information of the first device is received from the blockchain device through the communication unit, and it is determined that the first device has the authority to request the second device to perform the first operation according to the permission information.
[0048] In combination with the fifth aspect or any one of the first to fifth possible implementations of the fifth aspect, in a sixth possible implementation of the fifth aspect, the communication device is a control anchor function network element; the control anchor function network element belongs to the service network of the second device, and the control anchor function network element is a network element trusted by the home network of the second device.
[0049] In combination with the fifth aspect or any one of the first to sixth possible implementations of the fifth aspect, in the seventh possible implementation of the fifth aspect, the processing unit is specifically used to determine, based on the identification information of the first device and the identification information of the second device, whether the first device has the authority to request the second device to perform the first operation.
[0050] In combination with the fifth aspect or any one of the first to seventh possible implementations of the fifth aspect, in an eighth possible implementation of the fifth aspect, the communication unit is further used to receive identification information of the first device from the first device.
[0051] In a sixth aspect, a communication device is provided, which may be the second device or a component in the second device described in the embodiment of the present application. The communication device includes: a communication unit, which is used to receive a second message sent by a core network device; the second message is used by a first device to request a second device to perform a first operation, and the second message includes permission information of the first device, and the permission information indicates that the first device has permission to request the second device to perform the first operation; and a processing unit, which is used to perform the first operation according to the permission information.
[0052] In combination with the sixth aspect, in a first possible implementation manner of the sixth aspect, the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device.
[0053] In combination with the sixth aspect or the first possible implementation of the sixth aspect, in the second possible implementation of the sixth aspect, the communication unit is also used to receive service network information sent by the access network device, the service network information including the name of the service network accessed by the second device and the first information; the first information is used to indicate whether the service network includes a control anchor point function network element trusted by the home network of the second device; the control anchor point function network element is used to determine whether the first device has the authority to request the second device to perform the first operation.
[0054] In combination with the second possible implementation manner of the sixth aspect, in a third possible implementation manner of the sixth aspect, the service network information also includes a trust level of a control anchor function network element.
[0055] In a seventh aspect, a communication device is provided, which may be the second device or a component in the second device described in an embodiment of the present application. The communication device includes: a communication unit, which is used to send a first message to a core network device, the first message is used to verify whether the first device has the authority to request the second device to perform a first operation, and the first message includes identification information of the first device; the communication unit is also used to receive a second message sent by the core network device, the second message includes permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation; a processing unit, which is used to perform the first operation according to the permission information.
[0056] In combination with the seventh aspect, in a first possible implementation of the seventh aspect, the communication unit is also used to receive a third message from the first device; the third message is used to request the first device to perform the first operation, and the third message includes information about the first operation.
[0057] In combination with the seventh aspect or the first possible implementation of the seventh aspect, in the second possible implementation of the seventh aspect, the communication unit is also used to receive service network information from an access network device, the service network information including the name of the service network accessed by the second device and the first information; the first information is used to indicate whether the service network of the second device includes a control anchor point function network element trusted by the home network of the second device; the control anchor point function network element is used to determine whether the first device has the authority to request the second device to perform the first operation.
[0058] In combination with the second possible implementation manner of the seventh aspect, in a third possible implementation manner of the seventh aspect, the service network information also includes a trust level of a control anchor function network element.
[0059] In combination with the seventh aspect or any one of the first to third possible implementations of the seventh aspect, in a fourth possible implementation of the seventh aspect, the first message also includes: information about a first session; the first session is a session for communication between the first device and the second device.
[0060] In an eighth aspect, a communication device is provided, which may be a control anchor function network element or a component in a control anchor function network element as described in an embodiment of the present application. The communication device includes: a communication unit, which is used to receive a first message from a second device through a core network device, the first message is used to verify whether the first device has the authority to request the second device to perform a first operation, and the first message includes identification information of the first device; a processing unit, which is used to determine, based on the identification information of the first device, that the first device has the authority to request the second device to perform the first operation; the communication unit is also used to send a second message to the second device through the core network device; the second message includes the permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation.
[0061] In combination with the eighth aspect, in a first possible implementation manner of the eighth aspect, the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device.
[0062] In combination with the eighth aspect or the first possible implementation manner of the eighth aspect, in a second possible implementation manner of the eighth aspect, the communication unit is further used to send a key used for communication between the first device and the second device to the first device.
[0063] In combination with the eighth aspect or the first or second possible implementation of the eighth aspect, in the third possible implementation of the eighth aspect, the processing unit is specifically used to determine a target device group based on identification information of the second device, the target device group including one or more target devices, and the target device has the authority to request the second device to perform the first operation; based on the identification information of the one or more target devices including the identification information of the first device, determine that the first device has the authority to request the second device to perform the first operation.
[0064] In combination with the eighth aspect or any one of the first to third possible implementations of the eighth aspect, in a fourth possible implementation of the eighth aspect, the processing unit is specifically used to send identification information of the second device and identification information of the first device to the blockchain device through a communication unit; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has the authority to request the second device to perform a first operation, and the identification information of the one or more target devices includes the identification information of the first device; the permission information of the first device is received from the blockchain device through the communication unit, and it is determined that the first device has the authority to request the second device to perform the first operation according to the permission information.
[0065] In combination with the eighth aspect or any one of the first to fourth possible implementation methods of the eighth aspect, in the fifth possible implementation method of the eighth aspect, the communication device is a control anchor function network element; the control anchor function network element belongs to the service network of the second device, and the control anchor function network element is a network element trusted by the home network of the second device.
[0066] In combination with the eighth aspect or any one of the first to fifth possible implementations of the eighth aspect, in the sixth possible implementation of the eighth aspect, the processing unit is specifically used to determine, based on the identification information of the first device and the identification information of the second device, whether the first device has the authority to request the second device to perform the first operation.
[0067] In combination with the eighth aspect or any one of the first to sixth possible implementations of the eighth aspect, in a seventh possible implementation of the eighth aspect, the communication unit is further used to receive identification information of the second device sent by the second device.
[0068] In a ninth aspect, a communication device is disclosed, characterized in that it includes a processor, the processor is coupled to a memory, and the memory is used to store a computer program. The processor is used to execute the computer program stored in the memory, so that the device executes the method as described in the first aspect, any possible implementation of the first aspect, the fourth aspect, and any possible implementation of the fourth aspect.
[0069] In a tenth aspect, a communication device is disclosed, characterized in that it includes a processor, the processor is coupled to a memory, and the memory is used to store a computer program. The processor is used to execute the computer program stored in the memory, so that the device executes the method described in the second aspect, any possible implementation of the second aspect, the third aspect, and any possible implementation of the third aspect.
[0070] In the eleventh aspect, a readable storage medium is disclosed, including a program or instruction. When the program or instruction is executed by a processor, the method described in the first aspect, any possible implementation of the first aspect, the fourth aspect, and any possible implementation of the fourth aspect is performed.
[0071] In the twelfth aspect, a readable storage medium is disclosed, including a program or instruction. When the program or instruction is executed by a processor, the method described in the second aspect, any possible implementation of the second aspect, the third aspect, and any possible implementation of the third aspect is performed.
[0072] In the thirteenth aspect, a computer program product is disclosed, comprising instructions, which, when executed on a computer, enable the computer to execute the method described in the first aspect and any possible implementation of the first aspect, the second aspect and any possible implementation of the second aspect, the third aspect and any possible implementation of the third aspect, or the fourth aspect and any possible implementation of the fourth aspect.
[0073] In a fourteenth aspect, a wireless communication device is disclosed, comprising: instructions are stored in the wireless communication device; when the wireless communication device runs on the device described in the fifth aspect or the eighth aspect, the device executes the method described in the first aspect and any possible implementation method of the first aspect, the fourth aspect and any possible implementation method of the fourth aspect, and the wireless communication device is a chip.
[0074] In the fifteenth aspect, a wireless communication device is disclosed, comprising: instructions are stored in the wireless communication device; when the wireless communication device is run on the device described in the sixth aspect or the seventh aspect, the device executes the method described in the above-mentioned first aspect and any possible implementation method of the second aspect, the third aspect and any possible implementation method of the third aspect, and the wireless communication device is a chip.
[0075] In the sixteenth aspect, an embodiment of the present application provides a chip, which includes a processor and an interface circuit, which is coupled to the processor, and the processor is used to run a computer program or instruction to implement the method described in the first aspect and any possible implementation of the first aspect, the second aspect and any possible implementation of the second aspect, the third aspect and any possible implementation of the third aspect, or the fourth aspect and any possible implementation of the fourth aspect, and the interface circuit is used to communicate with other modules outside the chip.
[0076] In the seventeenth aspect, an embodiment of the present application provides a communication system, which includes any multiple of a first device, a second device, and a control anchor point function network element.
[0077] Among them, the control anchor point function network element receives a first message sent by the first device, the first message is used to request the second device to perform the first operation, and the first message may include the identification information of the second device. It can also be determined based on the identification information of the second device that the first device has the authority to request the second device to perform the first operation, and then a second message can be sent to the second device through the core network device, the second message is used to request the second device to perform the first operation, and the second message includes the permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation. The second device can receive the second message and perform the first operation according to the permission information.
[0078] Alternatively, the second device sends a first message to the core network device, the first message is used to verify whether the first device has the authority to request the second device to perform the first operation, and the first message includes the identification information of the first device. The control anchor function network element receives the first message from the second device through the core network device; determines that the first device has the authority to request the second device to perform the first operation based on the identification information of the first device; sends a second message to the second device through the core network device; the second message includes the permission information of the first device, and the permission information indicates that the first device has the authority to request the second device to perform the first operation. The second device receives the second message sent by the core network device, and performs the first operation based on the permission information. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] Figure 1 A schematic diagram of a communication system provided in an embodiment of the present application;
[0080] Figure 2 A schematic diagram of a blockchain provided in an embodiment of the present application;
[0081] Figure 3 Another schematic diagram of a communication system provided in an embodiment of the present application;
[0082] Figure 4 A schematic diagram of a service network and a home network provided in an embodiment of the present application;
[0083] Figure 5a A structural block diagram of a communication device provided in an embodiment of the present application;
[0084] Figure 5b Another structural block diagram of a communication device provided in an embodiment of the present application;
[0085] Figure 6 to Figure 9 A flow chart of a communication method provided in an embodiment of the present application;
[0086] Fig.10 A flowchart of an owner update method provided in an embodiment of the present application;
[0087] Fig.11 Another schematic diagram of the process of updating the owner provided by the embodiment of the present application;
[0088] Figure 12 to Figure 17 Another structural block diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0089] Figure 1 A schematic diagram of a communication system to which the technical solution provided in the present application is applicable is given. The communication system may include an access network device 100, a user device (only user device 201 and user device 202 are shown in the figure), a user plane function (UPF) network element 300, a data network (DN) 400, an access and mobility management function (AMF) network element 500, a control anchor function (CAF) network element 600, a unified data management (UDM) network element 700, and an authentication server function (AUSF) network element 800. Figure 1 It is only a schematic diagram and does not constitute a limitation on the applicable scenarios of the technical solution provided in this application.
[0090] In a specific implementation, the access network device 100 can be any device with wireless transceiver functions. Including but not limited to: evolved base stations (E-UTRAN NodeB or e-NodeB or eNB) in LTE, base stations (gNodeB or gNB) or transceiver points (TRP) in 5G or new radio (NR) access technology, base stations of subsequent evolution of 3GPP, access nodes in WiFi systems, wireless relay nodes, wireless backhaul nodes, etc. The base station can be: a macro base station, a micro base station, a micro-micro base station, a small station, a relay station, or a balloon station, etc. Multiple base stations can support the networks of the same technology mentioned above, or they can support the networks of different technologies mentioned above. The base station can include one or more co-sited or non-co-sited TRPs. The access network device can also be a wireless controller, a centralized unit (CU), and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario. The access network device can also be a server, a wearable device, or a vehicle-mounted device, etc. The following description is made by taking the access network device as a base station as an example. The multiple access network devices may be base stations of the same type or different types. The base station may communicate with the terminal device or communicate with the terminal device through a relay station. The terminal device may communicate with multiple base stations of different technologies. For example, the terminal device may communicate with a base station supporting an LTE network or a base station supporting a 5G network, and may also support dual connection with a base station of an LTE network and a base station of a 5G network.
[0091] User device 201 can request user device 202 to perform certain operations. User device 201 can be a terminal such as a mobile phone or a tablet computer; user device 202 can be a lightweight device with simpler functions, and can be a device with wireless transceiver function, which can be deployed on land, including indoors or outdoors, handheld, wearable or vehicle-mounted; it can also be deployed on the water surface (such as ships, etc.); it can also be deployed in the air (for example, on airplanes, balloons and satellites, etc.). It can also be a computer with wireless transceiver function, a virtual reality (VR) user device, an augmented reality (AR) user device, a wireless terminal in industrial control, a vehicle-mounted user device, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a wearable user device, etc. The embodiments of the present application do not limit the application scenarios. It can also be an access user equipment, a vehicle-mounted terminal, an industrial control terminal, a UE unit, a UE station, a mobile station, a mobile station, a remote station, a remote user equipment, a mobile device, a UE user equipment, a user equipment, a wireless communication device, a UE agent or a UE device, etc. The terminal can also be fixed or mobile. The user equipment of the present application can also be a vehicle-mounted module, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit built into the vehicle as one or more components or units, and the vehicle can implement the method of the present application through the built-in vehicle-mounted module, vehicle-mounted module, vehicle-mounted component, vehicle-mounted chip or vehicle-mounted unit.
[0092] The user plane network element 300 can be used as an anchor point on the user plane transmission logical channel to complete functions such as routing and forwarding of user plane data, such as: establishing a channel (i.e., user plane transmission logical channel) with the terminal, forwarding data packets between the terminal and the DN on the channel, and filtering data packets of the terminal, forwarding data, controlling the rate, and generating billing information. The user plane network element can be.
[0093] DN 400 may be an operator network that can provide data transmission services to users, such as an operator network that provides IP multimedia services (IMS) to users. An application server may be deployed in the DN, and the application server may provide data transmission services to users.
[0094] The AMF network element 500 is mainly responsible for terminal access authentication, mobility management, signaling interaction between various network elements, such as: managing the user's registration status, user connection status, user registration, tracking area update, cell switching user authentication and key security.
[0095] The CAF network element 600 is used to verify the identity and authority of the terminal device. In a possible implementation, the CAF network element 600 can communicate with the blockchain, and the CAF network element can query the authentication information stored in the blockchain and authenticate the terminal device based on the acquired information.
[0096] The UDM network element 700 may be used to store user data, such as user contract information, authentication or authorization data, etc.
[0097] Optional, Figure 1 The communication system shown may also include an authentication, authorization and accounting server (AAA) for performing authentication or authorization of the device.
[0098] First, the terms involved in the embodiments of the present application are explained:
[0099] (1) Remote control between devices
[0100] In the Internet of Things, a device can remotely control another device by transmitting operation instructions through the network. For example, in a smart home scenario, the smart device used by the user can remotely control the status of smart appliances, including turning them on or off.
[0101] (2) Blockchain
[0102] refer to Figure 2 , blockchain is a distributed storage architecture that can include multiple blockchain devices. In one possible implementation, blockchain devices can provide storage space for the Internet of Things, which is used to reliably store massive amounts of data and support various services of the Internet of Things. When storing data in the blockchain, the same data can be stored in each blockchain device of the blockchain. It is understandable that when updating data, the data stored in each blockchain device needs to be updated.
[0103] In one possible implementation, information is recorded reliably through smart contracts in the blockchain, such as device identity information, device permission information, etc.
[0104] (3) Control domain
[0105] In an embodiment of the present application, a control domain includes multiple devices, and a device may have control authority over the control domain. For example, a first device requests (or controls, or instructs) a second device in the control domain to perform certain operations. In a possible implementation, the remote control authority of the device is configured with the control domain as the granularity. For example, device A has the authority to control control domain 1, for example, device A has the authority to request certain devices (such as device 1) in control domain 1 to perform operation 1, or device A has the authority to request all devices in control domain 1 to perform operation 1.
[0106] It should be noted that the device that requests the device to perform certain operations can be called the owner or control device, and the device controlled by the owner in the control domain can be called the controlled device. By managing the control domain, unified management and maintenance of UEs in the form of groups can be achieved, and dynamic adjustment of owner permissions can be achieved based on groups.
[0107] In one possible implementation, the dynamic management of the control domain can be achieved through smart contracts. For example, the dynamic management of the control domain xxx can be achieved through smart contract 1 as shown below.
[0108]
[0109] Among them, the smart contract 1 may include identification information of the control domain, identification information of devices in the control domain, and optionally, may also include control domain member update rules.
[0110] For example, in smart contract 1, domain ID is the identifier of the control domain, for example, the identifier of the control domain is "XX"; member is the member of the control domain, that is, the devices included in the control domain, for example, the control domain includes UE_1~UE_i; memberchange rules are the rules that the control domain must meet to update the members, for example, if "UE administrator = request" is satisfied, the member of the control domain is allowed to be updated, that is, the member update request initiated by the administrator of the control domain can be allowed, that is, the administrator of the control domain is allowed to update the members of the control domain. Among them, updating the members of the control domain includes deleting members in the control domain, or adding members in the control domain.
[0111] (4) Device Group
[0112] In an embodiment of the present application, a device group may include multiple owners, and devices in the same device group may have different control permissions for the same control domain. In one possible implementation, the management of the owner can be achieved through a smart contract. For example, for devices in a control domain (or control domain), the smart contract can record the management permissions of different owners for the control domain (or control domain). For example, the dynamic management of the owner can be recorded through the smart contract 2 shown below.
[0113]
[0114] Among them, the smart contract 2 may include identification information of the control domain and permission information of the device. Optionally, it may also include permission update rules or other permission rules of the contract, such as the rental transaction form applicable to the contract.
[0115] For example, domain ID is the identifier of the control domain; domain administrator represents the administrator of the device group. For example, the identifier of the administrator of the device group is owner ID_1; control privilege organization is used to record the control rights of each owner in the device group over the control domain xxx. For example, the owner represented by owner ID_1 has control privilege 1 (privilege 1) over the control domain xxx, and the owner represented by owner ID_2 has control privilege 2 (privilege 2) over the control domain xxx; privilege change rules records the rules for updating rights. For example, if "UEadministrator = request" is satisfied, the owner's rights are allowed to be updated, that is, the member update request initiated by the administrator of the control domain can be allowed, that is, the administrator of the control domain is allowed to update the members of the control domain.
[0116] In an embodiment of the present application, CAF can query the blockchain device to obtain the smart contract and determine whether a device has the authority to control other devices based on the smart contract.
[0117] (5) Service network
[0118] In the embodiment of the present application, the serving network refers to the network to which the device is attached, that is, the network to which the device is connected. The home network may be a Serving network, and may also be referred to as an attached network.
[0119] Example, reference Figure 1 , the devices to be remotely controlled may belong to two different service networks, that is, the devices are connected to different access network devices. For example, user equipment 201 and user equipment 202.
[0120] refer to Figure 3 , the devices for remote control can also be in the same service network, that is, the devices are connected to the same access network device.
[0121] (6) Home Network
[0122] In the embodiment of the present application, the home network is the Home network, which can be considered as the network to which the device is subscribed.
[0123] Example, reference Figure 4 , the device is signed with the operator in Province A, and the operator network in Province A is the device's home network. When the device moves to Province B, it can also access the operator network in Province B, and the operator network in Province B is the device's service network.
[0124] In the prior art, two devices can rely on short-range communication technology (such as WiFi or Bluetooth) to exchange identity information and complete identity authentication. Devices can also communicate through the network side (such as access network device 100) to achieve control between devices. For example, Figure 1 In the system shown, the terminal device 201 can send an instruction set to the access network device 100 to instruct the terminal device 202 to perform a certain operation. The access network device 100 can forward the instruction set to the terminal device 202, and the terminal device 202 can perform the corresponding operation according to the instruction set.
[0125] It can be seen that in the prior art solution of remote control between devices, the authentication between devices is limited by the distance, which also imposes a certain degree of limitation on the remote control between devices. For example, two devices that are far away cannot be directly remotely controlled, and authentication must be completed through short-range communication before remote control between devices can be achieved.
[0126] The embodiment of the present application provides a communication method, which can realize device authentication through the core network, and the authentication between devices is not limited by distance. After completing the authentication through the core network, the device can send instructions through the core network to realize the control of other terminal devices. The flexibility of remote control between devices is greatly improved, meeting the current needs of the Internet of Things.
[0127] The terminal device described in the embodiment of the present application can be Figure 5a The communication device 510 is used to implement the communication device 510. Figure 5a FIG. 5 is a schematic diagram of the hardware structure of a communication device 510 provided in an embodiment of the present application. The communication device 510 includes a processor 5101, a memory 5102, and at least one communication interface ( Figure 5a The communication device 510 may include the communication interface 5103.
[0128] Processor 5101 can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present application.
[0129] The communication interface 5103 uses any transceiver-like device to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.
[0130] The memory 5102 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently or be connected to the processor. The memory may also be integrated with the processor.
[0131] The memory 5102 is used to store computer-executable instructions for executing the solution of the present application, and the execution is controlled by the processor 5101. The processor 5101 is used to execute the computer-executable instructions stored in the memory 5102, thereby realizing the intention processing method provided in the following embodiments of the present application.
[0132] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.
[0133] In a specific implementation, as an embodiment, the processor 5101 may include one or more CPUs, such as Figure 5a CPU0 and CPU1 in.
[0134] In a specific implementation, as an embodiment, the communication device 510 may include multiple processors, such as Figure 5a 5101 and 5106 in the embodiment of the present invention. Each of these processors may be a single-CPU processor or a multi-CPU processor. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0135] In a specific implementation, as an embodiment, the communication device 510 may also include an output device 5104 and an input device 5105. The output device 5104 communicates with the processor 5101 and can display information in a variety of ways. For example, the output device 5104 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 5105 communicates with the processor 5101 and can receive user input in a variety of ways. For example, the input device 5105 may be a mouse, a keyboard, a touch screen device, or a sensor device.
[0136] The communication device 510 can be a general-purpose device or a dedicated device. In a specific implementation, the communication device 510 can be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, an embedded device or a computer with a plurality of Figure 5a The embodiment of the present application does not limit the type of the communication device 510.
[0137] It should be noted that the communication device 510 may be a terminal device, a functional component or assembly implemented on the terminal, or a communication chip, such as a baseband chip. When the communication device 510 is a terminal device, the communication interface may be a radio frequency module. When the communication device 510 is a communication chip, the communication interface 5103 may be an input / output interface circuit of the chip, and the input / output interface circuit is used to read and output baseband signals.
[0138] Figure 5b is a schematic diagram of the structure of a network device. The structure of the network device 520 can be referred to Figure 5b The structure shown.
[0139] The network device includes at least one processor 5201, at least one memory 5202, at least one transceiver 5203, at least one network interface 5204 and one or more antennas 5205. The processor 5201, the memory 5202, the transceiver 5203 and the network interface 5204 are connected, for example, through a bus. The antenna 5205 is connected to the transceiver 5203. The network interface 5204 is used for the network device to be connected to other communication devices through a communication link, for example, the network device is connected to the core network element through the S1 interface. In the embodiment of the present application, the connection may include various interfaces, transmission lines or buses, etc., which are not limited in this embodiment. Optionally, the network device 520 may not include the memory 5202.
[0140] The processor in the embodiment of the present application, such as the processor 5201, may include at least one of the following types: a general-purpose central processing unit (CPU), a digital signal processor (DSP), a microprocessor, an application-specific integrated circuit (ASIC), a microcontroller unit (MCU), a field programmable gate array (FPGA), or an integrated circuit for implementing logical operations. For example, the processor 5201 may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. At least one processor 5201 may be integrated in one chip or located on multiple different chips.
[0141] The memory in the embodiment of the present application, such as memory 5202, may include at least one of the following types: read-only memory (ROM) or other types of static storage devices that can store static information and instructions, random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or electrically erasable programmable read-only memory (EEPROM). In some scenarios, the memory may also be a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this.
[0142] The memory 5202 may be independent and connected to the processor 5201. Optionally, the memory 5202 may be integrated with the processor 5201, for example, integrated into a chip. The memory 5202 may store program codes for executing the technical solutions of the embodiments of the present application, and the execution is controlled by the processor 5201. The various types of computer program codes executed may also be regarded as drivers of the processor 5201. For example, the processor 5201 is used to execute the computer program codes stored in the memory 5202, thereby realizing the technical solutions in the embodiments of the present application.
[0143] The transceiver 5203 can be used to support the reception or transmission of radio frequency signals between the network device and the terminal device, and the transceiver 5203 can be connected to the antenna 5205. Specifically, one or more antennas 5205 can receive radio frequency signals, and the transceiver 5203 can be used to receive the radio frequency signals from the antennas, convert the radio frequency signals into digital baseband signals or digital intermediate frequency signals, and provide the digital baseband signals or digital intermediate frequency signals to the processor 5201, so that the processor 5201 further processes the digital baseband signals or digital intermediate frequency signals, such as demodulation and decoding. In addition, the transceiver 5203 can be used to receive modulated digital baseband signals or digital intermediate frequency signals from the processor 5201, convert the modulated digital baseband signals or digital intermediate frequency signals into radio frequency signals, and send the radio frequency signals through one or more antennas 5205. Specifically, the transceiver 5203 can selectively perform one or more stages of down-mixing and analog-to-digital conversion processing on the RF signal to obtain a digital baseband signal or a digital intermediate frequency signal, and the order of the down-mixing and analog-to-digital conversion processing is adjustable. The transceiver 5203 can selectively perform one or more stages of up-mixing and digital-to-analog conversion processing on the modulated digital baseband signal or digital intermediate frequency signal to obtain a RF signal, and the order of the up-mixing and digital-to-analog conversion processing is adjustable. Digital baseband signals and digital intermediate frequency signals can be collectively referred to as digital signals. A transceiver can be referred to as a transceiver circuit, a transceiver unit, a transceiver device, a transmitting circuit, a transmitting unit, or a transmitting device, etc.
[0144] It should be noted that the network device 520 may be a complete network device, a component or assembly that implements the network device function, or a communication chip. When the network device 520 is a communication chip, the transceiver 5203 may be an interface circuit of the chip, which is used to read and output baseband signals.
[0145] The present application embodiment provides a communication method, in which the owner actively initiates the authentication of the owner's control authority. Figure 6 As shown, the method includes the following process:
[0146] 601. A first device sends a first message to a control anchor function network element, where the first message includes identification information of a second device.
[0147] It should be noted that the first device is the control device or owner described in the embodiment of the present application, and the first device can initiate a request to control the second device through a first message, requesting the second device to perform certain operations. The first message can be a control request, which is used to request (or control or instruct) the second device to perform a first operation, wherein the first operation can be an operation that the user device requests the IoT device to perform, such as power on, power off, adjust the operating status, and other operations.
[0148] In one possible implementation, after the first device initiates a control request, the authentication network element in the core network can authenticate the control authority of the first device, that is, determine whether the first device has the authority to request the second device. In other words, the authentication of the device is performed through the core network and is no longer limited by the distance between the devices. Even if the distance between the first device and the second device is far, the control authority of the device can be verified through the core network. After successful authentication, the devices can also communicate through the core network to realize remote control of the second device by the first device.
[0149] It should be noted that the above-mentioned authentication network element can be called a control anchor function network element, such as the CAF described in the embodiment of the present application. It is understandable that the authentication network element can be a network element in the core network that has the function of querying smart contracts and can identify the identity and authority of the owner. The name of the authentication network element is not limited to the control anchor function network element, and can also be named with other names as long as it can meet the above functions.
[0150] In the embodiment of the present application, the identification information of the second device is used to uniquely identify the second device, and may be the (GPSI) or other UE identification of the second device.
[0151] 602. The control anchor function network element determines, according to the identification information of the second device, that the first device has the authority to request the second device to perform a first operation.
[0152] In the embodiment of the present application, the control anchor point functional network element can determine the control domain (hereinafter referred to as the first control domain) where the second device is located according to the identifier of the second device, and can also determine the device group corresponding to the first control domain (hereinafter referred to as the first device group). The devices in the first device group have the authority to control the first control domain.
[0153] In a specific implementation, the control anchor function network element can obtain the smart contract and verify the control authority of the first device according to the information recorded in the smart contract, for example, whether the first device has the authority to request the second device to perform the first operation. In the embodiment of the present application, the control anchor function network element can verify the control authority of the first device over the second device by combining the information recorded in the smart contract in the following two ways, specifically including:
[0154] The first method is to control the anchor point function network element to obtain the control domain information and the device group information in the locally stored smart contract, and verify the control authority of the first device over the second device based on the obtained information.
[0155] The control domain information includes identification information of the control domain and identification information of devices in the control domain.
[0156] Optionally, the control domain information may further include a control domain member update rule, and members may be added or deleted in the control domain according to the rule.
[0157] In addition, the device group information includes identification information of the device group and the control domain corresponding to the device group, and permission information of each device in the device group.
[0158] Optionally, the device group information may further include a rule for updating device permissions, and the permission information of the devices in the device group may be updated according to the rule.
[0159] It should be noted that the control domain corresponding to the device group is the control domain controlled by the device group, and the devices in the device group have the authority to request the devices in the control domain to perform certain operations. The device group corresponds to the control domain one by one, that is, one device group controls one control domain; or, one device group corresponds to multiple control domains, that is, one device group can control multiple control domains; or, multiple management control domains correspond to the same control domain, that is, different device groups can control the same control domain.
[0160] In a possible implementation, a target device group may be determined according to the identification information of the second device, the target device group including one or more target devices, and the target device has the authority to request the second device to perform the first operation;
[0161] If the one or more target devices include the first device, it is determined that the first device has permission to request the second device to perform the first operation.
[0162] It is understandable that the target control domain can be determined by searching the control domain information according to the identification information of the second device. If the control domain information includes the identification information of the second device, the second device belongs to the control domain, and the control domain is the target control domain.
[0163] Furthermore, the device group information can also be searched according to the identification information of the control domain to determine the target device group; if the device group information includes the identification information of the target control domain, then the device group is the device group corresponding to the target control domain, that is, the target device group described in the embodiment of the present application, and the devices in the target device group have the authority to request (or control) the devices in the target control domain to perform certain operations (for example, the first operation).
[0164] If the first device belongs to the target device group, it is determined that the first device has the authority to control the second device.
[0165] Taking the smart contract 1 and smart contract 2 shown in the previous text as examples, assuming that the identification information of the first device is UE_1 and the identification information of the second device is UE_2, the member information recorded in smart contract 1 includes "UE_2", that is, the control domain xxx includes the second device. Smart contract 2 is found according to the identification "xxx" of the control domain, that is, smart contract 2 records the members and permissions of the device group corresponding to the control domain xxx. The member information recorded in smart contract 2 includes owner ID_1, that is, the device group includes the first device, and the control permission of the first device is "privilege 1", for example, the first device has the permission to request the second device to perform the first operation.
[0166] The second type is that the smart contract for managing the control domain and the device group is stored in the blockchain device, and the blockchain device verifies the control authority of the first device over the second device.
[0167] In the specific implementation, the smart contract stored in the blockchain device records the control domain information and device group information. The specific description of the control domain information and device group information is referred to the previous article and will not be repeated here.
[0168] For example, the control anchor function network element sends the identification information of the first device and the identification information of the second device to the blockchain device.
[0169] The blockchain device can determine the target device group based on the identification information of the second device. The specific process is described in the first method above and will not be repeated here. If the target device group includes the first device, the blockchain device can determine that the first device has the authority to control the second device.
[0170] In addition, the blockchain device can also obtain the permission information of the first device in the device group information, and send the permission information of the first device to the control anchor function network element.
[0171] The control anchor point function network element receives the permission information of the first device from the blockchain device, and can determine, based on the permission information, whether the first device has the permission to control the second device.
[0172] For example, CAF sends a query instruction to the blockchain device, the query instruction includes the identification information of the first device and the identification information of the second device. The blockchain device determines the control domain (i.e., the target control domain) to which the second device belongs based on the identification information of the second device, and then queries the device group corresponding to the control domain to which the second device belongs.
[0173] If the first device belongs to the device group, it can be determined that the first device has the authority to control the target control domain, and the specific control authority of the first device can also be queried, such as privilege 1. The authority information "privilege 1" is sent to the control anchor point functional network element, and the control anchor point functional network element can determine that the first device has the authority to request the second device to perform the first operation based on "privilege 1".
[0174] 603. The control anchor function network element sends a second message to the second device through the core network device; the second message includes permission information of the first device, and the permission information indicates that the first device has the permission to request the second device to perform the first operation.
[0175] The control anchor function network element may send the permission information of the first device to the core network device (eg, AMF or AAA) of the second device.
[0176] The core network device receives the permission information of the first device from the control anchor point function network element, and sends a second message to the second device, where the second message may be a service request (serve request) for requesting the second device to perform the first operation.
[0177] It should be noted that the permission information may indicate whether the first device has the permission to request the second device to perform the first operation. For example, the permission information is 1 bit, and the state of the 1 bit is "0", indicating that the first device does not have the permission to request the second device to perform the first operation; the state of the 1 bit is "1", indicating that the first device has the permission to request the second device to perform the first operation.
[0178] The permission information may also indicate specific permissions of the first device. For example, the permission information includes "control permission 1", indicating that the first device has control permission 1, for example, the first device has the permission to request the second device to perform a first operation. The first operation may be "turn on the second device" or "turn off the second device".
[0179] 604. The second device receives a second message, and performs the first operation according to the permission information in the second message.
[0180] In a specific implementation, the second device can determine, based on the second message, that it can be controlled by the first device and how it can be controlled by the first device.
[0181] In a possible implementation, the permission information in the second message may include identification information of at least one operation, indicating that the first device has the permission to request the second device to perform the above operation. Assume that the operation identification information may be constraint 1, constraint 2, constraint 3, and constraint 4. The representative operations are "power on", "power off", "adjust wind speed", "adjust temperature", etc.
[0182] If the permission information in the second message includes constraint 1, the first device has the permission to request the second device to perform the "power on" operation. After receiving the second message, the second device accepts the request of the first device and performs the "power on" operation.
[0183] Optional, Figure 6 The method shown also includes: before step 601, the second device can receive service network information from the access network device, and the service network information includes the name of the service network accessed by the second device and the first information; the first information is used to indicate whether the service network accessed by the second device includes a control anchor point function network element trusted by the second device's home network.
[0184] Specifically, when the second device attaches to the network, a system message may be received from the access network device, and the system message includes a serving network name field, which may indicate the serving network to which the second device attaches. In the method provided in the embodiment of the present application, the serving network name field is extended, and the extended serving network name field may indicate the serving network name and network credibility information. The serving network name is the name of the network currently accessed by the second device, and the network credibility information is the first information described in the embodiment of the present application.
[0185] In a possible implementation, the first information may also include a network credibility level, which may indicate a trust level of the control anchor function network element.
[0186] Understandably, Figure 6 In the method shown, the control anchor point function network element belongs to the service network of the second device, and the control anchor point function network element is a network element trusted by the home network of the second device.
[0187] Taking 5G (Authentication and Key Agreement, AKA) as an example, in addition to completing two-way authentication between the second device and the network during the 5G AKA process, the home network of the second device needs to inform the second device of the trustworthiness of the service network, that is, the current network security environment. Specifically, UDM can generate an authentication vector AV (authentication vector) based on the long-term key K corresponding to the second device and the sequence number SQN (sequence number) synchronized by the second device, and UDM can also send the authentication vector AV to AUSF.
[0188] AUSF can bind the authentication vector to the AV and the serving network name. The binding method is as follows: AV involves K_AUSF, which is the key established between the second device and AUSF. AUSF derives the key K_SEAF based on the K_AUSF and serving network name fields.
[0189] Among them, the service network name field = original service network name + network credibility information. The network credibility information indicates whether the service network to which the second device is attached contains a CAF trusted by the home network of the second device. Optionally, the trust level of the CAF can also be used. The 5G AKA process can ensure that the attached network cannot falsely report the serving network name to the second device, and therefore can also ensure that the network credibility information can be truly delivered to the second device.
[0190] Optionally, the second message also includes a random number; the random number is used to determine a key used by the second device and the first device to communicate.
[0191] In a specific implementation, the control anchor function network element may send the random number to the second device via a second message.
[0192] The second device may determine the key used by the second device to communicate with the first device based on the random number, the identification information of the first device and K_CAF. The control anchor function network element may send the identification information of the first device to the core network device, and the core network device may send the identification information of the first device to the second device through a second message. K_CAF is the public key of the control anchor function network element.
[0193] It should be noted that the second device can learn that there is a trusted CAF in the core network through the serving network name field obtained during the AKA process, and can provide authentication of the owner. And there is a shared key K_CAF between CAF and UE. In a possible implementation, K_CAF can be derived from K_AMF, where K_AMF is the public key of AMF.
[0194] Optionally, the method further includes: the control anchor point function network element sending a third message to the first device, the third message including a key used by the first device and the second device for communication.
[0195] In a specific implementation, the control anchor function network element determines the key used by the second device and the first device for communication based on the random number, the identification information of the first device and K_CAF. The random number is the same as the random number sent to the second device, which facilitates the end-to-end collaboration between the first device and the second device, and uses the same key to encrypt and decrypt messages. For example, the first device uses the key key to encrypt the message, and the second device can use the key key to decrypt the message from the first device.
[0196] Optionally, the method further includes: the control anchor point function network element receiving identification information of the first device from the first device.
[0197] In a specific implementation, before step 601, the control anchor point function network element may perform two-way authentication with the first device. In this process, the control anchor point function network element may receive identification information of the first device from the first device. In a specific implementation, the control anchor point function network element may perform identity authentication with the first device through the blockchain device.
[0198] Optionally, the control anchor point function network element may determine, based on the identification information of the first device and the identification information of the second device, that the first device has the authority to request the second device to perform the first operation.
[0199] For example, a target device group is determined according to the identification information of the second device; the target device group includes at least one target device, and the target device has the authority to request the second device to perform the first operation. If the identification information of at least one target device includes the identification information of the first device, that is, the first device belongs to the target device group, then the first device has the authority to request the second device to perform the first operation.
[0200] Figure 6In the provided method, before realizing remote control between devices, there is no need for the devices to perform two-way authentication through short-range communication, and remote control between devices is no longer limited by the distance between the devices. Through the service network currently attached to the second device, the authority of the owner to be connected (for example, the first device) is authenticated, and remote control between devices can be realized, which greatly improves the flexibility of remote control and meets the current needs of the Internet of Things.
[0201] The present application also provides a communication method. Figure 6 The difference between the method shown is that the controlled device initiates the authentication of the owner's control authority. Figure 7 As shown, the method comprises the following steps:
[0202] 701. The second device sends a first message to the control anchor function network element through the core network device, where the first message is used to verify whether the first device has the authority to request the second device to perform a first operation, and the first message includes identification information of the first device.
[0203] In a specific implementation, the second device may be informed in advance of the operation that the first device expects the second device to perform, including the first operation. For example, the second device receives a third message sent by the first device; the third message is used to request the first device to perform the first operation, and the third message includes information about the first operation.
[0204] In a possible implementation, in response to the third message, the second device may initiate authentication of the first device to verify whether the first device has the authority to request the second device to perform the first operation.
[0205] For example, the first message may be an authentication request. The second device sends an authentication request to a core network device (e.g., AMF or AAA), and the authentication request includes identification information of the first device. After receiving the authentication request, the core network device may also send an authentication request to a control anchor function network element, and the authentication request sent by the core network device to the control anchor function network element includes identification information of the first device.
[0206] The first message may be an authentication request.
[0207] It should be noted that the detailed introduction of the second device and the first device refers to the relevant description of step 601 above, which will not be repeated here.
[0208] 702. The control anchor function network element determines, according to the identification information of the first device, that the first device has the authority to request the second device to perform the first operation.
[0209] In a specific implementation, the control anchor point functional network element can determine the control domain where the second device is located (hereinafter referred to as the first control domain) according to the identifier of the second device, and can also determine the device group corresponding to the first control domain (hereinafter referred to as the first device group). The devices in the first device group have the authority to control the first control domain.
[0210] In a specific implementation, the control anchor function network element can obtain the smart contract and verify the control authority of the first device according to the information recorded in the smart contract, for example, whether the first device has the authority to request the second device to perform the first operation. In the embodiment of the present application, the control anchor function network element can verify the control authority of the first device over the second device by combining the information recorded in the smart contract in two ways. The above two methods refer to the relevant description of step 602 above, which will not be repeated here.
[0211] 703. The control anchor function network element sends a second message to the second device through the core network device; the second message includes the permission information of the first device.
[0212] In a possible implementation manner, the second message may be session establishment signaling.
[0213] The control anchor function network element sends a session establishment signaling to the core network device, and the session establishment signaling includes the permission information of the first device.
[0214] The core network device receives the session establishment signaling and sends a second message to the second device, where the second message includes the permission information of the first device.
[0215] It should be noted that the permission information indicates that the first device has the permission to request the second device to perform the first operation.
[0216] 704. The second device performs the first operation according to the permission information.
[0217] In a specific implementation, the second device can determine, based on the second message, that it can be controlled by the first device and how it can be controlled by the first device.
[0218] In a possible implementation, the permission information in the second message may include identification information of at least one operation, indicating that the first device has the permission to request the second device to perform the above operation. Assume that the operation identification information may be constraint 1, constraint 2, constraint 3, and constraint 4. The representative operations are "power on", "power off", "adjust wind speed", "adjust temperature", etc.
[0219] If the permission information in the second message includes constraint 1, the first device has the permission to request the second device to perform the "power on" operation. After receiving the second message, the second device accepts the request of the first device and performs the "power on" operation.
[0220] Optional, Figure 7 The method shown also includes: the second device receives service network information from the access network device, the service network information includes the name of the service network accessed by the second device and first information; the first information is used to indicate whether the service network of the second device includes a control anchor point function network element trusted by the home network of the second device; the control anchor point function network element is used to determine whether the first device has the authority to request the second device to perform the first operation.
[0221] Optionally, the service network information also includes a trust level of the control anchor function network element.
[0222] Optionally, the first message further includes: information about a first session; the first session is a session for communication between the first device and the second device.
[0223] Specifically, the authentication request sent by the second device to the core network device (eg, AMF or AAA) may include information of the first session, and the core network device may carry the information of the first session in the second message.
[0224] In a possible implementation manner, the information of the first session includes an identifier of the first session and a token of the first session.
[0225] compared to Figure 6 The method shown, Figure 7 In the method shown, the controlled device (e.g., the second device) initiates authentication of the owner through the attached network. In this method, the owner does not need to find the core network to which the second device is attached in advance, which prevents the second device from exposing too much information to the owner during the process, protects the privacy of the device to a certain extent, and is more conducive to actual deployment.
[0226] The communication method provided by the embodiment of the present application is described below with reference to specific examples. The controlled device is called UE, and the device controlling the UE is called the owner. Figure 6 The same is that the authentication of control authority is initiated by the owner (for example, the first device in the method shown in 6). The verification of the owner's control authority is realized through CAF. The UE (for example, the second device in the method shown in 6) can communicate with CAF through the core network device (for example, AMF or AAA), and the owner can communicate directly with CAF. Figure 8 As shown, the method comprises the following steps:
[0227] 801. The owner sends a control request to the CAF, where the control request includes identification information of the UE and identification information of the owner.
[0228] The control request is used to initiate control of the UE and request the UE to perform certain instruction operations. The control request may be the first message described in the embodiment of the present application. The identification information of the UE is used to uniquely identify the UE and may be the GPSI of the UE or other identification of the UE. The identification information of the owner is used to uniquely identify the owner and may be the owner ID or other identification, which is not limited in the embodiment of the present application.
[0229] Optionally, the control request may also include the control authority of the owner for this control. For example, the control request includes authority information "privilege 1" for requesting the second device to perform a "power on" operation.
[0230] 802. CAF sends a query signaling to the blockchain device to query the control authority of the owner.
[0231] In a specific implementation, the query signaling sent by the CAF includes the identification information of the UE and the identification information of the owner.
[0232] 803. The blockchain device queries the smart contract of the control domain to which the UE belongs to determine the control authority of the owner.
[0233] Among them, the smart contract of the control domain to which the UE belongs is used to dynamically manage the control domain to which the UE belongs. In a specific implementation, the blockchain device determines the control domain to which the UE belongs based on the identification information of the UE. The smart contract of the control domain can also be determined based on the identification information of the control domain to which the UE belongs.
[0234] If the smart contract of the control domain includes the identification information of the owner, it is determined that the owner has the authority to control the UE.
[0235] Optionally, you can also obtain the owner's permission information in the smart contract, for example, "privilege 1".
[0236] 804. The blockchain device sends the owner's permission information to CAF.
[0237] 805. CAF sends a service request to AMF / AAA, where the service request includes the owner ID, the owner's permission information, and a random number.
[0238] The random number (nonce) is used to determine the communication key between the owner and the UE.
[0239] 806. AMF / AAA sends a service request to the UE, including the owner ID, the owner's permission information and the random number.
[0240] 807. The UE sends a response message to the CAF.
[0241] It should be noted that step 807 is an optional step, and the response message is used to respond to the service request sent by AMF / AAA.
[0242] 808. CAF sends a control request confirmation message to the owner.
[0243] The control request confirmation message is used to respond to the control request initiated by the owner in step 801, and the control request confirmation message includes a token.
[0244] It should be noted that the token may also be referred to as a key, which is used for communication between the owner and the UE. In a specific implementation, CAF generates a token based on K_CAF, owner ID, and a random number nonce. The random number nonce is the same as the nonce in steps 805-806 to ensure that the UE can generate the same token based on K_CAF, owner ID, and random number nonce for communication between the owner and the UE.
[0245] 809. The owner initiates a connection to the UE via the data plane.
[0246] It should be noted that the owner uses the token obtained in step 808 to protect the integrity of the message during the connection process. Specifically, the token obtained in step 808 can be directly used as a key to encrypt the message, or a key can be derived from the token and the message can be encrypted according to the derived key.
[0247] In addition, UE can generate a token based on nonce, K_CAF and owner ID. After receiving the message sent by the owner, it decrypts the message based on the generated token.
[0248] The communication method provided by the embodiment of the present application is described below with reference to specific examples. The controlled device is called UE, and the device controlling the UE is called the owner. Figure 7 The same is that the authentication of the control authority is initiated by the controlled UE (for example, the second device in the method shown in 7). Fig. 9 As shown, the method comprises the following steps:
[0249] 901. UE sends an authentication request to AMF / AAA.
[0250] The authentication request includes an owner identity (owner ID), a session ID (session ID) and a session token (token), which are used to initiate authentication of the owner and request the CAF to authenticate the control authority of the owner.
[0251] It should be noted that the session identifier and the session token are parameters that are securely negotiated when the UE and the owner establish a session through the user plane before step 901, and are used to protect the security of the session between the owner and the UE.
[0252] In a possible implementation, the session identifier and the session token may be combined into one parameter, and the session between the owner and the UE is securely protected by the parameter.
[0253] 902. AMF / AAA sends an authentication request to CAF.
[0254] The authentication request includes an owner identity (owner ID), a session ID (session ID) and a session token (token), which are used to request the CAF to authenticate the control authority of the owner.
[0255] 903. CAF sends a query signaling to the blockchain device to query the control authority of the owner.
[0256] In a specific implementation, the query signaling sent by the CAF includes the identification information of the UE and the identification information of the owner.
[0257] 904. The blockchain device queries the smart contract of the control domain to which the UE belongs to determine the control authority of the owner.
[0258] In a specific implementation, the blockchain device determines the control domain to which the UE belongs based on the identification information of the UE. The smart contract of the control domain can also be determined based on the identification information of the control domain to which the UE belongs.
[0259] If the smart contract of the control domain includes the identification information of the owner, it is determined that the owner has the authority to control the UE.
[0260] Optionally, you can also obtain the owner's permission information in the smart contract, for example, "privilege 1".
[0261] 905. The blockchain device sends the owner's permission information to CAF.
[0262] 906. CAF sends an identity authentication request to the owner.
[0263] The identity authentication request includes a session ID provided by the UE, that is, the session ID obtained by the CAF through the authentication request in step 902 .
[0264] 907. The owner sends the identity authentication result to CAF.
[0265] In a specific implementation, the owner first verifies the session identifier. If the session activated by the owner and the currently connected UE is the first session, it indicates that the owner is the device for which the UE requests authentication.
[0266] In addition, the identity authentication result is used to notify the CAF that the owner is the device corresponding to the owner ID in the authentication request, that is, the owner is the device for which the UE requests authentication.
[0267] 908. CAF sends the session token and key to the owner.
[0268] The session token is used by the owner to confirm the authenticity of the UE, which is the same as the session token in step 901 and step 902. CAF generates the key based on K_CAF, owner ID and random number nonce. The key is used to establish a secure control channel between the UE and the owner, and to protect the integrity of the communication between the owner and the UE.
[0269] 909. CAF sends a session establishment signaling of a control channel to UE through AMF / AAA.
[0270] The session establishment signaling includes a random number nonce selected by the CAF. It should be noted that the nonce is the same as the random number used by the CAF when generating the key in step 908.
[0271] 910. The owner initiates a connection to the UE via the data plane.
[0272] It should be noted that the owner uses the key obtained in step 908 to perform integrity protection on the message during the connection process. Specifically, the key obtained in step 908 can be directly used to encrypt the message.
[0273] In addition, UE can generate a key based on nonce, K_CAF and owner ID. After receiving the message sent by the owner, it decrypts the message based on the generated key.
[0274] In the method provided in the embodiment of the present application, the owner or the owner's authority in the device group can also be updated. Specifically, it can be done in the following two modes:
[0275] Mode 1: The administrator of the device group actively assigns permissions to other owners. The administrator of the device group can manage the members of the device group, for example, add or delete owners in the device group. The administrator can also manage the permissions of other owners in the device group, for example, update the permission information of the owner.
[0276] For the convenience of description, the administrator of the device group is referred to as the first owner (Owner 1), and the owner to whom permissions are assigned is referred to as the second owner (Owner 2).
[0277] refer to Fig.10 , the method provided by mode 1 includes the following steps:
[0278] Step S1: The first owner sends an owner update request message to the blockchain device to call the smart contract corresponding to the first owner.
[0279] In a specific implementation, the first owner selects the second owner and obtains the identification information of the second owner. Optionally, the public key of the second owner can also be obtained. The smart contract corresponding to the first owner can be the smart contract of the device group to which the first owner belongs, which is used to manage the owners in the device group.
[0280] In addition, the first owner can also send an owner update request message through the blockchain device, and the owner update request message includes the identification information of the second owner. The owner update request message is used to request to add an owner to the device group, for example, to add the second owner described in the embodiment of the present application.
[0281] Optionally, the owner update request message includes time information, where the time information indicates the expiration time of the permission of the second owner.
[0282] The first owner may also use the private key of the first owner to obtain signature information, and the owner update request message may also include the signature information.
[0283] Step S2: The blockchain device records the identification information of the second owner and the permission information of the second owner into the smart contract of the device group.
[0284] Specifically, the blockchain device can verify whether the call initiated by the owner update request message is valid. For example, the blockchain device verifies the signature information through the public key to determine the identity of the second owner. Alternatively, the blockchain device can also verify whether the first owner has the ability to assign permissions based on the permission update rules recorded in the smart contract of the device group.
[0285] If the verification is successful, that is, the call is valid, the smart contract of the device group is updated, and the second owner and the permission information of the second owner are recorded in the contract.
[0286] Mode 2: The administrator of the device group discloses permission information, and other devices call the smart contract of the device group to obtain control permissions in the form of a rental transaction.
[0287] like Fig.11 As shown, the method provided by Mode 2 includes the following steps:
[0288] Step T1: The first owner sends a lease transaction notification message to call the smart contract corresponding to the first owner.
[0289] In a specific implementation, the rental transaction notification message represents that the first owner will rent and sell the smart contract corresponding to the first owner in the form of a rental transaction. The rental transaction notification message includes a smart contract ID, price details, wallet address, etc. Among them, the smart contract ID is used to indicate the smart contract corresponding to the first owner, which can be a smart contract of the device group to which the first owner belongs, and is used to manage the owners in the device group. The price details represent the price of renting the permission. The wallet address can be a payment account for collecting the rental fee of the permission.
[0290] Step T2: The blockchain device verifies the validity of this call.
[0291] Specifically, the blockchain device can verify whether the current call initiated by the rental transaction notification message is valid. For example, the blockchain device verifies the signature information through the public key to determine the identity of the second owner. Alternatively, the blockchain device can also verify whether the first owner has the ability to assign permissions based on the permission update rules recorded in the smart contract of the device group.
[0292] Optionally, the blockchain device verifies whether the smart contract can update the owner or owner's rights in an external rental manner. If the verification is successful, the state of the smart contract is recorded as a rentable contract.
[0293] If the above verification passes, that is, the blockchain device verifies that the call is valid, and / or the blockchain device verifies that the smart contract can update the owner or owner authority by external leasing, then execute step T3.
[0294] Optionally, the blockchain device verification can also notify the first owner of the verification result.
[0295] Step T3: The second owner sends a contract lease signaling to the blockchain device, requesting to lease the smart contract.
[0296] Specifically, the contract lease signaling is used to initiate a lease transaction, and the contract lease signaling may include the smart contract ID, identification information of the second owner, the second owner's lease authority, and payment information.
[0297] The payment information is used to indicate the payment method of the second owner.
[0298] Step T4: The blockchain device executes the lease transaction initiated by the second owner through the contract lease signaling.
[0299] In a specific implementation, before executing the rental transaction, the blockchain device can verify whether the call initiated by the second owner is valid. For example, the blockchain device can verify whether the payment information is valid.
[0300] After the blockchain device passes the verification, the owner and permission information can be updated. For example, the identification information of the second owner and the permission information rented by the second owner are recorded in the smart contract.
[0301] In addition, after the blockchain device is updated, the contract account executes the payment action, deducts the account balance of the second owner, and updates the balance of the account corresponding to the wallet address mentioned above. For example, if the rental fee is 50¥, 50¥ will be deducted from the second owner's account, and 50¥ will be added to the account corresponding to the wallet address.
[0302] Regardless of mode 1 or mode 2, after the owner or permissions are updated, the smart contract in the blockchain device is in a trusted state.
[0303] The method provided in the embodiment of the present application can realize batch management of massive devices based on the control domain, thereby reducing the difficulty of management. The owner or owner authority can be updated by calling and modifying the smart contract, which is highly feasible and conducive to deployment.
[0304] In the case of dividing each functional module into corresponding functional modules, Fig.12 A possible structural diagram of the communication device involved in the above embodiments is shown. Fig.12 The communication device shown may be the first device described in the embodiment of the present application, or may be a component in the first device that implements the above method, or may be a chip used in the first device. The chip may be a system-on-a-chip (SOC) or a baseband chip with communication functions. Fig.12 As shown, the communication device includes a processing unit 1201 and a communication unit 1202. The processing unit may be one or more processors, and the communication unit may be a transceiver or a communication interface.
[0305] The processing unit 1201, for example, can be used to support the first device to perform internal processing such as message generation or message parsing, for example, to support the first device to generate a first message, and / or other processes for the technology described in this document.
[0306] The communication unit 1202 is used to support communication between the first device and other communication devices, for example, to support interaction between the first device and the second device, to support the first device to execute step 601, etc., and / or other processes for the technology described in this document.
[0307] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0308] like Fig.13As shown, the communication device may further include a storage unit 1203, and the storage unit 1203 is used to store program codes and / or data of the communication device.
[0309] The processing unit 1201 may include at least one processor, the communication unit 1202 may be a transceiver or a communication interface, and the storage unit 1203 may include a memory.
[0310] It should be noted that, in the above-mentioned embodiments of the communication device, each unit may also be referred to as a module, a component, a circuit, etc.
[0311] In the case of dividing each functional module into corresponding functional modules, Fig.14 A possible structural diagram of the communication device involved in the above embodiments is shown. Fig.14 The communication device shown may be the second device described in the embodiment of the present application, or may be a component in the second device that implements the above method, or may be a chip used in the second device. The chip may be a system-on-a-chip (SOC) or a baseband chip with communication functions. Fig.14 As shown, the communication device includes a processing unit 1301 and a communication unit 1302. The processing unit may be one or more processors, and the communication unit may be a transceiver or a communication interface.
[0312] The processing unit 1301 , for example, may be configured to support the second device in executing steps 604 , 704 , and / or other processes for the technology described herein.
[0313] The communication unit 1302 is used to support communication between the second device and other communication devices, for example, to support interaction between the second device and the second device, to support the second device to execute step 601, step 701, step 703, etc., and / or other processes for the technology described in this document.
[0314] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0315] like Fig.15 As shown, the communication device may further include a storage unit 1303, and the storage unit 1303 is used to store program codes and / or data of the communication device.
[0316] The processing unit 1301 may include at least one processor, the communication unit 1302 may be a transceiver or a communication interface, and the storage unit 1303 may include a memory.
[0317] It should be noted that, in the above-mentioned embodiments of the communication device, each unit may also be referred to as a module, a component, a circuit, etc.
[0318] In the case of dividing each functional module into corresponding functional modules, Fig.16 A possible structural diagram of the communication device involved in the above embodiments is shown. Fig.16 The communication device shown may be the control anchor point function network element described in the embodiment of the present application, or may be a component in the control anchor point function network element that implements the above method, or may be a chip used in the control anchor point function network element. The chip may be a system-on-a-chip (SOC) or a baseband chip with communication function. Fig.16 As shown, the communication device includes a processing unit 1401 and a communication unit 1402. The processing unit may be one or more processors, and the communication unit may be a transceiver or a communication interface.
[0319] The processing unit 1401, for example, may be used to support the control anchor function network element to execute steps 602, 702, and / or other processes of the technology described herein.
[0320] The communication unit 1402 is used to support communication between the control anchor point function network element and other communication devices, for example, to support interaction between control anchor point function network elements and control anchor point function network elements, to support the control anchor point function network elements to execute step 603, step 703, etc., and / or other processes for the technology described in this document.
[0321] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0322] like Fig.17 As shown, the communication device may further include a storage unit 1403, and the storage unit 1403 is used to store program codes and / or data of the communication device.
[0323] The processing unit 1401 may include at least one processor, the communication unit 1402 may be a transceiver or a communication interface, and the storage unit 1403 may include a memory.
[0324] It should be noted that, in the above-mentioned embodiments of the communication device, each unit may also be referred to as a module, a component, a circuit, etc.
[0325] The present application embodiment provides a computer-readable storage medium, in which instructions are stored; the instructions are used to execute Figure 6 to Figure 11 The method shown.
[0326] The embodiment of the present application provides a computer program product including instructions, which, when executed on a communication device, enables the communication device to execute the following Figure 6 to Figure 11 The method shown.
[0327] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the communication device can be divided into different functional modules to complete all or part of the functions described above.
[0328] The processor in the embodiment of the present application may include but is not limited to at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor and other types of computing devices that run software, each of which may include one or more cores for executing software instructions to perform operations or processing. The processor may be a separate semiconductor chip, or it may be integrated into a semiconductor chip together with other circuits. For example, it may form a SoC (system on chip) with other circuits (such as a codec circuit, a hardware acceleration circuit, or various buses and interface circuits), or it may be integrated as a built-in processor of an ASIC in the ASIC, and the ASIC with the integrated processor may be packaged separately or with other circuits. In addition to the core for executing software instructions for operations or processing, the processor may further include necessary hardware accelerators, such as field programmable gate arrays (FPGAs), PLDs (programmable logic devices), or logic circuits that implement dedicated logic operations.
[0329] The memory in the embodiments of the present application may include at least one of the following types: read-only memory (ROM) or other types of static storage devices that can store static information and instructions, random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, and electrically erasable programmable read-only memory (EEPROM). In some scenarios, the memory may also be a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this.
[0330] In the present application, "at least one" refers to one or more. "Multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there may be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or its similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the words "first" and "second" are used to distinguish the same or similar items with basically the same functions and effects. Those skilled in the art can understand that the words "first", "second", etc. do not limit the quantity and execution order, and the words "first", "second", etc. do not necessarily limit the differences.
[0331] In the several embodiments provided in the present application, it should be understood that the disclosed database access device and method can be implemented in other ways. For example, the above-described database access device embodiment is only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the database access device or unit can be electrical, mechanical or other forms.
[0332] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0333] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0334] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks or optical disks.
[0335] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A communication method, It is characterized in that include: receiving a first message sent by a first device, where the first message is used to request a second device to perform a first operation, and the first message includes identification information of the second device; Determining, according to the identification information of the second device, that the first device has the authority to request the second device to perform the first operation; Sending a second message to the second device through a core network device, the second message being used to request the second device to perform the first operation, the second message including permission information of the first device, the permission information indicating that the first device has permission to request the second device to perform the first operation; wherein the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device; The determining, according to the identification information of the second device, that the first device has the authority to request the second device to perform the first operation includes: Determine a target device group according to the identification information of the second device, where the target device group includes one or more target devices, and the target devices have the authority to request the second device to perform the first operation; Determining, based on the one or more target devices including the first device, that the first device has permission to request the second device to perform the first operation; or, Sending identification information of the second device to the blockchain device; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has the authority to request the second device to perform the first operation, and the one or more target devices include the first device; Receive permission information of the first device from the blockchain device, and determine, based on the permission information, whether the first device has permission to request the second device to perform the first operation.
2. The method according to claim 1, It is characterized in that The method further comprises: A key used by the first device and the second device for communication is sent to the first device.
3. The method according to claim 1 or 2, It is characterized in that The execution subject of the method is a control anchor point function network element; the control anchor point function network element belongs to the service network of the second device, and the control anchor point function network element is a network element trusted by the home network of the second device.
4. The method according to claim 1 or 2, It is characterized in that The method further comprises: Identification information of the first device is received from the first device.
5. A communication method, It is characterized in that include: receiving, through a core network device, a first message from a second device, where the first message is used to verify whether the first device has authority to request the second device to perform a first operation, and the first message includes identification information of the first device; determining, according to the identification information of the first device, whether the first device has the authority to request the second device to perform the first operation; Sending a second message to the second device through the core network device; the second message includes permission information of the first device, and the permission information indicates that the first device has permission to request the second device to perform the first operation; wherein the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device; The determining, according to the identification information of the first device, that the first device has the authority to request the second device to perform the first operation includes: Determine a target device group according to the identification information of the second device, where the target device group includes one or more target devices, and the target devices have the authority to request the second device to perform the first operation; determining, according to the identification information of the one or more target devices including the identification information of the first device, that the first device has permission to request the second device to perform the first operation; or, Sending identification information of the second device and identification information of the first device to the blockchain device; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target devices have the authority to request the second device to perform the first operation, and the identification information of the one or more target devices includes the identification information of the first device; Receive permission information of the first device from the blockchain device, and determine, based on the permission information, whether the first device has permission to request the second device to perform the first operation.
6. The method according to claim 5, It is characterized in that The method further comprises: A key used by the first device and the second device for communication is sent to the first device.
7. The method according to claim 5 or 6, It is characterized in that The execution subject of the method is a control anchor point function network element; the control anchor point function network element belongs to the service network of the second device, and the control anchor point function network element is a network element trusted by the home network of the second device.
8. The method according to claim 5 or 6, It is characterized in that The method further comprises: Receive identification information of the second device sent by the second device.
9. A communication device, It is characterized in that include: a communication unit, configured to receive a first message sent by a first device, wherein the first message is used to request a second device to perform a first operation, and the first message includes identification information of the second device; a processing unit, configured to determine, according to the identification information of the second device, whether the first device has the authority to request the second device to perform the first operation; The communication unit is further used to send a second message to the second device through the core network device, the second message is used to request the second device to perform the first operation, the second message includes permission information of the first device, the permission information indicates that the first device has the permission to request the second device to perform the first operation; the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device; The processing unit is specifically used for: Determine a target device group according to the identification information of the second device, where the target device group includes one or more target devices, and the target devices have the authority to request the second device to perform the first operation; Determining, based on the one or more target devices including the first device, that the first device has permission to request the second device to perform the first operation; or, Sending identification information of the second device to the blockchain device through the communication unit; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has the authority to request the second device to perform the first operation, and the one or more target devices include the first device; The communication unit receives permission information of the first device from the blockchain device, and determines, based on the permission information, that the first device has permission to request the second device to perform the first operation.
10. The communication device according to claim 9, It is characterized in that The communication unit is further configured to send, to the first device, a key used by the first device and the second device for communication.
11. The communication device according to claim 9 or 10, It is characterized in that The communication device is a control anchor point function network element; the control anchor point function network element belongs to a service network of the second device, and the control anchor point function network element is a network element trusted by a home network of the second device.
12. The communication device according to claim 9 or 10, It is characterized in that The communication unit is further configured to receive identification information of the first device from the first device.
13. A communication device, It is characterized in that include: A communication unit, configured to receive a first message from a second device through a core network device, wherein the first message is used to verify whether the first device has authority to request the second device to perform a first operation, and the first message includes identification information of the first device; a processing unit, configured to determine, according to the identification information of the first device, whether the first device has the authority to request the second device to perform the first operation; The communication unit is further used to send a second message to the second device through the core network device; the second message includes permission information of the first device, and the permission information indicates that the first device has permission to request the second device to perform the first operation; the second message also includes a random number; the random number is used by the second device to determine a key used by the second device to communicate with the first device; The processing unit is specifically configured to determine a target device group according to the identification information of the second device, where the target device group includes one or more target devices, and the target device has the authority to request the second device to perform the first operation; determining, according to the identification information of the one or more target devices including the identification information of the first device, that the first device has permission to request the second device to perform the first operation; or, Sending identification information of the second device and identification information of the first device to the blockchain device through the communication unit; the identification information of the second device is used by the blockchain device to determine a target device group; the target device group includes one or more target devices, the target device has the authority to request the second device to perform the first operation, and the identification information of the one or more target devices includes the identification information of the first device; The communication unit receives permission information of the first device from the blockchain device, and determines, based on the permission information, that the first device has permission to request the second device to perform the first operation.
14. The device according to claim 13, It is characterized in that The communication unit is further configured to send, to the first device, a key used by the first device and the second device for communication.
15. The device according to claim 13 or 14, It is characterized in that The communication device is a control anchor point function network element; the control anchor point function network element belongs to a service network of the second device, and the control anchor point function network element is a network element trusted by a home network of the second device.
16. The device according to claim 13 or 14, It is characterized in that The communication unit is further configured to receive identification information of the second device sent by the second device.
17. A communication device, It is characterized in that comprising a processor coupled to a memory; Memory for storing computer programs; A processor, configured to execute the computer program stored in the memory, so that the apparatus performs the method according to any one of claims 1 to 8.
18. A computer-readable storage medium, It is characterized in that The method comprises a program or an instruction, and when the program or the instruction is executed by a processor, the method according to any one of claims 1 to 8 is executed.
19. A computer program product, It is characterized in that The computer program product comprises instructions, which, when executed, cause the method according to any one of claims 1 to 8 to be performed.
20. A chip, It is characterized in that The chip includes a processor and an interface circuit, wherein the interface circuit is coupled to the processor, and the processor is configured to run a computer program or instruction so that the method according to any one of claims 1 to 8 is executed.
Citation Information
Patent Citations
Method, server and system for authority control
CN103546489A
Smart device monitoring method and device
CN106899603A