Communication method, device and equipment
By introducing network element management equipment into the network operation and maintenance architecture, directly interacting with the tenant NMS, obtaining and verifying permissions, the data and resource security risks existing in operator NMS management of private networks are solved, and the secure access and protection of information is achieved.
Patent Information
- Application Number
- CN202110480099.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-30
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2041-04-30
AI Technical Summary
When multiple groups and organizations conduct network operation and maintenance management through operator NMS, there are security risks in private network data and network resources, which may lead to data leakage and cross-breach.
By introducing network element management equipment into the network operation and maintenance architecture, it directly interacts with the tenant NMS, obtains and verifys the tenant's service permissions and access rights, ensuring that the information access process does not pass through the operator's NMS, and the information security is achieved.
Effectively prevent the leakage of private network information, ensure the security of data and network resources, and avoid the risk of privacy leakage caused by forwarding data and resources in operator NMS.
Smart Images

Figure CN115277034B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method, apparatus, and device. Background Art
[0002] Since the fifth generation (5 th 5G communication technology has the characteristics of high bandwidth, interconnection of all things, and low power consumption. In addition to mobile communication systems, 5G communication technology can also be extended to network operation and maintenance scenarios.
[0003] See Figure 1 As shown in the figure, the current network operation and maintenance architecture based on 5G communication technology generally includes three layers, namely: network element (NE), element management system (EMS), and network management system (NMS).
[0004] Among them, NE refers to various network devices that make up the network, which may include but are not limited to base stations, access points, various core network devices, etc. Optionally, the NE can be a physical entity device or a virtual network function, which is not limited in this application. EMS can not only manage NE, but also be the provider (producer) of network operation and maintenance management services, and can perform specific network operation and maintenance management service operations according to the service call request sent by NMS. As the caller (consumer) of network operation and maintenance management services, NMS can send service call requests to EMS according to the customer's network operation and maintenance management needs, so as to call the network operation and maintenance management services in EMS that meet the customer's operation and maintenance management needs. Both EMS and NMS are composed of at least one device. The devices in EMS can be called network element management devices, and the devices in NMS can be called network management devices.
[0005] Currently, organizations with networking capabilities (such as enterprises, companies, etc.) can Figure 1 The network operation and maintenance architecture shown in the figure is used to maintain and manage the private network deployed by the organization. However, some organizations do not have the ability to independently perform network operation and maintenance. Therefore, many organizations choose to rent the network operation and maintenance management services of the operator's NMS, that is, adopt a hosted model to perform network operation and maintenance through the operator.
[0006] Many groups and organizations have the need to securely protect data and network resources in private networks. Some groups and organizations require that data do not leave the campus to ensure that private data is not leaked. These data may include, but are not limited to, business data and network management data. Among them, network management data may include network configuration management data, network performance management data, network fault management data, etc. Network resources may include: physical network elements (such as physical network functions (PNF)), virtual network functions (such as virtual network functions (VNF)), container network elements (such as containerized network functions (CNF)), etc. By accessing network resources, information such as the utilization rate or inventory of network resources can be obtained.
[0007] The following uses vertical industries as an example. Vertical industries refer to businesses with clearly defined downstream users, often developing products specifically for a specific user group. Because they involve trade secrets, vertical industries generally require privacy and security protection for network data and resources.
[0008] However, when multiple organizations use a managed service provider to manage their private networks, this can create security risks for private network data and resources. For example, private network data or resources could be leaked to the service provider. Alternatively, if different organizations access data and network resources through the same service provider's NMS, there could be a risk of cross-data leakage. Summary of the Invention
[0009] The present application provides a communication method, apparatus, and device for ensuring information security of a private network in a network operation and maintenance architecture.
[0010] In a first aspect, an embodiment of the present application provides a communication method that can be applied to a network element management device in an EMS in a network operation and maintenance architecture. The method comprises the following steps:
[0011] The network element management device obtains the service permission information of the target tenant and obtains the access permission information of the target tenant; wherein the service permission information is used to indicate that the first network management device has the permission to call the first service, and the first network management device is located in the network management system of the target tenant; the access permission information is used to indicate that the first network management device has the permission to access the first information; when the network element management device receives the access request from the first network management device, it sends the first information to the first network management device based on the service permission information, the access permission information and the first information parameter; wherein the access request includes the first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service.
[0012] This method supports tenants with certain network operation and maintenance capabilities in the network operation and maintenance architecture to have the right to directly call certain services in the EMS. In this method, the network element management device in the EMS maintains the service authority information and access permission information of the target tenant; when the target tenant has network operation and maintenance management needs, the first network management device in the tenant NMS of the target tenant can directly interact with the network element management device in the EMS and call the services therein, thereby achieving information access. Since the above-mentioned service call and information access process is realized by the interaction between the first network management device and the network element management device, and does not pass through the second network management device in the operator's NMS, this method will not cause privacy leakage and can ensure the security of private network information.
[0013] In one possible design, the network element management device can obtain the service permission information of the target tenant in the following ways:
[0014] Method 1: receiving service authority information from the first network management device;
[0015] Method 2: receiving service authority information from the second network management device;
[0016] Method 3: Obtain pre-configured service permission information.
[0017] This design can improve the flexibility of the network element management device in obtaining the service permission information of the target tenant.
[0018] In one possible design, the network element management device can obtain the access permission information of the target tenant in the following ways:
[0019] Method 1: receiving access permission information from the first network management device;
[0020] Method 2: Receive access permission information from the second network management device;
[0021] Method 3: Obtain pre-configured access permission information.
[0022] This design can improve the flexibility of the network element management device in obtaining the access permission information of the target tenant.
[0023] In one possible design, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0024] In one possible design, the network element management device may implement sending the first information to the first network management device based on the service permission information, the access permission information, and the first information parameter through the following steps:
[0025] The network element management device verifies, based on the service authority information, that the first network management device has the authority to call the first service; and verifies, based on the access authority information, that the first network management device has the authority to access the first information; then, the network element management device calls the first service based on the first information parameter and obtains the first information indicated by the first information parameter; finally, the network element management device sends the first information to the first network management device.
[0026] In this way, the network element management device can perform service call authority verification and information access authority verification on the first network management device, and then call the first service to obtain the first information after the verification is passed; and send the first information to the first network management device. The network element management device can ensure the security of the first information by performing authority verification on the first network management device.
[0027] In a possible design, the access request also includes an identifier of the target tenant.
[0028] In a second aspect, an embodiment of the present application provides a communication method, which can be applied to a first network management device located in a tenant NMS of a target tenant in a network operation and maintenance architecture. The method includes the following steps:
[0029] The first network management device sends the service permission information of the target tenant and the access permission information of the target tenant to the network element management device; wherein the service permission information is used to indicate that the first network management device has the permission to call the first service, and the access permission information is used to indicate that the first network device has the permission to access the first information; then, after sending an access request to the network element management device, the first network management device receives the first information from the network element management device; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service.
[0030] This solution supports tenants with certain network operation and maintenance capabilities in the network operation and maintenance architecture to have the right to directly call certain services in the EMS. In this method, the network element management device in the EMS maintains the service authority information and access permission information of the target tenant; when the target tenant has network operation and maintenance management needs, the first network management device in the tenant NMS of the target tenant can directly interact with the network element management device in the EMS and call the services therein to achieve information access. Since the above-mentioned service call and information access process is realized by the interaction between the first network management device and the network element management device, and does not pass through the second network management device in the operator's NMS, this method will not cause privacy leakage and can ensure the security of private network information.
[0031] In one possible design, the first information includes first network operation and maintenance management data, and / or first network resource data.
[0032] In a possible design, the access request also includes an identifier of the target tenant.
[0033] In one possible design, before sending an access request to the network element management device, the first network management device can also verify that the first network management device has the authority to call the first service based on the service authority information; and verify that the first network management device has the authority to access the first information based on the access authority information.
[0034] Through this design, the first network management device performs permission verification and sends an access request to the network element management device after the verification is passed. This can ensure that the network element management device will pass the permission verification on the first network management device, thereby ensuring that this access can be successful.
[0035] In a third aspect, an embodiment of the present application provides a communication method that can be applied to a network element management device in an EMS in a network operation and maintenance architecture. The method comprises the following steps:
[0036] The network element management device obtains access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information; the first network management device is located in the network management system of the target tenant; after receiving the identifier of the target tenant and the first information parameter from the second network management device, the first information indicated by the first information parameter is sent to the first network management device based on the access permission information, the identifier of the target tenant and the first information parameter.
[0037] This method supports tenants in the network operation and maintenance architecture who do not have the authority to call certain services. In this method, when the target tenant has a network operation and maintenance management demand to access the target information, if the tenant NMS of the target tenant does not have the authority to call the target service, the tenant NMS of the target tenant can communicate and interact with the EMS through the operator NMS to call the target service. In addition, in order to ensure the security of the operation results, after the EMS obtains the target information after executing the service operation of the target service, the target information can be directly sent to the tenant NMS of the target tenant instead of to the operator NMS. In this method, although the service call and information access process are realized by the interaction between the second network management device in the operator NMS and the network element management device in the EMS, since the final target information is sent from the network element management device to the first network management device without passing through the second network management device, this method will not cause privacy leakage and can ensure the security of the information of the private network.
[0038] In one possible design, the identifier of the target tenant and the first information parameter can be carried in the access request; that is, the network element management device receives the access request from the second network management device, and the access request includes the identifier of the target tenant and the first information parameter; the access request is used to request access to the first information indicated by the first information parameter through the first service; wherein the first network management device does not have the authority to call the first service; and the second network management device has the authority to call the first service.
[0039] With this design, the second network management device having the authority to call the first service can request to call the first service and access the first information through an access request.
[0040] In one possible design, the network element management device may also receive indication information from the second network management device, where the indication information is used to instruct the first information to be sent to the first network management device.
[0041] Through this design, the second network management device can instruct the network element management device to send the first information to the first network management device, thereby avoiding information leakage caused by the first information being forwarded via the second network management device.
[0042] In one possible design, the network element management device can obtain the access permission information of the target tenant in the following ways:
[0043] Method 1: receiving access permission information from the first network management device;
[0044] Method 2: Receive access permission information from the second network management device;
[0045] Method 3: Obtain pre-configured access permission information.
[0046] This design can improve the flexibility of the network element management device in obtaining the access permission information of the target tenant.
[0047] In one possible design, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0048] In one possible design, the network element management device may implement sending the first information indicated by the first information parameter to the first network management device based on the access permission information, the identifier of the target tenant, and the first information parameter through the following steps, including:
[0049] The network element management device verifies that the first network management device has the authority to access the first information based on the identification and access permission information of the target tenant; then, the network element management device calls the first service based on the first information parameters to obtain the first information; finally, the network element management device sends the first information to the first network management device.
[0050] With this design, the network element management device can verify the information access rights of the first network management device. After verification, it can call the first service to obtain the first information and send the first information to the first network management device. The network element management device can ensure the security of the first information by verifying the rights of the first network management device.
[0051] In one possible design, the network element management device may also send an access response to the second network management device, where the access response is used to indicate a successful call to the first service.
[0052] In a fourth aspect, an embodiment of the present application provides a communication method, which can be applied to a second network management device in an operator's NMS. The method includes the following steps:
[0053] After receiving the first information parameter from the first network management device, the second network management device sends the identifier of the target tenant and the first information parameter to the network element management device; wherein the identifier of the target tenant and the first information parameter are used to instruct the network element management device to send the first information indicated by the first information parameter to the first network management device; the first network management device is located in the network management system of the target tenant; and the first information parameter is used to indicate the first information.
[0054] Through this method, when the target tenant has a network operation and maintenance management need to access the target information, if the tenant NMS of the target tenant does not have the authority to call the target service, the tenant NMS of the target tenant can communicate and interact with the EMS through the operator NMS to call the target service. In addition, in order to ensure the security of the operation results, after the EMS obtains the target information by executing the service operation of the target service, it can directly send the target information to the tenant NMS of the target tenant instead of sending it to the operator NMS. In this method, although the service call and information access process are realized by the interaction between the second network management device in the operator NMS and the network element management device in the EMS, since the final target information is sent from the network element management device to the first network management device without passing through the second network management device, this method will not cause privacy leakage and can ensure the security of information in the private network.
[0055] In one possible design, the second network management device may also receive an identifier of the target tenant from the first network management device.
[0056] In one possible design, the second network management device sends an access request to the network management device, where the access request includes an identifier of the target tenant and a first information parameter; the access request is used to request access to the first information indicated by the first information parameter through the first service; wherein the first network management device does not have permission to call the first service; and the second network management device has permission to call the first service.
[0057] With this design, the second network management device having the authority to call the first service can request to call the first service and access the first information through an access request.
[0058] In one possible design, the second network management device may also send indication information to the network element management device, where the indication information is used to instruct the first information to be sent to the first network management device.
[0059] Through this design, the second network management device can instruct the network element management device to send the first information to the first network management device, thereby avoiding information leakage caused by the first information being forwarded via the second network management device.
[0060] In one possible design, after obtaining the access permission information of the target tenant, the second network management device may also send the access permission information to the network element management device; wherein the access permission information is used to indicate that the first network management device has the permission to access the first information.
[0061] Through this design, the second network management device can send the access permission information of the target tenant to the network element management device.
[0062] In one possible design, the second network management device may obtain the access permission information of the target tenant in the following manner:
[0063] Method 1: receiving access permission information from the first network management device;
[0064] Method 2: Obtain pre-configured access permission information.
[0065] This design can improve the flexibility of the second network management device in obtaining the access permission information of the target tenant.
[0066] In one possible design, before sending the target tenant's identifier and the first information parameters to the network element management device, the second network management device may also verify, based on the access permission information, that the first network management device has permission to access the first information.
[0067] Through this design, the second network management device performs permission verification and sends the target tenant's identifier and the first information parameter to the network element management device after the verification is passed. This can ensure that the network element management device will pass the permission verification on the first network management device, thereby ensuring that this access can be successful.
[0068] In one possible design, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0069] In one possible design, the second network management device may also receive an access response from the network element management device, where the access response is used to indicate a successful call to the first service.
[0070] In a fifth aspect, an embodiment of the present application provides a communication method, which can be applied to a first network management device in a tenant NMS of a target tenant. The method includes the following steps:
[0071] The first network management device sends a first information parameter to the second network management device, wherein the first information parameter is used to indicate the first information; finally, the first network management device receives the first information from the network element management device.
[0072] Through this method, when the target tenant has a network operation and maintenance management need to access the target information, if the tenant NMS of the target tenant does not have the authority to call the target service, the tenant NMS of the target tenant can communicate and interact with the EMS through the operator NMS to call the target service. In addition, in order to ensure the security of the operation results, after the EMS obtains the target information by executing the service operation of the target service, it can directly send the target information to the tenant NMS of the target tenant instead of sending it to the operator NMS. In this method, although the service call and information access process are realized by the interaction between the second network management device in the operator NMS and the network element management device in the EMS, since the final target information is sent from the network element management device to the first network management device without passing through the second network management device, this method will not cause privacy leakage and can ensure the security of information in the private network.
[0073] In one possible design, the first network management device may also send an identifier of the target tenant to the first network management device.
[0074] In one possible design, after obtaining the access permission information of the target tenant, the first network management device may also send the access permission information to the second network management device; wherein the access permission information is used to indicate that the first network management device has permission to access the first information.
[0075] In one possible design, the first network management device may obtain pre-configured access permission information.
[0076] In one possible design, before sending the first information parameters to the second network management device, the first network management device may also verify, based on the access permission information, that the first network management device has permission to access the first information.
[0077] Through this design, the first network management device performs permission verification and sends the first information parameter to the second network management device after the verification is passed. This can ensure that the second network management device and the network element management device will pass the permission verification on the first network management device, thereby ensuring that this access can be successful.
[0078] In one possible design, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0079] In a sixth aspect, an embodiment of the present application provides a communication device, comprising a unit for executing each step in the above first to sixth aspects.
[0080] In the seventh aspect, an embodiment of the present application provides a communication device, comprising at least one processing element and at least one storage element, wherein the at least one storage element is used to store programs and data, and the at least one processing element is used to execute the methods provided in the first to sixth aspects of the present application.
[0081] In an eighth aspect, an embodiment of the present application further provides a communication system, comprising a network element management device for executing the method provided in the first aspect of the present application, and a first network management device for executing the method provided in the second aspect of the present application.
[0082] In the ninth aspect, an embodiment of the present application also provides a communication system, including a network element management device for executing the method provided in the third aspect of the present application, a second network management device for executing the method provided in the fourth aspect of the present application, and a first network management device for executing the method provided in the fifth aspect of the present application.
[0083] In the tenth aspect, an embodiment of the present application further provides a computer program, which, when executed on a computer, enables the computer to execute the method provided in any of the above aspects.
[0084] In the eleventh aspect, an embodiment of the present application further provides a computer storage medium, in which a computer program is stored. When the computer program is executed by a computer, the computer executes the method provided in any of the above aspects.
[0085] In the twelfth aspect, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory and execute the method provided in any of the above aspects.
[0086] Thirteenthly, embodiments of the present application further provide a chip system, comprising a processor configured to support a computer device in implementing the method provided in any of the above aspects. In one possible design, the chip system further comprises a memory configured to store programs and data necessary for the computer device. The chip system may be composed solely of a chip, or may include a chip and other discrete components. BRIEF DESCRIPTION OF THE DRAWINGS
[0087] Figure 1 This is a diagram of a traditional network operation and maintenance architecture;
[0088] Figure 2 A schematic diagram of a network operation and maintenance architecture provided in an embodiment of the present application;
[0089] Figure 3 A flow chart of a communication method provided in an embodiment of the present application;
[0090] Figure 4A schematic diagram of the architecture of a tenant object class and a tenant rights object class provided in an embodiment of the present application;
[0091] Figure 5 A flow chart of another communication method provided in an embodiment of the present application;
[0092] Figure 6 A flowchart of an example of a communication method provided in an embodiment of the present application;
[0093] Figure 7 A flowchart of another communication method example provided in an embodiment of the present application;
[0094] Figure 8 A structural diagram of a communication device provided in an embodiment of the present application;
[0095] Figure 9 A structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0096] This application provides a communication method, apparatus, and device for ensuring information security in a private network within a network operation and maintenance architecture. The method, apparatus, and device are based on the same technical concept. Since the method, apparatus, and device solve similar problems, the implementation of the apparatus, device, and method can be referenced in conjunction with each other, and any repetitions will not be repeated.
[0097] Below, some terms in this application are explained to facilitate understanding by those skilled in the art.
[0098] 1) Group organizations: social organizations with networking capabilities and the ability to deploy private networks. Optionally, the group organizations can be in the form of enterprises, companies, industries, etc., which are not limited in this application.
[0099] In the embodiments of the present application, only the group organization as a vertical industry is used as an example for illustration.
[0100] In the network operation and maintenance architecture, if a group organization chooses to rent the network operation and maintenance management services of an operator's NMS to implement network operation and maintenance management of its private network, then the group organization can also be called a tenant, user, customer, etc.
[0101] In the subsequent embodiments and descriptions of this application, only tenants are used as an example for illustration.
[0102] 2) NE, the basic element of the network, is also called a network device. The embodiments of the present application do not limit the form of the NE. Optionally, the NE may include, but is not limited to: a base station, an access point, a core network device, a forwarding device (switches, routers, etc.), a gateway, etc. It should also be noted that the NE can be a physical device, a virtualized network function (VNF), or a virtual container (VC).
[0103] 3) EMS, the core component of the network operation and maintenance architecture, manages the NEs in each tenant's private network and provides various network operation and maintenance management services. Specifically, the EMS can invoke corresponding services based on service invocation requests from the NMS, execute the service operations, and obtain operation results (various data information). The EMS then feeds these results back to organizations with network operation and maintenance management needs through the NMS.
[0104] The EMS may include at least one network element management device for implementing the functions of the EMS.
[0105] 4) NMS is used to call the network operation and maintenance management service in EMS that meets the network operation and maintenance management needs of the tenant according to the network operation and maintenance management needs of the tenant, and then feedback the operation results (various data information) returned by EMS to the tenant.
[0106] According to the different divisions of management permissions and roles, in this application, NMS can be divided into two types: operator NMS and tenant NMS.
[0107] The operator's NMS is deployed and managed by the operator and generally has the authority to call all network operation and maintenance management services in the EMS.
[0108] The tenant NMS is deployed and managed by the tenant. It may have the authority to call some network operation and maintenance management services in the EMS, or it may not have the authority to call any network operation and maintenance management services. For example, the operator may negotiate with the tenant in advance and grant the tenant the authority to call some network operation and maintenance management services. For another example, if there is no prior negotiation with the operator, or if the operator does not grant the tenant the authority to call any network operation and maintenance management services during the negotiation process, the tenant NMS will not have the authority to call any network operation and maintenance management services.
[0109] It should be noted that since the tenant NMS is deployed and managed by the tenant, its identity in the network operation and maintenance architecture is equivalent to that of the tenant. In other words, the tenant's service permission and access rights information are equivalent to the service permission and access rights information of the tenant NMS (or the network management device within the tenant NMS).
[0110] Optionally, the operator and tenant can pre-negotiate the access rights for network operation and maintenance management services offline, obtaining the negotiation result—the tenant's service rights information. Alternatively, the operator and tenant can interact online, with the tenant's NMS and the operator's NMS interacting to obtain the negotiation result—the tenant's service rights information. Furthermore, the operator's NMS or the tenant's NMS can each store the tenant's service rights information. Optionally, the tenant's service rights information can also be stored in the EMS.
[0111] When the tenant's network operation and maintenance management needs require calling the first target service, if the tenant NMS has the authority to call the first target service, then the tenant NMS can interact with the EMS, call the first target service in the EMS, and receive the first operation result obtained by executing the service operation of the first target service from the EMS.
[0112] When the tenant's network operation and maintenance management needs require calling the second target service, if the tenant NMS does not have the authority to call the second target service, then the tenant NMS needs to call the second target service in the EMS through the operator NMS, and then the tenant NMS can receive the second operation result obtained by executing the service operation of the second target service from the EMS.
[0113] The NMS may include at least one network management device for implementing the functions of the NMS. For the sake of distinction, in the embodiments of the present application, the network management device located in the tenant NMS is referred to as the first network management device; the network management device located in the operator NMS is referred to as the second network management device.
[0114] 5) Network operation and maintenance management service (MnS) is a series of resources in EMS to realize network operation and maintenance management functions, including computing resources, software resources, data resources, hardware resources, etc.
[0115] For example, the network operation and maintenance management services provided by EMS may include, but are not limited to:
[0116] GetMOIAttributes: A service that retrieves management object instance attributes. In EMS network operations management, a management object instance (MOI) represents a network resource. This service helps the NMS access network resources and obtain network resource data.
[0117] GetAlarmList service: This service helps the NMS obtain some alarm data in the network.
[0118] GetMeasureReport service for obtaining performance data. This service can help the NMS obtain some performance data in the network.
[0119] Optionally, different network operation and maintenance management services can be called using different service call interfaces. That is, in this application, there can be multiple service call interfaces between the EMS and the NMS. When the NMS needs to call the first target service, it can call the first target service in the EMS through the service call interface corresponding to the first target service.
[0120] The service call interface may specify at least one of the following: message type, message format, and carried data. Upon receiving a service call request message, the EMS can use the above content in the message to determine which service call interface the message was sent through, and thus which service the message is used to invoke.
[0121] 6) Network operation and maintenance management information, including network operation and maintenance management data in the tenant's private network, and / or network resource data.
[0122] The network operation and maintenance management data may include, but is not limited to, the following types of data:
[0123] Network configuration management (CM) data, such as network configuration management information (network resource management (NRM) management objects (MO)). The NMS can call the GetMOIAttributes service in the EMS to obtain this type of data.
[0124] Network fault management (FM) data, such as network alarm data, can be obtained by the NMS by calling the GetAlarmList service.
[0125] Network performance management (PM) data, such as network performance measurement reports, etc. The NMS can call the GetMeasureReport service to obtain this type of data.
[0126] Network resources are those allocated to private networks, including but not limited to physical network elements (e.g., PNFs), virtual network functions (e.g., VNFs), and container network elements (e.g., CNFs). By invoking services that access network resources, you can obtain network resource data, such as resource usage or idle capacity.
[0127] It should be noted that when the NMS calls the target network operation and maintenance management service according to the tenant's network operation and maintenance management needs, it also needs to determine the information parameters of the target information to be accessed according to the network operation and maintenance management needs, so that the EMS can call the target network operation and maintenance management service according to the information parameters, thereby accurately obtaining the target information.
[0128] For example, when a tenant needs to obtain network alarm data, the NMS needs to call the GetAlarmList service in the EMS and set the information parameters shown in the first row of Table 1 below:
[0129] Table 1
[0130]
[0131]
[0132] 7) "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the related objects are in an "or" relationship.
[0133] It should be noted that the term "plurality" in this application refers to two or more, and "at least one" refers to one or more.
[0134] In addition, it should be understood that, in the description of this application, words such as "first" and "second" are only used for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0135] The embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0136] Figure 2 The diagram shows a network operation and maintenance architecture diagram applicable to the communication method provided in the embodiment of the present application. Figure 2 As shown, the architecture includes: tenant NMS, operator NMS, EMS, and at least one tenant's private network.
[0137] Tenant NMSs are deployed and managed by tenants, such as Tenant 1's and Tenant 2's NMSs in the figure. By default, a tenant NMS does not have the authority to invoke any network operation and maintenance management services in the EMS. However, a tenant NMS can obtain the authority to invoke some network operation and maintenance management services in the EMS based on the pre-negotiated results (tenant service permission information) between the tenant and the operator.
[0138] For example, Tenant 1 can negotiate with the operator offline and obtain the negotiation result—Tenant 1's service permission information. Tenant 1's network administrator can then save Tenant 1's service permission information to Tenant 1's tenant NMS; the operator's network administrator can also save Tenant 1's service permission information to the operator's NMS. Optionally, the operator's NMS or Tenant 1's tenant NMS can also send the saved Tenant 1 service permission information to the EMS, so that Tenant 1's tenant NMS can subsequently verify service permissions when Tenant 1's tenant NMS calls related services.
[0139] For example, the pre-negotiation process between Tenant 1 and the operator can also be conducted online. That is, the Tenant NMS and the Operator NMS can interact to obtain the negotiation result—Tenant 1's service permission information. Tenant 1's Tenant NMS can then save Tenant 1's service permission information; the Operator NMS can also save Tenant 1's service permission information. Optionally, the Operator NMS or Tenant 1's Tenant NMS can also send the saved Tenant 1 service permission information to the EMS, allowing for subsequent service permission verification when Tenant 1's Tenant NMS invokes related services.
[0140] For example, if Tenant 2 uses a fully managed service provider's NMS to manage its private network, Tenant 2 (i.e., its NMS) will not have the authority to invoke any network operation and management services. For another example, if Tenant 2 fails to reach a conclusion regarding service rights during negotiation with the carrier, Tenant 2 (i.e., its NMS) will not have the authority to invoke any network operation and management services.
[0141] It should also be noted that, in the embodiment of the present application, when the tenant negotiates with the operator about the tenant's right to access information, the above process of negotiating the right to call services may also be referred to, which will not be repeated here.
[0142] When the target tenant has a network operation and maintenance management requirement to call the target service and access the target information, if the tenant NMS of the target tenant has the authority to call the target service, the tenant NMS of the target tenant can communicate and interact with the EMS to call the target service; after the EMS executes the service operation of the target service and obtains the operation result (target information), the NMS of the target tenant can receive the operation result from the EMS.
[0143] When the target tenant has a network operation and maintenance management requirement to call the target service and access the target information, if the target tenant's tenant NMS does not have permission to call the target service, the target tenant's tenant NMS needs to send the above network operation and maintenance management requirement to the operator NMS, which will then communicate with the EMS to call the target service. In addition, to ensure the security of the operation results, after executing the service operation of the target service and obtaining the operation result (target information), the EMS can send the operation result directly to the target tenant's tenant NMS instead of to the operator NMS.
[0144] The operator NMS is deployed and managed by the operator and generally has the authority to call all network operation and maintenance management services in the EMS. The operator NMS also has functions such as managing tenants' service call permissions and information access rights.
[0145] The EMS, a key component of the network operation and maintenance architecture, manages the NEs within each tenant's private network and provides various network operation and maintenance services to the operator's NMS and tenant NMSs. To ensure the security of the target information requested by the target tenant, the EMS directly feeds the results (i.e., the target information) of the operation to the target tenant's NMS after performing the service operation.
[0146] It should be noted that in Figure 2 In the network operation and maintenance architecture shown, different devices interact with each other through corresponding communication interfaces.
[0147] A service proxy interface exists between the tenant NMS and the operator NMS. When a target tenant has network operation and maintenance management requirements for invoking a target service or accessing target information, but the target tenant's NMS does not have permission to do so, the target tenant can use this service proxy interface to send the network operation and maintenance management requirements to the operator NMS, authorizing the operator to invoke the target service in the EMS.
[0148] When the target tenant has the permission to call the target service in the EMS, a service call interface for the target service exists between the target tenant's tenant NMS and the EMS. The target tenant's tenant NMS and the EMS can call the target service through the target service call interface based on the target tenant's identity.
[0149] There is a service call interface corresponding to each network operation and maintenance management service between the operator's NMS and EMS. In this way, when the operator's NMS calls any network operation and maintenance management service, it can do so through the corresponding service call interface.
[0150] In addition, a tenant management interface may exist between the operator's NMS and EMS to manage and maintain tenants' information access rights.
[0151] It should also be pointed out that Figure 2 As an example of a network operation and maintenance architecture, it does not impose any limitation on the network operation and maintenance architecture to which the communication method provided in the embodiments of the present application is applicable. In actual applications, the number of tenants' private networks in this architecture can be greater. In addition, some network resources can be shared between different tenants' private networks, or between a tenant's private network and the operator's NMS, or between the operator's NMS and the EMS, and between the tenant's private network and the EMS. For example, some core network equipment can be shared between tenant 2's private network and the operator's NMS.
[0152] In addition, the embodiments of the present application are not Figure 2 The name of each system and the name of the device in the system are defined. According to the logical function division, the first network management device located in the tenant NMS can also be called the tenant service invocation module; the second network management device located in the operator NMS can also be called the operator service invocation module; the network element management device in the EMS can also be divided into the tenant management module and the service provision module.
[0153] The present application provides a communication method that can be applied to Figure 2 In the network operation and maintenance architecture shown in the following example, the target tenant is taken as an example. Figure 3 The flowchart shown in FIG. 4 specifically illustrates the steps of the method.
[0154] S300: After the target tenant negotiates with the operator about the target tenant's authority to call services, the target tenant's service authority information is determined; the target tenant negotiates with the operator about the target tenant's authority to access information, and the target tenant's access authority information is determined.
[0155] Since the tenant NMS is deployed and managed by the tenant, Figure 2 In the network operation and maintenance architecture shown, the tenant NMS is identical to the tenant. In other words, the tenant's service permission and access rights are identical to those of the tenant NMS (or the network management device within the tenant NMS).
[0156] Therefore, in S300, the target tenant's service permission information is used to indicate that the target tenant's tenant NMS (the first network management device) has the permission to call at least one service (hereinafter referred to as the authorized service). The target tenant's access permission information is used to indicate that the first network management device has the permission to access at least one information (hereinafter referred to as the authorized information).
[0157] The authorization service includes at least one network operation and maintenance management service in the EMS, including the first service. The authorization information is at least one piece of information in the target tenant's private network, including the first information. The authorization information may include: at least one piece of network operation and maintenance management data, and / or at least one piece of network resource data.
[0158] It should also be noted that in S300 , the target tenant and the operator may negotiate the target tenant's authority to call services and / or access information through offline negotiation or online negotiation.
[0159] In the offline negotiation mode, the operator's network management personnel can save the negotiation results (the target tenant's service permission information and / or access permission information) to the second network management device in the operator's NMS; the target tenant's network management personnel can also save the negotiation results (the target tenant's service permission information and / or access permission information) to the first network management device in the target tenant's tenant NMS.
[0160] In online negotiation, the second network management device in the operator's NMS communicates with the first network management device in the target tenant's NMS to implement the negotiation process. After the negotiation is complete, the second network management device in the operator's NMS can directly save the negotiation results (the target tenant's service permission information and / or access permission information); the first network management device in the target tenant's NMS can also directly save the negotiation results (the target tenant's service permission information and / or access permission information).
[0161] After the target tenant negotiates with the operator regarding the target tenant's rights to invoke services and / or access information, the second network management device in the operator's NMS and / or the first network management device in the target tenant's tenant NMS may send the negotiation results to the EMS. Alternatively, the EMS's network administrator may input the negotiation results into the network element management device in the EMS. This allows the network element management device in the EMS to later verify the rights of the first network management device in the target tenant's NMS.
[0162] S301: The network element management device in the EMS obtains the service permission information of the target tenant.
[0163] Optionally, the network element management device may obtain the service authority information in, but is not limited to, the following three ways:
[0164] Method 1: When the service authority information is stored in the first network management device in the tenant NMS of the target tenant, the network element management device may receive the service authority information from the first network management device.
[0165] Method 2: When the service authority information is stored in the second network management device in the operator's NMS, the network element management device may receive the service authority information from the second network management device.
[0166] Method three: when the service authority information is pre-configured in the EMS, the network element management device obtains the pre-configured service authority information.
[0167] S302: The network element management device obtains access permission information of the target tenant.
[0168] Optionally, the network element management device may obtain the access permission information in, but is not limited to, the following three ways:
[0169] Method 1: When the access permission information is stored in the first network management device in the tenant NMS of the target tenant, the network element management device may receive the access permission information from the first network management device.
[0170] Method 2: When the access permission information is stored in the second network management device in the operator's NMS, the network element management device may receive the access permission information from the second network management device.
[0171] Method three: when the access permission information is pre-configured in the network element management device, the network element management device obtains the pre-configured access permission information.
[0172] It should be noted that the present application does not limit the execution order of S301 and S302. For example, the network element management device may execute S301 and S302 simultaneously, or execute S301 first and then S302, or execute S302 first and then S301.
[0173] It should also be noted that, in this embodiment of the present application, the network element management device can trigger the execution of S301 and S302 through various triggering methods. For example, the first network management device or the second network management device can send a management request to the network element management device, requesting management of the target tenant's service permission information and access permission information. After receiving the management request, the network element management device executes S301 and S302 based on the management request. Optionally, the management request can carry the target tenant's service permission information and / or access permission information. In addition, the management request can also carry the target tenant's identifier.
[0174] In a possible implementation, the network element management device may maintain the service permission information and access permission information of the target tenant in the following manner.
[0175] The network element management device internally maintains a tenant object model and a tenant rights object model associated with the tenant object model, wherein the tenant rights object model includes: a tenant's service rights information variable (referred to as the first variable) and a tenant's access rights information variable (referred to as the second variable).
[0176] After executing S301 and S302, the network element management device can instantiate the tenant object model for the target tenant and create a target tenant object instance; and instantiate the tenant permission object model for the target tenant based on the service permission information and access permission information of the target tenant, that is, assign values to the first variable and the second variable in the tenant permission object model to create a target tenant permission object instance.
[0177] The target tenant object instance is used to describe the target tenant; the target tenant rights object instance is associated with the tenant object instance and is used to describe the service rights information and access rights information of the target tenant.
[0178] Optionally, the network element management device can represent the tenant object model through the tenant object class (Tenant); and represent the tenant permission object model through the tenant permission object class (TenantPermission). In addition, there are multiple member variables in the tenant permission object class (TenantPermission): service invoking permission variable (ServiceInvokingPermission), data access permission variable (DataAccessPermission), network resource access permission variable (ResourceAccessPermission). The structure of the tenant object class (Tenant) and the tenant permission object class (TenantPermission) can be as follows: Figure 4 shown.
[0179] Among them, the service calling permission variable (ServiceInvokingPermission) is the tenant's service permission information variable (first variable); the data access permission variable (DataAccessPermission) and the network resource access permission variable (ResourceAccessPermission) are the tenant's access permission information variable (second variable).
[0180] When the network element management device creates a target tenant object instance, it can do so by creating an object of the tenant object class (Tenant). When the network element management device creates a target tenant permission object instance, it can do so by creating an object of the tenant permission object class (TenantPermission). The values of the variables in the object of the tenant permission object class (TenantPermission) are set based on the service permission information and access permission information of the target tenant.
[0181] The value of the service invoking permission variable (ServiceInvokingPermission) is determined according to the service permission information of the target tenant, and its value may be the authorized service indicated by the service permission information.
[0182] The values of the data access permission variable (DataAccessPermission) and the network resource access permission variable (ResourceAccessPermission) are determined based on the target tenant's access permission information. The value of the data access permission variable (DataAccessPermission) can be at least one type of network operation and maintenance management data included in the authorization information indicated by the access permission information. The value of the network resource access permission variable (ResourceAccessPermission) can be at least one type of network resource data included in the authorization information indicated by the access permission information.
[0183] For example, the value of the service invoking permission variable (ServiceInvokingPermission) indicates the services that the target tenant can call. For example:
[0184] The service invoking permission variable (ServiceInvokingPermission) includes: the service for obtaining management object instance parameters, that is, 'CMpermission': ['GetMOIAttributes'], indicating that the target tenant can call the configuration management CM-related service of obtaining MOI parameters.
[0185] The service invoking permission variable (ServiceInvokingPermission) includes the service for obtaining alarm information, namely 'FMpermission': ['GetAlarmList'], indicating that the target tenant can call the service related to fault management FM, such as obtaining alarm information.
[0186] The service invoking permission variable (ServiceInvokingPermission) includes: the service for obtaining performance data, that is, 'PMpermission': ['GetMeasurementReport'], indicating that the target tenant can call and access performance measurement reports, which are related to performance management PM.
[0187] For example, the value of the data access permission variable (DataAccessPermission) indicates the network operation and maintenance management data that the target tenant can access. For example:
[0188] The data access permission variable (DataAccessPermission) includes: network performance management data, namely 'PMkpi': ['PacketDelay', 'RadioResourceUtilization'], indicating that the target tenant can access network performance management data related to packet delay and radio resource utilization.
[0189] The data access permission variable (DataAccessPermission) contains: network alarm data, that is, 'AlarmType': ['Communications Alarm', 'Processing Error Alarm'], indicating that the target tenant can access communication alarm data and fault management data related to processing error alarms).
[0190] For example, the value of the network resource access permission variable (ResourceAccessPermission) indicates the network resource data that the target tenant can access. For example:
[0191] The network resource access permission variable (ResourceAccessPermission) includes: resource management object type, namely 'MOtype': ['NRCellDU'], indicating that the target tenant can access the network resource data representing the cell NRCellDU type instance.
[0192] S303: When the target tenant has a network operation and maintenance management demand for accessing the first information by calling the first service, the first network management device in the tenant NMS of the target tenant performs authority verification and passes the verification.
[0193] The first information may include: first network operation and maintenance management data, and / or first network resource data.
[0194] It should be noted that this step is optional, and the first network management device may not perform permission verification, that is, execute S304. By executing this step, it can be ensured that the first network management device sends an access request to the EMS only when it has the permission to call the first service and the permission to access the first information.
[0195] In one embodiment, when the first network management device saves the service permission information of the target tenant during the execution of S303, it can verify that the first network management device has the permission to call the first service based on the service permission information, that is, determine that the authorized service indicated by the service permission information includes the first service.
[0196] In one embodiment, when the first network device saves the access permission information of the target tenant during the execution of S303, it can verify that the first network management device has the permission to access the first information based on the access permission information, that is, determine that the authorization information indicated by the access permission information contains the first information.
[0197] By performing authority verification through the first network management device and sending an access request to the network element management device after passing the verification, it can be ensured that the network element management device will pass the authority verification of the first network management device, thereby ensuring that this access can be successful.
[0198] S304: The first network management device sends an access request to the network element management device; the network element management device receives the access request from the first network management device. The access request includes a first information parameter. The first information parameter is used to indicate the first information. The access request is used to request access to the first information indicated by the first information parameter through the first service.
[0199] The access request is transmitted via a service call interface corresponding to the first service between the first network management device and the network element management device. Therefore, the access request can be carried in a service call request message, and the service call request message complies with the message type, format, and data content requirements of the service call interface corresponding to the first service.
[0200] In one embodiment, in order to identify that the access is initiated by the target tenant, or initiated by the tenant NMS of the target tenant, the access request may further include an identifier of the target tenant.
[0201] Among them, the identifier of the target tenant can be any information that can uniquely identify the target tenant, such as: the identifier of the tenant NMS of the target tenant, the identifier of the first network management device in the tenant NMS of the target tenant, the account of the target tenant, the name of the target tenant, the signed contract identifier of the target tenant, etc.
[0202] From the above explanation and description of network operation and maintenance management information, it can be seen that to access each type of data, it is necessary to set the parameters of this type of data, such as shown in Table 1. Therefore, in the embodiment of the present application, the first information parameter is the parameter of the first information, which is used to indicate the first information.
[0203] For example, the target tenant wants to access Communications Alarm type data in the target tenant's private network. The first network management device in the tenant NMS of the target tenant determines that the first network management device has the authority to access Communications Alarm type data and also has the authority to call the service for obtaining alarm information (GetAlarmList). Therefore, the first network management device verifies its own authority and passes the verification. Then, it can directly send an access request to the network element management device in the EMS, requesting to call the service for obtaining alarm information (GetAlarmList) to access Communications Alarm type data. The access request can carry the identifier of the target tenant and the parameters of the Communications Alarm type data to be accessed (these parameters describe which resources and data need to be accessed through the service).
[0204] S305: The network element management device obtains the first information according to the service authority information, the access authority information and the first information parameter.
[0205] In one embodiment, when executing S305, the network element management device may first perform authority verification on the first network management device and pass the verification, and then call the first service to obtain the first information, which may specifically include the following steps:
[0206] The network element management device verifies, based on the service authority information, that the first network management device has the authority to call the first service;
[0207] The network element management device verifies, based on the access permission information, that the first network management device has permission to access the first information;
[0208] The network element management device calls the first service based on the first information parameter, performs a service operation of the first service, and obtains the first information indicated by the first information parameter.
[0209] S306: The network element management device sends the first information to the first network management device; the first network management device receives the first information from the network element management device.
[0210] Optionally, in response to the access request, the network element management device sends an access response to the first network management device, where the access response includes the first information. Optionally, the access response may also indicate successful invocation of the first service. In addition, the access response may also include an identifier of the target tenant.
[0211] In one embodiment, when the first information is carried in the access response, the network element management device can transmit the access response through the service call interface corresponding to the first service. In this case, the access response can be carried in the service call response message, and the service call response message complies with the provisions of the service call interface corresponding to the first service on the message type, format and data content.
[0212] In another embodiment, when the network element management device does not send the first information via the access response, the network element management device may transmit the first information via the data transmission interface between the network element management device and the first network management device. Optionally, the network element management device may also encrypt the first information when transmitting the first information; accordingly, upon receiving the encrypted first information, the first network management device needs to decrypt it to obtain the first information.
[0213] In summary, an embodiment of the present application provides a communication method. This solution supports tenants with certain network operation and maintenance capabilities in the network operation and maintenance architecture to have the right to directly call certain services in the EMS. In this method, the network element management device in the EMS maintains the service authority information and access permission information of the target tenant; when the target tenant has network operation and maintenance management needs, the first network management device in the tenant NMS of the target tenant can directly interact with the network element management device in the EMS, call the services therein, and thus achieve information access. Since the above-mentioned service call and information access process is realized by the interaction between the first network management device and the network element management device, and does not pass through the second network management device in the operator's NMS, the method will not cause privacy leakage and can ensure the security of information. In summary, this method can ensure the information security of the private network in the network operation and maintenance architecture.
[0214] The present application provides a communication method that can be applied to Figure 2 In the network operation and maintenance architecture shown in the following example, the target tenant is taken as an example. Figure 5 The flowchart shown in FIG. 4 specifically illustrates the steps of the method.
[0215] S500: The target tenant negotiates with the operator about the target tenant's access rights to information, and determines the access rights information of the target tenant.
[0216] Since the tenant NMS is deployed and managed by the tenant, Figure 2 In the network operation and maintenance architecture shown, the identity of the tenant NMS is equivalent to the tenant. In other words, the tenant's access rights information is equivalent to the access rights information of the tenant NMS (or the network management device in the tenant NMS).
[0217] Therefore, in S500, the access permission information of the target tenant is used to indicate that the first network management device has permission to access at least one type of information (hereinafter referred to as authorization information).
[0218] The authorization information is at least one type of information in the private network of the target tenant, and the authorization information includes the first information. The authorization information may include: at least one type of network operation and maintenance management data, and / or at least one type of network resource data.
[0219] It should also be noted that in S500 , the target tenant and the operator may negotiate the target tenant's access rights to information through offline negotiation or online negotiation.
[0220] In the offline negotiation mode, the operator's network management personnel can save the negotiation results (the access permission information of the target tenant) to the second network management device in the operator's NMS; the target tenant's network management personnel can also save the negotiation results (the access permission information of the target tenant) to the first network management device in the tenant NMS of the target tenant.
[0221] In online negotiation, the second network management device in the operator's NMS communicates with the first network management device in the target tenant's NMS to implement the negotiation process. After the negotiation is complete, the second network management device in the operator's NMS can directly save the negotiation results (the target tenant's access rights information); the first network management device in the target tenant's NMS can also directly save the negotiation results (the target tenant's access rights information).
[0222] After the target tenant negotiates with the operator about the target tenant's access rights, the second network management device in the operator's NMS and / or the first network management device in the target tenant's tenant NMS can send the negotiation results to the EMS. Alternatively, the EMS network administrator can input the negotiation results to the network element management device in the EMS. This allows the network element management device in the EMS to later verify the rights of the first network management device in the target tenant's NMS.
[0223] S501: The network element management device obtains access permission information of the target tenant.
[0224] Optionally, the network element management device may obtain the access permission information in, but is not limited to, the following three ways:
[0225] Method 1: When the access permission information is stored in the first network management device in the tenant NMS of the target tenant, the network element management device may receive the access permission information from the first network management device.
[0226] Method 2: When the access permission information is stored in the second network management device in the operator's NMS, the network element management device may receive the access permission information from the second network management device.
[0227] Method three: when the access permission information is pre-configured in the network element management device, the network element management device obtains the pre-configured access permission information.
[0228] It should also be noted that, in this embodiment of the present application, the network element management device can trigger the execution of S501 through various triggering methods. For example, the first network management device or the second network management device can send a management request to the network element management device, requesting management of the target tenant's access rights information. Upon receiving the management request, the network element management device executes S501 based on the management request. Optionally, the management request can include the target tenant's access rights information. Furthermore, the management request can also include the target tenant's identifier.
[0229] In a possible implementation, the network element management device may maintain the access permission information of the target tenant in the following manner.
[0230] The network element management device internally maintains a tenant object model and a tenant authority object model associated with the tenant object model. The tenant authority object model includes: a tenant's access authority information variable. Of course, in order to save storage space, the tenant authority object model in the embodiment of the present application can be combined with the tenant object model. Figure 3 In the embodiment shown, the tenant permission object model set for the tenant with service permission information is the same model, that is, the tenant permission object model may also include the tenant's service permission information.
[0231] After executing S501, the network element management device can instantiate the tenant object model for the target tenant and create a target tenant object instance; and based on the access permission information of the target tenant, instantiate the tenant permission model for the target tenant, that is, assign the tenant's access permission information variable in the tenant permission model to create a target tenant permission object instance.
[0232] The target tenant object instance is used to describe the target tenant; the target tenant rights object instance is associated with the tenant object instance and is used to describe the access rights information of the target tenant.
[0233] Optionally, the network element management device can represent the tenant object model through the tenant object class (Tenant); and represent the tenant permission object model through the tenant permission object class (TenantPermission). In addition, there are multiple member variables in the tenant permission object class (TenantPermission): service calling permission variable (ServiceInvokingPermission) (optional), data access permission variable (DataAccessPermission), network resource access permission variable (ResourceAccessPermission). The structure of the tenant object class (Tenant) and the tenant permission object class (TenantPermission) can be as follows: Figure 4 For details, please refer to Figure 3 The description in the illustrated embodiment will not be repeated here.
[0234] S502: When the target tenant has a network operation and maintenance management demand for accessing the first information, the first network management device in the tenant NMS of the target tenant performs authority verification and passes the verification.
[0235] The first information may include: first network operation and maintenance management data, and / or first network resource data.
[0236] It should be noted that this step is optional, and the first network management device may not perform permission verification, i.e., execute S503. By executing this step, it is ensured that the first network management device has permission to access the first information before sending the information of the current network operation and maintenance management requirements (i.e., the first information parameters) to the second network management device in the operator's NMS.
[0237] In one embodiment, when the first network device saves the access permission information of the target tenant during the execution of S502, it can verify that the first network management device has the permission to access the first information based on the access permission information, that is, determine that the authorization information indicated by the access permission information contains the first information.
[0238] Optionally, when the first network management device determines that accessing the first information requires invoking a first service, the first network management device may further verify that it does not have permission to invoke the first service. For example, if the first network management device has pre-negotiated the target tenant's permission to invoke services, the first network management device may verify that the first service is not included in the authorized services indicated by the target tenant's service permission information.
[0239] By performing permission verification through the first network management device and sending the information of the network operation and maintenance management requirements (i.e., the first information parameter) to the second network management device after the verification is passed, it can be ensured that the second network management device or network element management device will pass the permission verification of the first network management device, thereby ensuring that the access can be successful.
[0240] S503: The first network management device sends information about the current network operation and maintenance management requirements (ie, first information parameters) to the second network management device in the operator's NMS; the second network management device receives the first information parameters from the first network management device.
[0241] Optionally, the first network device may send the first information parameter via a service proxy interface with the operator's NMS. Thus, the first network management device may send information regarding current network operation and maintenance management requirements to the second network management device in the operator's NMS via the service proxy interface, thereby authorizing the operator to invoke the first service in the EMS to access the first information indicated by the first information parameter.
[0242] Optionally, when executing S503 , the first network management device may further send the identifier of the target tenant to the second network management device.
[0243] S504: The second network management device sends the identifier of the target tenant and the first information parameter to the network element management device; the network element management device receives the identifier of the target tenant and the first information parameter from the second network management device.
[0244] The identifier of the target tenant and the first information parameter are used to instruct the network element management device to send the first information indicated by the first information parameter to the first network management device.
[0245] In one embodiment, the second network management device may carry the identifier of the target tenant and the first information parameter in the access request. That is, in S504, the following steps are included:
[0246] The second network management device sends an access request to the network element management device, and the network element management device receives the access request from the second network management device. The access request includes an identifier of the target tenant and the first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through a first service.
[0247] In this embodiment, the access request is transmitted via the service call interface corresponding to the first service between the second network management device and the network element management device. Therefore, the access request can be carried in a service call request message, and the service call request message complies with the message type, format, and data content requirements of the service call interface corresponding to the first service.
[0248] In one embodiment, the second network management device may further perform authority verification on the first network management device before executing S504. Specifically, the verification may include:
[0249] The second network management device determines that accessing the first information requires calling the first service; when the second network management device saves the service permission information of the target tenant, it can verify based on the service permission information that the first network management device does not have the permission to call the first service, that is, it determines that the authorized services indicated by the service permission information include the first service.
[0250] When the second network management device saves the access permission information of the target tenant, it can verify, based on the access permission information, that the first network management device has the permission to access the first information, that is, determine that the authorization information indicated by the access permission information includes the first information.
[0251] By performing permission verification on the first network management device through the second network management device, and executing S504 after the service call permission verification fails but the access permission verification passes, it can be ensured that the network element management device will pass the access permission verification on the first network management device, thereby ensuring that this access can be successful.
[0252] In one embodiment, in order to identify that the access is initiated by the target tenant or the target tenant's tenant NMS, the access request may further include the target tenant's identifier, wherein the target tenant's identifier may be any information that can uniquely identify the target tenant.
[0253] S505: The network element management device obtains the first information according to the access permission information, the identifier of the target tenant and the first information parameter.
[0254] In one embodiment, when executing S505, the network element management device may first verify the access permission of the first network management device and pass the verification, and then call the first service to obtain the first information. Specifically, the following steps may be included:
[0255] The network element management device verifies that the first network management device has permission to access the first information based on the access permission information and the identifier of the target tenant. For example, the network management device first obtains the access permission information of the target tenant based on the identifier of the target tenant, and then determines that the authorization information indicated by the access permission information includes the first information. This determines that the first network management device has permission to access the first information, and thus the access permission verification of the first network management device is successful.
[0256] Afterwards, the network element management device calls the first service based on the first information parameter, performs a service operation of the first service, and obtains the first information indicated by the first information parameter.
[0257] It should also be noted that when the second network management device executes S504 by sending an access request, the network element management device may send an access response to the second network management device after successfully calling the first service. The access response is used to indicate that the first service is successfully called.
[0258] S506: The network element management device sends the first information to the first network management device; the first network management device receives the first information from the network element management device.
[0259] In this step, the network element management device may determine, based on the identifier of the target tenant, that the transmission target of the first information is the first network management device.
[0260] Since there is no service call interface for the first service between the network element management device and the first network management device, the network element management device can transmit the first information via the data transmission interface between the network element management device and the first network management device. Optionally, the network element management device can also encrypt the first information when transmitting it; accordingly, upon receiving the encrypted first information, the first network management device needs to decrypt it to obtain the first information.
[0261] In summary, an embodiment of the present application provides a communication method. This solution supports tenants in the network operation and maintenance architecture who do not have the authority to call certain services. In this method, when the target tenant has a network operation and maintenance management requirement to access target information, if the target tenant's tenant NMS does not have the authority to call the target service, the target tenant's tenant NMS needs to send the above-mentioned network operation and maintenance management requirement to the operator NMS, and the operator NMS will communicate and interact with the EMS to call the target service. In addition, to ensure the security of the operation results, after the EMS performs the service operation of the target service and obtains the target information, it can directly send the target information to the tenant NMS of the target tenant instead of to the operator NMS. In this method, although the service call and information access process is implemented by the interaction between the second network management device in the operator NMS and the network element management device in the EMS, since the final target information is sent from the network element management device to the first network management device without passing through the second network management device, this method will not cause privacy leakage and can ensure information security. In summary, this method can ensure the information security of the private network in the network operation and maintenance architecture.
[0262] Based on the above embodiments, this application also provides the following two examples: Example 1 and Example 2 can be applied to Figure 2 In the operation and maintenance architecture shown in Figure 1, it should be noted that, based on the logical functional division, in this architecture, the first network management device in the tenant NMS is called the tenant service invocation module; the second network management device in the operator NMS is called the operator service invocation module; and the network element management device in the EMS can be divided into the tenant management module and the service provision module. The tenant management module is used to provide tenant management and tenant rights management functions, while the service provision module is used to provide various network operation and maintenance management services.
[0263] Example 1: This example uses Figure 2 In the architecture shown, we take the example of tenant 1 who has negotiated with the operator in advance about the service access rights. Figure 6 The flowchart shown in FIG. 1 specifically describes the steps in this example.
[0264] S600: Tenant 1 negotiates with the operator about the right of tenant 1 to call services and determines the service right information of tenant 1; Tenant 1 negotiates with the operator about the right of tenant 1 to access information and determines the access right information of tenant 1.
[0265] In this example, tenant 1 and the operator can negotiate online or offline to determine tenant 1's authority to call services and / or access information. For details, see Figure 3 The description of S300 in the illustrated embodiment will not be repeated here.
[0266] S601: The operator service calling module in the operator NMS obtains the service permission information of tenant 1 and the access permission information of tenant 1.
[0267] Optionally, the operator service calling module may receive tenant 1's service permission information and / or tenant 1's access permission information from the tenant service calling module in tenant 1's tenant NMS; or the network administrator of the operator NMS may upload tenant 1's service permission information and / or tenant 1's access permission information to the operator service calling module; or, if tenant 1 and the operator adopt an online negotiation method, after the negotiation is completed, the operator service calling module may determine tenant 1's service permission information and / or tenant 1's access permission information based on the negotiation results. In short, this application does not limit the manner in which the operator service calling module obtains tenant 1's service permission information and tenant 1's access permission information.
[0268] S602: The operator service calling module sends a tenant management request to the tenant management module in the EMS. The tenant management request includes the identifier of tenant 1, the service permission information of tenant 1, and the access permission information of tenant 1. The tenant management request is used to request the tenant management module to manage the permissions of tenant 1.
[0269] It should be noted that when the EMS stores the service permission information of tenant 1, the tenant management request may not include the service permission information of tenant 1; similarly, when the EMS stores the access permission information of tenant 1, the tenant management request may not include the access permission information of tenant 1.
[0270] For example, the access permission information of tenant 1 in the tenant management request can be represented by the following code:
[0271] 'DataAccessPermission':
[0272] {
[0273] 'AlarmType':['Communications Alarm','Processing Error Alarm'],
[0274] 'PMkpi':['PacketDelay','RadioResourceUtilization']},
[0275] }
[0276] 'ResourceAccessPermission':
[0277] {
[0278] 'MOType': ['NRCellCU'],
[0279] 'MOIid': ['AABB-AB-BA']},
[0280] }
[0281] The above code indicates that tenant 1 can access the following information in the resource object instance with the class NRCellCU and the ID AABB-AB-BA:
[0282] 'Communications Alarm' (communication alarm data), 'Processing Error Alarm' (processing error alarm data), 'PacketDelay' (packet delay) and 'RadioResourceUtilization' (radio resource utilization).
[0283] S603: The tenant management module in the EMS creates a tenant rights object instance of tenant 1 according to the tenant management request.
[0284] Optionally, the tenant management module may maintain a tenant authority object model, such as Figure 4 As shown. The tenant management module can instantiate the tenant permission object model based on the service permission information of tenant 1 and the access permission information of tenant 1, that is, assign values to the tenant's service permission information variable (referred to as the first variable) and the tenant's access permission information variable (referred to as the second variable) in the tenant permission object model to create a tenant permission object instance of tenant 1. The above process of creating a tenant permission object instance of tenant 1 can be referred to Figure 3 The description of S301 and S302 in the illustrated embodiment will not be repeated here.
[0285] S604: After creating the tenant rights object instance for tenant 1, the tenant management module sends a tenant management response to the operator service call module in the operator NMS. The tenant management response is used to notify the result (whether the creation of the tenant rights object instance for tenant 1 is successful). The tenant management response may also include the identifier of tenant 1.
[0286] S605: When tenant 1 has a network operation and maintenance management requirement to access first information through the first service, the tenant service calling module in the tenant NMS of tenant 1 performs authority verification on itself, including: service calling authority verification and information access authority verification.
[0287] During the execution of S605, the tenant service calling module can perform permission verification in the following ways:
[0288] When the service permission information of tenant 1 is saved in the tenant service calling module, it can be verified based on the service permission information whether the tenant service calling module has the permission to call the first service, that is, whether the authorized services indicated by the service permission information include the first service.
[0289] When the access permission information of tenant 1 is saved in the tenant service calling module, the tenant service calling module can be verified based on the access permission information to determine whether it has the permission to access the first information, i.e., to determine whether the authorization information indicated by the access permission information contains the first information.
[0290] This example is divided into two cases depending on the verification results. The following describes the execution process under different verification results.
[0291] Case 1: The verification result is: the service call permission verification of the tenant service call module is passed, and the information access permission verification is passed. That is, the authorized service indicated by the service permission information of tenant 1 includes the first service, and the authorization information indicated by the access permission information of tenant 1 includes the first information. In this case, the tenant service call module can pass Figure 3 The method flow provided by the illustrated embodiment calls a first service to access first information.
[0292] S606: When the tenant service calling module determines that the service calling permission verification of the tenant service calling module has passed and the information access permission verification has passed, the tenant service calling module sends a service calling request to the tenant management module in the EMS. The service calling request includes the identifier of tenant 1 and a first information parameter. The first information parameter is used to indicate the first information.
[0293] S607: After receiving the service call request, the tenant management module determines the tenant permission object of tenant 1 according to the identifier of tenant 1; based on the tenant permission object instance of tenant 1, the tenant service call module is verified for service call permission and information access permission, and the verification passes.
[0294] In this step, the tenant management module can verify whether the tenant service calling module has the authority to call the first service based on the service permission information of tenant 1 described by the tenant permission object instance of tenant 1, that is, determine whether the authorized service indicated by the service permission information includes the first service.
[0295] The tenant management module can verify whether the tenant service calling module has the authority to access the first information based on the access permission information of tenant 1 described by the tenant permission object instance of tenant 1, that is, determine whether the authorization information indicated by the access permission information contains the first information.
[0296] S608: The tenant management module sends a service request to the service provision module, wherein the service request includes the identifier of tenant 1 and the first information parameter.
[0297] S609: The service providing module performs a service operation of the first service according to the first information parameter to obtain the first information.
[0298] S610: The service providing module sends a service response to the tenant management module. The service response includes the identifier of tenant 1 and the first information.
[0299] S611: The tenant management module sends a service call response to the tenant service call module in the tenant NMS of tenant 1. The service call response includes the first information. Optionally, the service call response may also include an identifier of tenant 1.
[0300] Case 2: The verification result is: the service call permission verification of the tenant service call module fails, but the information access permission verification passes. That is, the authorized service indicated by the service permission information of tenant 1 does not include the first service, and the authorization information indicated by the access permission information of tenant 1 includes the first information. In this case, the tenant service call module can pass Figure 5 The method flow provided in the illustrated embodiment calls the first service through the operator service calling module in the operator NMS to access the first information.
[0301] S612: When the tenant service calling module determines that the service calling authority verification of the tenant service calling module has failed, but the information access authority verification has passed, the tenant service calling module sends network operation and maintenance management demand information to the operator service calling module in the operator NMS. The network operation and maintenance management demand information includes a first information parameter, and the first information parameter is used to indicate the first information.
[0302] Optionally, the network operation and maintenance management requirement information may also include the identifier of tenant 1.
[0303] S613: The operator service calling module verifies the information access rights of the tenant service calling module, and after passing the verification, sends a service calling request to the tenant management module in the EMS, wherein the service calling request includes the identifier of tenant 1 and the first information parameter.
[0304] When the operator service calling module stores the access permission information of tenant 1, it can verify whether the tenant service calling module has the permission to access the first information based on the access permission information, that is, determine whether the authorization information indicated by the access permission information contains the first information.
[0305] S614: After receiving the service call request, the tenant management module determines the tenant permission object of tenant 1 according to the identifier of tenant 1; and verifies the information access permission of the tenant service call module according to the tenant permission object instance of tenant 1, and the verification passes.
[0306] In this step, the tenant management module can verify whether the tenant service calling module has the authority to access the first information based on the access permission information of tenant 1 described by the tenant permission object instance of tenant 1, that is, determine whether the authorization information indicated by the access permission information contains the first information.
[0307] S615: The tenant management module sends a service request to the service provision module, wherein the service request includes the identifier of tenant 1 and the first information parameter.
[0308] S616: The service providing module performs a service operation of the first service according to the first information parameter to obtain the first information.
[0309] S617: When the service providing module successfully runs the first service, it sends a service response to the tenant management module, where the service response includes the identifier of tenant 1. The service response is used to successfully call the first service.
[0310] S618: The tenant management module sends a service call response to the operator service call module in the operator NMS, wherein the service call response includes the identifier of tenant 1 and a service call result indicating that the first service has been successfully called.
[0311] S619: After obtaining the first information, the service providing module sends the identifier of tenant 1 and the first information to the tenant management module.
[0312] S620: The tenant management module sends the first information to the tenant service calling module in the tenant NMS of tenant 1.
[0313] In this example, if Tenant 1 has pre-negotiated service call permissions with the operator, and if Tenant 1 has a network operation and maintenance management need to access first information through the first service, Tenant 1 can successfully access the first information regardless of whether Tenant 1 has permission to call the first service. Furthermore, the first information is transmitted between the EMS and Tenant 1's tenant NMS without passing through the operator's NMS, thus ensuring the security of the first information.
[0314] Example 2: This example uses Figure 2 In the architecture shown, we take the example of tenant 2 who has not negotiated with the operator in advance about the right to call services. Figure 7 The flowchart shown in FIG. 1 specifically describes the steps in this example.
[0315] S700: Tenant 2 negotiates with the operator about the access rights of tenant 2 to information, and determines the access rights information of tenant 2.
[0316] In this example, tenant 2 and the operator can negotiate online or offline to determine tenant 2's access rights. For details, see Figure 5 The description of S500 in the illustrated embodiment will not be repeated here.
[0317] S701: The operator service calling module in the operator NMS obtains the access permission information of tenant 2.
[0318] Optionally, the operator service calling module may receive tenant 2's access permission information from a tenant service calling module in tenant 2's tenant NMS; alternatively, the network administrator of the operator's NMS may upload tenant 2's access permission information to the operator service calling module; or alternatively, when tenant 2 and the operator negotiate online, the operator service calling module may determine tenant 2's access permission information based on the negotiation results after the negotiation is complete. In short, this application does not limit the manner in which the operator service calling module obtains tenant 2's access permission information.
[0319] S702: The operator service calling module sends a tenant management request to the tenant management module in the EMS. The tenant management request includes the identifier of tenant 2 and the access permission information of tenant 2. The tenant management request is used to request the tenant management module to manage the permissions of tenant 2.
[0320] It should be noted that, when the access permission information of tenant 2 is stored in the EMS, the tenant management request may not include the access permission information of tenant 2.
[0321] For example, the access permission information of tenant 2 included in the tenant management request may be represented by the following code:
[0322] 'DataAccessPermission':
[0323] {
[0324] 'AlarmType':['Communications Alarm','Processing Error Alarm'],
[0325] 'PMkpi':['PacketDelay','RadioResourceUtilization']},
[0326] }
[0327] 'ResourceAccessPermission':
[0328] {
[0329] 'MOType': ['NRCellCU'],
[0330] 'MOIid': ['AABB-AB-BA']},
[0331] }
[0332] The above code indicates that tenant 2 can access the following information in the resource object instance with the class NRCellCU and the ID AABB-AB-BA:
[0333] 'Communications Alarm' (communication alarm data), 'Processing Error Alarm' (processing error alarm data), 'PacketDelay' (packet delay) and 'RadioResourceUtilization' (radio resource utilization).
[0334] S703: The tenant management module in the EMS creates a tenant rights object instance of tenant 2 according to the tenant management request.
[0335] Optionally, the tenant management module may maintain a tenant authority object model, such as Figure 4 The tenant management module can instantiate the tenant permission object model based on the access permission information of tenant 2, that is, assign the tenant's access permission information variable in the tenant permission object model to create a tenant permission object instance of tenant 2. The above process of creating a tenant permission object instance of tenant 1 can refer to Figure 3 The description of S301 and S302 in the illustrated embodiment will not be repeated here.
[0336] S704: After creating the tenant rights object instance for tenant 2, the tenant management module sends a tenant management response to the operator service call module in the operator NMS. The tenant management response is used to notify the result (whether the creation of the tenant rights object instance for tenant 2 is successful). The tenant management response may also include the identifier of tenant 2.
[0337] S705: When tenant 2 has a network operation and maintenance management requirement to access the first information, the tenant service calling module in tenant 2's tenant NMS verifies its own information access rights. If the verification is successful, the tenant service calling module sends the network operation and maintenance management requirement information to the operator service calling module in the operator NMS. The network operation and maintenance management requirement includes a first information parameter. The first information parameter is used to indicate the first information.
[0338] Optionally, the network operation and maintenance management requirement information may also include the identifier of tenant 2.
[0339] During the execution of S705, when the access permission information of tenant 2 is saved in the tenant service calling module, the tenant service calling module can verify whether the tenant service calling module has the permission to access the first information based on the access permission information, that is, determine whether the authorization information indicated by the access permission information contains the first information.
[0340] Subsequent steps S706-S713 are the same as steps S613-S620 in Example 1. Therefore, the specific processes can be referenced to each other and will not be repeated here. Among them, the operator service calling module has the authority to call all network operation and maintenance management services in the EMS. Therefore, before sending the service call request to the tenant management model, the operator service calling module can determine the first service required to access the first information based on the network operation and maintenance management requirement information received in S705.
[0341] In this example, if Tenant 2 does not have permission to invoke the service but needs to access the first information through network operation and maintenance management, Tenant 1 can invoke the corresponding service through the carrier's NMS and successfully access the first information. Furthermore, the first information is transmitted between the EMS and Tenant 1's NMS without passing through the carrier's NMS, thus ensuring its security.
[0342] In the embodiments provided above, the various schemes of the communication method provided in the embodiments of the present application are introduced from the perspective of each device itself and from the perspective of the interaction between each device. It is understandable that each device, such as the network element management device, the first network management device, and the second network management device, includes hardware structures and / or software modules corresponding to the execution of each function in order to implement the above functions. It should be readily appreciated by those skilled in the art that, in combination with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner where computer software drives hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present application. The following embodiments illustrate the functions of each device from the perspective of software modules and hardware structures.
[0343] Based on the same technical concept, the present application also provides a communication device, which can be applied to Figure 2 The network operation and maintenance architecture shown is used to implement the methods provided in the above embodiments and examples. Figure 8 As shown, the communication device 800 includes a communication unit 801 and a processing unit 802 .
[0344] The communication unit 801 is used to receive and send data. For example, the communication unit 801 can be implemented by a physical interface, a communication module, a communication interface, or an input / output interface. The communication device 800 can connect to a network cable or a cable through the communication unit 801 to establish a physical connection with other devices.
[0345] The communication device 800 is applied to Figure 2 The functions of the processing unit 802 of each device in the network operation and maintenance architecture are introduced.
[0346] In one embodiment, the communication device 800 is used to Figure 3 In the network element management device in the EMS in the embodiment shown, the processing unit 802 is configured to:
[0347] Obtaining service permission information of the target tenant; wherein the service permission information is used to indicate that the first network management device has permission to call the first service, and the first network management device is located in the network management system of the target tenant; obtaining access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information;
[0348] Receive an access request from the first network management device through the communication unit 801; wherein the access request includes a first information parameter, and the access request is used to request access to first information indicated by the first information parameter through the first service;
[0349] The first information is sent to the first network management device through the communication unit 801 according to the service authority information, the access authority information and the first information parameter.
[0350] Optionally, when obtaining the service permission information of the target tenant, the processing unit 802 is specifically configured to:
[0351] Receive service authority information from the first network management device via the communication unit 801; or
[0352] Receive service authority information from the second network management device via the communication unit 801; or
[0353] Get pre-configured service permission information.
[0354] Optionally, the processing unit 802 obtains the access permission information of the target tenant, including:
[0355] Receive access permission information from the first network management device via the communication unit 801; or
[0356] Receive access permission information from the second network management device via the communication unit 801; or
[0357] Get pre-configured access permission information.
[0358] Optionally, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0359] Optionally, the processing unit 802, when sending the first information to the first network management device according to the service authority information, the access authority information, and the first information parameter, is specifically configured to:
[0360] Verifying, based on the service authority information, that the first network management device has authority to invoke the first service;
[0361] Verifying, based on the access permission information, that the first network management device has permission to access the first information;
[0362] Invoking a first service based on a first information parameter to obtain first information indicated by the first information parameter;
[0363] The first information is sent to the first network management device through the communication unit 801.
[0364] Optionally, the access request also includes the identifier of the target tenant.
[0365] In one embodiment, the communication device 800 is used to Figure 3 In the illustrated embodiment, the processing unit 802 is located in the first network management device in the tenant NMS of the target tenant, and is configured to:
[0366] Sending the target tenant's service permission information to the network element management device through the communication unit 801; wherein the service permission information is used to indicate that the first network management device has the permission to call the first service;
[0367] Sending access permission information of the target tenant to the network element management device through the communication unit 801; wherein the access permission information is used to indicate that the first network device has permission to access the first information;
[0368] Sending an access request to the network element management device through the communication unit 801; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service;
[0369] The communication unit 801 receives first information from the network element management device.
[0370] Optionally, the first information includes first network operation and maintenance management data, and / or first network resource data.
[0371] Optionally, the access request also includes the identifier of the target tenant.
[0372] Optionally, the processing unit 802 is further configured to:
[0373] Before sending the access request to the network element management device through the communication unit 801, verifying that the first network management device has the authority to call the first service according to the service authority information;
[0374] According to the access permission information, it is verified that the first network management device has permission to access the first information.
[0375] In one embodiment, the communication device 800 is used to Figure 5 In the network element management device in the EMS in the embodiment shown, the processing unit 802 is configured to:
[0376] Obtaining access permission information of a target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information; the first network management device is located in the network management system of the target tenant;
[0377] Receiving the identifier of the target tenant and the first information parameter from the second network management device through the communication unit 801; the first information parameter is used to indicate the first information;
[0378] According to the access permission information, the identifier of the target tenant and the first information parameter, the first information indicated by the first information parameter is sent to the first network management device through the communication unit 801 .
[0379] Optionally, when receiving the identifier of the target tenant and the first information parameter from the second network management device through the communication unit 801, the processing unit 802 is specifically configured to:
[0380] Receive an access request from the second network management device through the communication unit 801, where the access request includes an identifier of a target tenant and a first information parameter; the access request is used to request access to first information indicated by the first information parameter through a first service;
[0381] The first network management device does not have the authority to call the first service; the second network management device has the authority to call the first service.
[0382] Optionally, the processing unit 802 is further configured to:
[0383] Instruction information is received from the second network management device through the communication unit 801, where the instruction information is used to instruct the first information to be sent to the first network management device.
[0384] Optionally, when obtaining the access permission information of the target tenant, the processing unit 802 is specifically configured to:
[0385] Receive access permission information from the first network management device via the communication unit 801; or
[0386] Receive access permission information from the second network management device via the communication unit 801; or
[0387] Get pre-configured access permission information.
[0388] Optionally, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0389] Optionally, the processing unit 802, when sending the first information indicated by the first information parameter to the first network management device according to the access permission information, the identifier of the target tenant, and the first information parameter, is specifically configured to:
[0390] Verifying, based on the target tenant's identifier and access permission information, that the first network management device has permission to access the first information;
[0391] Invoking a first service based on the first information parameter to obtain first information;
[0392] The first information is sent to the first network management device through the communication unit 801.
[0393] Optionally, the processing unit 802 is further configured to:
[0394] An access response is sent to the second network management device through the communication unit 801 , where the access response is used to indicate that the first service is successfully called.
[0395] In one embodiment, the communication device 800 is used to Figure 5 In the embodiment shown, in the second network management device located in the operator's NMS, the processing unit 802 is configured to:
[0396] Receive a first information parameter from a first network management device through the communication unit 801; wherein the first network management device is located in the network management system of the target tenant; and the first information parameter is used to indicate the first information;
[0397] The target tenant's identifier and the first information parameter are sent to the network element management device through the communication unit 801. The target tenant's identifier and the first information parameter are used to instruct the network element management device to send the first information indicated by the first information parameter to the first network management device.
[0398] Optionally, the processing unit 802 is further configured to:
[0399] The communication unit 801 receives the identifier of the target tenant from the first network management device.
[0400] Optionally, the processing unit 802, when sending the identifier of the target tenant and the first information parameter to the network element management device through the communication unit 801, is specifically configured to:
[0401] Sending an access request to the network management device through the communication unit 801, where the access request includes an identifier of the target tenant and a first information parameter; the access request is used to request access to the first information indicated by the first information parameter through the first service;
[0402] The first network management device does not have the authority to call the first service; the second network management device has the authority to call the first service.
[0403] Optionally, the processing unit 802 is further configured to:
[0404] The communication unit 801 sends instruction information to the network element management device, where the instruction information is used to instruct the first information to be sent to the first network management device.
[0405] Optionally, the processing unit 802 is further configured to:
[0406] Obtaining access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information;
[0407] The access permission information is sent to the network element management device via the communication unit 801 .
[0408] Optionally, when obtaining the access permission information of the target tenant, the processing unit 802 is specifically configured to:
[0409] Receive access permission information from the first network management device via the communication unit 801; or
[0410] Get pre-configured access permission information.
[0411] Optionally, the processing unit 802 is further configured to:
[0412] Before sending the identifier of the target tenant and the first information parameter to the network element management device through the communication unit 801, it is verified that the first network management device has the authority to access the first information according to the access permission information.
[0413] Optionally, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0414] Optionally, the processing unit 802 is further configured to:
[0415] An access response is received from the network element management device through the communication unit 801 , where the access response is used to indicate that the first service is successfully called.
[0416] In one embodiment, the communication device 800 is used to Figure 5 In the illustrated embodiment, in the first network management device located in the tenant NMS of the target tenant, the processing unit 802 is configured to:
[0417] Sending a first information parameter to the second network management device through the communication unit 801; wherein the first information parameter is used to indicate the first information;
[0418] The communication unit 801 receives first information from the network element management device.
[0419] Optionally, the processing unit 802 is further configured to:
[0420] The identifier of the target tenant is sent to the first network management device through the communication unit 801 .
[0421] Optionally, the processing unit 802 is further configured to:
[0422] Obtaining access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information;
[0423] The access permission information is sent to the second network management device via the communication unit 801 .
[0424] Optionally, when obtaining the access permission information of the target tenant, the processing unit 802 is specifically configured to:
[0425] Get pre-configured access permission information.
[0426] Optionally, the processing unit 802 is further configured to:
[0427] Before sending the first information parameter to the second network management device through the communication unit 801, it is verified that the first network management device has the authority to access the first information according to the access authority information.
[0428] Optionally, the first information includes: first network operation and maintenance management data, and / or first network resource data.
[0429] It should be noted that the division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0430] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0431] Based on the same technical concept, the embodiment of the present application also provides a communication device, which can be applied to Figure 2 In the network operation and maintenance architecture shown, the methods provided in the above embodiments and examples can be implemented, and the functions of the communication device 800 provided in the above embodiments can be realized. Figure 9 As shown, the communication device 900 includes: a communication interface 901, a processor 902, and a memory 903. The communication interface 901, the processor 902, and the memory 903 are interconnected.
[0432] Optionally, the communication interface 901, the processor 902, and the memory 903 are interconnected via a bus 904. The bus 904 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, Figure 9 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0433] The communication interface 901 is used to receive and send data and implement communication with other devices in the network operation and maintenance architecture. The communication interface 901 can be implemented through a physical interface, a communication module, or an input / output interface.
[0434] The processor 902 is configured to implement the methods provided in the above embodiments or examples.
[0435] In one embodiment, the communication device 900 is Figure 3 In the embodiment shown, the network element management device in the EMS, the processor 902, is configured to:
[0436] Obtaining service permission information of the target tenant; wherein the service permission information is used to indicate that the first network management device has permission to call the first service, and the first network management device is located in the network management system of the target tenant; obtaining access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information;
[0437] Receive an access request from the first network management device through the communication interface 901; wherein the access request includes a first information parameter, and the access request is used to request access to first information indicated by the first information parameter through the first service;
[0438] The first information is sent to the first network management device through the communication interface 901 according to the service authority information, the access authority information and the first information parameter.
[0439] In one embodiment, the communication device 900 is Figure 3 In the embodiment shown, the first network management device in the tenant NMS of the target tenant, the processor 902, is configured to:
[0440] Sending the target tenant's service permission information to the network element management device through the communication interface 901; wherein the service permission information is used to indicate that the first network management device has the permission to call the first service;
[0441] Sending access permission information of the target tenant to the network element management device through the communication interface 901; wherein the access permission information is used to indicate that the first network device has permission to access the first information;
[0442] Sending an access request to the network element management device through the communication interface 901; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service;
[0443] First information is received from the network element management device through the communication interface 901.
[0444] In one embodiment, the communication device 900 is Figure 5 In the embodiment shown, the network element management device in the EMS, the processor 902, is configured to:
[0445] Obtaining access permission information of a target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access the first information; the first network management device is located in the network management system of the target tenant;
[0446] Receiving the identifier of the target tenant and the first information parameter from the second network management device through the communication interface 901; the first information parameter is used to indicate the first information;
[0447] According to the access permission information, the identifier of the target tenant and the first information parameter, the first information indicated by the first information parameter is sent to the first network management device through the communication interface 901 .
[0448] In one embodiment, the communication device 900 is Figure 5 In the embodiment shown, the second network management device, processor 902, located in the operator's NMS is configured to:
[0449] Receiving a first information parameter from a first network management device through a communication interface 901; wherein the first network management device is located in a network management system of a target tenant; and the first information parameter is used to indicate the first information;
[0450] The target tenant's identifier and the first information parameter are sent to the network element management device through the communication interface 901. The target tenant's identifier and the first information parameter are used to instruct the network element management device to send the first information indicated by the first information parameter to the first network management device.
[0451] In one embodiment, the communication device 900 is Figure 5 In the illustrated embodiment, the first network management device, processor 902, located in the tenant NMS of the target tenant is configured to:
[0452] Sending a first information parameter to the second network management device through the communication interface 901; wherein the first information parameter is used to indicate the first information;
[0453] First information is received from the network element management device through the communication interface 901.
[0454] The specific functions of the processor 902 can be referred to the description in the above embodiments and will not be repeated here.
[0455] The processor 902 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor 902 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. When implementing the above functions, the processor 902 may be implemented through hardware, or may also execute corresponding software implementations through hardware.
[0456] Memory 903 is used to store program instructions, etc. Specifically, program instructions may include program code, which includes computer operating instructions. Memory 903 may include random access memory (RAM) or non-volatile memory (non-volatile memory), such as at least one disk storage device. Processor 902 executes the program instructions stored in memory 903 to implement the above functions, thereby implementing the methods provided in the above embodiments.
[0457] Based on the above embodiments, an embodiment of the present application further provides a computer program, which, when executed on a computer, enables the computer to execute the method provided in the above embodiments.
[0458] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the computer executes the method provided in the above embodiments.
[0459] The storage medium may be any available medium that can be accessed by a computer. By way of example and not limitation, computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer.
[0460] Based on the above embodiments, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory to implement the method provided in the above embodiments.
[0461] Based on the above embodiments, embodiments of the present application provide a chip system, which includes a processor for supporting a computer device to implement the functions involved in the communication device in the above embodiments. In one possible design, the chip system also includes a memory for storing the necessary programs and data for the computer device. The chip system can be composed of a chip or can include a chip and other discrete devices.
[0462] In summary, embodiments of the present application provide a communication method, apparatus, and device. Through this method, when a target tenant has a network operation and maintenance management requirement to access first information through a first service, the target tenant's NMS can successfully access the first information, regardless of whether the target tenant has permission to invoke the first service. Furthermore, the first information is transmitted between the EMS and the target tenant's tenant NMS without passing through the operator's NMS, thereby ensuring the security of the first information.
[0463] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0464] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0465] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0466] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0467] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A communication method, applied to a network element management device, characterized in that: The method comprises: Obtaining service permission information of a target tenant; wherein the service permission information is used to indicate that a first network management device has permission to call a first service, the first network management device is located in a network management system of the target tenant, and the network management system of the target tenant is deployed and managed by the target tenant; the network element management device is located in a network element management system, and the network element management system is used to provide at least one network operation and maintenance management service; the at least one network operation and maintenance management service includes the first service; Obtaining access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access first information; the first information is information in the private network of the target tenant; receiving an access request from the first network management device; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service; The first information is sent to the first network management device according to the service authority information, the access authority information and the first information parameter.
2. The method according to claim 1, wherein Obtain the target tenant's service permission information, including: receiving the service authority information from the first network management device; or receiving the service authority information from a second network management device; or Obtain the pre-configured service permission information.
3. The method according to claim 1, wherein Obtaining access rights information for the target tenant, including: receiving the access permission information from the first network management device; or receiving the access permission information from a second network management device; or Acquire the pre-configured access permission information.
4. The method according to any one of claims 1 to 3, wherein The first information includes: first network operation and maintenance management data, and / or first network resource data.
5. The method according to any one of claims 1 to 3, wherein Sending the first information to the first network management device according to the service authority information, the access authority information, and the first information parameter includes: Verifying, based on the service authority information, that the first network management device has authority to invoke the first service; Verifying, based on the access permission information, that the first network management device has permission to access the first information; calling the first service based on the first information parameter to obtain the first information indicated by the first information parameter; The first information is sent to the first network management device.
6. The method according to any one of claims 1 to 3, wherein: The access request also includes the identifier of the target tenant.
7. A communication method, applied to a first network management device, wherein the first network management device is located in a network management system of a target tenant, characterized in that: The method comprises: Sending service permission information of the target tenant to a network element management device; wherein the service permission information is used to indicate that the first network management device has permission to call the first service, and the network management system of the target tenant is deployed and managed by the target tenant; the network element management device is located in the network element management system, and the network element management system is used to provide at least one network operation and maintenance management service; the at least one network operation and maintenance management service includes the first service; Sending access permission information of the target tenant to the network element management device; wherein the access permission information is used to indicate that the first network device has permission to access first information; the first information is information in the private network of the target tenant; Sending an access request to the network element management device; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service; The first information is received from the network element management device.
8. The method according to claim 7, wherein The first information includes first network operation and maintenance management data and / or first network resource data.
9. The method according to claim 7 or 8, wherein The access request also includes the identifier of the target tenant.
10. The method according to claim 7 or 8, characterized in that Before sending the access request to the network element management device, the method further includes: Verifying, based on the service authority information, that the first network management device has authority to invoke the first service; According to the access permission information, it is verified that the first network management device has permission to access the first information.
11. A communication method, applied to a network element management device, characterized in that: The method comprises: Obtaining access permission information for a target tenant; wherein the access permission information is used to indicate that a first network management device has permission to access first information; the first network management device is located in a network management system of the target tenant, and the network management system of the target tenant is deployed and managed by the target tenant; the network element management device is located in a network element management system, and the network element management system is used to provide at least one network operation and maintenance management service; and the first information is information in the private network of the target tenant; An access request is received from a second network management device, where the access request includes an identifier of the target tenant and a first information parameter; the first information parameter is used to indicate the first information, and the access request is used to request access to the first information indicated by the first information parameter through a first service; the at least one network operation and maintenance management service includes the first service; the second network management device is located in a network management system of an operator, and the network management system of the operator is deployed and managed by the operator; the first network management device does not have permission to call the first service; and the second network management device has permission to call the first service; The first information indicated by the first information parameter is sent to the first network management device according to the access permission information, the identifier of the target tenant, and the first information parameter.
12. The method according to claim 11, wherein The method further comprises: Instruction information is received from the second network management device, where the instruction information is used to instruct the first information to be sent to the first network management device.
13. The method according to claim 11, wherein Obtain access rights information for the target tenant, including: receiving the access permission information from the first network management device; or receiving the access permission information from a second network management device; or Acquire the pre-configured access permission information.
14. The method according to any one of claims 11 to 13, wherein: The first information includes: first network operation and maintenance management data, and / or first network resource data.
15. The method according to any one of claims 11 to 13, wherein: The step of sending the first information indicated by the first information parameter to the first network management device according to the access permission information, the identifier of the target tenant, and the first information parameter includes: Verifying, based on the identifier of the target tenant and the access permission information, that the first network management device has permission to access the first information; Invoking a first service based on the first information parameter to obtain the first information; The first information is sent to the first network management device.
16. The method according to any one of claims 11 to 13, wherein: The method further comprises: An access response is sent to the second network management device, where the access response is used to indicate that the first service is successfully called.
17. A communication device, applied to a network element management device, characterized in that: The device comprises: a communication unit for receiving and sending data; A processing unit for: Obtaining service permission information of a target tenant; wherein the service permission information is used to indicate that a first network management device has permission to call a first service, the first network management device is located in a network management system of the target tenant, and the network management system of the target tenant is deployed and managed by the target tenant; the network element management device is located in a network element management system, and the network element management system is used to provide at least one network operation and maintenance management service; the at least one network operation and maintenance management service includes the first service; Obtaining access permission information of the target tenant; wherein the access permission information is used to indicate that the first network management device has permission to access first information; the first information is information in the private network of the target tenant; receiving an access request from the first network management device through the communication unit; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service; The first information is sent to the first network management device through the communication unit according to the service authority information, the access authority information and the first information parameter.
18. The device according to claim 17, wherein The processing unit is specifically configured to: receiving the service authority information from the first network management device through the communication unit; or receiving the service authority information from a second network management device through the communication unit; or Obtain the pre-configured service permission information.
19. The device according to claim 17, wherein The processing unit, when obtaining the access permission information of the target tenant, includes: receiving the access permission information from the first network management device through the communication unit; or receiving the access permission information from a second network management device through the communication unit; or Acquire the pre-configured access permission information.
20. The device according to any one of claims 17 to 19, characterized in that The first information includes: first network operation and maintenance management data, and / or first network resource data.
21. The device according to any one of claims 17 to 19, characterized in that The processing unit is configured to, when sending the first information to the first network management device according to the service authority information, the access authority information, and the first information parameter, specifically: Verifying, based on the service authority information, that the first network management device has authority to invoke the first service; Verifying, based on the access permission information, that the first network management device has permission to access the first information; calling the first service based on the first information parameter to obtain the first information indicated by the first information parameter; The first information is sent to the first network management device through the communication unit.
22. The device according to any one of claims 17 to 19, characterized in that The access request also includes the identifier of the target tenant.
23. A communication device, applied to a first network management device, wherein the first network management device is located in a network management system of a target tenant, characterized in that: The device comprises: a communication unit for receiving and sending data; A processing unit for: sending, via the communication unit, service permission information of the target tenant to a network element management device; wherein the service permission information is used to indicate that the first network management device has permission to invoke a first service, and the network management system of the target tenant is deployed and managed by the target tenant; the network element management device is located in a network element management system, and the network element management system is used to provide at least one network operation and maintenance management service; and the at least one network operation and maintenance management service includes the first service; Sending access permission information of the target tenant to the network element management device through the communication unit; wherein the access permission information is used to indicate that the first network device has permission to access first information; the first information is information in the private network of the target tenant; Sending an access request to the network element management device through the communication unit; wherein the access request includes a first information parameter, and the access request is used to request access to the first information indicated by the first information parameter through the first service; The first information is received from the network element management device through the communication unit.
24. The device according to claim 23, wherein The first information includes first network operation and maintenance management data and / or first network resource data.
25. The device according to claim 23 or 24, characterized in that The access request also includes the identifier of the target tenant.
26. The device according to claim 23 or 24, characterized in that The processing unit is further configured to: Before sending the access request to the network element management device through the communication unit, verifying, based on the service authority information, that the first network management device has the authority to call the first service; According to the access permission information, it is verified that the first network management device has permission to access the first information.
27. A communication device, applied to a network element management device, characterized in that: The device comprises: a communication unit for receiving and sending data; A processing unit for: Obtaining access permission information for a target tenant; wherein the access permission information is used to indicate that a first network management device has permission to access first information; the first network management device is located in a network management system of the target tenant, and the network management system of the target tenant is deployed and managed by the target tenant; the network element management device is located in a network element management system, and the network element management system is used to provide at least one network operation and maintenance management service; and the first information is information in the private network of the target tenant; An access request is received from a second network management device via the communication unit, wherein the access request includes an identifier of the target tenant and a first information parameter; the first information parameter is used to indicate the first information, and the access request is used to request access to the first information indicated by the first information parameter through a first service; the at least one network operation and maintenance management service includes the first service; the second network management device is located in a network management system of an operator, and the network management system of the operator is deployed and managed by the operator; wherein the first network management device does not have permission to call the first service; and the second network management device has permission to call the first service; The first information indicated by the first information parameter is sent to the first network management device through the communication unit according to the access permission information, the identifier of the target tenant, and the first information parameter.
28. The device according to claim 27, wherein The processing unit is further configured to: Instruction information is received from the second network management device through the communication unit, where the instruction information is used to instruct sending the first information to the first network management device.
29. The device according to claim 27, wherein The processing unit is specifically configured to, when obtaining the access permission information of the target tenant: receiving the access permission information from the first network management device through the communication unit; or receiving the access permission information from a second network management device through the communication unit; or Acquire the pre-configured access permission information.
30. The device according to any one of claims 27 to 29, characterized in that The first information includes: first network operation and maintenance management data, and / or first network resource data.
31. The device according to any one of claims 27 to 29, characterized in that The processing unit is configured to, when sending the first information indicated by the first information parameter to the first network management device according to the access permission information, the identifier of the target tenant, and the first information parameter, specifically: Verifying, based on the identifier of the target tenant and the access permission information, that the first network management device has permission to access the first information; Invoking a first service based on the first information parameter to obtain the first information; The first information is sent to the first network management device through the communication unit.
32. The device according to any one of claims 27 to 29, characterized in that The processing unit is further configured to: An access response is sent to the second network management device through the communication unit, where the access response is used to indicate that the first service is successfully called.
33. A communication device, characterized in that: include: Communication interface for receiving and sending data; Memory, used to store program instructions and data; A processor is configured to read program instructions and data in the memory and implement the method according to any one of claims 1 to 16 through the communication interface.
34. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the method according to any one of claims 1 to 16.